IOC Report
https://click.e.miro.com/?qs=c3e69aad2d9381bc648c78299feae71fdb22ac757a070f4e5905cd8c7629ef7e370f37ef935070c1c307b7ee869054f949dffacb0988454aa20b89404a806863

loading gif

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1932 --field-trial-handle=1724,i,2876507980441582479,18001650036527390366,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe" "https://click.e.miro.com/?qs=c3e69aad2d9381bc648c78299feae71fdb22ac757a070f4e5905cd8c7629ef7e370f37ef935070c1c307b7ee869054f949dffacb0988454aa20b89404a806863

URLs

Name
IP
Malicious
https://click.e.miro.com/?qs=c3e69aad2d9381bc648c78299feae71fdb22ac757a070f4e5905cd8c7629ef7e370f37ef935070c1c307b7ee869054f949dffacb0988454aa20b89404a806863
https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1
142.250.180.174
https://click.e.miro.com/?qs=c3e69aad2d9381bc648c78299feae71fdb22ac757a070f4e5905cd8c7629ef7e370f37ef935070c1c307b7ee869054f949dffacb0988454aa20b89404a806863
159.92.136.102
https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard
216.58.209.45
https://click.e.miro.com/favicon.ico
159.92.136.102

Domains

Name
IP
Malicious
accounts.google.com
216.58.209.45
www.google.com
142.250.184.100
clients.l.google.com
142.250.180.174
click.e.miro.com
159.92.136.102
clients2.google.com
unknown

IPs

IP
Domain
Country
Malicious
192.168.2.1
unknown
unknown
159.92.136.102
click.e.miro.com
United States
239.255.255.250
unknown
Reserved
216.58.209.45
accounts.google.com
United States
142.250.184.100
www.google.com
United States
192.168.2.4
unknown
unknown
142.250.180.174
clients.l.google.com
United States
127.0.0.1
unknown
unknown

