IOC Report
https://link.sbstck.com/redirect/306ab949-0275-40e7-bea9-4cb193d7dc25?j=eyJ1IjoiM3FrZmpsIn0%5B.%5DTLODH25e71uRDLQmwzZN0JdYi2ahQdRGkTm6ooL-HuQ

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 38
HTML document, ASCII text, with very long lines (622), with no line terminators
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2204 --field-trial-handle=2008,i,14923606894730561617,12323826205918887687,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://link.sbstck.com/redirect/306ab949-0275-40e7-bea9-4cb193d7dc25?j=eyJ1IjoiM3FrZmpsIn0%5B.%5DTLODH25e71uRDLQmwzZN0JdYi2ahQdRGkTm6ooL-HuQ"

URLs

Name
IP
Malicious
https://link.sbstck.com/redirect/306ab949-0275-40e7-bea9-4cb193d7dc25?j=eyJ1IjoiM3FrZmpsIn0%5B.%5DTLODH25e71uRDLQmwzZN0JdYi2ahQdRGkTm6ooL-HuQ
https://www.whtenvlpe.com/acTcl2kTmPSJi_Ld_mhpL5dNumT258E0ztzYJGo7sYTHmy1SnIHoHTr_lyuA2BZnhF49nvpBtTPseiLflrqOEA~~/17?utm_source=substack&utm_medium=email
216.107.139.70
https://link.sbstck.com/redirect/306ab949-0275-40e7-bea9-4cb193d7dc25?j=eyJ1IjoiM3FrZmpsIn0%5B.%5DTLODH25e71uRDLQmwzZN0JdYi2ahQdRGkTm6ooL-HuQ
104.21.26.123
https://t4.ignitevoyage.com/aff_c?offer_id=437&aff_id=1677&aff_sub=us-dh&aff_sb3=822225&aff_click_id=758706323
104.21.12.162
https://www.whtenvlpe.com/acTcl2kTmPSJi_Ld_mhpL5dNumT258E0ztzYJGo7sYTHmy1SnIHoHTr_lyuA2BZnhF49nvpBtT
unknown

Domains

Name
IP
Malicious
www.whtenvlpe.com
216.107.139.70
bg.microsoft.map.fastly.net
199.232.214.172
google.com
142.251.2.101
www.google.com
142.250.141.104
link.sbstck.com
104.21.26.123
t4.ignitevoyage.com
104.21.12.162
1713954478866.com
unknown

IPs

IP
Domain
Country
Malicious
104.21.12.162
t4.ignitevoyage.com
United States
192.168.2.7
unknown
unknown
192.168.2.6
unknown
unknown
239.255.255.250
unknown
Reserved
142.250.141.104
www.google.com
United States
216.107.139.70
www.whtenvlpe.com
United States
104.21.26.123
link.sbstck.com
United States