Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://clickproxy.retailrocket.net/?url=https*3A*2F*2Ftocafootball.net*auth*cred*muowj5*james.laufman@automationanywhere.com__;JSUlLy8vLw!!BHlfX_zbyOAjqHI!zHvvcPnXBAkkLycQe5qD8UDSOTlGzeWMqwuayGo8vyctnqkCxBKd39LtgqPAZ3sR4XqqsS8gyKZjUckizpLqmTBUPl6ZxcUmIVb0QZWQeT0T$

Overview

General Information

Sample URL:https://clickproxy.retailrocket.net/?url=https*3A*2F*2Ftocafootball.net*auth*cred*muowj5*james.laufman@automationanywhere.com__;JSUlLy8vLw!!BHlfX_zbyOAjqHI!zHvvcPnXBAkkLycQe5qD8UDSOTlGzeWMqwuayGo8vyct
Analysis ID:1432232

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Stores files to the Windows start menu directory
URL contains potential PII (phishing indication)

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 2148 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://clickproxy.retailrocket.net/?url=https*3A*2F*2Ftocafootball.net*auth*cred*muowj5*james.laufman@automationanywhere.com__;JSUlLy8vLw!!BHlfX_zbyOAjqHI!zHvvcPnXBAkkLycQe5qD8UDSOTlGzeWMqwuayGo8vyctnqkCxBKd39LtgqPAZ3sR4XqqsS8gyKZjUckizpLqmTBUPl6ZxcUmIVb0QZWQeT0T$ MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
    • chrome.exe (PID: 5560 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2108 --field-trial-handle=1776,i,11745920494594389,8939508074749307379,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
  • cleanup
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://clickproxy.retailrocket.net/?url=https*3A*2F*2Ftocafootball.net*auth*cred*muowj5*james.laufman@automationanywhere.com__;JSUlLy8vLw!!BHlfX_zbyOAjqHI!zHvvcPnXBAkkLycQe5qD8UDSOTlGzeWMqwuayGo8vyctnqkCxBKd39LtgqPAZ3sR4XqqsS8gyKZjUckizpLqmTBUPl6ZxcUmIVb0QZWQeT0T$Sample URL: PII: https*3A*2F*2Ftocafootball.net*auth*cred*muowj5*james.laufman@automationanywhere.com__;JSUlLy8vLw!!BHlfX_zbyOAjqHI!zHvvcPnXBAkkLycQe5qD8UDSOTlGzeWMqwuayGo8vyctnqkCxBKd39LtgqPAZ3sR4XqqsS8gyKZjUckizpLqmTBUPl6ZxcUmIVb0QZWQeT0T$
Source: https://clickproxy.retailrocket.net/?url=https*3A*2F*2Ftocafootball.net*auth*cred*muowj5*james.laufman@automationanywhere.com__;JSUlLy8vLw!!BHlfX_zbyOAjqHI!zHvvcPnXBAkkLycQe5qD8UDSOTlGzeWMqwuayGo8vyctnqkCxBKd39LtgqPAZ3sR4XqqsS8gyKZjUckizpLqmTBUPl6ZxcUmIVb0QZWQeT0T$Sample URL: PII: https*3A*2F*2Ftocafootball.net*auth*cred*muowj5*james.laufman@automationanywhere.com__;JSUlLy8vLw!!BHlfX_zbyOAjqHI!zHvvcPnXBAkkLycQe5qD8UDSOTlGzeWMqwuayGo8vyctnqkCxBKd39LtgqPAZ3sR4XqqsS8gyKZjUckizpLqmTBUPl6ZxcUmIVb0QZWQeT0T$
Source: https://clickproxy.retailrocket.net/?url=https*3A*2F*2Ftocafootball.net*auth*cred*muowj5*james.laufman@automationanywhere.com__;JSUlLy8vLw!!BHlfX_zbyOAjqHI!zHvvcPnXBAkkLycQe5qD8UDSOTlGzeWMqwuayGo8vyctnqkCxBKd39LtgqPAZ3sR4XqqsS8gyKZjUckizpLqmTBUPl6ZxcUmIVb0QZWQeT0T$Sample URL: PII: https*3A*2F*2Ftocafootball.net*auth*cred*muowj5*james.laufman@automationanywhere.com__;JSUlLy8vLw!!BHlfX_zbyOAjqHI!zHvvcPnXBAkkLycQe5qD8UDSOTlGzeWMqwuayGo8vyctnqkCxBKd39LtgqPAZ3sR4XqqsS8gyKZjUckizpLqmTBUPl6ZxcUmIVb0QZWQeT0T$
Source: https://clickproxy.retailrocket.net/?url=https*3A*2F*2Ftocafootball.net*auth*cred*muowj5*james.laufman@automationanywhere.com__;JSUlLy8vLw!!BHlfX_zbyOAjqHI!zHvvcPnXBAkkLycQe5qD8UDSOTlGzeWMqwuayGo8vyctnqkCxBKd39LtgqPAZ3sR4XqqsS8gyKZjUckizpLqmTBUPl6ZxcUmIVb0QZWQeT0T$Sample URL: PII: https*3A*2F*2Ftocafootball.net*auth*cred*muowj5*james.laufman@automationanywhere.com__;JSUlLy8vLw!!BHlfX_zbyOAjqHI!zHvvcPnXBAkkLycQe5qD8UDSOTlGzeWMqwuayGo8vyctnqkCxBKd39LtgqPAZ3sR4XqqsS8gyKZjUckizpLqmTBUPl6ZxcUmIVb0QZWQeT0T$
