Click to jump to signature section
Source: Yara match | File source: dropped/chromecache_63, type: DROPPED |
Source: Yara match | File source: 0.3.id.script.csv, type: HTML |
Source: Yara match | File source: 0.4.id.script.csv, type: HTML |
Source: Yara match | File source: 3.2.pages.csv, type: HTML |
Source: Yara match | File source: 0.3.id.script.csv, type: HTML |
Source: Yara match | File source: 0.4.id.script.csv, type: HTML |
Source: Yara match | File source: 3.2.pages.csv, type: HTML |
Source: 0.4.id.script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: https://g8c4.aldemeres.com/zBuFL/... This script demonstrates high-risk behavior by using the `eval()` function to execute dynamic code. This allows for the potential execution of malicious code, which poses a significant security risk. Additionally, the script uses obfuscated code, making it difficult to analyze and understand the true intent. Overall, this script should be considered highly suspicious and potentially malicious. |
Source: 0.2.id.script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: https://g8c4.aldemeres.com/zBuFL/... This script demonstrates several high-risk behaviors, including dynamic code execution, data exfiltration, and obfuscated code/URLs. The use of `atob` and `decodeURIComponent` to decode and execute remote code is a clear indicator of malicious intent. Additionally, the script appears to be sending user data to an untrusted domain, which poses a significant risk of data theft or other malicious activities. Overall, this script exhibits a high level of suspicion and should be treated as a potential security threat. |
Source: 0.3.id.script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: https://g8c4.aldemeres.com/zBuFL/... This script demonstrates high-risk behaviors, including dynamic code execution through the use of `eval()` and the `Proxy` object. It also appears to be heavily obfuscated, which is a common tactic used to conceal malicious intent. The combination of these factors suggests a high likelihood of malicious activity, potentially involving data exfiltration or other harmful actions. |
Source: https://www.bing.com/ck/a?!&&p=03393a15f6ac2f3e18e9a53e23664491f88e763b1b1f8dfe8ed088a707d16975JmltdHM9MTc0MTA0NjQwMA&ptn=3&ver=2&hsh=4&fclid=2041c032-4fae-62e3-26ce-d55e4e1e63be&u=a1aHR0cHM6Ly93d3cuc3VubmlhY2FkZW15LmNvbS90YWcvcXVyYW4tcGFkaG5hLXNpa2hlLw&ntb=1 | HTTP Parser: No favicon |
Source: https://www.sunniacademy.com/tag/quran-padhna-sikhe/ | HTTP Parser: No favicon |
Source: https://g8c4.aldemeres.com/zBuFL/ | HTTP Parser: No favicon |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.10 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.160.2 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.160.2 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.160.2 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.160.2 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.160.2 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.160.2 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.160.2 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.160.2 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.160.2 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.30.131.245 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.190.160.2 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.30.131.245 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.199.214.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.199.214.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.199.214.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.199.214.10 |
Source: global traffic | HTTP traffic detected: GET /tag/quran-padhna-sikhe/ HTTP/1.1Host: www.sunniacademy.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://www.bing.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /zBuFL/ HTTP/1.1Host: g8c4.aldemeres.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://www.sunniacademy.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /favicon.ico HTTP/1.1Host: g8c4.aldemeres.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://g8c4.aldemeres.com/zBuFL/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: XSRF-TOKEN=eyJpdiI6IlozNlAxL2J6YzdVeEphWWx3aFF0aFE9PSIsInZhbHVlIjoic09IMU9TM2Z5aEJvaW9hYzF4RXc4OHBnVjh0YnJMMGNxL0RwVFJaalEwbGkzUmRJK1FsVlMrbjN6eTg5eFdXSkhONXBjTnM5aDd3S2NQSWFBbnY1bFF2NU1IbmRDRy9qdDVYZUhhRm0zM05YL2VJWWIxeXlkbDY5U05tSUN2R1MiLCJtYWMiOiJkZWE3ZTEyMGRjNGQxMjYwOTJmY2VmNzUzMWVkN2RlZGRmMjRkMTFiYzZjMjg3YWMyOTFhMzdmZWJmOTgyOTI3IiwidGFnIjoiIn0%3D; laravel_session=eyJpdiI6InQzKzlUVytnVlZxQXZ1NG83L3V6UHc9PSIsInZhbHVlIjoiRVVPek9iUGhzRHRhRGRTYkRWWVNndko2N1ZuRS84eVduRjQ4bzBNQXViR01FOWVyTXI2UGZCcDJUWElFWkpvZ3l3L0pMa0xlSUpKSWVrOCtEOVRiUFFKUHNESE43d2tkR2RjcG95ZnVoYTA2ZVBqRjl1VFNRcGY0Um4vc3Jub3MiLCJtYWMiOiIzZWI5NDhkMTQ1NmNiZDExMjkyYjg4OWM2MWZjNzUyN2YwNjIwYzg2Y2FhNTFhOGM2ZTg2MGVlY2M5YTMxNzUyIiwidGFnIjoiIn0%3D |
