IOC Report
https://botnet.app/k4q.exe

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\Downloads\18f0d795-3375-4d20-880f-3f371ff87569.tmp
PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\Downloads\Unconfirmed 744513.crdownload
PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
dropped
malicious
Chrome Cache Entry: 107
PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
downloaded
malicious

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2416 --field-trial-handle=2300,i,11782296733921319634,16497411758730434776,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://botnet.app/k4q.exe"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilReadIcon --lang=en-US --service-sandbox-type=icon_reader --mojo-platform-channel-handle=5644 --field-trial-handle=2300,i,11782296733921319634,16497411758730434776,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8

URLs

Name
IP
Malicious
https://botnet.app/k4q.exe
malicious
https://botnet.app/k4q.exe
69.167.61.168

Domains

Name
IP
Malicious
botnet.app
69.167.61.168
www.google.com
216.58.212.132
s-part-0039.t-0009.fb-t-msedge.net
13.107.253.67
s-part-0032.t-0009.t-msedge.net
13.107.246.60

IPs

IP
Domain
Country
Malicious
69.167.61.168
botnet.app
United States
239.255.255.250
unknown
Reserved
216.58.212.132
www.google.com
United States
192.168.2.4
unknown
unknown