IOC Report
https://massgrave.dev/get

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 40
ASCII text, with CRLF line terminators
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2412 --field-trial-handle=2372,i,12420559780093315104,12576080289001828152,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://massgrave.dev/get"

URLs

Name
IP
Malicious
https://massgrave.dev/get
malicious
https://dev.azure.com/massgrave/Microsoft-Activation-Scripts/_apis/git/repositories/Microsoft-Activa
unknown
https://git.activated.win/massgrave/Microsoft-Activation-Scripts/raw/commit/52d4c52dba8e29a3c1fb295c
unknown
https://massgrave.dev/get
104.21.22.3
https://massgrave.dev/get.ps1
https://raw.githubusercontent.com/massgravel/Microsoft-Activation-Scripts/52d4c52dba8e29a3c1fb295c89
unknown
https://massgrave.dev/favicon.ico
104.21.22.3
https://a.nel.cloudflare.com/report/v4?s=vPTY0xFb3CBGMjuhF3E8dI7qHK%2BzbUneS1j45ngcVEvIjoNdt6Q5uaQRy4vsxM0XbCQGPCM3M9V29C95EBzXR3dUzzsP76dXF2zLokd%2Fcp3DAFdDHGfKMDL6FUhsK6om
35.190.80.1
https://get.activated.win
unknown
https://massgrave.dev/troubleshoot
unknown

Domains

Name
IP
Malicious
a.nel.cloudflare.com
35.190.80.1
massgrave.dev
104.21.22.3
s-part-0015.t-0009.t-msedge.net
13.107.246.43
s-part-0017.t-0009.t-msedge.net
13.107.246.45
www.google.com
142.250.186.100
fp2e7a.wpc.phicdn.net
192.229.221.95

IPs

IP
Domain
Country
Malicious
239.255.255.250
unknown
Reserved
104.21.22.3
massgrave.dev
United States
142.250.186.100
www.google.com
United States
35.190.80.1
a.nel.cloudflare.com
United States
192.168.2.4
unknown
unknown

DOM / HTML

URL
Malicious
https://massgrave.dev/get.ps1