IOC Report
https://wpt158.blob.core.windows.net/wpt158/index.html

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 101
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 102
XML 1.0 document, Unicode text, UTF-8 (with BOM) text
downloaded
Chrome Cache Entry: 103
HTML document, ASCII text, with no line terminators
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1948 --field-trial-handle=1728,i,5077115762642821101,12055652744373229981,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe" "https://wpt158.blob.core.windows.net/wpt158/index.html

URLs

Name
IP
Malicious
https://wpt158.blob.core.windows.net/wpt158/index.html
about:blank
https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1
216.58.215.238
https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard
172.217.168.45
https://www.carlitxs.com/
46.101.19.251

Domains

Name
IP
Malicious
accounts.google.com
172.217.168.45
www.google.com
142.250.203.100
clients.l.google.com
216.58.215.238
carlitxs.com
46.101.19.251
clients2.google.com
unknown
www.carlitxs.com
unknown

IPs

IP
Domain
Country
Malicious
46.101.19.251
carlitxs.com
Netherlands
172.217.168.45
accounts.google.com
United States
192.168.2.1
unknown
unknown
239.255.255.250
unknown
Reserved
216.58.215.238
clients.l.google.com
United States
142.250.203.100
www.google.com
United States

DOM / HTML

URL
Malicious
about:blank
about:blank