IOC Report
https://allieduniversalsecurity.my.salesforce.com/servlet/servlet.ImageServer?oid=00D20000000BeEh&esid=018Tc00000AmX38&from=ext

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 41
MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
downloaded
Chrome Cache Entry: 42
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 43
MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
dropped

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2096 --field-trial-handle=2056,i,17377784132043557208,12673799475390323741,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://allieduniversalsecurity.my.salesforce.com/servlet/servlet.ImageServer?oid=00D20000000BeEh&esid=018Tc00000AmX38&from=ext"

URLs

Name
IP
Malicious
https://allieduniversalsecurity.my.salesforce.com/servlet/servlet.ImageServer?oid=00D20000000BeEh&esid=018Tc00000AmX38&from=ext
https://allieduniversalsecurity.my.salesforce.com/s.gif
https://allieduniversalsecurity.my.salesforce.com/favicon.ico
13.48.144.137
https://allieduniversalsecurity.my.salesforce.com/servlet/servlet.ImageServer?oid=00D20000000BeEh&esid=018Tc00000AmX38&from=ext
13.48.144.137

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.210.172
swe68.sfdc-cehfhs.salesforce.com
13.48.144.137
www.google.com
142.250.185.132
default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com
217.20.57.19
allieduniversalsecurity.my.salesforce.com
unknown

IPs

IP
Domain
Country
Malicious
13.48.144.137
swe68.sfdc-cehfhs.salesforce.com
United States
239.255.255.250
unknown
Reserved
192.168.2.7
unknown
unknown
142.250.185.132
www.google.com
United States

DOM / HTML

URL
Malicious
https://allieduniversalsecurity.my.salesforce.com/s.gif