IOC Report
https://steamcomunmnity.com/app/1648413/STALKER_2_Heert_of_Chornobyl

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 103
HTML document, ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 104
HTML document, ASCII text, with no line terminators
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2368 --field-trial-handle=2284,i,17785876782238166378,16159648369973155101,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://steamcomunmnity.com/app/1648413/STALKER_2_Heert_of_Chornobyl"

URLs

Name
IP
Malicious
https://steamcomunmnity.com/app/1648413/STALKER_2_Heert_of_Chornobyl
malicious
https://steamcomunmnity.com/app/1648413/STALKER_2_Heert_of_Chornobyl
malicious
https://steamcomunmnity.com/favicon.ico
188.114.96.3
https://a.nel.cloudflare.com/report/v4?s=oZMPQMkxsAldRTCfAQ%2BDZ1WwWUzC8TsysAMY02rjD7vZK4BxamemvLaGCHul2WjTzZsqWN1hcY653zKKqT5g5H4wvvOOMsDVp2G8Eqlz5pe9DjJpCH%2FnX25tBYRYykdSjTE36vQH
35.190.80.1
https://a.nel.cloudflare.com/report/v4?s=GMnP03AJBgK9dRnvweLgAP9R1t4jSYOJWFDN3TPRjv7S1lbl%2F3gJG9TY2tsTk8muSlnPtgP8Mau4qKOLpkqXSG%2BlDc2x%2BuXTIKmzUuhycqwJ54mmlSmoUph92C%2BouU0DBWHkmoAE
35.190.80.1

Domains

Name
IP
Malicious
a.nel.cloudflare.com
35.190.80.1
www.google.com
172.217.18.4
steamcomunmnity.com
188.114.96.3
fp2e7a.wpc.phicdn.net
192.229.221.95

IPs

IP
Domain
Country
Malicious
239.255.255.250
unknown
Reserved
188.114.96.3
steamcomunmnity.com
European Union
172.217.18.4
www.google.com
United States
35.190.80.1
a.nel.cloudflare.com
United States
192.168.2.4
unknown
unknown
192.168.2.5
unknown
unknown

DOM / HTML

URL
Malicious
https://steamcomunmnity.com/app/1648413/STALKER_2_Heert_of_Chornobyl