IOC Report
https://deublin.portalapi.us.clicklearn.com/api/Common/DownloadClickLearnStudio?Identification=aHR0cHM6Ly9kZXVibGluLnBvcnRhbGFwaS51cy5jbGlja2xlYXJuLmNvbS98YzMzODdiZmEtOWY2Ny00YzM1LWIxNGYtMzcyYzc4MDczMDNi

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\Downloads\24ff2e2c-e9b3-41ce-88c4-8d24dce3b92d.tmp
XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with very long lines (11393)
dropped
C:\Users\user\Downloads\Unconfirmed 507367.crdownload (copy)
XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with very long lines (11393)
dropped
Chrome Cache Entry: 43
XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with very long lines (11393)
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2296 --field-trial-handle=1712,i,10409865053093719078,10940050848297659008,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://deublin.portalapi.us.clicklearn.com/api/Common/DownloadClickLearnStudio?Identification=aHR0cHM6Ly9kZXVibGluLnBvcnRhbGFwaS51cy5jbGlja2xlYXJuLmNvbS98YzMzODdiZmEtOWY2Ny00YzM1LWIxNGYtMzcyYzc4MDczMDNi"

URLs

Name
IP
Malicious
https://deublin.portalapi.us.clicklearn.com/api/Common/DownloadClickLearnStudio?Identification=aHR0cHM6Ly9kZXVibGluLnBvcnRhbGFwaS51cy5jbGlja2xlYXJuLmNvbS98YzMzODdiZmEtOWY2Ny00YzM1LWIxNGYtMzcyYzc4MDczMDNi
https://apps.clicklearn.com/Studio12/CLStudio.application?clidentification=aHR0cHM6Ly9kZXVibGluLnBvcnRhbGFwaS51cy5jbGlja2xlYXJuLmNvbS98YzMzODdiZmEtOWY2Ny00YzM1LWIxNGYtMzcyYzc4MDczMDNi
152.199.21.175
http://www.clicklearn.com/
unknown
https://apps.clicklearn.com/Studio12/CLStudio.application
unknown
https://deublin.portalapi.us.clicklearn.com/api/Common/DownloadClickLearnStudio?Identification=aHR0cHM6Ly9kZXVibGluLnBvcnRhbGFwaS51cy5jbGlja2xlYXJuLmNvbS98YzMzODdiZmEtOWY2Ny00YzM1LWIxNGYtMzcyYzc4MDczMDNi
13.107.246.60

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.214.172
www.google.com
142.250.186.164
default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com
217.20.57.34
s-part-0032.t-0009.t-msedge.net
13.107.246.60
sni1gl.wpc.deltacdn.net
152.199.21.175
15.164.165.52.in-addr.arpa
unknown
apps.clicklearn.com
unknown
deublin.portalapi.us.clicklearn.com
unknown

IPs

IP
Domain
Country
Malicious
142.250.184.196
unknown
United States
239.255.255.250
unknown
Reserved
152.199.21.175
sni1gl.wpc.deltacdn.net
United States
142.250.186.164
www.google.com
United States
192.168.2.7
unknown
unknown
13.107.246.60
s-part-0032.t-0009.t-msedge.net
United States