IOC Report
https://husgu4aab.cc.rs6.net/tn.jsp?f=001Kgt4Y2UB61RJ-8HwGvpJdBIbmN2KmnsaQqGoOmBznZv-sZNQDwRSSQ7g-eK51O4by9IOD2KnWORRgU0x0E3aNqtENPlCG9IRkHoovRH87tIhjQapV8qvGaEivg08QWSvEYUiMWZbUAA5F-TBphmYo54Yji4b0P6N0DJh_NbVO20TarWgnPQ3SuLKbE7xetLRM8vyBQFA3FDAk2Yb7PHHNhkTNOnLAjlPaIIitR9YG-b5PWKzzl53xiiNEfQzHPo5f_H

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 54
ASCII text, with very long lines (4212)
downloaded
Chrome Cache Entry: 55
ASCII text, with very long lines (65449)
dropped
Chrome Cache Entry: 56
JSON data
dropped
Chrome Cache Entry: 57
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 58
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 59
JSON data
dropped
Chrome Cache Entry: 60
ASCII text, with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 61
JSON data
dropped
Chrome Cache Entry: 62
JSON data
downloaded
Chrome Cache Entry: 63
HTML document, Unicode text, UTF-8 text, with very long lines (17753), with no line terminators
downloaded
Chrome Cache Entry: 64
MS Windows icon resource - 8 icons, 256x256 with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 32 bits/pixel, 256x256 with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 32 bits/pixel
dropped
Chrome Cache Entry: 65
ASCII text, with very long lines (65449)
downloaded
Chrome Cache Entry: 66
JSON data
dropped
Chrome Cache Entry: 67
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 68
MS Windows icon resource - 8 icons, 256x256 with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 32 bits/pixel, 256x256 with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 32 bits/pixel
downloaded
Chrome Cache Entry: 69
MS Windows icon resource - 8 icons, 256x256 with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 32 bits/pixel, 256x256 with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 32 bits/pixel
dropped
Chrome Cache Entry: 70
MS Windows icon resource - 8 icons, 256x256 with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 32 bits/pixel, 256x256 with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 32 bits/pixel
downloaded
Chrome Cache Entry: 71
JSON data
dropped
Chrome Cache Entry: 72
SVG Scalable Vector Graphics image
downloaded
There are 10 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1956,i,6092507988752134403,9764446571161814838,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://husgu4aab.cc.rs6.net/tn.jsp?f=001Kgt4Y2UB61RJ-8HwGvpJdBIbmN2KmnsaQqGoOmBznZv-sZNQDwRSSQ7g-eK51O4by9IOD2KnWORRgU0x0E3aNqtENPlCG9IRkHoovRH87tIhjQapV8qvGaEivg08QWSvEYUiMWZbUAA5F-TBphmYo54Yji4b0P6N0DJh_NbVO20TarWgnPQ3SuLKbE7xetLRM8vyBQFA3FDAk2Yb7PHHNhkTNOnLAjlPaIIitR9YG-b5PWKzzl53xiiNEfQzHPo5f_HVv0eLJVI13jaoVLCWlUD41vb-4jiIEzxYy7L3VVF3KxBtVO6BE2E1jRiUdWGiYagIkSTi87BHv9cWMOqrRRElHJKtM_LH7LWPcyQYm-e7t7Np0yuIiSG2a7kcUa83fxnFKBlD3XQWk3tBK_A6UHfOpVtGfh58aA3wMAw29cIbI5nWpV6ItQSoKR9GlwPgZ9_RwLBJtBRlGly3vddfujNsc6LR0pWXaYSrJULantDqQJ_4b9XaCQ==&c=IyjvwkVNXkSM3EQNeu1AFyYVkMBKrNrka4UrFHY9Xgi8_nQQx7j-YA==&ch=Kpqbu5OxQl-CnKQeZK4xThguts9KPf_lvJrsntwD6ZjuGxnpSh2o9w=="

