IOC Report
http://ZRsivJd9eJZYI6hYZjp4HaBmXIoenPbMYtTOvHDYBU1biEGhdygsHh9L2pifi7NsFd8FFuTKZy7oRJyRVkGRbLUy69jTFmb4TriJxwINiudeD8EFPxuOWL6Gz7Y1Q_Nhu9YF0CDO1a9GpmuT_JaBulU9ZlgG0XUtjfn6OtQHLGfj_7jywaNlGcgZDMEl6kwUBbnirb_9br0X5shiNiwX4VUZDcx4TYOb3sM2wpz2yfKg1MgxZ1YJL-O2Cgk4bYCNefiWCiFF6AWzX5TW-0MLSz0G_WzeGmbrF2OdN

loading gif

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1692,i,17621815830497467087,13166226885346699693,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://ZRsivJd9eJZYI6hYZjp4HaBmXIoenPbMYtTOvHDYBU1biEGhdygsHh9L2pifi7NsFd8FFuTKZy7oRJyRVkGRbLUy69jTFmb4TriJxwINiudeD8EFPxuOWL6Gz7Y1Q_Nhu9YF0CDO1a9GpmuT_JaBulU9ZlgG0XUtjfn6OtQHLGfj_7jywaNlGcgZDMEl6kwUBbnirb_9br0X5shiNiwX4VUZDcx4TYOb3sM2wpz2yfKg1MgxZ1YJL-O2Cgk4bYCNefiWCiFF6AWzX5TW-0MLSz0G_WzeGmbrF2OdN0t4ZaqmVPDCNASJelVCumDRTBmHv8sIc2WmxIRpA8qkLj06C6cWMpqHsEj6IYHXdzG6zw8bE0uRgAFYaztmMGMfBs5Ou90QtGia25xnEYig2RimxQAVmP4oxXMlmRiYxndT0-RDxmvx3k_BuoWxzTrt35UuefUC2PNrEt7DqDzvymqQE8az3WUFcrdKVEpRTdUH4zq-nCBg0JhgBMYtqLppPzNE5vLHgHwvB5J4iGlrnsWA2iGo-KimvthNAA96Mjj0vhzXJq6aZZWcezookCdv6cRGm76TFE-eBVXjDcNWZ7pTeVhlZVBE-nWHFXCW5epYz-roVt5e_k5gOZmbC1Bv1z1RMTAkxNK3N4YKGvvwCV3dmuNIncEfrV6CcQrEh_k5sZC-9S7Jgk7ifHL0ufBo6awzBPiJsKSokti992kEAPGlVwMxbWJNcjKuJs48fsvKjXzK1lPPLeIx_w3cfpg11UXMUN4_WTXdDqXSCHVDy0gQmAlEOodYXzVL27FKnQEDckRfNx_GFF1zc1PYklLH3ygh_zwV5b1zh_JD4Q2xICJySXrTX45B_ZAjPhU2FM8IsVbeHGqNNdLqW7xePm48sx8ni2LO4ZfADTbQfDhPASjRLJ5-RvfeQZIj2SYlR&state=18471666-cc8e-484a-a9f8-e361977136bc&session_state=3961325a-3a84-4a62-86ce-1defb25719b4#"

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.214.172
google.com
64.233.185.139
www.google.com
64.233.177.106
fp2e7a.wpc.phicdn.net
192.229.211.108

IPs

IP
Domain
Country
Malicious
64.233.177.106
www.google.com
United States
239.255.255.250
unknown
Reserved
192.168.2.6
unknown
unknown