IOC Report
https://gist.github.com/Tantalor93/6c5baab344acf237e72b231d50408f4a/raw/%207aa875ebcd3819772d0f1d36100c19fe3c786cd7/top-1m

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 49
ASCII text, with very long lines (5296)
downloaded
Chrome Cache Entry: 50
ASCII text, with no line terminators
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http:///
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://%3cfnc1%3e(%05)/
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2292 --field-trial-handle=2236,i,11054285937259490056,7033709406176175706,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2152 --field-trial-handle=1952,i,1702136743850697031,13245467354693393187,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=860 --field-trial-handle=2008,i,12349818873830694159,1268196577353770583,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://gist.github.com/Tantalor93/6c5baab344acf237e72b231d50408f4a/raw/%207aa875ebcd3819772d0f1d36100c19fe3c786cd7/top-1m"

URLs

Name
IP
Malicious
https://gist.github.com/Tantalor93/6c5baab344acf237e72b231d50408f4a/raw/%207aa875ebcd3819772d0f1d36100c19fe3c786cd7/top-1m
https://gist.github.com/Tantalor93/6c5baab344acf237e72b231d50408f4a/raw/%207aa875ebcd3819772d0f1d36100c19fe3c786cd7/top-1m
140.82.112.3
https://www.google.com/async/newtab_promos
142.250.64.196
https://www.google.com/sorry/index?continue=https://www.google.com/async/newtab_ogb%3Fhl%3Den-US%26async%3Dfixed:0&hl=en-US&q=EgRmgZjcGPTsrrEGIjBd9SG8FF89M4CzXW8hr1o5SgUmmE-vgqWz72M58Lh6C8lHO1J9fpw1Y1Plc3PmvtkyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM
142.250.64.196
https://www.google.com/async/newtab_ogb?hl=en-US&async=fixed:0
142.250.64.196
https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw
142.250.64.196
https://www.google.com/sorry/index?continue=https://www.google.com/async/newtab_promos&q=EgRmgZjcGPTsrrEGIjBdNSeLOI1TVNN_UZn_ZHFDIclR065SREe8jhoSetoCwaswoMREl_RX-g7mAscwCu4yAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM
142.250.64.196
https://gist.githubusercontent.com/Tantalor93/6c5baab344acf237e72b231d50408f4a/raw/%207aa875ebcd3819772d0f1d36100c19fe3c786cd7/top-1m

Domains

Name
IP
Malicious
github.com
140.82.112.3
gist.githubusercontent.com
185.199.111.133
www.google.com
142.250.64.196
gist.github.com
unknown

IPs

IP
Domain
Country
Malicious
142.250.64.196
www.google.com
United States
140.82.112.3
github.com
United States
239.255.255.250
unknown
Reserved
192.168.2.4
unknown
unknown
185.199.111.133
gist.githubusercontent.com
Netherlands

DOM / HTML

URL
Malicious
https://gist.githubusercontent.com/Tantalor93/6c5baab344acf237e72b231d50408f4a/raw/%207aa875ebcd3819772d0f1d36100c19fe3c786cd7/top-1m