IOC Report
https://cdn.discordapp.com/attachments/1238968627324125338/1298909870246072383/7_pending_messages.pdf.z?ex=671b4795&is=6719f615&hm=4dd19baf712a8440a7d8049efbd9c477b434a409fa213dececb065adf64ee0b5&

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\Downloads\7_pending_messages.pdf.z.crdownload
RAR archive data, v5
dropped
malicious
C:\Users\user\Downloads\7_pending_messages.pdf.z (copy)
RAR archive data, v5
dropped
C:\Users\user\Downloads\d0a9aa22-c243-4f30-b2ef-b6f472f22099.tmp
RAR archive data, v5
dropped

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2476 --field-trial-handle=2440,i,2568975150551077627,2539420849066546122,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://cdn.discordapp.com/attachments/1238968627324125338/1298909870246072383/7_pending_messages.pdf.z?ex=671b4795&is=6719f615&hm=4dd19baf712a8440a7d8049efbd9c477b434a409fa213dececb065adf64ee0b5&"

URLs

Name
IP
Malicious
https://cdn.discordapp.com/attachments/1238968627324125338/1298909870246072383/7_pending_messages.pdf.z?ex=671b4795&is=6719f615&hm=4dd19baf712a8440a7d8049efbd9c477b434a409fa213dececb065adf64ee0b5&
https://cdn.discordapp.com/attachments/1238968627324125338/1298909870246072383/7_pending_messages.pdf.z?ex=671b4795&is=6719f615&hm=4dd19baf712a8440a7d8049efbd9c477b434a409fa213dececb065adf64ee0b5&
162.159.134.233

Domains

Name
IP
Malicious
cdn.discordapp.com
162.159.134.233
www.google.com
142.250.186.132
171.39.242.20.in-addr.arpa
unknown

IPs

IP
Domain
Country
Malicious
216.58.212.132
unknown
United States
192.168.2.16
unknown
unknown
192.168.2.4
unknown
unknown
192.168.2.6
unknown
unknown
239.255.255.250
unknown
Reserved
192.168.2.23
unknown
unknown
142.250.186.132
www.google.com
United States
162.159.134.233
cdn.discordapp.com
United States