Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://179.60.147.91/

Overview

General Information

Sample URL:https://179.60.147.91/
Analysis ID:1417374
Infos:
Errors
  • URL not reachable

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file

Classification

  • System is w10x64
  • chrome.exe (PID: 3260 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 2188 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=1996,i,13412642258922341580,10365056035635511600,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6508 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://179.60.147.91/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://179.60.147.91/Virustotal: Detection: 6%Perma Link
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 179.60.147.91
Source: unknownTCP traffic detected without corresponding DNS query: 179.60.147.91
Source: unknownTCP traffic detected without corresponding DNS query: 179.60.147.91
Source: unknownTCP traffic detected without corresponding DNS query: 179.60.147.91
Source: unknownTCP traffic detected without corresponding DNS query: 179.60.147.91
Source: unknownTCP traffic detected without corresponding DNS query: 179.60.147.91
Source: unknownTCP traffic detected without corresponding DNS query: 179.60.147.91
Source: unknownTCP traffic detected without corresponding DNS query: 179.60.147.91
Source: unknownTCP traffic detected without corresponding DNS query: 179.60.147.91
Source: unknownTCP traffic detected without corresponding DNS query: 179.60.147.91
Source: unknownTCP traffic detected without corresponding DNS query: 179.60.147.91
Source: unknownTCP traffic detected without corresponding DNS query: 179.60.147.91
Source: unknownTCP traffic detected without corresponding DNS query: 179.60.147.91
Source: unknownTCP traffic detected without corresponding DNS query: 179.60.147.91
Source: unknownTCP traffic detected without corresponding DNS query: 179.60.147.91
Source: unknownTCP traffic detected without corresponding DNS query: 179.60.147.91
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownDNS traffic detected: queries for: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: classification engineClassification label: mal48.win@17/0@2/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=1996,i,13412642258922341580,10365056035635511600,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://179.60.147.91/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=1996,i,13412642258922341580,10365056035635511600,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://179.60.147.91/0%Avira URL Cloudsafe
https://179.60.147.91/7%VirustotalBrowse
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
fp2e7a.wpc.phicdn.net0%VirustotalBrowse
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.251.16.106
truefalse
    high
    fp2e7a.wpc.phicdn.net
    192.229.211.108
    truefalseunknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    239.255.255.250
    unknownReserved
    unknownunknownfalse
    179.60.147.91
    unknownBelize
    42237ICMESEfalse
    142.251.16.106
    www.google.comUnited States
    15169GOOGLEUSfalse
    IP
    192.168.2.4
    Joe Sandbox version:40.0.0 Tourmaline
    Analysis ID:1417374
    Start date and time:2024-03-29 06:44:43 +01:00
    Joe Sandbox product:CloudBasic
    Overall analysis duration:0h 1m 48s
    Hypervisor based Inspection enabled:false
    Report type:full
    Cookbook file name:browseurl.jbs
    Sample URL:https://179.60.147.91/
    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
    Number of analysed new started processes analysed:5
    Number of new started drivers analysed:0
    Number of existing processes analysed:0
    Number of existing drivers analysed:0
    Number of injected processes analysed:0
    Technologies:
    • HCA enabled
    • EGA enabled
    • AMSI enabled
    Analysis Mode:default
    Analysis stop reason:Timeout
    Detection:MAL
    Classification:mal48.win@17/0@2/4
    EGA Information:Failed
    HCA Information:
    • Successful, ratio: 100%
    • Number of executed functions: 0
    • Number of non-executed functions: 0
    Cookbook Comments:
    • URL browsing timeout or error
    • URL not reachable
    • Exclude process from analysis (whitelisted): SIHClient.exe, svchost.exe