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
ahfgeienlihckogmohjhadlkjgocpleb
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
gdaefkejpgkiemlaofpalmlakkmbjdnl
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
kmendfapggjehodndflmmgagdbamhnfd
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
mhjfbmdgcfjbbpaeojofohoefgiehjai
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
neajdppkdcdipfabeoofebfddakdcjhd
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nkeimhogjdpnpccoofpliimaahmaaome
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
prefs.preference_reset_time
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\LastWasDefault
S-1-5-21-3853321935-2125563209-4053062332-1002
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
gdaefkejpgkiemlaofpalmlakkmbjdnl
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
kmendfapggjehodndflmmgagdbamhnfd
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
neajdppkdcdipfabeoofebfddakdcjhd
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nkeimhogjdpnpccoofpliimaahmaaome
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nmmhkkegccagdldgiimedpiccmgmieda
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nmmhkkegccagdldgiimedpiccmgmieda
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nmmhkkegccagdldgiimedpiccmgmieda
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
dr
HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics
user_experience_metrics.stability.exited_cleanly
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
media.cdm.origin_data
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
software_reporter.reporting
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
media.storage_id_salt
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
google.services.last_account_id
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
google.services.account_id
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.last_triggered_for_startup_urls
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.last_triggered_for_homepage
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
module_blocklist_cache_md5_digest
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
software_reporter.prompt_seed
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
default_search_provider_data.template_url_data
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
safebrowsing.incidents_sent
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
pinned_tabs
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
browser.show_home_button
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
search_provider_overrides
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.last_triggered_for_default_search
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
prefs.preference_reset_time
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
software_reporter.prompt_version
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
google.services.last_username
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
session.startup_urls
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
session.restore_on_startup
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.prompt_wave
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
homepage
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
homepage_is_newtabpage
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
lastrun
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
lastrun
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\LastWasDefault
S-1-5-21-3853321935-2125563209-4053062332-1002
HKEY_USERSS-1-5-19\Software\Microsoft\Cryptography\TPM\Telemetry
TraceTimeLast
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
There are 42 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
22CEE454000
heap
page read and write
8D0AAFE000
stack
page read and write
23C7C268000
heap
page read and write
23C7C22E000
heap
page read and write
8D0AA7F000
stack
page read and write
D101F7E000
stack
page read and write
7C1A7A000
stack
page read and write
23C7C26A000
heap
page read and write
140D9180000
trusted library allocation
page read and write
1C015A3E000
heap
page read and write
2280BD13000
heap
page read and write
23C7C241000
heap
page read and write
942FCFB000
stack
page read and write
2280BD02000
heap
page read and write
140D9D22000
heap
page read and write
2280C602000
trusted library allocation
page read and write
23C7C26E000
heap
page read and write
27696202000
heap
page read and write
27696300000
heap
page read and write
2280BC2A000
heap
page read and write
8D0AD7F000
stack
page read and write
140D9277000
heap
page read and write
A33467E000
stack
page read and write
140D91A0000
trusted library allocation
page read and write
23C7C25E000
heap
page read and write
D10207C000
stack
page read and write
23C7C265000
heap
page read and write
140D9200000
heap
page read and write
8D0A5EB000
stack
page read and write
140D923D000
heap
page read and write
23C7C27F000
heap
page read and write
140D9E30000
heap
page read and write
942F9FC000
stack
page read and write
8E58B7F000
stack
page read and write
2280C480000
trusted library allocation
page read and write
942FF7C000
stack
page read and write
23C7C248000
heap
page read and write
27695A70000
heap
page read and write
2280BB70000
heap
page read and write
27695ABD000
heap
page read and write
27695B13000
heap
page read and write
2280BC00000
heap
page read and write
140D9274000
heap
page read and write
140D9259000
heap
page read and write
23C7C25E000
heap
page read and write
140D9292000
heap
page read and write
2280BC58000
heap
page read and write
1C015A52000
heap
page read and write
140D9D43000
heap
page read and write
1C015A2A000
heap
page read and write
942FB7E000
stack
page read and write
23C7CC02000
trusted library allocation
page read and write
D10247F000
stack
page read and write
942FDFE000
stack
page read and write
2280BC40000
heap
page read and write
23C7C27B000
heap
page read and write
A333EEB000
stack
page read and write
140D93E5000
heap
page read and write
27695810000
heap