Source: global traffic | DNS traffic detected: DNS query: www.sunniacademy.com |
Source: global traffic | DNS traffic detected: DNS query: g8c4.aldemeres.com |
Source: global traffic | DNS traffic detected: DNS query: www.google.com |
Source: global traffic | DNS traffic detected: DNS query: a.nel.cloudflare.com |
Source: unknown | HTTP traffic detected: POST /report/v4?s=3Jyejs1ptB8p5DFcqwDCiadSLUk6ujT6dKjyJiObYCd2uQzy9Ph0%2BlkY3OTB72NkMAvNDchhq9bd7v5o68nqkxbl4P6kKZ4yYUm57OsWol2MSaFXnKaI9lDG5IHG8w%3D%3D HTTP/1.1Host: a.nel.cloudflare.comConnection: keep-aliveContent-Length: 430Content-Type: application/reports+jsonUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: HTTP/1.1 404 Not FoundDate: Wed, 05 Mar 2025 13:40:40 GMTContent-Type: text/html; charset=UTF-8Transfer-Encoding: chunkedConnection: closeAge: 4170Cache-Control: max-age=14400Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=3Jyejs1ptB8p5DFcqwDCiadSLUk6ujT6dKjyJiObYCd2uQzy9Ph0%2BlkY3OTB72NkMAvNDchhq9bd7v5o68nqkxbl4P6kKZ4yYUm57OsWol2MSaFXnKaI9lDG5IHG8w%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Vary: Accept-Encodingalt-svc: h3=":443"; ma=86400server-timing: cfL4;desc="?proto=TCP&rtt=21279&min_rtt=20451&rtt_var=1353&sent=320&recv=109&lost=0&retrans=0&sent_bytes=335480&recv_bytes=13829&delivery_rate=2239202&cwnd=258&unsent_bytes=0&cid=cdf2c7079ba4b2fc&ts=2776&x=0"CF-Cache-Status: HITServer: cloudflareCF-RAY: 91ba06c9fe1341ba-EWRserver-timing: cfL4;desc="?proto=TCP&rtt=1746&min_rtt=1729&rtt_var=683&sent=6&recv=8&lost=0&retrans=0&sent_bytes=2832&recv_bytes=1899&delivery_rate=1564006&cwnd=220&unsent_bytes=0&cid=ec7311325821c16b&ts=1049&x=0" |
Source: unknown | Network traffic detected: HTTP traffic on port 49758 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49765 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49764 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49786 |
Source: unknown | Network traffic detected: HTTP traffic on port 49779 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49784 |
Source: unknown | Network traffic detected: HTTP traffic on port 49678 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49702 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49989 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49764 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49770 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49701 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49758 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49757 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49779 |
Source: unknown | Network traffic detected: HTTP traffic on port 49757 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49698 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49698 |
Source: unknown | Network traffic detected: HTTP traffic on port 49673 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49771 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49770 |
Source: unknown | Network traffic detected: HTTP traffic on port 49703 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49786 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49784 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49765 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49989 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49703 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49702 |
Source: unknown | Network traffic detected: HTTP traffic on port 49771 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49701 |
Source: classification engine | Classification label: mal68.phis.win@19/9@8/148 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps |
Source: unknown | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=1968,i,15708862942189160107,8136080379522309171,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 |
Source: unknown | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.bing.com/ck/a?!&&p=03393a15f6ac2f3e18e9a53e23664491f88e763b1b1f8dfe8ed088a707d16975JmltdHM9MTc0MTA0NjQwMA&ptn=3&ver=2&hsh=4&fclid=2041c032-4fae-62e3-26ce-d55e4e1e63be&u=a1aHR0cHM6Ly93d3cuc3VubmlhY2FkZW15LmNvbS90YWcvcXVyYW4tcGFkaG5hLXNpa2hlLw&ntb=1" |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=1968,i,15708862942189160107,8136080379522309171,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: Window Recorder | Window detected: More than 3 window changes detected |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk |