Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://kneegard.com

Overview

General Information

Sample URL:http://kneegard.com
Analysis ID:1504868
Infos:

Detection

Score:22
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Phishing site detected (based on image similarity)
Detected non-DNS traffic on DNS port
Found iframes
HTML title does not match URL
Stores files to the Windows start menu directory

Classification

  • System is w10x64
  • chrome.exe (PID: 2104 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 4180 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1976 --field-trial-handle=1884,i,5789691665587422594,12756250204531100792,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6048 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://kneegard.com" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

Phishing

barindex
Source: https://www.kneegard.com/crm.asp?action=contactusMatcher: Found strong image similarity, brand: GOOGLE
Source: https://www.kneegard.com/crm.asp?action=contactusHTTP Parser: Iframe src: https://www.google.com/maps/embed?pb=!1m14!1m8!1m3!1d12853.509910764415!2d-92.3732626!3d36.3516346!3m2!1i1024!2i768!4f13.1!3m3!1m2!1s0x87d1dbdcee407357%3A0xbd2a7de0dc8aa369!2sKneegard%20Workwear!5e0!3m2!1sen!2sin!4v1721025018433!5m2!1sen!2sin
Source: https://www.kneegard.com/crm.asp?action=contactusHTTP Parser: Iframe src: https://www.google.com/maps/embed?pb=!1m14!1m8!1m3!1d12853.509910764415!2d-92.3732626!3d36.3516346!3m2!1i1024!2i768!4f13.1!3m3!1m2!1s0x87d1dbdcee407357%3A0xbd2a7de0dc8aa369!2sKneegard%20Workwear!5e0!3m2!1sen!2sin!4v1721025018433!5m2!1sen!2sin
Source: https://www.kneegard.com/clearence-.htmlHTTP Parser: Title: Clearance does not match URL
Source: https://www.kneegard.com/canvas.htmlHTTP Parser: Title: Canvas does not match URL
Source: https://www.kneegard.com/About-Us_ep_7.htmlHTTP Parser: Title: About Us! does not match URL
Source: https://www.kneegard.com/myaccount.aspHTTP Parser: <input type="password" .../> found
Source: https://www.kneegard.com/HTTP Parser: No favicon
Source: https://www.kneegard.com/HTTP Parser: No favicon
Source: https://www.kneegard.com/knee-pads.htmlHTTP Parser: No favicon
Source: https://www.kneegard.com/clearence-.htmlHTTP Parser: No favicon
Source: https://www.kneegard.com/belts.htmlHTTP Parser: No favicon
Source: https://www.kneegard.com/Shorts_c_27.htmlHTTP Parser: No favicon
Source: https://www.kneegard.com/canvas.htmlHTTP Parser: No favicon
Source: https://www.kneegard.com/Jeans_c_29.htmlHTTP Parser: No favicon
Source: https://www.kneegard.com/About-Us_ep_7.htmlHTTP Parser: No favicon
Source: https://www.kneegard.com/myaccount.aspHTTP Parser: No favicon
Source: https://www.kneegard.com/crm.asp?action=contactusHTTP Parser: No favicon
Source: https://www.kneegard.com/crm.asp?action=contactusHTTP Parser: No favicon
Source: https://www.kneegard.com/crm.asp?action=contactusHTTP Parser: No favicon
Source: https://www.kneegard.com/crm.asp?action=contactusHTTP Parser: No favicon
Source: https://www.kneegard.com/crm.asp?action=contactusHTTP Parser: No favicon
Source: https://www.kneegard.com/crm.asp?action=contactusHTTP Parser: No favicon
Source: https://www.kneegard.com/HTTP Parser: No <meta name="author".. found
Source: https://www.kneegard.com/HTTP Parser: No <meta name="author".. found
Source: https://www.kneegard.com/knee-pads.htmlHTTP Parser: No <meta name="author".. found
Source: https://www.kneegard.com/clearence-.htmlHTTP Parser: No <meta name="author".. found
Source: https://www.kneegard.com/belts.htmlHTTP Parser: No <meta name="author".. found
Source: https://www.kneegard.com/Shorts_c_27.htmlHTTP Parser: No <meta name="author".. found
Source: https://www.kneegard.com/canvas.htmlHTTP Parser: No <meta name="author".. found
Source: https://www.kneegard.com/Jeans_c_29.htmlHTTP Parser: No <meta name="author".. found
Source: https://www.kneegard.com/About-Us_ep_7.htmlHTTP Parser: No <meta name="author".. found
Source: https://www.kneegard.com/myaccount.aspHTTP Parser: No <meta name="author".. found
Source: https://www.kneegard.com/crm.asp?action=contactusHTTP Parser: No <meta name="author".. found
Source: https://www.kneegard.com/crm.asp?action=contactusHTTP Parser: No <meta name="author".. found
Source: https://www.kneegard.com/HTTP Parser: No <meta name="copyright".. found
Source: https://www.kneegard.com/HTTP Parser: No <meta name="copyright".. found
Source: https://www.kneegard.com/knee-pads.htmlHTTP Parser: No <meta name="copyright".. found
Source: https://www.kneegard.com/clearence-.htmlHTTP Parser: No <meta name="copyright".. found
Source: https://www.kneegard.com/belts.htmlHTTP Parser: No <meta name="copyright".. found
Source: https://www.kneegard.com/Shorts_c_27.htmlHTTP Parser: No <meta name="copyright".. found
Source: https://www.kneegard.com/canvas.htmlHTTP Parser: No <meta name="copyright".. found
Source: https://www.kneegard.com/Jeans_c_29.htmlHTTP Parser: No <meta name="copyright".. found
Source: https://www.kneegard.com/About-Us_ep_7.htmlHTTP Parser: No <meta name="copyright".. found
Source: https://www.kneegard.com/myaccount.aspHTTP Parser: No <meta name="copyright".. found
Source: https://www.kneegard.com/crm.asp?action=contactusHTTP Parser: No <meta name="copyright".. found
Source: https://www.kneegard.com/crm.asp?action=contactusHTTP Parser: No <meta name="copyright".. found