IOC Report
https://photomate.zendesk.com/attachments/token/YbytXc7guK6MTPVLFvW08Q72q/?name=image008.jpg

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 43
JPEG image data, JFIF standard 1.01, resolution (DPI), density 220x220, segment length 16, baseline, precision 8, 600x203, components 3
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2580 --field-trial-handle=2540,i,1330555557757443289,9150461567389321118,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://photomate.zendesk.com/attachments/token/YbytXc7guK6MTPVLFvW08Q72q/?name=image008.jpg"

URLs

Name
IP
Malicious
https://photomate.zendesk.com/attachments/token/YbytXc7guK6MTPVLFvW08Q72q/?name=image008.jpg
https://photomate.zendesk.com/attachments/token/YbytXc7guK6MTPVLFvW08Q72q/?name=image008.jpg
216.198.54.1
https://p29.zdusercontent.com/hc/favicon.ico
104.18.173.234
https://p29.zdusercontent.com/attachment/10733069/YbytXc7guK6MTPVLFvW08Q72q?token=eyJhbGciOiJkaXIiLCJlbmMiOiJBMTI4Q0JDLUhTMjU2In0..6TSvQVzvBiut2Dauwj0t1A.Roz9KJAsswd2PW825HV1jjN_kCPRZsbQh7OBWdHIX0iTv9eIBagAt2TcP7pOicbCXkofGVthsi3LsrcrQyEkLZ9HAdHHYxESX-LFYn_FhmefLOly86UVyMGpDgsCsjlbUz_-tfH3Cdnu8Ou1b8KcvV526I1u8iPqbhB7_Qibvm7EOQxLWoHBJDdFo8oOpgJiCo2X-FYiXoivWRKQVSajs2q-WI4pvuRsfVMsBUpC3vFyv6gQt0dEu_Zacq634HbGUGqUzekCaXxWFHP6ZcVE_lmgMSGrNiJ15ibV6LhUP9w.UHkqpp8UDtMn5VBtzTyMeQ
https://p29.zdusercontent.com/favicon.ico
104.18.173.234

Domains

Name
IP
Malicious
photomate.zendesk.com
216.198.54.1
bg.microsoft.map.fastly.net
199.232.210.172
www.google.com
142.250.186.132
default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com
217.20.57.18
p29.zdusercontent.com
104.18.173.234
www.zendesk.com
unknown

IPs

IP
Domain
Country
Malicious
239.255.255.250
unknown
Reserved
216.198.54.1
photomate.zendesk.com
United States
192.168.2.7
unknown
unknown
142.250.186.132
www.google.com
United States
104.18.173.234
p29.zdusercontent.com
United States

DOM / HTML

URL
Malicious
https://p29.zdusercontent.com/attachment/10733069/YbytXc7guK6MTPVLFvW08Q72q?token=eyJhbGciOiJkaXIiLCJlbmMiOiJBMTI4Q0JDLUhTMjU2In0..6TSvQVzvBiut2Dauwj0t1A.Roz9KJAsswd2PW825HV1jjN_kCPRZsbQh7OBWdHIX0iTv9eIBagAt2TcP7pOicbCXkofGVthsi3LsrcrQyEkLZ9HAdHHYxESX-LFYn_FhmefLOly86UVyMGpDgsCsjlbUz_-tfH3Cdnu8Ou1b8KcvV526I1u8iPqbhB7_Qibvm7EOQxLWoHBJDdFo8oOpgJiCo2X-FYiXoivWRKQVSajs2q-WI4pvuRsfVMsBUpC3vFyv6gQt0dEu_Zacq634HbGUGqUzekCaXxWFHP6ZcVE_lmgMSGrNiJ15ibV6LhUP9w.UHkqpp8UDtMn5VBtzTyMeQ