Source: https://clickproxy.retailrocket.net/?url=https*3A*2F*2Ftocafootball.net*auth*cred*muowj5*james.laufman@automationanywhere.com__;JSUlLy8vLw!!BHlfX_zbyOAjqHI!zHvvcPnXBAkkLycQe5qD8UDSOTlGzeWMqwuayGo8vyctnqkCxBKd39LtgqPAZ3sR4XqqsS8gyKZjUckizpLqmTBUPl6ZxcUmIVb0QZWQeT0T$Sample URL: PII: https*3A*2F*2Ftocafootball.net*auth*cred*muowj5*james.laufman@automationanywhere.com__;JSUlLy8vLw!!BHlfX_zbyOAjqHI!zHvvcPnXBAkkLycQe5qD8UDSOTlGzeWMqwuayGo8vyctnqkCxBKd39LtgqPAZ3sR4XqqsS8gyKZjUckizpLqmTBUPl6ZxcUmIVb0QZWQeT0T$
Source: https://clickproxy.retailrocket.net/?url=https*3A*2F*2Ftocafootball.net*auth*cred*muowj5*james.laufman@automationanywhere.com__;JSUlLy8vLw!!BHlfX_zbyOAjqHI!zHvvcPnXBAkkLycQe5qD8UDSOTlGzeWMqwuayGo8vyctnqkCxBKd39LtgqPAZ3sR4XqqsS8gyKZjUckizpLqmTBUPl6ZxcUmIVb0QZWQeT0T$Sample URL: PII: https*3A*2F*2Ftocafootball.net*auth*cred*muowj5*james.laufman@automationanywhere.com__;JSUlLy8vLw!!BHlfX_zbyOAjqHI!zHvvcPnXBAkkLycQe5qD8UDSOTlGzeWMqwuayGo8vyctnqkCxBKd39LtgqPAZ3sR4XqqsS8gyKZjUckizpLqmTBUPl6ZxcUmIVb0QZWQeT0T$
Source: https://clickproxy.retailrocket.net/?url=https*3A*2F*2Ftocafootball.net*auth*cred*muowj5*james.laufman@automationanywhere.com__;JSUlLy8vLw!!BHlfX_zbyOAjqHI!zHvvcPnXBAkkLycQe5qD8UDSOTlGzeWMqwuayGo8vyctnqkCxBKd39LtgqPAZ3sR4XqqsS8gyKZjUckizpLqmTBUPl6ZxcUmIVb0QZWQeT0T$Sample URL: PII: https*3A*2F*2Ftocafootball.net*auth*cred*muowj5*james.laufman@automationanywhere.com__;JSUlLy8vLw!!BHlfX_zbyOAjqHI!zHvvcPnXBAkkLycQe5qD8UDSOTlGzeWMqwuayGo8vyctnqkCxBKd39LtgqPAZ3sR4XqqsS8gyKZjUckizpLqmTBUPl6ZxcUmIVb0QZWQeT0T$
Source: https://clickproxy.retailrocket.net/?url=https*3A*2F*2Ftocafootball.net*auth*cred*muowj5*james.laufman@automationanywhere.com__;JSUlLy8vLw!!BHlfX_zbyOAjqHI!zHvvcPnXBAkkLycQe5qD8UDSOTlGzeWMqwuayGo8vyctnqkCxBKd39LtgqPAZ3sR4XqqsS8gyKZjUckizpLqmTBUPl6ZxcUmIVb0QZWQeT0T$Sample URL: PII: https*3A*2F*2Ftocafootball.net*auth*cred*muowj5*james.laufman@automationanywhere.com__;JSUlLy8vLw!!BHlfX_zbyOAjqHI!zHvvcPnXBAkkLycQe5qD8UDSOTlGzeWMqwuayGo8vyctnqkCxBKd39LtgqPAZ3sR4XqqsS8gyKZjUckizpLqmTBUPl6ZxcUmIVb0QZWQeT0T$
Source: https://clickproxy.retailrocket.net/?url=https*3A*2F*2Ftocafootball.net*auth*cred*muowj5*james.laufman@automationanywhere.com__;JSUlLy8vLw!!BHlfX_zbyOAjqHI!zHvvcPnXBAkkLycQe5qD8UDSOTlGzeWMqwuayGo8vyctnqkCxBKd39LtgqPAZ3sR4XqqsS8gyKZjUckizpLqmTBUPl6ZxcUmIVb0QZWQeT0T$Sample URL: PII: https*3A*2F*2Ftocafootball.net*auth*cred*muowj5*james.laufman@automationanywhere.com__;JSUlLy8vLw!!BHlfX_zbyOAjqHI!zHvvcPnXBAkkLycQe5qD8UDSOTlGzeWMqwuayGo8vyctnqkCxBKd39LtgqPAZ3sR4XqqsS8gyKZjUckizpLqmTBUPl6ZxcUmIVb0QZWQeT0T$
Source: https://clickproxy.retailrocket.net/?url=https*3A*2F*2Ftocafootball.net*auth*cred*muowj5*james.laufman@automationanywhere.com__;JSUlLy8vLw!!BHlfX_zbyOAjqHI!zHvvcPnXBAkkLycQe5qD8UDSOTlGzeWMqwuayGo8vyctnqkCxBKd39LtgqPAZ3sR4XqqsS8gyKZjUckizpLqmTBUPl6ZxcUmIVb0QZWQeT0T$Sample URL: PII: https*3A*2F*2Ftocafootball.net*auth*cred*muowj5*james.laufman@automationanywhere.com__;JSUlLy8vLw!!BHlfX_zbyOAjqHI!zHvvcPnXBAkkLycQe5qD8UDSOTlGzeWMqwuayGo8vyctnqkCxBKd39LtgqPAZ3sR4XqqsS8gyKZjUckizpLqmTBUPl6ZxcUmIVb0QZWQeT0T$
