IOC Report
https://auth.berger-levrault.com

loading gifFilesProcessesURLsDomainsIPsDOM5432Label

Files

File Path
Type
Category
Malicious
Download
Chrome Cache Entry: 49
HTML document, Unicode text, UTF-8 text, with very long lines (7405)
downloaded
Chrome Cache Entry: 50
ASCII text, with very long lines (5456)
downloaded
Chrome Cache Entry: 51
HTML document, Unicode text, UTF-8 text, with very long lines (7405)
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1800,i,5765859814087684943,14114047180601535032,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2040 /prefetch:3
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://auth.berger-levrault.com"

URLs

Name
IP
Malicious
https://auth.berger-levrault.com
http://c.pki.goog/r/gsr1.crl
142.251.41.3
http://c.pki.goog/r/r4.crl
142.251.41.3
https://auth.berger-levrault.com/
https://auth.berger-levrault.com/favicon.ico
20.19.141.174
https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE
142.251.41.4

Domains

Name
IP
Malicious
beacons-handoff.gcp.gvt2.com
142.251.116.94
www.google.com
142.251.41.4
auth.berger-levrault.com
20.19.141.174
beacons.gcp.gvt2.com
unknown

IPs

IP
Domain
Country
Malicious
192.168.2.7
unknown
unknown
20.19.141.174
auth.berger-levrault.com
United States
142.251.41.4
www.google.com
United States

DOM / HTML

URL
Malicious
https://auth.berger-levrault.com/