IOC Report
https://r.envoi.eeva.net/tr/un/li/kwezYt0x649-vMy1-d3m8XWm0XDG9tdQGXwiNuM2LGBkoE_XVSp9wKRKTTo84zlVB30dtE4Qxb6bTdQ7BLiXy4vJLNGaMqGupBNu6KitW_AR1uqeyWU4G1Jbs8y7H-FTWpH-kUlzeBVIIZhezEix_Juexn4ZIOxJvZntvjaVOZRauce-TQQjIsMdtQe92HQHFZ4uqUrxeDlPccAo9Yhwy9FCZGRicVrFDp8pXgJzm-17u_h3Ps2IWs7KrW7e4hI

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 44
Web Open Font Format (Version 2), TrueType, length 48236, version 1.0
downloaded
Chrome Cache Entry: 45
ASCII text, with very long lines (1572)
downloaded
Chrome Cache Entry: 46
HTML document, ASCII text
downloaded
Chrome Cache Entry: 47
HTML document, ASCII text, with very long lines (310)
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2052 --field-trial-handle=2012,i,6330271476746337855,15990199757900187295,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://r.envoi.eeva.net/tr/un/li/kwezYt0x649-vMy1-d3m8XWm0XDG9tdQGXwiNuM2LGBkoE_XVSp9wKRKTTo84zlVB30dtE4Qxb6bTdQ7BLiXy4vJLNGaMqGupBNu6KitW_AR1uqeyWU4G1Jbs8y7H-FTWpH-kUlzeBVIIZhezEix_Juexn4ZIOxJvZntvjaVOZRauce-TQQjIsMdtQe92HQHFZ4uqUrxeDlPccAo9Yhwy9FCZGRicVrFDp8pXgJzm-17u_h3Ps2IWs7KrW7e4hI"

URLs

Name
IP
Malicious
https://r.envoi.eeva.net/tr/un/li/kwezYt0x649-vMy1-d3m8XWm0XDG9tdQGXwiNuM2LGBkoE_XVSp9wKRKTTo84zlVB30dtE4Qxb6bTdQ7BLiXy4vJLNGaMqGupBNu6KitW_AR1uqeyWU4G1Jbs8y7H-FTWpH-kUlzeBVIIZhezEix_Juexn4ZIOxJvZntvjaVOZRauce-TQQjIsMdtQe92HQHFZ4uqUrxeDlPccAo9Yhwy9FCZGRicVrFDp8pXgJzm-17u_h3Ps2IWs7KrW7e4hI
https://r.envoi.eeva.net/tr/un/li/kwezYt0x649-vMy1-d3m8XWm0XDG9tdQGXwiNuM2LGBkoE_XVSp9wKRKTTo84zlVB30dtE4Qxb6bTdQ7BLiXy4vJLNGaMqGupBNu6KitW_AR1uqeyWU4G1Jbs8y7H-FTWpH-kUlzeBVIIZhezEix_Juexn4ZIOxJvZntvjaVOZRauce-TQQjIsMdtQe92HQHFZ4uqUrxeDlPccAo9Yhwy9FCZGRicVrFDp8pXgJzm-17u_h3Ps2IWs7KrW7e4hI
https://r.envoi.eeva.net/favicon.ico
1.179.112.195
https://r.envoi.eeva.net/tr/un/do

Domains

Name
IP
Malicious
r1.mailin.fr
1.179.112.195
www.google.com
142.250.186.100
r.envoi.eeva.net
unknown

IPs

IP
Domain
Country
Malicious
239.255.255.250
unknown
Reserved
142.250.186.100
www.google.com
United States
192.168.2.4
unknown
unknown
1.179.112.195
r1.mailin.fr
Australia

DOM / HTML

URL
Malicious
https://r.envoi.eeva.net/tr/un/li/kwezYt0x649-vMy1-d3m8XWm0XDG9tdQGXwiNuM2LGBkoE_XVSp9wKRKTTo84zlVB30dtE4Qxb6bTdQ7BLiXy4vJLNGaMqGupBNu6KitW_AR1uqeyWU4G1Jbs8y7H-FTWpH-kUlzeBVIIZhezEix_Juexn4ZIOxJvZntvjaVOZRauce-TQQjIsMdtQe92HQHFZ4uqUrxeDlPccAo9Yhwy9FCZGRicVrFDp8pXgJzm-17u_h3Ps2IWs7KrW7e4hI
https://r.envoi.eeva.net/tr/un/do