Source: https://clickproxy.retailrocket.net/?url=https*3A*2F*2Ftocafootball.net*auth*cred*muowj5*james.laufman@automationanywhere.com__;JSUlLy8vLw!!BHlfX_zbyOAjqHI!zHvvcPnXBAkkLycQe5qD8UDSOTlGzeWMqwuayGo8vyctnqkCxBKd39LtgqPAZ3sR4XqqsS8gyKZjUckizpLqmTBUPl6ZxcUmIVb0QZWQeT0T$Sample URL: PII: https*3A*2F*2Ftocafootball.net*auth*cred*muowj5*james.laufman@automationanywhere.com__;JSUlLy8vLw!!BHlfX_zbyOAjqHI!zHvvcPnXBAkkLycQe5qD8UDSOTlGzeWMqwuayGo8vyctnqkCxBKd39LtgqPAZ3sR4XqqsS8gyKZjUckizpLqmTBUPl6ZxcUmIVb0QZWQeT0T$
Source: https://clickproxy.retailrocket.net/?url=https*3A*2F*2Ftocafootball.net*auth*cred*muowj5*james.laufman@automationanywhere.com__;JSUlLy8vLw!!BHlfX_zbyOAjqHI!zHvvcPnXBAkkLycQe5qD8UDSOTlGzeWMqwuayGo8vyctnqkCxBKd39LtgqPAZ3sR4XqqsS8gyKZjUckizpLqmTBUPl6ZxcUmIVb0QZWQeT0T$Sample URL: PII: https*3A*2F*2Ftocafootball.net*auth*cred*muowj5*james.laufman@automationanywhere.com__;JSUlLy8vLw!!BHlfX_zbyOAjqHI!zHvvcPnXBAkkLycQe5qD8UDSOTlGzeWMqwuayGo8vyctnqkCxBKd39LtgqPAZ3sR4XqqsS8gyKZjUckizpLqmTBUPl6ZxcUmIVb0QZWQeT0T$
Source: https://clickproxy.retailrocket.net/?url=https*3A*2F*2Ftocafootball.net*auth*cred*muowj5*james.laufman@automationanywhere.com__;JSUlLy8vLw!!BHlfX_zbyOAjqHI!zHvvcPnXBAkkLycQe5qD8UDSOTlGzeWMqwuayGo8vyctnqkCxBKd39LtgqPAZ3sR4XqqsS8gyKZjUckizpLqmTBUPl6ZxcUmIVb0QZWQeT0T$Sample URL: PII: https*3A*2F*2Ftocafootball.net*auth*cred*muowj5*james.laufman@automationanywhere.com__;JSUlLy8vLw!!BHlfX_zbyOAjqHI!zHvvcPnXBAkkLycQe5qD8UDSOTlGzeWMqwuayGo8vyctnqkCxBKd39LtgqPAZ3sR4XqqsS8gyKZjUckizpLqmTBUPl6ZxcUmIVb0QZWQeT0T$
Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.17:49706 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.204.76.112:443 -> 192.168.2.17:49712 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.204.76.112:443 -> 192.168.2.17:49713 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.17:49714 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.126.29.12:443 -> 192.168.2.17:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.5.88:443 -> 192.168.2.17:49716 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.219.0.152:443 -> 192.168.2.17:49720 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 23.56.6.64
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: unknownTCP traffic detected without corresponding DNS query: 23.204.76.112
Source: global trafficDNS traffic detected: DNS query: clickproxy.retailrocket.net
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49700
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49676 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49691 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 49680 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49677 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49691
Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.17:49706 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.204.76.112:443 -> 192.168.2.17:49712 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.204.76.112:443 -> 192.168.2.17:49713 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.17:49714 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.126.29.12:443 -> 192.168.2.17:49715 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.5.88:443 -> 192.168.2.17:49716 version: TLS 1.2
Source: unknownHTTPS traffic detected: 23.219.0.152:443 -> 192.168.2.17:49720 version: TLS 1.2
