IOC Report
https://www.weblakes.com/products/wrplot/update/Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\Downloads\Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe (copy)
PE32 executable (GUI) Intel 80386, for MS Windows, RAR self-extracting archive
dropped
C:\Users\user\Downloads\Unconfirmed 502867.crdownload
PE32 executable (GUI) Intel 80386, for MS Windows, RAR self-extracting archive
dropped
Chrome Cache Entry: 42
PE32 executable (GUI) Intel 80386, for MS Windows, RAR self-extracting archive
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2320 --field-trial-handle=2268,i,8980632643634516992,12389035430774156763,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.weblakes.com/products/wrplot/update/Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilReadIcon --lang=en-US --service-sandbox-type=icon_reader --mojo-platform-channel-handle=5604 --field-trial-handle=2268,i,8980632643634516992,12389035430774156763,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8

URLs

Name
IP
Malicious
https://www.weblakes.com/products/wrplot/update/Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe
http://www.acresso.com0
unknown
https://www.weblakes.com/products/wrplot/update/Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe
199.58.195.170

Domains

Name
IP
Malicious
weblakes.com
199.58.195.170
www.google.com
142.250.217.100
www.weblakes.com
unknown

IPs

IP
Domain
Country
Malicious
142.250.217.100
www.google.com
United States
239.255.255.250
unknown
Reserved
199.58.195.170
weblakes.com
Canada
192.168.2.4
unknown
unknown