Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/

Overview

General Information

Sample URL:https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/
Analysis ID:1589273
Infos:

Detection

Score:68
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

AI detected phishing page
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
AI detected landing page (webpage, office document or email)
Form action URLs do not match main URL
HTML body contains low number of good links
Invalid T&C link found

Classification

  • System is w10x64
  • chrome.exe (PID: 5332 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
    • chrome.exe (PID: 7084 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2564 --field-trial-handle=2520,i,14649947336694683425,5017290247439971393,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • chrome.exe (PID: 6628 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/Avira URL Cloud: detection malicious, Label: phishing
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/styles/style.cssAvira URL Cloud: Label: phishing
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/img/doc.pngAvira URL Cloud: Label: phishing
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/img/meta-logo-grey.pngAvira URL Cloud: Label: phishing
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/styles/bootstrap.min.cssAvira URL Cloud: Label: phishing
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/img/save_img.pngAvira URL Cloud: Label: phishing
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/img/2FA.pngAvira URL Cloud: Label: phishing
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/img/no_avatar.pngAvira URL Cloud: Label: phishing
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/img/phone.pngAvira URL Cloud: Label: phishing
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/img/dir.pngAvira URL Cloud: Label: phishing
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/ico.icoAvira URL Cloud: Label: phishing
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/img/block_2.pngAvira URL Cloud: Label: phishing
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/img/star.pngAvira URL Cloud: Label: phishing
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/img/fb_round_logo.pngAvira URL Cloud: Label: phishing

