IOC Report
https://2h.ae/HWtB

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 41
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 42
ASCII text, with no line terminators
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1952,i,7220497278789268327,86842902818398423,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://2h.ae/HWtB"

URLs

Name
IP
Malicious
https://2h.ae/HWtB
malicious
https://2h.ae/HWtB
172.67.205.158
malicious
https://dgt.lat/favicon.ico
104.21.56.244
https://a.nel.cloudflare.com/report/v4?s=T1G3MdaVaNfmcutBNGcnKEMa4t04PtBGAK4fCxv6aDPlONIspAQ4S7CJlD3qzK8ONufr9brsP00Vsffg85oiAYa1id%2Fw5%2FbvZaCpVOh5c2Rg4WQGaZtZkX2q
35.190.80.1
https://a.nel.cloudflare.com/report/v4?s=vWtfxXmzRTuAWAaU3TcHGjdCOP8h9jp%2BPGFqoLu5G6MVoysJa%2FoonHBct64fEVzHi8uyaWSbomlO0htqkfbtxzSJmFT165GKM%2FwV7ozoT7k6WWJ2yEPxAbrW
35.190.80.1
https://dgt.lat/entra

Domains

Name
IP
Malicious
a.nel.cloudflare.com
35.190.80.1
dgt.lat
104.21.56.244
www.google.com
142.250.141.104
2h.ae
172.67.205.158
fp2e7a.wpc.phicdn.net
192.229.211.108

IPs

IP
Domain
Country
Malicious
239.255.255.250
unknown
Reserved
104.21.56.244
dgt.lat
United States
35.190.80.1
a.nel.cloudflare.com
United States
142.250.141.104
www.google.com
United States
192.168.2.4
unknown
unknown
172.67.205.158
2h.ae
United States
192.168.2.5
unknown
unknown

DOM / HTML

URL
Malicious
https://dgt.lat/entra