IOC Report
http://logiamutusliber.com.ar/dan/gbsources

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 41
gzip compressed data, from Unix, original size modulo 2^32 6022
downloaded
Chrome Cache Entry: 42
PNG image data, 32 x 31, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 43
PNG image data, 32 x 31, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 44
JPEG image data, baseline, precision 8, 820x76, components 3
dropped
Chrome Cache Entry: 45
JPEG image data, baseline, precision 8, 820x76, components 3
downloaded
Chrome Cache Entry: 46
ASCII text, with no line terminators
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2244 --field-trial-handle=2300,i,1858375456544592284,11987062658215177213,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://logiamutusliber.com.ar/dan/gbsources"

URLs

Name
IP
Malicious
http://logiamutusliber.com.ar/dan/gbsources
malicious
http://logiamutusliber.com.ar/dan/gbsources/
malicious
http://logiamutusliber.com.ar/dan/gbsources
198.27.76.221
malicious
https://i.imgur.com/Ornos2v.jpg
199.232.192.193
https://i.imgur.com/WDYixm6.png
199.232.192.193

Domains

Name
IP
Malicious
logiamutusliber.com.ar
198.27.76.221
malicious
bg.microsoft.map.fastly.net
199.232.214.172
s-part-0017.t-0009.fb-t-msedge.net
13.107.253.45
www.google.com
142.250.186.68
fp2e7a.wpc.phicdn.net
192.229.221.95
ipv4.imgur.map.fastly.net
199.232.192.193
i.imgur.com
unknown

IPs

IP
Domain
Country
Malicious
198.27.76.221
logiamutusliber.com.ar
Canada
malicious
142.250.186.68
www.google.com
United States
239.255.255.250
unknown
Reserved
199.232.192.193
ipv4.imgur.map.fastly.net
United States
192.168.2.4
unknown
unknown
192.168.2.5
unknown
unknown

DOM / HTML

URL
Malicious
http://logiamutusliber.com.ar/dan/gbsources/
malicious