IOC Report
https://docsend.com/view/ws65kkaar2fwghua

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 41
very short file (no magic)
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2084 --field-trial-handle=1952,i,742254302403329463,5183052963729679332,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://docsend.com/view/ws65kkaar2fwghua"

URLs

Name
IP
Malicious
https://docsend.com/view/ws65kkaar2fwghua
malicious
https://docsend.com/view/ws65kkaar2fwghua
18.173.205.86
malicious
https://captainsquarterscigars.com/favicon.ico
192.185.91.220
https://captainsquarterscigars.com/n/?c3Y9bzM2NV8xX25vbSZyYW5kPVZITlRiMWs9JnVpZD1VU0VSMzAwOTIwMjRVNTkwOTMwMTE=N0123N[randy.hibberd@cityofweiser.net]

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.214.172
captainsquarterscigars.com
192.185.91.220
www.google.com
216.58.206.36
docsend.com
18.173.205.86
windowsupdatebg.s.llnwi.net
87.248.205.0

IPs

IP
Domain
Country
Malicious
239.255.255.250
unknown
Reserved
192.185.91.220
captainsquarterscigars.com
United States
18.173.205.86
docsend.com
United States
192.168.2.7
unknown
unknown
216.58.206.36
www.google.com
United States

DOM / HTML

URL
Malicious
https://captainsquarterscigars.com/n/?c3Y9bzM2NV8xX25vbSZyYW5kPVZITlRiMWs9JnVpZD1VU0VSMzAwOTIwMjRVNTkwOTMwMTE=N0123N[randy.hibberd@cityofweiser.net]