IOC Report
https:/t.ly/nFn-y

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\Downloads\Proof of copyright infringement.zip.crdownload
Zip archive data, at least v1.0 to extract, compression method=store
dropped

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2584 --field-trial-handle=2196,i,9120880453123462526,15123474519900035901,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https:/t.ly/nFn-y"

IPs

IP
Domain
Country
Malicious
64.233.166.84
unknown
United States
142.250.181.238
unknown
United States
1.1.1.1
unknown
Australia
142.250.185.68
unknown
United States
162.125.66.18
unknown
United States
239.255.255.250
unknown
Reserved
142.250.185.163
unknown
United States
216.58.206.67
unknown
United States
192.168.2.7
unknown
unknown
142.250.185.100
unknown
United States
104.20.6.133
unknown
United States
162.125.66.15
unknown
United States
There are 2 hidden IPs, click here to show them.