Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://y7dsfdsfdsfdfdfsdsf.z13.web.core.windows.net/

Overview

General Information

Sample URL:https://y7dsfdsfdsfdfdfsdsf.z13.web.core.windows.net/
Analysis ID:1431382
Infos:
Errors
  • URL not reachable

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample

Classification

  • System is w10x64
  • chrome.exe (PID: 3584 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 1020 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2056 --field-trial-handle=1980,i,14398456343102796191,7123280685848904353,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6460 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://y7dsfdsfdsfdfdfsdsf.z13.web.core.windows.net/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://y7dsfdsfdsfdfdfsdsf.z13.web.core.windows.net/SlashNext: detection malicious, Label: Scareware type: Phishing & Social Engineering
Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: google.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: classification engineClassification label: mal48.win@19/0@4/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2056 --field-trial-handle=1980,i,14398456343102796191,7123280685848904353,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://y7dsfdsfdsfdfdfsdsf.z13.web.core.windows.net/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2056 --field-trial-handle=1980,i,14398456343102796191,7123280685848904353,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://y7dsfdsfdsfdfdfsdsf.z13.web.core.windows.net/0%Avira URL Cloudsafe
https://y7dsfdsfdsfdfdfsdsf.z13.web.core.windows.net/100%SlashNextScareware type: Phishing & Social Engineering
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
google.com
142.251.15.101
truefalse
    high
    www.google.com
    74.125.136.104
    truefalse
      high
      fp2e7a.wpc.phicdn.net
      192.229.211.108
      truefalse
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        239.255.255.250
        unknownReserved
        unknownunknownfalse
        74.125.136.104
        www.google.comUnited States
        15169GOOGLEUSfalse
        IP
        192.168.2.4
        Joe Sandbox version:40.0.0 Tourmaline
        Analysis ID:1431382
        Start date and time:2024-04-25 00:37:38 +02:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 1m 57s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:https://y7dsfdsfdsfdfdfsdsf.z13.web.core.windows.net/
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:5
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:MAL
        Classification:mal48.win@19/0@4/3
        EGA Information:Failed
        HCA Information:
        • Successful, ratio: 100%
        • Number of executed functions: 0
        • Number of non-executed functions: 0
        Cookbook Comments:
        • URL browsing timeout or error
        • URL not reachable
        • Exclude process from analysis (whitelisted): SIHClient.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 142.250.105.94, 142.250.105.138, 142.250.105.139, 142.250.105.101, 142.250.105.102, 142.250.105.113, 142.250.105.100, 173.194.219.84, 34.104.35.123, 184.31.50.93, 52.165.165.26, 72.21.81.240, 192.229.211.108, 13.95.31.18
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtSetInformationFile calls found.
        • VT rate limit hit for: https://y7dsfdsfdsfdfdfsdsf.z13.web.core.windows.net/
        No simulations
        No context
        No context
        No context
        No context
        No context
        No created / dropped files found
        No static file info
        TimestampSource PortDest PortSource IPDest IP
        Apr 25, 2024 00:38:21.223215103 CEST49678443192.168.2.4104.46.162.224
