IOC Report
https://6125106173.docs.google.com/drawings/d/1skxkdfIAmUOzY8P2mw2fAOuoLVEquwg5wjlqsJfNzHs/preview

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 53
ASCII text, with very long lines (10838)
downloaded
Chrome Cache Entry: 54
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=1, orientation=upper-left], baseline, precision 8, 1093x258, components 3
downloaded
Chrome Cache Entry: 55
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 56
ASCII text, with very long lines (3027)
downloaded
Chrome Cache Entry: 57
MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
downloaded
Chrome Cache Entry: 58
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=1, orientation=upper-left], baseline, precision 8, 1093x258, components 3
dropped
Chrome Cache Entry: 59
Web Open Font Format (Version 2), TrueType, length 15344, version 1.0
downloaded
Chrome Cache Entry: 60
PNG image data, 400 x 400, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 61
PNG image data, 400 x 400, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 62
MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
dropped

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2144 --field-trial-handle=1712,i,15347724259960520691,9144545762647224658,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http:///
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://%3cfnc1%3e(5)%3cfnc1%3e(%02)/
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1812 --field-trial-handle=2076,i,12905221470938519090,15953591901878050253,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1916 --field-trial-handle=1996,i,5466060823698890482,1351892748397088521,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://6125106173.docs.google.com/drawings/d/1skxkdfIAmUOzY8P2mw2fAOuoLVEquwg5wjlqsJfNzHs/preview"

URLs

Name
IP
Malicious
https://6125106173.docs.google.com/drawings/d/1skxkdfIAmUOzY8P2mw2fAOuoLVEquwg5wjlqsJfNzHs/preview
https://www.google.com/async/ddljson?async=ntp:2
142.250.64.196
https://www.google.com/sorry/index?continue=https://www.google.com/async/newtab_ogb%3Fhl%3Den-US%26async%3Dfixed:0&hl=en-US&q=EgRmgZjcGKHVrrEGIjCGTIFNgwCqg6KBz5rBbLFCyjWo_wrNhn_m27xtdwcxgTfsjn6kArLmSGZDuCewgJQyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM
142.250.64.196
https://lh7-us.googleusercontent.com/drawings/AFUiIQ8MRM9WEJ3IbNxbP-A6EFAove5OIO45p7cWz5_F8KVL3_ECysjZGhCu5hPbIy8CoQUWblDdNlIn_h_dppVwHto9P_HNaXSxXliaIeHW7bvAzszH2oFzIVD2iTxLEeGz0dMx8kYwhjGArg-b7Z6wGkilrPj4Zx6ZZ2eEudTZvLs
142.250.217.225
https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw
142.250.64.196
https://6125106173.docs.google.com/drawings/d/1skxkdfIAmUOzY8P2mw2fAOuoLVEquwg5wjlqsJfNzHs/preview
173.194.210.189
https://docs.google.com/static/drawings/client/js/2099830619-preview_core.js
172.217.2.206
https://www.google.com/sorry/index?continue=https://www.google.com/async/newtab_promos&q=EgRmgZjcGKHVrrEGIjCAwqd5aHTOlyUE6jH5e1xF0ingjmOr7JoUxUSGQTlQ_ULyex8YCxJ6Uqj_J6tA-uMyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM
142.250.64.196
https://lh7-us.googleusercontent.com/drawings/AFUiIQ_VXsB-s8LtgOBeLC1lfL44D-LruraHz4l-xbvB-2a7pqISDjOot3qHG83vA4RN62hT3c6FUYdMToQC8IsqB2381mPM7dEFRltBm_KpuZg7If7SlgXeRMqLtlPiPH1kQ9ekIDTG9DD1k5s5wpFruxKX453TgljRIz3EfpsXSdo
142.250.217.225
https://www.google.com/async/newtab_promos
142.250.64.196
https://www.google.com/async/newtab_ogb?hl=en-US&async=fixed:0
142.250.64.196
https://docs.google.com/static/drawings/client/css/4013897977-preview_css_ltr.css
172.217.2.206
https://www.google.com/sorry/index?continue=https://www.google.com/async/ddljson%3Fasync%3Dntp:2&q=EgRmgZjcGKHVrrEGIjAM6pg0sk4j-FMPZ_hJZJKTKDM0SVUw_6TyPx8OtG0dA6bxJcOs3Tnu_R8uc-avnL0yAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM
142.250.64.196
https://docs.google.com/drawings/d/1skxkdfIAmUOzY8P2mw2fAOuoLVEquwg5wjlqsJfNzHs/preview
https://uberproxy-pen-redirect.corp.google.com/uberproxy/pen?url=
unknown
There are 4 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
docs.google.com
172.217.2.206
browserchannel-sites.l.google.com
173.194.210.189
www.google.com
142.250.64.196
googlehosted.l.googleusercontent.com
142.250.217.225
6125106173.docs.google.com
unknown
lh7-us.googleusercontent.com
unknown

IPs

IP
Domain
Country
Malicious
173.194.210.189
browserchannel-sites.l.google.com
United States
192.168.2.4
unknown
unknown
192.168.2.5
unknown
unknown
142.250.64.196
www.google.com
United States
239.255.255.250
unknown
Reserved
142.250.217.225
googlehosted.l.googleusercontent.com
United States
142.250.64.193
unknown
United States
172.217.2.206
docs.google.com
United States

DOM / HTML

URL
Malicious
https://docs.google.com/drawings/d/1skxkdfIAmUOzY8P2mw2fAOuoLVEquwg5wjlqsJfNzHs/preview