    • Excluded IPs from analysis (whitelisted): 172.253.62.94, 172.253.115.138, 172.253.115.139, 172.253.115.113, 172.253.115.100, 172.253.115.102, 172.253.115.101, 172.253.63.84, 34.104.35.123, 172.253.63.94, 23.221.242.90, 40.127.169.103, 72.21.81.240, 192.229.211.108, 13.95.31.18
    • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, clientservices.googleapis.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, wu.azureedge.net, clients2.google.com, ocsp.digicert.com, e16604.g.akamaiedge.net, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, www.gstatic.com, prod.fs.microsoft.com.akadns.net, glb.sls.prod.dcat.dsp.trafficmanager.net, fs.microsoft.com, accounts.google.com, wu.ec.azureedge.net, ctldl.windowsupdate.com, wu-bg-shim.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, edgedl.me.gvt1.com, clients.l.google.com
    • Not all processes where analyzed, report is missing behavior information
    • Report size getting too big, too many NtSetInformationFile calls found.
    No simulations
    No context
    No context
    No context
    No context
    No context
    No created / dropped files found
    No static file info
    TimestampSource PortDest PortSource IPDest IP
    Mar 29, 2024 06:45:25.203387022 CET49678443192.168.2.4104.46.162.224
    Mar 29, 2024 06:45:25.953243017 CET49675443192.168.2.4173.222.162.32
    Mar 29, 2024 06:45:32.276644945 CET49735443192.168.2.4179.60.147.91
    Mar 29, 2024 06:45:32.276685953 CET44349735179.60.147.91192.168.2.4
    Mar 29, 2024 06:45:32.276741982 CET49735443192.168.2.4179.60.147.91
    Mar 29, 2024 06:45:32.276945114 CET49736443192.168.2.4179.60.147.91
    Mar 29, 2024 06:45:32.276974916 CET44349736179.60.147.91192.168.2.4
    Mar 29, 2024 06:45:32.277029991 CET49736443192.168.2.4179.60.147.91
    Mar 29, 2024 06:45:32.277178049 CET49735443192.168.2.4179.60.147.91
    Mar 29, 2024 06:45:32.277195930 CET44349735179.60.147.91192.168.2.4
    Mar 29, 2024 06:45:32.277590990 CET49736443192.168.2.4179.60.147.91
    Mar 29, 2024 06:45:32.277605057 CET44349736179.60.147.91192.168.2.4
    Mar 29, 2024 06:45:32.671443939 CET44349735179.60.147.91192.168.2.4
    Mar 29, 2024 06:45:32.671859026 CET49735443192.168.2.4179.60.147.91
    Mar 29, 2024 06:45:32.671873093 CET44349735179.60.147.91192.168.2.4
    Mar 29, 2024 06:45:32.672244072 CET44349736179.60.147.91192.168.2.4
    Mar 29, 2024 06:45:32.672446012 CET49736443192.168.2.4179.60.147.91
    Mar 29, 2024 06:45:32.672460079 CET44349736179.60.147.91192.168.2.4
    Mar 29, 2024 06:45:32.672873974 CET44349735179.60.147.91192.168.2.4
    Mar 29, 2024 06:45:32.672930002 CET49735443192.168.2.4179.60.147.91
    Mar 29, 2024 06:45:32.673453093 CET44349736179.60.147.91192.168.2.4
    Mar 29, 2024 06:45:32.673500061 CET49736443192.168.2.4179.60.147.91
    Mar 29, 2024 06:45:32.673959970 CET49735443192.168.2.4179.60.147.91
    Mar 29, 2024 06:45:32.674052954 CET49736443192.168.2.4179.60.147.91
    Mar 29, 2024 06:45:32.674098015 CET49736443192.168.2.4179.60.147.91
    Mar 29, 2024 06:45:32.674118996 CET44349735179.60.147.91192.168.2.4
    Mar 29, 2024 06:45:32.674170017 CET49735443192.168.2.4179.60.147.91
    Mar 29, 2024 06:45:32.674187899 CET44349736179.60.147.91192.168.2.4
    Mar 29, 2024 06:45:32.674236059 CET49736443192.168.2.4179.60.147.91
    Mar 29, 2024 06:45:32.674249887 CET49735443192.168.2.4179.60.147.91
    Mar 29, 2024 06:45:32.674262047 CET44349735179.60.147.91192.168.2.4
    Mar 29, 2024 06:45:34.755743980 CET49740443192.168.2.4142.251.16.106
    Mar 29, 2024 06:45:34.755781889 CET44349740142.251.16.106192.168.2.4
    Mar 29, 2024 06:45:34.755918980 CET49740443192.168.2.4142.251.16.106
    Mar 29, 2024 06:45:34.756450891 CET49740443192.168.2.4142.251.16.106
    Mar 29, 2024 06:45:34.756472111 CET44349740142.251.16.106192.168.2.4
    Mar 29, 2024 06:45:34.967840910 CET44349740142.251.16.106192.168.2.4
    Mar 29, 2024 06:45:34.968326092 CET49740443192.168.2.4142.251.16.106
    Mar 29, 2024 06:45:34.968343019 CET44349740142.251.16.106192.168.2.4
    Mar 29, 2024 06:45:34.969320059 CET44349740142.251.16.106192.168.2.4
    Mar 29, 2024 06:45:34.969449043 CET49740443192.168.2.4142.251.16.106
    Mar 29, 2024 06:45:34.972255945 CET49740443192.168.2.4142.251.16.106