URLs

Name
IP
Malicious
https://husgu4aab.cc.rs6.net/tn.jsp?f=001Kgt4Y2UB61RJ-8HwGvpJdBIbmN2KmnsaQqGoOmBznZv-sZNQDwRSSQ7g-eK51O4by9IOD2KnWORRgU0x0E3aNqtENPlCG9IRkHoovRH87tIhjQapV8qvGaEivg08QWSvEYUiMWZbUAA5F-TBphmYo54Yji4b0P6N0DJh_NbVO20TarWgnPQ3SuLKbE7xetLRM8vyBQFA3FDAk2Yb7PHHNhkTNOnLAjlPaIIitR9YG-b5PWKzzl53xiiNEfQzHPo5f_HVv0eLJVI13jaoVLCWlUD41vb-4jiIEzxYy7L3VVF3KxBtVO6BE2E1jRiUdWGiYagIkSTi87BHv9cWMOqrRRElHJKtM_LH7LWPcyQYm-e7t7Np0yuIiSG2a7kcUa83fxnFKBlD3XQWk3tBK_A6UHfOpVtGfh58aA3wMAw29cIbI5nWpV6ItQSoKR9GlwPgZ9_RwLBJtBRlGly3vddfujNsc6LR0pWXaYSrJULantDqQJ_4b9XaCQ==&c=IyjvwkVNXkSM3EQNeu1AFyYVkMBKrNrka4UrFHY9Xgi8_nQQx7j-YA==&ch=Kpqbu5OxQl-CnKQeZK4xThguts9KPf_lvJrsntwD6ZjuGxnpSh2o9w==
https://husgu4aab.cc.rs6.net/tn.jsp?f=001Kgt4Y2UB61RJ-8HwGvpJdBIbmN2KmnsaQqGoOmBznZv-sZNQDwRSSQ7g-eK51O4by9IOD2KnWORRgU0x0E3aNqtENPlCG9IRkHoovRH87tIhjQapV8qvGaEivg08QWSvEYUiMWZbUAA5F-TBphmYo54Yji4b0P6N0DJh_NbVO20TarWgnPQ3SuLKbE7xetLRM8vyBQFA3FDAk2Yb7PHHNhkTNOnLAjlPaIIitR9YG-b5PWKzzl53xiiNEfQzHPo5f_HVv0eLJVI13jaoVLCWlUD41vb-4jiIEzxYy7L3VVF3KxBtVO6BE2E1jRiUdWGiYagIkSTi87BHv9cWMOqrRRElHJKtM_LH7LWPcyQYm-e7t7Np0yuIiSG2a7kcUa83fxnFKBlD3XQWk3tBK_A6UHfOpVtGfh58aA3wMAw29cIbI5nWpV6ItQSoKR9GlwPgZ9_RwLBJtBRlGly3vddfujNsc6LR0pWXaYSrJULantDqQJ_4b9XaCQ==&c=IyjvwkVNXkSM3EQNeu1AFyYVkMBKrNrka4UrFHY9Xgi8_nQQx7j-YA==&ch=Kpqbu5OxQl-CnKQeZK4xThguts9KPf_lvJrsntwD6ZjuGxnpSh2o9w==
208.75.122.11
http://creativecommons.org/publicdomain/zero/1.0/
unknown
http://underscorejs.org/
unknown
https://js.foundation/
unknown
https://github.com/lodash/lodash
unknown

Domains

Name
IP
Malicious
www.google.com
142.250.181.228
husgu4aab.cc.rs6.net
208.75.122.11
s-0005.dual-s-msedge.net
52.123.129.14

IPs

IP
Domain
Country
Malicious
52.123.129.14
s-0005.dual-s-msedge.net
United States
192.168.2.4
unknown
unknown
239.255.255.250
unknown
Reserved
142.250.181.228
www.google.com
United States
208.75.122.11
husgu4aab.cc.rs6.net
United States

DOM / HTML

URL
Malicious
https://teams.microsoft.com/dl/launcher/launcher.html?url=%2F_%23%2Fl%2Fmeetup-join%2F19%3Ameeting_MmE0NjAzMTAtYzgyMS00MDliLWE1YTUtZjJhZmM1ZGY4YzZh%40thread.v2%2F0%3Fcontext%3D%257B%2522Tid%2522%253A%25221a40aa3f-1477-4f8f-980e-9c88fa937847%2522%252C%2522Oid%2522%253A%2522b08fca2d-a34f-492c-bc56-309cea6ba5ef%2522%257D%26anon%3Dtrue&type=meetup-join&deeplinkId=7b269b0b-80a8-409d-acb8-e82f8261e524&directDl=true&msLaunch=true&enableMobilePage=true&suppressPrompt=true
https://teams.microsoft.com/dl/launcher/launcher.html?url=%2F_%23%2Fl%2Fmeetup-join%2F19%3Ameeting_MmE0NjAzMTAtYzgyMS00MDliLWE1YTUtZjJhZmM1ZGY4YzZh%40thread.v2%2F0%3Fcontext%3D%257B%2522Tid%2522%253A%25221a40aa3f-1477-4f8f-980e-9c88fa937847%2522%252C%2522Oid%2522%253A%2522b08fca2d-a34f-492c-bc56-309cea6ba5ef%2522%257D%26anon%3Dtrue&type=meetup-join&deeplinkId=7b269b0b-80a8-409d-acb8-e82f8261e524&directDl=true&msLaunch=true&enableMobilePage=true&suppressPrompt=true
https://teams.microsoft.com/dl/launcher/attribution.txt