        Apr 25, 2024 00:38:21.816824913 CEST49675443192.168.2.4173.222.162.32
        Apr 25, 2024 00:38:31.426207066 CEST49675443192.168.2.4173.222.162.32
        Apr 25, 2024 00:38:32.703104019 CEST49737443192.168.2.474.125.136.104
        Apr 25, 2024 00:38:32.703188896 CEST4434973774.125.136.104192.168.2.4
        Apr 25, 2024 00:38:32.703351021 CEST49737443192.168.2.474.125.136.104
        Apr 25, 2024 00:38:32.703536987 CEST49737443192.168.2.474.125.136.104
        Apr 25, 2024 00:38:32.703566074 CEST4434973774.125.136.104192.168.2.4
        Apr 25, 2024 00:38:32.940865993 CEST4434973774.125.136.104192.168.2.4
        Apr 25, 2024 00:38:32.941319942 CEST49737443192.168.2.474.125.136.104
        Apr 25, 2024 00:38:32.941355944 CEST4434973774.125.136.104192.168.2.4
        Apr 25, 2024 00:38:32.943016052 CEST4434973774.125.136.104192.168.2.4
        Apr 25, 2024 00:38:32.943089962 CEST49737443192.168.2.474.125.136.104
        Apr 25, 2024 00:38:32.945432901 CEST49737443192.168.2.474.125.136.104
        Apr 25, 2024 00:38:32.945554018 CEST4434973774.125.136.104192.168.2.4
        Apr 25, 2024 00:38:32.988306999 CEST49737443192.168.2.474.125.136.104
        Apr 25, 2024 00:38:32.988341093 CEST4434973774.125.136.104192.168.2.4
        Apr 25, 2024 00:38:33.035195112 CEST49737443192.168.2.474.125.136.104
        Apr 25, 2024 00:38:42.972337008 CEST4434973774.125.136.104192.168.2.4
        Apr 25, 2024 00:38:42.972501040 CEST4434973774.125.136.104192.168.2.4
        Apr 25, 2024 00:38:42.972573042 CEST49737443192.168.2.474.125.136.104
        Apr 25, 2024 00:38:44.459016085 CEST49737443192.168.2.474.125.136.104
        Apr 25, 2024 00:38:44.459096909 CEST4434973774.125.136.104192.168.2.4
        TimestampSource PortDest PortSource IPDest IP
        Apr 25, 2024 00:38:28.030286074 CEST53594201.1.1.1192.168.2.4
        Apr 25, 2024 00:38:28.041229963 CEST53535291.1.1.1192.168.2.4
        Apr 25, 2024 00:38:28.895116091 CEST53609931.1.1.1192.168.2.4
        Apr 25, 2024 00:38:29.424555063 CEST53639781.1.1.1192.168.2.4
        Apr 25, 2024 00:38:29.446043015 CEST53632021.1.1.1192.168.2.4
        Apr 25, 2024 00:38:29.600752115 CEST53577681.1.1.1192.168.2.4
        Apr 25, 2024 00:38:29.627522945 CEST5702953192.168.2.48.8.8.8
        Apr 25, 2024 00:38:29.627856016 CEST5187453192.168.2.41.1.1.1
        Apr 25, 2024 00:38:29.739595890 CEST53518741.1.1.1192.168.2.4
        Apr 25, 2024 00:38:29.744337082 CEST53570298.8.8.8192.168.2.4
        Apr 25, 2024 00:38:30.746958017 CEST53648831.1.1.1192.168.2.4
        Apr 25, 2024 00:38:30.787297964 CEST53614691.1.1.1192.168.2.4
        Apr 25, 2024 00:38:32.579169035 CEST5729153192.168.2.41.1.1.1
        Apr 25, 2024 00:38:32.579513073 CEST5800553192.168.2.41.1.1.1
        Apr 25, 2024 00:38:32.689738989 CEST53572911.1.1.1192.168.2.4
        Apr 25, 2024 00:38:32.690171003 CEST53580051.1.1.1192.168.2.4
        Apr 25, 2024 00:38:36.081016064 CEST53587101.1.1.1192.168.2.4
        Apr 25, 2024 00:38:36.081511021 CEST53622971.1.1.1192.168.2.4
        Apr 25, 2024 00:38:36.234899998 CEST53563881.1.1.1192.168.2.4
        Apr 25, 2024 00:38:46.037605047 CEST53637911.1.1.1192.168.2.4
        TimestampSource IPDest IPChecksumCodeType
        Apr 25, 2024 00:38:30.787445068 CEST192.168.2.41.1.1.1c258(Port unreachable)Destination Unreachable
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Apr 25, 2024 00:38:29.627522945 CEST192.168.2.48.8.8.80x1409Standard query (0)google.comA (IP address)IN (0x0001)false
        Apr 25, 2024 00:38:29.627856016 CEST192.168.2.41.1.1.10x67b7Standard query (0)google.comA (IP address)IN (0x0001)false
        Apr 25, 2024 00:38:32.579169035 CEST192.168.2.41.1.1.10x3382Standard query (0)www.google.comA (IP address)IN (0x0001)false