Source: classification engineClassification label: clean1.win@15/6@4/97
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://clickproxy.retailrocket.net/?url=https*3A*2F*2Ftocafootball.net*auth*cred*muowj5*james.laufman@automationanywhere.com__;JSUlLy8vLw!!BHlfX_zbyOAjqHI!zHvvcPnXBAkkLycQe5qD8UDSOTlGzeWMqwuayGo8vyctnqkCxBKd39LtgqPAZ3sR4XqqsS8gyKZjUckizpLqmTBUPl6ZxcUmIVb0QZWQeT0T$
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2108 --field-trial-handle=1776,i,11745920494594389,8939508074749307379,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2108 --field-trial-handle=1776,i,11745920494594389,8939508074749307379,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Registry Run Keys / Startup Folder
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://clickproxy.retailrocket.net/?url=https*3A*2F*2Ftocafootball.net*auth*cred*muowj5*james.laufman@automationanywhere.com__;JSUlLy8vLw!!BHlfX_zbyOAjqHI!zHvvcPnXBAkkLycQe5qD8UDSOTlGzeWMqwuayGo8vyctnqkCxBKd39LtgqPAZ3sR4XqqsS8gyKZjUckizpLqmTBUPl6ZxcUmIVb0QZWQeT0T$0%Avira URL Cloudsafe
https://clickproxy.retailrocket.net/?url=https*3A*2F*2Ftocafootball.net*auth*cred*muowj5*james.laufman@automationanywhere.com__;JSUlLy8vLw!!BHlfX_zbyOAjqHI!zHvvcPnXBAkkLycQe5qD8UDSOTlGzeWMqwuayGo8vyctnqkCxBKd39LtgqPAZ3sR4XqqsS8gyKZjUckizpLqmTBUPl6ZxcUmIVb0QZWQeT0T$0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
cl-ca3c00b0.edgecdn.world0%VirustotalBrowse
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
cl-ca3c00b0.edgecdn.world
193.17.93.93
truefalseunknown
www.google.com
142.251.35.228
truefalse
    high
    clickproxy.retailrocket.net
    unknown
    unknownfalse
      high
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      192.178.50.67
      unknownUnited States
      15169GOOGLEUSfalse
      1.1.1.1
      unknownAustralia
      13335CLOUDFLARENETUSfalse
      74.125.26.84
      unknownUnited States
      15169GOOGLEUSfalse
      192.178.50.46
      unknownUnited States
      15169GOOGLEUSfalse
      239.255.255.250
      unknownReserved
      unknownunknownfalse
      172.217.165.195
      unknownUnited States
      15169GOOGLEUSfalse
      142.251.35.228
      www.google.comUnited States
      15169GOOGLEUSfalse
      142.250.217.238
      unknownUnited States
      15169GOOGLEUSfalse
      193.17.93.93
      cl-ca3c00b0.edgecdn.worldRussian Federation
      209418ASN-KUKUAITfalse
      IP
      192.168.2.17
      192.168.2.4
      Joe Sandbox version:40.0.0 Tourmaline
      Analysis ID:1432232
      Start date and time:2024-04-26 18:01:51 +02:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:defaultwindowsinteractivecookbook.jbs
      Sample URL:https://clickproxy.retailrocket.net/?url=https*3A*2F*2Ftocafootball.net*auth*cred*muowj5*james.laufman@automationanywhere.com__;JSUlLy8vLw!!BHlfX_zbyOAjqHI!zHvvcPnXBAkkLycQe5qD8UDSOTlGzeWMqwuayGo8vyctnqkCxBKd39LtgqPAZ3sR4XqqsS8gyKZjUckizpLqmTBUPl6ZxcUmIVb0QZWQeT0T$
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:19
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • EGA enabled
      Analysis Mode:stream
      Analysis stop reason:Timeout
      Detection:CLEAN
      Classification:clean1.win@15/6@4/97
      • Exclude process from analysis (whitelisted): SIHClient.exe
      • Excluded IPs from analysis (whitelisted): 192.178.50.67, 74.125.26.84, 142.250.217.238, 34.104.35.123
