IOC Report
http://2fa.telefon-de.com

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 134
Web Open Font Format (Version 2), TrueType, length 18668, version 1.0
downloaded
Chrome Cache Entry: 135
PNG image data, 300 x 908, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 136
PNG image data, 300 x 908, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 137
HTML document, ASCII text
downloaded
Chrome Cache Entry: 138
ASCII text, with very long lines (1572)
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2252 --field-trial-handle=2168,i,11221259460610057314,13659175793779925463,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://2fa.telefon-de.com"

URLs

Name
IP
Malicious
http://2fa.telefon-de.com
https://2fa.telefon-de.com/favicon.ico
54.154.95.205
https://tse1.mm.bing.net/th?id=OADD2.10239381875620_105WFGICYAOBXCJJA&pid=21.2&c=16&roil=0&roit=0&roir=1&roib=1&w=1920&h=1080&dynsize=1&qlt=90
150.171.27.10
https://tse1.mm.bing.net/th?id=OADD2.10239370639329_16GDTY03HO5SY2UBG&pid=21.2&c=3&w=1080&h=1920&dynsize=1&qlt=90
150.171.27.10
http://2fa.telefon-de.com/
46.137.49.168
https://tse1.mm.bing.net/th?id=OADD2.10239340418597_1J0EQ8ZTOVJVXHV7G&pid=21.2&c=3&w=1080&h=1920&dynsize=1&qlt=90
150.171.27.10
https://tse1.mm.bing.net/th?id=OADD2.10239381875621_18WKHVUE81K5HM47F&pid=21.2&c=3&w=1080&h=1920&dynsize=1&qlt=90
150.171.27.10
https://2fa.telefon-de.com/img/404-stu.png
54.154.95.205
https://tse1.mm.bing.net/th?id=OADD2.10239340418598_1HURUV6S4V3U642BB&pid=21.2&c=16&roil=0&roit=0&roir=1&roib=1&w=1920&h=1080&dynsize=1&qlt=90
150.171.27.10
https://2fa.telefon-de.com/
https://tse1.mm.bing.net/th?id=OADD2.10239370639330_1D80T5H13WVAODNQ8&pid=21.2&c=16&roil=0&roit=0&roir=1&roib=1&w=1920&h=1080&dynsize=1&qlt=90
150.171.27.10

Domains

Name
IP
Malicious
2fa.telefon-de.com
46.137.49.168
malicious
www.google.com
142.250.181.100
ax-0001.ax-msedge.net
150.171.27.10

IPs

IP
Domain
Country
Malicious
46.137.49.168
2fa.telefon-de.com
Ireland
malicious
192.168.2.8
unknown
unknown
192.168.2.6
unknown
unknown
142.250.181.100
www.google.com
United States
239.255.255.250
unknown
Reserved
54.154.95.205
unknown
United States

DOM / HTML

URL
Malicious
https://2fa.telefon-de.com/