IOC Report
https://emails.microsoft.com/dc/pTEFlGZ9Q3ITrVt7_I2wJfSaXP4fVmu5GQerBk9DuUvl5x7Y3oenMbTn6pJFU_xLXduQCRntWDUo2iRUxZiFdgMv1eBcbMLxa9GOqZ80Pwgqgg5sHNtbdPG0VlNGeOUH/MTU3LUdRRS0zODIAAAGSjMBCixNjjpdbsch2hBISSU_d4RDaOOPgcKA4fi0zZKziDrpeajknElEVFX3y46dg33OHqLM=

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 40
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 41
PDF document, version 1.7 (zip deflate encoded)
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2084 --field-trial-handle=1968,i,7431271362146528332,18172803629473885196,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://emails.microsoft.com/dc/pTEFlGZ9Q3ITrVt7_I2wJfSaXP4fVmu5GQerBk9DuUvl5x7Y3oenMbTn6pJFU_xLXduQCRntWDUo2iRUxZiFdgMv1eBcbMLxa9GOqZ80Pwgqgg5sHNtbdPG0VlNGeOUH/MTU3LUdRRS0zODIAAAGSjMBCixNjjpdbsch2hBISSU_d4RDaOOPgcKA4fi0zZKziDrpeajknElEVFX3y46dg33OHqLM="

URLs

Name
IP
Malicious
https://emails.microsoft.com/dc/pTEFlGZ9Q3ITrVt7_I2wJfSaXP4fVmu5GQerBk9DuUvl5x7Y3oenMbTn6pJFU_xLXduQCRntWDUo2iRUxZiFdgMv1eBcbMLxa9GOqZ80Pwgqgg5sHNtbdPG0VlNGeOUH/MTU3LUdRRS0zODIAAAGSjMBCixNjjpdbsch2hBISSU_d4RDaOOPgcKA4fi0zZKziDrpeajknElEVFX3y46dg33OHqLM=
http://cipa.jp/exif/1.0/
unknown
http://doc.exr-io.com/metadata/1.0/attribute
unknown
http://doc.exr-io.com/metadata/1.0/
unknown
http://doc.exr-io.com/metadata/1.0/part
unknown

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.210.172
www.google.com
142.250.105.104
fp2e7a.wpc.phicdn.net
192.229.211.108
mkto-sj180011.com
104.17.71.206

IPs

IP
Domain
Country
Malicious
239.255.255.250
unknown
Reserved
104.17.71.206
mkto-sj180011.com
United States
192.168.2.18
unknown
unknown
192.168.2.6
unknown
unknown
142.250.105.104
www.google.com
United States

DOM / HTML

URL
Malicious
https://clouddamcdnprodep.azureedge.net/gdc/gdcTUQfwK/original?ocid=eml_pg404347_gdc_comm_mw&mkt_tok=MTU3LUdRRS0zODIAAAGSjMBCi2CJv2uc8K-qobPwZVcCkpTFsYIgVOJ0j-QKAQBFYnwQ5edYwqZGCxukjoCDuVav_PV2seur8BBnD2o5pxtlRC9zGamfyex8_tf-z4dGEEbocSLxcIsZ