      • Excluded domains from analysis (whitelisted): clients2.google.com, accounts.google.com, edgedl.me.gvt1.com, clientservices.googleapis.com, clients.l.google.com
      • Not all processes where analyzed, report is missing behavior information
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 15:02:25 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2677
      Entropy (8bit):3.995293295494092
      Encrypted:false
      SSDEEP:
      MD5:3B74BC3C4A511C8E4FA299387635BEDA
      SHA1:293C90E24DB6810DBB6272F8EF5D4D8286F5E299
      SHA-256:5C10044BAC3834034198C7DDA99936E4539A6D42D099AA84448C55DBB6D1A7B8
      SHA-512:C8852F6B5AC76E3CAC3134836CC30D2A633667A7FD000001EB874D3E7BDFBE1575297DBCD3EAB02988347FC32537771165FE652AA0F004773003DF208D1084AC
      Malicious:false
      Reputation:unknown
      Preview:L..................F.@.. ...$+.,.....(.!.......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I.XC.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.XL.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V.XL.....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V.XL............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V.XM............................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............g.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 15:02:25 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2679
      Entropy (8bit):4.007594883026273
      Encrypted:false
      SSDEEP:
      MD5:AB9839E6026D8B84D5FD9FD4147929F7
      SHA1:0A0ED6528E0209DA14627736772F8AD7AE2994A7
      SHA-256:49BE3B12876CBC575918FB87C0AC5FB600281988E7FDD72A0C879AAC30822FE5
      SHA-512:40C8F843CEE1A408EEF9C87C0FF80242C170DC5D8D68325CF1138B3567612B1787288A2771B67D5CA8DA401614E45B966708839B8D17C261C3BB30F1818F5D63
      Malicious:false
      Reputation:unknown
      Preview:L..................F.@.. ...$+.,....E.y!.......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I.XC.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.XL.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V.XL.....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V.XL............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V.XM............................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............g.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:54:41 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2693
      Entropy (8bit):4.016270944547911
      Encrypted:false
      SSDEEP:
      MD5:2DA8E3F29B07E78D252046E41D82F1EB
      SHA1:867020637F4E489B136F106D7760664A8D07820F
      SHA-256:7983E215B1A8647714AAC1935DC566B19EE8EF39980F670F3FABB935D7445F3B
      SHA-512:D2C6102D201C30974656328EAF06590D9C4D2966298797A1A8EDD38627173E16157278C4B1D9D9F750EE017BDC5D0FA02DCC743BCB54DE63032975F88E6FB992
      Malicious:false
      Reputation:unknown
      Preview:L..................F.@.. ...$+.,.....v. ;.......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I.XC.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.XL.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V.XL.....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V.XL............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VFW.N...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............g.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 15:02:25 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2681
