IOC Report
http://104.18.42.23

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 43
gzip compressed data, from Unix, original size modulo 2^32 8013
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2452 --field-trial-handle=2268,i,10696446724765080427,6992652642255804812,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://104.18.42.23"

URLs

Name
IP
Malicious
http://104.18.42.23
http://104.18.42.23/cdn-cgi/styles/main.css
104.18.42.23
http://104.18.42.23/favicon.ico
104.18.42.23
https://sparrow.cloudflare.com/api/v1/event
104.18.2.57
http://104.18.42.23/
https://performance.radar.cloudflare.com/beacon.js
104.18.30.78

Domains

Name
IP
Malicious
sparrow.cloudflare.com
104.18.2.57
www.cloudflare.com
104.16.123.96
performance.radar.cloudflare.com
104.18.30.78
www.google.com
172.217.23.100

IPs

IP
Domain
Country
Malicious
104.18.42.23
unknown
United States
104.18.3.57
unknown
United States
239.255.255.250
unknown
Reserved
104.18.2.57
sparrow.cloudflare.com
United States
104.18.30.78
performance.radar.cloudflare.com
United States
172.217.23.100
www.google.com
United States
192.168.2.4
unknown
unknown

DOM / HTML

URL
Malicious
http://104.18.42.23/
http://104.18.42.23/