IOC Report
http://www.google.ca/url?q=5Y3o34NdhGxTDQuuOadB&rct=O8SBsg83R6pO5QPyrQaf&sa=t&esrc=ws7RdZP5BzfS4Pk22aWC&source=&cd=lUnR24ByNilBvlkks5nc&uact=&url=amp%2Fgpsmx.net/new/auth/lW8OZa4Nou6Cs1KywRHfyFJs/c3RlcGhlbi5rbGVpbkB3ZWxsY2FyZS5jb20=

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 41
HTML document, ASCII text
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2028 --field-trial-handle=1968,i,17674543270455948108,633807133464980553,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.google.ca/url?q=5Y3o34NdhGxTDQuuOadB&rct=O8SBsg83R6pO5QPyrQaf&sa=t&esrc=ws7RdZP5BzfS4Pk22aWC&source=&cd=lUnR24ByNilBvlkks5nc&uact=&url=amp%2Fgpsmx.net/new/auth/lW8OZa4Nou6Cs1KywRHfyFJs/c3RlcGhlbi5rbGVpbkB3ZWxsY2FyZS5jb20="

URLs

Name
IP
Malicious
http://www.google.ca/url?q=5Y3o34NdhGxTDQuuOadB&rct=O8SBsg83R6pO5QPyrQaf&sa=t&esrc=ws7RdZP5BzfS4Pk22aWC&source=&cd=lUnR24ByNilBvlkks5nc&uact=&url=amp%2Fgpsmx.net/new/auth/lW8OZa4Nou6Cs1KywRHfyFJs/c3RlcGhlbi5rbGVpbkB3ZWxsY2FyZS5jb20=
http://gpsmx.net/favicon.ico
107.161.179.91
https://www.google.ca/url?q=5Y3o34NdhGxTDQuuOadB&rct=O8SBsg83R6pO5QPyrQaf&sa=t&esrc=ws7RdZP5BzfS4Pk22aWC&source=&cd=lUnR24ByNilBvlkks5nc&uact=&url=amp%2Fgpsmx.net/new/auth/lW8OZa4Nou6Cs1KywRHfyFJs/c3RlcGhlbi5rbGVpbkB3ZWxsY2FyZS5jb20=
142.250.185.163
http://gpsmx.net/new/auth/lW8OZa4Nou6Cs1KywRHfyFJs/c3RlcGhlbi5rbGVpbkB3ZWxsY2FyZS5jb20=
107.161.179.91
https://www.google.ca/amp/gpsmx.net/new/auth/lW8OZa4Nou6Cs1KywRHfyFJs/c3RlcGhlbi5rbGVpbkB3ZWxsY2FyZS5jb20=
142.250.185.163

Domains

Name
IP
Malicious
google.com
142.250.184.206
www.google.ca
142.250.185.163
s-part-0017.t-0009.t-msedge.net
13.107.246.45
www.google.com
142.250.185.100
gpsmx.net
107.161.179.91
fp2e7a.wpc.phicdn.net
192.229.221.95
nurt1fy.ernctw.com
unknown

IPs

IP
Domain
Country
Malicious
239.255.255.250
unknown
Reserved
142.250.185.163
www.google.ca
United States
107.161.179.91
gpsmx.net
United States
142.250.185.100
www.google.com
United States
192.168.2.4
unknown
unknown