IOC Report
https://www.dwnxiiwurwodzaaaqie8.info/

loading gif

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2052 --field-trial-handle=1976,i,10302743457371201948,177399357409615086,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.dwnxiiwurwodzaaaqie8.info/"

URLs

Name
IP
Malicious
https://www.dwnxiiwurwodzaaaqie8.info/
https://www.dwnxiiwurwodzaaaqie8.info/
172.67.139.85
https://vlaamsedocumentenonline.info/v/log.php
172.67.189.235
https://a.nel.cloudflare.com/report/v4?s=BwyaX6zN6FAHKrQx%2BZP8OMY3n6Yb1kwpQKGt9zp02KuCX5FiMElbOsLlMhNS5VA1O%2Bl3557XwFgon4o%2B4Xa1GKpMMmiO29NMCZ79N6vHdy7sT5bjIwZQ8lLbWUmppKBYMzOdhCsY01BQqGGQS5um
35.190.80.1

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.210.172
a.nel.cloudflare.com
35.190.80.1
www.google.com
74.125.136.147
fp2e7a.wpc.phicdn.net
192.229.211.108
www.dwnxiiwurwodzaaaqie8.info
172.67.139.85
vlaamsedocumentenonline.info
172.67.189.235
time.windows.com
unknown

IPs

IP
Domain
Country
Malicious
239.255.255.250
unknown
Reserved
172.67.189.235
vlaamsedocumentenonline.info
United States
192.168.2.7
unknown
unknown
35.190.80.1
a.nel.cloudflare.com
United States
74.125.136.147
www.google.com
United States
172.67.139.85
www.dwnxiiwurwodzaaaqie8.info
United States