IOC Report
http://hub-res.selvas.com/market/fatalraid/en/hub.html?download_url=https://meatmsges.com

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\Downloads\64b19808-2094-4b3b-a526-325965c491a2.tmp
ASCII text, with very long lines (32768), with no line terminators
dropped
C:\Users\user\Downloads\Unconfirmed 387418.crdownload
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 44
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 45
HTML document, Unicode text, UTF-8 (with BOM) text
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2552 --field-trial-handle=2540,i,13889271777353788833,17058743533629641007,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://hub-res.selvas.com/market/fatalraid/en/hub.html?download_url=https://meatmsges.com"

URLs

Name
IP
Malicious
http://hub-res.selvas.com/market/fatalraid/en/hub.html?download_url=https://meatmsges.com
http://hub-res.selvas.com/market/fatalraid/en/img/title.jpg
unknown
https://meatmsges.com/
185.172.129.102
http://hub-res.selvas.com/market/fatalraid/en/hub.html?download_url=https://meatmsges.com
52.219.162.147
http://hub-res.selvas.com/market/fatalraid/en/hub.html
unknown

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.214.172
meatmsges.com
185.172.129.102
www.google.com
142.250.186.132
default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com
217.20.57.18
fp2e7a.wpc.phicdn.net
192.229.221.95
s3-website-ap-northeast-1.amazonaws.com
52.219.162.147
windowsupdatebg.s.llnwi.net
87.248.204.0
hub-res.selvas.com
unknown

IPs

IP
Domain
Country
Malicious
52.219.162.147
s3-website-ap-northeast-1.amazonaws.com
United States
192.168.2.6
unknown
unknown
239.255.255.250
unknown
Reserved
185.172.129.102
meatmsges.com
Russian Federation
192.168.2.15
unknown
unknown
192.168.2.14
unknown
unknown
142.250.186.132
www.google.com
United States