page read and write
22CEE402000
heap
page read and write
140D9D6D000
heap
page read and write
140D928D000
heap
page read and write
276957A0000
heap
page read and write
140D9244000
heap
page read and write
22CEE300000
heap
page read and write
23C7C24F000
heap
page read and write
7C1879000
stack
page read and write
2280BBE0000
heap
page read and write
D10257E000
stack
page read and write
D10237E000
stack
page read and write
7C14FE000
stack
page read and write
140D9E02000
heap
page read and write
8D0AEFF000
stack
page read and write
23C7C245000
heap
page read and write
2280BC76000
heap
page read and write
23C7C24B000
heap
page read and write
140D9E23000
heap
page read and write
23C7C180000
heap
page read and write
23C7C302000
heap
page read and write
23C7C275000
heap
page read and write
22CEE390000
trusted library allocation
page read and write
7C147E000
stack
page read and write
23C7C26C000
heap
page read and write
2280BC5B000
heap
page read and write
8E5867B000
stack
page read and write
23C7C27C000
heap
page read and write
2280BC13000
heap
page read and write
140D90E0000
heap
page read and write
22CEE45C000
heap
page read and write
140D9DBC000
heap
page read and write
22CEE413000
heap
page read and write
140D9313000
heap
page read and write
23C7C1B0000
trusted library allocation
page read and write
942F5AC000
stack
page read and write
1C015A3C000
heap
page read and write
27695B02000
heap
page read and write
23C7C22D000
heap
page read and write
140D9D92000
heap
page read and write
1C015A45000
heap
page read and write
1C0158E0000
heap
page read and write
23C7C249000
heap
page read and write
D10267F000
stack
page read and write
27695A44000
heap
page read and write
23C7C120000
heap
page read and write
942FC7E000
stack
page read and write
D1019CB000
stack
page read and write
1C015A37000
heap
page read and write
A33447E000
stack
page read and write
23C7C244000
heap
page read and write
23C7C278000
heap
page read and write
140D9D00000
heap
page read and write
A333FEE000
stack
page read and write
23C7C260000
heap
page read and write
140D9E27000
heap
page read and write
943027E000
stack
page read and write
A33437E000
stack
page read and write
23C7C261000
heap
page read and write
27695A29000
heap
page read and write
942FE7B000
stack
page read and write
22CEE2F0000
heap
page read and write
140D938C000
heap
page read and write
140D9229000
heap
page read and write
23C7C229000
heap
page read and write
943017C000
stack
page read and write
1C015B02000
heap
page read and write
27695A13000
heap
page read and write
140D9267000
heap
page read and write
23C7C110000
heap
page read and write
23C7C263000
heap
page read and write
7C15FA000
stack
page read and write
23C7C240000
heap
page read and write
D10217E000
stack
page read and write
943007F000
stack
page read and write
1C015A4A000
heap
page read and write
22CEE502000
heap
page read and write
140D9292000
heap
page read and write
23C7C247000
heap
page read and write
140D9285000
heap
page read and write
8E5897A000
stack
page read and write
2280BC02000
heap
page read and write
23C7C230000
heap
page read and write
22CEE360000
heap
page read and write
23C7C267000
heap
page read and write
8D0A8FE000
stack
page read and write
27695A67000
heap
page read and write
D101DFA000
stack
page read and write
23C7C276000
heap
page read and write
140D9D02000
heap
page read and write
27695A65000
heap
page read and write
A33457E000
stack
page read and write
1C015940000
heap
page read and write
7C1B7F000
stack
page read and write
7C1C7E000
stack
page read and write
7C17FC000
stack
page read and write
23C7C213000
heap
page read and write
7C197F000
stack
page read and write
1C015A13000
heap
page read and write
7C11AC000
stack
page read and write
140D9D22000
heap
page read and write
8D0A87E000
stack
page read and write
8E5877E000
stack
page read and write
1C015970000
trusted library allocation
page read and write
23C7C23A000
heap
page read and write
8D0ABFF000
stack
page read and write
27695AE2000
heap
page read and write
140D90F0000
heap
page read and write
140D9D54000
heap
page read and write
23C7C246000
heap
page read and write
7C16FF000
stack
page read and write
140D9213000
heap
page read and write
22CEE3C0000
remote allocation
page read and write
140D9150000
heap
page read and write
140D928A000
heap
page read and write
27695A00000
heap
page read and write
A333F6E000
stack
page read and write
D10227D000
stack
page read and write
23C7C239000
heap
page read and write
23C7C264000
heap
page read and write
1C015A00000
heap
page read and write
8D0AFFE000
stack
page read and write
7C1BFE000
stack
page read and write
22CEE400000
heap
page read and write
140D9255000
heap
page read and write
140D9E13000
heap
page read and write
22CEE3C0000
remote allocation
page read and write
140D9E00000
heap
page read and write
140D9DB0000
heap
page read and write
1C0158F0000
heap
page read and write
276957B0000
heap
page read and write
8E58C7A000
stack
page read and write
140D9DC6000
heap
page read and write
27695A8B000
heap
page read and write
22CEE3C0000
remote allocation
page read and write
8D0ACFE000
stack
page read and write
140D93B9000
heap
page read and write
23C7C200000
heap
page read and write
22CEEE02000
trusted library allocation
page read and write
22CEE428000
heap
page read and write
1C016402000
trusted library allocation
page read and write
23C7C242000
heap
page read and write
27695ACE000
heap
page read and write
23C7C262000
heap
page read and write
1C015A2F000
heap
page read and write
23C7C285000
heap
page read and write
D10277E000
stack
page read and write
8D0AE7D000
stack
page read and write
2280BB80000
heap
page read and write
140D9C02000
heap
page read and write
8E58A7E000
stack
page read and write
27695910000
trusted library allocation
page read and write
22CEE43D000
heap
page read and write
23C7C24E000
heap
page read and write
1C015A02000
heap
page read and write
23C7C23D000
heap
page read and write
140D922F000
heap
page read and write
There are 205 hidden memdumps, click here to show them.

DOM / HTML

URL
Malicious
https://click.e.miro.com/expired.html