IOC Report
http://exchange.postrelease.com

loading gif

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2076 --field-trial-handle=2012,i,14093298385548247986,2622126802954929212,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://exchange.postrelease.com"

URLs

Name
IP
Malicious
http://exchange.postrelease.com
https://tse1.mm.bing.net/th?id=OADD2.10239395841513_1SZ4KNTW171PGDIM2&pid=21.2&c=16&roil=0&roit=0&roir=1&roib=1&w=1920&h=1080&dynsize=1&qlt=90
150.171.28.10
https://tse1.mm.bing.net/th?id=OADD2.10239370639329_16GDTY03HO5SY2UBG&pid=21.2&c=3&w=1080&h=1920&dynsize=1&qlt=90
150.171.28.10
http://exchange.postrelease.com/
https://tse1.mm.bing.net/th?id=OADD2.10239395019081_1G8JFT41D9TYPNUJJ&pid=21.2&c=16&roil=0&roit=0&roir=1&roib=1&w=1920&h=1080&dynsize=1&qlt=90
150.171.28.10
https://tse1.mm.bing.net/th?id=OADD2.10239395841512_1O57G4N5HMGWCZRF4&pid=21.2&c=3&w=1080&h=1920&dynsize=1&qlt=90
150.171.28.10
https://tse1.mm.bing.net/th?id=OADD2.10239370639702_1LY06F7YB2ZF9D3G5&pid=21.2&c=16&roil=0&roit=0&roir=1&roib=1&w=1920&h=1080&dynsize=1&qlt=90
150.171.28.10
https://tse1.mm.bing.net/th?id=OADD2.10239340783932_1JCHO8JLBZ4TPAX49&pid=21.2&c=3&w=1080&h=1920&dynsize=1&qlt=90
150.171.28.10
https://tse1.mm.bing.net/th?id=OADD2.10239351692251_14GVW2N70NV16EC3R&pid=21.2&c=16&roil=0&roit=0&roir=1&roib=1&w=1920&h=1080&dynsize=1&qlt=90
150.171.28.10
https://tse1.mm.bing.net/th?id=OADD2.10239351692250_1WOMJ1ST1OYJPQSJF&pid=21.2&c=3&w=1080&h=1920&dynsize=1&qlt=90
150.171.28.10
https://tse1.mm.bing.net/th?id=OADD2.10239370639330_1D80T5H13WVAODNQ8&pid=21.2&c=16&roil=0&roit=0&roir=1&roib=1&w=1920&h=1080&dynsize=1&qlt=90
150.171.28.10
https://tse1.mm.bing.net/th?id=OADD2.10239340783933_1QOIM48UV8MGOV4SU&pid=21.2&c=16&roil=0&roit=0&roir=1&roib=1&w=1920&h=1080&dynsize=1&qlt=90
150.171.28.10
https://tse1.mm.bing.net/th?id=OADD2.10239395019080_17DEM3LK5H7QUOJTP&pid=21.2&c=3&w=1080&h=1920&dynsize=1&qlt=90
150.171.28.10
https://tse1.mm.bing.net/th?id=OADD2.10239370639703_1XZVEAKL3PD7EZGL4&pid=21.2&c=3&w=1080&h=1920&dynsize=1&qlt=90
150.171.28.10
There are 3 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
www.google.com
142.250.185.100
ax-0001.ax-msedge.net
150.171.28.10
exchange.postrelease.com
unknown
tse1.mm.bing.net
unknown

IPs

IP
Domain
Country
Malicious
239.255.255.250
unknown
Reserved
142.250.185.100
www.google.com
United States
192.168.2.4
unknown
unknown
192.168.2.6
unknown
unknown

DOM / HTML

URL
Malicious
http://exchange.postrelease.com/