IOC Report
https://thubanoa.com/1?z=8001368

loading gif

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2352 --field-trial-handle=2212,i,15467594854020006260,8663195987752380635,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://thubanoa.com/1?z=8001368"

URLs

Name
IP
Malicious
https://thubanoa.com/1?z=8001368
malicious
https://thubanoa.com/1?z=8001368
malicious
https://thubanoa.com/favicon.ico
139.45.197.242

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.210.172
thubanoa.com
139.45.197.242
www.google.com
142.250.181.228
fp2e7a.wpc.phicdn.net
192.229.221.95

IPs

IP
Domain
Country
Malicious
239.255.255.250
unknown
Reserved
142.250.181.228
www.google.com
United States
139.45.197.242
thubanoa.com
Netherlands
192.168.2.4
unknown
unknown

DOM / HTML

URL
Malicious
https://thubanoa.com/1?z=8001368