IOC Report
https://d.adroll.com/ipixel/QOMWAZM2G5FXXNFT6DGH3J/CTTD5UQGMJF53KNMVQ2V6A?name=9b9a30a6

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 41
GIF image data, version 89a, 1 x 1
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2288 --field-trial-handle=2204,i,15302550918165274945,8975374887919318014,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://d.adroll.com/ipixel/QOMWAZM2G5FXXNFT6DGH3J/CTTD5UQGMJF53KNMVQ2V6A?name=9b9a30a6"

URLs

Name
IP
Malicious
https://d.adroll.com/ipixel/QOMWAZM2G5FXXNFT6DGH3J/CTTD5UQGMJF53KNMVQ2V6A?name=9b9a30a6
https://d.adroll.com/favicon.ico
34.200.189.226
https://d.adroll.com/ipixel/QOMWAZM2G5FXXNFT6DGH3J/CTTD5UQGMJF53KNMVQ2V6A?name=9b9a30a6

Domains

Name
IP
Malicious
adserver-vpc-alb-0-2075095491.us-west-2.elb.amazonaws.com
44.232.82.158
bg.microsoft.map.fastly.net
199.232.214.172
www.google.com
64.233.177.106
adserver-vpc-alb-1-2048135467.us-east-1.elb.amazonaws.com
34.200.189.226
fp2e7a.wpc.phicdn.net
192.229.211.108
d.adroll.com
unknown

IPs

IP
Domain
Country
Malicious
64.233.177.106
www.google.com
United States
0.0.0.0
unknown
unknown
239.255.255.250
unknown
Reserved
192.168.2.4
unknown
unknown
34.200.189.226
adserver-vpc-alb-1-2048135467.us-east-1.elb.amazonaws.com
United States
192.168.2.6
unknown
unknown
44.232.82.158
adserver-vpc-alb-0-2075095491.us-west-2.elb.amazonaws.com
United States

DOM / HTML

URL
Malicious
https://d.adroll.com/ipixel/QOMWAZM2G5FXXNFT6DGH3J/CTTD5UQGMJF53KNMVQ2V6A?name=9b9a30a6