IOC Report
https://rosemarychill.pro/23d80j2d/qwd13d8jqd/t2z5gydm.mp3

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 40
Audio file with ID3 version 2.4.0, contains: MPEG ADTS, layer III, v1, 56 kbps, 44.1 kHz, Monaural
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2232 --field-trial-handle=2028,i,2747704083434283978,9390215517206140616,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://rosemarychill.pro/23d80j2d/qwd13d8jqd/t2z5gydm.mp3"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5452 --field-trial-handle=2028,i,2747704083434283978,9390215517206140616,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8

URLs

Name
IP
Malicious
https://rosemarychill.pro/23d80j2d/qwd13d8jqd/t2z5gydm.mp3
https://rosemarychill.pro/23d80j2d/qwd13d8jqd/t2z5gydm.mp3
https://a.nel.cloudflare.com/report/v4?s=%2BfMLj%2BUlTqK5%2FQxCAeBbWEigkqCzv0CdlOUX7H2X8fFA0qlp2evIo5YGp8%2FYrrtZFLHLfBaZjXOPK2Z%2FMoM%2Bztg2NDe7Ei4ssDAycyAIIOuSa8pG9FSE3DDVVxK%2BgIW%2BBkl7nQ%3D%3D
35.190.80.1

Domains

Name
IP
Malicious
a.nel.cloudflare.com
35.190.80.1
rosemarychill.pro
104.21.25.221
www.google.com
172.217.2.196
fp2e7a.wpc.phicdn.net
192.229.211.108

IPs

IP
Domain
Country
Malicious
239.255.255.250
unknown
Reserved
172.217.2.196
www.google.com
United States
35.190.80.1
a.nel.cloudflare.com
United States
192.168.2.4
unknown
unknown
104.21.25.221
rosemarychill.pro
United States

DOM / HTML

URL
Malicious
https://rosemarychill.pro/23d80j2d/qwd13d8jqd/t2z5gydm.mp3