IOC Report
https*3a*2f*2fonedrive.live.com*2fredir*3fresid*3dC414D8BF31B1FA3F*252144859*26authkey*3d*2521AOmZRPKM9y7aQlY*26page*3dView*26wd*3dtarget*2528Quick*2520Notes.one*257Cdc26582b-4838-4e71-9b6e-eef44b1f22ec*252FPDF*2520Note*2520T7860OJUE9JDHJDHU89893-HUYW9JOSKSO098*257Cf68a4ebc-2a72-4087-99b0-00af52713a

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 42
ASCII text, with very long lines (5018)
downloaded
Chrome Cache Entry: 43
ASCII text
downloaded
Chrome Cache Entry: 44
ASCII text
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2172 --field-trial-handle=1988,i,417336537980281095,16248366989582212918,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https*3a*2f*2fonedrive.live.com*2fredir*3fresid*3dC414D8BF31B1FA3F*252144859*26authkey*3d*2521AOmZRPKM9y7aQlY*26page*3dView*26wd*3dtarget*2528Quick*2520Notes.one*257Cdc26582b-4838-4e71-9b6e-eef44b1f22ec*252FPDF*2520Note*2520T7860OJUE9JDHJDHU89893-HUYW9JOSKSO098*257Cf68a4ebc-2a72-4087-99b0-00af52713a95*252F*2529*26wdorigin*3dNavigationUrl&c=E,1,Bk0X4hW504OesGOrQd9ootdt6dkMgQKDHlxWcLXBrGUKLPX8btLZ2QXhAhjam3_sXZpCKBEsMQhH7mkje0Lsnh2fphkNinluN4rAoaXtcaY,&typo=1__;JSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJQ!!EhqYCQ!c6bbFSWPgjt8bjhFxSF375J6gr8tHDqSRzqR9tfr-QPdPUmwDE8mfKKFkJeFx0eL3r22aaQ1YadN6BIL4otLYK2OcUJHL-xhtP353hwM$"

URLs

Name
IP
Malicious
https*3a*2f*2fonedrive.live.com*2fredir*3fresid*3dC414D8BF31B1FA3F*252144859*26authkey*3d*2521AOmZRPKM9y7aQlY*26page*3dView*26wd*3dtarget*2528Quick*2520Notes.one*257Cdc26582b-4838-4e71-9b6e-eef44b1f22ec*252FPDF*2520Note*2520T7860OJUE9JDHJDHU89893-HUYW9JOSKSO098*257Cf68a4ebc-2a72-4087-99b0-00af52713a95*252F*2529*26wdorigin*3dNavigationUrl&c=E,1,Bk0X4hW504OesGOrQd9ootdt6dkMgQKDHlxWcLXBrGUKLPX8btLZ2QXhAhjam3_sXZpCKBEsMQhH7mkje0Lsnh2fphkNinluN4rAoaXtcaY,&typo=1__;JSUlJSUlJSUlJSUlJSUlJSUlJSUlJSUlJQ!!EhqYCQ!c6bbFSWPgjt8bjhFxSF375J6gr8tHDqSRzqR9tfr-QPdPUmwDE8mfKKFkJeFx0eL3r22aaQ1YadN6BIL4otLYK2OcUJHL-xhtP353hwM$
https://www.google.com/async/ddljson?async=ntp:2
172.217.23.100
https://www.google.com/async/newtab_promos
172.217.23.100
https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw
172.217.23.100
https://www.google.com/async/newtab_ogb?hl=en-US&async=fixed:0
172.217.23.100

Domains

Name
IP
Malicious
s-part-0017.t-0009.t-msedge.net
13.107.246.45
www.google.com
172.217.23.100
241.42.69.40.in-addr.arpa
unknown
200.163.202.172.in-addr.arpa
unknown

IPs

IP
Domain
Country
Malicious
142.250.186.36
unknown
United States
239.255.255.250
unknown
Reserved
172.217.23.100
www.google.com
United States
192.168.2.4
unknown
unknown