    Mar 29, 2024 06:45:34.972316027 CET44349740142.251.16.106192.168.2.4
    Mar 29, 2024 06:45:35.030230999 CET49740443192.168.2.4142.251.16.106
    Mar 29, 2024 06:45:35.030245066 CET44349740142.251.16.106192.168.2.4
    Mar 29, 2024 06:45:35.077100039 CET49740443192.168.2.4142.251.16.106
    Mar 29, 2024 06:45:35.561475992 CET49675443192.168.2.4173.222.162.32
    Mar 29, 2024 06:45:44.963202000 CET44349740142.251.16.106192.168.2.4
    Mar 29, 2024 06:45:44.963258028 CET44349740142.251.16.106192.168.2.4
    Mar 29, 2024 06:45:44.963382959 CET49740443192.168.2.4142.251.16.106
    Mar 29, 2024 06:45:46.688613892 CET49740443192.168.2.4142.251.16.106
    Mar 29, 2024 06:45:46.688635111 CET44349740142.251.16.106192.168.2.4
    TimestampSource PortDest PortSource IPDest IP
    Mar 29, 2024 06:45:30.323980093 CET53608381.1.1.1192.168.2.4
    Mar 29, 2024 06:45:30.357335091 CET53637271.1.1.1192.168.2.4
    Mar 29, 2024 06:45:31.023363113 CET53555581.1.1.1192.168.2.4
    Mar 29, 2024 06:45:32.788619995 CET53528201.1.1.1192.168.2.4
    Mar 29, 2024 06:45:34.659358025 CET5948853192.168.2.41.1.1.1
    Mar 29, 2024 06:45:34.659358025 CET5154953192.168.2.41.1.1.1
    Mar 29, 2024 06:45:34.754163027 CET53515491.1.1.1192.168.2.4
    Mar 29, 2024 06:45:34.754553080 CET53594881.1.1.1192.168.2.4
    Mar 29, 2024 06:45:48.125154972 CET53646831.1.1.1192.168.2.4
    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
    Mar 29, 2024 06:45:34.659358025 CET192.168.2.41.1.1.10xd791Standard query (0)www.google.comA (IP address)IN (0x0001)false
    Mar 29, 2024 06:45:34.659358025 CET192.168.2.41.1.1.10x610cStandard query (0)www.google.com65IN (0x0001)false
    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
    Mar 29, 2024 06:45:34.754163027 CET1.1.1.1192.168.2.40x610cNo error (0)www.google.com65IN (0x0001)false
    Mar 29, 2024 06:45:34.754553080 CET1.1.1.1192.168.2.40xd791No error (0)www.google.com142.251.16.106A (IP address)IN (0x0001)false
    Mar 29, 2024 06:45:34.754553080 CET1.1.1.1192.168.2.40xd791No error (0)www.google.com142.251.16.105A (IP address)IN (0x0001)false
    Mar 29, 2024 06:45:34.754553080 CET1.1.1.1192.168.2.40xd791No error (0)www.google.com142.251.16.104A (IP address)IN (0x0001)false
    Mar 29, 2024 06:45:34.754553080 CET1.1.1.1192.168.2.40xd791No error (0)www.google.com142.251.16.99A (IP address)IN (0x0001)false
    Mar 29, 2024 06:45:34.754553080 CET1.1.1.1192.168.2.40xd791No error (0)www.google.com142.251.16.147A (IP address)IN (0x0001)false
    Mar 29, 2024 06:45:34.754553080 CET1.1.1.1192.168.2.40xd791No error (0)www.google.com142.251.16.103A (IP address)IN (0x0001)false
    Mar 29, 2024 06:45:48.578147888 CET1.1.1.1192.168.2.40x9b36No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
    Mar 29, 2024 06:45:48.578147888 CET1.1.1.1192.168.2.40x9b36No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false

    Click to jump to process

    Click to jump to process

    Click to jump to process

    Target ID:0
    Start time:06:45:26
    Start date:29/03/2024
    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
    Wow64 process (32bit):false
    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
    Imagebase:0x7ff76e190000
    File size:3'242'272 bytes
    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:false

    Target ID:2
    Start time:06:45:28
    Start date:29/03/2024
    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
    Wow64 process (32bit):false
    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=1996,i,13412642258922341580,10365056035635511600,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
    Imagebase:0x7ff76e190000
    File size:3'242'272 bytes
    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:false

    Target ID:3
    Start time:06:45:31
    Start date:29/03/2024
    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
    Wow64 process (32bit):false
    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://179.60.147.91/"
    Imagebase:0x7ff76e190000
    File size:3'242'272 bytes
    MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
    Has elevated privileges:true
    Has administrator privileges:true
    Programmed in:C, C++ or other language
    Reputation:low
    Has exited:true

    No disassembly