IOC Report
http://74.248.123.196/d/msdownload/update/software/defu/2024/10/updateplatform.amd64fre_d3f6f8300855e56b8ed00da6dac55a3c4cbf8c20.exe?cacheHostOrigin=au.download.windowsupdate.com

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\Downloads\6cd661b5-5baa-4966-8993-bc408410a2c1.tmp
PE32+ executable (GUI) x86-64, for MS Windows
dropped
C:\Users\user\Downloads\Unconfirmed 321376.crdownload
PE32+ executable (GUI) x86-64, for MS Windows
dropped
Chrome Cache Entry: 40
PE32+ executable (GUI) x86-64, for MS Windows
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1712 --field-trial-handle=1820,i,9117272042142998473,5427164369196099377,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://74.248.123.196/d/msdownload/update/software/defu/2024/10/updateplatform.amd64fre_d3f6f8300855e56b8ed00da6dac55a3c4cbf8c20.exe?cacheHostOrigin=au.download.windowsupdate.com"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilReadIcon --lang=en-US --service-sandbox-type=icon_reader --mojo-platform-channel-handle=3980 --field-trial-handle=1820,i,9117272042142998473,5427164369196099377,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8

Domains

Name
IP
Malicious
www.google.com
142.250.181.228
fp2e7a.wpc.phicdn.net
192.229.221.95

IPs

IP
Domain
Country
Malicious
74.248.123.196
unknown
United States
239.255.255.250
unknown
Reserved
192.168.2.23
unknown
unknown
142.250.181.228
www.google.com
United States
192.168.2.8
unknown
unknown
192.168.2.6
unknown
unknown