      Entropy (8bit):4.004101356911825
      Encrypted:false
      SSDEEP:
      MD5:F40CFEE4074C6ECE5BA7EF1F8C4E5F90
      SHA1:47A578857F2DBEF4D541BE58AF2CA755C6245A84
      SHA-256:F26D43B1C74C8F7D3D83BFF644C7BB54753D77B81BE2A9F137924670EEE4A2DB
      SHA-512:6024C16BF537283C58A8DEAEB1E57292ADDA973D0C5FF07DC6EC962B1B535A1E52C0FFDFFB0CD993F92752C481FA8D491B6C441F4ECB149927962C87ED93F3A9
      Malicious:false
      Reputation:unknown
      Preview:L..................F.@.. ...$+.,....."t!.......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I.XC.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.XL.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V.XL.....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V.XL............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V.XM............................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............g.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 15:02:25 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2681
      Entropy (8bit):3.998239009976874
      Encrypted:false
      SSDEEP:
      MD5:C547F2F514482C11DF0DFCCCA15C74D6
      SHA1:B0183D0035DDCA3C042E2A8F0CC86D46D89D8114
      SHA-256:2183D7DFD77051E27FFB6190CD448BF4E9CC0797797EF5BD2074F14BD925C061
      SHA-512:48A1E0C3BBF28E5FA947D2126EFAA4A443829AEAA8A5A58E946C27F36214A918F651DF5F5396B89A88767D4E66AB0EB083C85475B9934DF60D3579AD41DE4703
      Malicious:false
      Reputation:unknown
      Preview:L..................F.@.. ...$+.,....E..!.......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I.XC.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.XL.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V.XL.....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V.XL............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V.XM............................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............g.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      Process:C:\Program Files\Google\Chrome\Application\chrome.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 15:02:25 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
      Category:dropped
      Size (bytes):2683
      Entropy (8bit):4.00755737161504
      Encrypted:false
      SSDEEP:
      MD5:B4FB3A98640204A1AD5B91986E30D010
      SHA1:395D92DF14C515D27B04097DF88F1E27945D32C1
      SHA-256:8CAFC6CB390FEAB48B3AC7F0ACD79966A29FD5C0C3D5E0AF4319109AF14C905E
      SHA-512:0AC8FA4AC3B3FAD9FA1286EC65BFFD4B24B21D230D2CC8147BA56D27C6254B7619E2FD58AB2EC4B78CD45C71631A4541759374E32BBFCD917C0B7D815EB69614
      Malicious:false
      Reputation:unknown
      Preview:L..................F.@.. ...$+.,....@.j!.......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.I.XC.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.XL.....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.V.XL.....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.V.XL............................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.V.XM............................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i............g.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
      No static file info