        Apr 25, 2024 00:38:32.579513073 CEST192.168.2.41.1.1.10x2a65Standard query (0)www.google.com65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Apr 25, 2024 00:38:29.739595890 CEST1.1.1.1192.168.2.40x67b7No error (0)google.com142.251.15.101A (IP address)IN (0x0001)false
        Apr 25, 2024 00:38:29.739595890 CEST1.1.1.1192.168.2.40x67b7No error (0)google.com142.251.15.100A (IP address)IN (0x0001)false
        Apr 25, 2024 00:38:29.739595890 CEST1.1.1.1192.168.2.40x67b7No error (0)google.com142.251.15.113A (IP address)IN (0x0001)false
        Apr 25, 2024 00:38:29.739595890 CEST1.1.1.1192.168.2.40x67b7No error (0)google.com142.251.15.139A (IP address)IN (0x0001)false
        Apr 25, 2024 00:38:29.739595890 CEST1.1.1.1192.168.2.40x67b7No error (0)google.com142.251.15.102A (IP address)IN (0x0001)false
        Apr 25, 2024 00:38:29.739595890 CEST1.1.1.1192.168.2.40x67b7No error (0)google.com142.251.15.138A (IP address)IN (0x0001)false
        Apr 25, 2024 00:38:29.744337082 CEST8.8.8.8192.168.2.40x1409No error (0)google.com173.194.77.113A (IP address)IN (0x0001)false
        Apr 25, 2024 00:38:29.744337082 CEST8.8.8.8192.168.2.40x1409No error (0)google.com173.194.77.139A (IP address)IN (0x0001)false
        Apr 25, 2024 00:38:29.744337082 CEST8.8.8.8192.168.2.40x1409No error (0)google.com173.194.77.102A (IP address)IN (0x0001)false
        Apr 25, 2024 00:38:29.744337082 CEST8.8.8.8192.168.2.40x1409No error (0)google.com173.194.77.100A (IP address)IN (0x0001)false
        Apr 25, 2024 00:38:29.744337082 CEST8.8.8.8192.168.2.40x1409No error (0)google.com173.194.77.101A (IP address)IN (0x0001)false
        Apr 25, 2024 00:38:29.744337082 CEST8.8.8.8192.168.2.40x1409No error (0)google.com173.194.77.138A (IP address)IN (0x0001)false
        Apr 25, 2024 00:38:32.689738989 CEST1.1.1.1192.168.2.40x3382No error (0)www.google.com74.125.136.104A (IP address)IN (0x0001)false
        Apr 25, 2024 00:38:32.689738989 CEST1.1.1.1192.168.2.40x3382No error (0)www.google.com74.125.136.103A (IP address)IN (0x0001)false
        Apr 25, 2024 00:38:32.689738989 CEST1.1.1.1192.168.2.40x3382No error (0)www.google.com74.125.136.106A (IP address)IN (0x0001)false
        Apr 25, 2024 00:38:32.689738989 CEST1.1.1.1192.168.2.40x3382No error (0)www.google.com74.125.136.99A (IP address)IN (0x0001)false
        Apr 25, 2024 00:38:32.689738989 CEST1.1.1.1192.168.2.40x3382No error (0)www.google.com74.125.136.147A (IP address)IN (0x0001)false
        Apr 25, 2024 00:38:32.689738989 CEST1.1.1.1192.168.2.40x3382No error (0)www.google.com74.125.136.105A (IP address)IN (0x0001)false
        Apr 25, 2024 00:38:32.690171003 CEST1.1.1.1192.168.2.40x2a65No error (0)www.google.com65IN (0x0001)false
        Apr 25, 2024 00:38:44.892337084 CEST1.1.1.1192.168.2.40x1864No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Apr 25, 2024 00:38:44.892337084 CEST1.1.1.1192.168.2.40x1864No error (0)fp2e7a.wpc.phicdn.net192.229.211.108A (IP address)IN (0x0001)false

        Click to jump to process

        Click to jump to process

        Click to jump to process

        Target ID:0
        Start time:00:38:24
        Start date:25/04/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:2
        Start time:00:38:26
        Start date:25/04/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2056 --field-trial-handle=1980,i,14398456343102796191,7123280685848904353,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:3
        Start time:00:38:28
        Start date:25/04/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://y7dsfdsfdsfdfdfsdsf.z13.web.core.windows.net/"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true

        No disassembly