Phishing

barindex
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/Joe Sandbox AI: Score: 9 Reasons: The brand 'Meta' is well-known and is associated with the domain 'meta.com'., The URL 'page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com' does not match the legitimate domain 'meta.com'., The URL uses a subdomain structure that is common in phishing attempts, with multiple hyphenated words that are not typically associated with Meta's official domains., The domain 'amplifyapp.com' is a legitimate domain used by AWS Amplify, a cloud service provider, which can host various applications, but it is not directly associated with Meta., The presence of input fields requesting personal information such as 'Full Name', 'Personal Email', 'Business Email', 'Mobile phone number', and 'Facebook Page Name' is typical in phishing sites attempting to gather sensitive information. DOM: 1.1.pages.csv
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/Joe Sandbox AI: Page contains button: 'Appeal Submission Review' Source: '1.0.pages.csv'
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/HTTP Parser: Form action: https://facebook.com/ amplifyapp facebook
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/HTTP Parser: Form action: https://facebook.com/ amplifyapp facebook
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/HTTP Parser: Form action: https://facebook.com/ amplifyapp facebook
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/HTTP Parser: Number of links: 0
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/HTTP Parser: Invalid link: Privacy Policy
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/HTTP Parser: Invalid link: Terms of use
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/HTTP Parser: Invalid link: Privacy Policy
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/HTTP Parser: Invalid link: Community Payment Terms
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/HTTP Parser: Invalid link: Commercial terms
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/HTTP Parser: Invalid link: Privacy Policy
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/HTTP Parser: Invalid link: Terms of use
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/HTTP Parser: Invalid link: Privacy Policy
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/HTTP Parser: Invalid link: Community Payment Terms
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/HTTP Parser: Invalid link: Commercial terms
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/HTTP Parser: Invalid link: Privacy Policy
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/HTTP Parser: Invalid link: Terms of use
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/HTTP Parser: Invalid link: Privacy Policy
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/HTTP Parser: Invalid link: Community Payment Terms
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/HTTP Parser: Invalid link: Commercial terms
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/HTTP Parser: <input type="password" .../> found
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/HTTP Parser: No <meta name="author".. found
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/HTTP Parser: No <meta name="author".. found
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/HTTP Parser: No <meta name="author".. found
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/HTTP Parser: No <meta name="copyright".. found
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/HTTP Parser: No <meta name="copyright".. found
Source: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/HTTP Parser: No <meta name="copyright".. found
Source: unknownHTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:49718 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:49776 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:49865 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:49990 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:50028 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /styles/bootstrap.min.css HTTP/1.1Host: page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /styles/style.css HTTP/1.1Host: page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/block_2.png HTTP/1.1Host: page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/no_avatar.png HTTP/1.1Host: page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/save_img.png HTTP/1.1Host: page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /v2/free/self/ HTTP/1.1Host: api.db-ip.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Origin: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.comSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/doc.png HTTP/1.1Host: page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/meta-logo-grey.png HTTP/1.1Host: page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/fb_round_logo.png HTTP/1.1Host: page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/2FA.png HTTP/1.1Host: page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/phone.png HTTP/1.1Host: page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/no_avatar.png HTTP/1.1Host: page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/block_2.png HTTP/1.1Host: page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /v2/free/self/ HTTP/1.1Host: api.db-ip.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/save_img.png HTTP/1.1Host: page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/star.png HTTP/1.1Host: page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/doc.png HTTP/1.1Host: page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/dir.png HTTP/1.1Host: page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/meta-logo-grey.png HTTP/1.1Host: page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/2FA.png HTTP/1.1Host: page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/fb_round_logo.png HTTP/1.1Host: page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/phone.png HTTP/1.1Host: page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/star.png HTTP/1.1Host: page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ico.ico HTTP/1.1Host: page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /img/dir.png HTTP/1.1Host: page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ico.ico HTTP/1.1Host: page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com
Source: global trafficDNS traffic detected: DNS query: api.db-ip.com
Source: chromecache_77.3.dr, chromecache_58.3.dr, chromecache_54.3.dr, chromecache_64.3.drString found in binary or memory: http://www.gimp.org/xmp/
Source: chromecache_66.3.drString found in binary or memory: https://ajax.googleapis.com/ajax/libs/jquery/3.7.1/jquery.min.js
Source: chromecache_66.3.drString found in binary or memory: https://api.db-ip.com/v2/free/self/
Source: chromecache_66.3.drString found in binary or memory: https://api.emailjs.com/api/v1.0/email/send
Source: chromecache_78.3.drString found in binary or memory: https://getbootstrap.com/)
Source: chromecache_78.3.drString found in binary or memory: https://github.com/twbs/bootstrap/blob/main/LICENSE)
Source: chromecache_66.3.drString found in binary or memory: https://popper.js.org)
Source: unknownNetwork traffic detected: HTTP traffic on port 49865 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49865
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49784
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49990 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50028
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50027
Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49777 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
Source: unknownNetwork traffic detected: HTTP traffic on port 49790 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 49783 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50028 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49990
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49790
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50027 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49775 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownHTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:49718 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:49776 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:49865 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:49990 version: TLS 1.2
Source: unknownHTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:50028 version: TLS 1.2
Source: classification engineClassification label: mal68.phis.win@16/47@10/7
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2564 --field-trial-handle=2520,i,14649947336694683425,5017290247439971393,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2564 --field-trial-handle=2520,i,14649947336694683425,5017290247439971393,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Browser Extensions
1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/styles/style.css100%Avira URL Cloudphishing
https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/img/doc.png100%Avira URL Cloudphishing
https://api.emailjs.com/api/v1.0/email/send0%Avira URL Cloudsafe
https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/img/meta-logo-grey.png100%Avira URL Cloudphishing
https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/styles/bootstrap.min.css100%Avira URL Cloudphishing
https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/img/save_img.png100%Avira URL Cloudphishing
https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/img/2FA.png100%Avira URL Cloudphishing
https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/img/no_avatar.png100%Avira URL Cloudphishing
https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/img/phone.png100%Avira URL Cloudphishing
https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/img/dir.png100%Avira URL Cloudphishing
https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/ico.ico100%Avira URL Cloudphishing
https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/img/block_2.png100%Avira URL Cloudphishing
https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/img/star.png100%Avira URL Cloudphishing
https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/img/fb_round_logo.png100%Avira URL Cloudphishing
NameIPActiveMaliciousAntivirus DetectionReputation
api.db-ip.com
172.67.75.166
truefalse
    high
    www.google.com
    172.217.18.4
    truefalse
      high
      page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com
      18.172.112.14
      truetrue
        unknown
        NameMaliciousAntivirus DetectionReputation
        https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/img/dir.pngtrue
        • Avira URL Cloud: phishing
        unknown
        https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/img/no_avatar.pngtrue
        • Avira URL Cloud: phishing
        unknown
        https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/img/doc.pngtrue
        • Avira URL Cloud: phishing
        unknown
        https://api.db-ip.com/v2/free/self/false
          high
          https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/img/2FA.pngtrue
          • Avira URL Cloud: phishing
          unknown
          https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/img/meta-logo-grey.pngtrue
          • Avira URL Cloud: phishing
          unknown
          https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/true
            unknown
            https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/img/phone.pngtrue
            • Avira URL Cloud: phishing
            unknown
            https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/styles/bootstrap.min.csstrue
            • Avira URL Cloud: phishing
            unknown
            https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/styles/style.csstrue
            • Avira URL Cloud: phishing
            unknown
            https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/img/save_img.pngtrue
            • Avira URL Cloud: phishing
            unknown
            https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/ico.icotrue
            • Avira URL Cloud: phishing
            unknown
            https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/img/star.pngtrue
            • Avira URL Cloud: phishing
            unknown
            https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/img/block_2.pngtrue
            • Avira URL Cloud: phishing
            unknown
            https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/img/fb_round_logo.pngtrue
            • Avira URL Cloud: phishing
            unknown
            NameSourceMaliciousAntivirus DetectionReputation
            https://api.emailjs.com/api/v1.0/email/sendchromecache_66.3.drfalse
            • Avira URL Cloud: safe
            unknown
            https://github.com/twbs/bootstrap/blob/main/LICENSE)chromecache_78.3.drfalse
              high
              http://www.gimp.org/xmp/chromecache_77.3.dr, chromecache_58.3.dr, chromecache_54.3.dr, chromecache_64.3.drfalse
                high
                https://getbootstrap.com/)chromecache_78.3.drfalse
                  high
                  https://popper.js.org)chromecache_66.3.drfalse
                    high
                    • No. of IPs < 25%
                    • 25% < No. of IPs < 50%
                    • 50% < No. of IPs < 75%
                    • 75% < No. of IPs
                    IPDomainCountryFlagASNASN NameMalicious
                    18.172.112.14
                    page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.comUnited States
                    3MIT-GATEWAYSUStrue
                    172.217.18.4
                    www.google.comUnited States
                    15169GOOGLEUSfalse
                    172.67.75.166
                    api.db-ip.comUnited States
                    13335CLOUDFLARENETUSfalse
                    104.26.4.15
                    unknownUnited States
                    13335CLOUDFLARENETUSfalse
                    239.255.255.250
                    unknownReserved
                    unknownunknownfalse
                    IP
                    192.168.2.4
                    192.168.2.6
                    Joe Sandbox version:42.0.0 Malachite
                    Analysis ID:1589273
                    Start date and time:2025-01-12 00:18:18 +01:00
                    Joe Sandbox product:CloudBasic
                    Overall analysis duration:0h 3m 25s
                    Hypervisor based Inspection enabled:false
                    Report type:full
                    Cookbook file name:browseurl.jbs
                    Sample URL:https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/
                    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                    Number of analysed new started processes analysed:7
                    Number of new started drivers analysed:0
                    Number of existing processes analysed:0
                    Number of existing drivers analysed:0
                    Number of injected processes analysed:0
                    Technologies:
                    • HCA enabled
                    • EGA enabled
                    • AMSI enabled
                    Analysis Mode:default
                    Analysis stop reason:Timeout
                    Detection:MAL
                    Classification:mal68.phis.win@16/47@10/7
                    EGA Information:Failed
                    HCA Information:
                    • Successful, ratio: 100%
                    • Number of executed functions: 0
                    • Number of non-executed functions: 0
                    • Exclude process from analysis (whitelisted): WMIADAP.exe, SIHClient.exe, svchost.exe
                    • Excluded IPs from analysis (whitelisted): 142.250.186.99, 142.250.186.174, 108.177.15.84, 142.250.74.206, 142.250.184.206, 172.217.18.110, 142.250.186.74, 172.217.18.106, 172.217.16.202, 216.58.206.74, 142.250.184.234, 142.250.185.138, 142.250.185.202, 142.250.186.138, 142.250.184.202, 142.250.185.106, 142.250.185.170, 142.250.185.74, 172.217.16.138, 216.58.212.138, 142.250.186.42, 172.217.18.10, 142.250.181.234, 192.229.221.95, 142.250.186.78, 172.217.16.206, 142.250.184.238, 142.250.185.206, 199.232.210.172, 142.250.186.67, 216.58.206.78, 142.250.181.238, 13.107.246.45, 2.23.242.162, 52.149.20.212
                    • Excluded domains from analysis (whitelisted): client.wns.windows.com, fs.microsoft.com, accounts.google.com, content-autofill.googleapis.com, otelrules.azureedge.net, slscr.update.microsoft.com, ajax.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com
                    • Not all processes where analyzed, report is missing behavior information
                    • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                    • VT rate limit hit for: https://page-helpdesk-review-center.d21l3gt8ix4jpi.amplifyapp.com/
                    No simulations