Click to jump to signature section
Source: Yara match | File source: 0.4..script.csv, type: HTML |
Source: Yara match | File source: 0.14..script.csv, type: HTML |
Source: Yara match | File source: 0.2.pages.csv, type: HTML |
Source: Yara match | File source: 0.3.pages.csv, type: HTML |
Source: Yara match | File source: 0.4.pages.csv, type: HTML |
Source: Yara match | File source: 0.6.pages.csv, type: HTML |
Source: 0.65.d.script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: ... This script demonstrates high-risk behaviors, including dynamic code execution through the use of the `Function` constructor and the ability to modify the `sRandomBlob` property, which could potentially be used for data exfiltration or other malicious purposes. The script is also heavily obfuscated, making it difficult to analyze and understand its true intent. These factors contribute to a high-risk assessment. |
Source: 0.14..script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: https://cpatronal.cardosonettoyages.website/?OsiC1... This script exhibits several high-risk behaviors, including dynamic code execution, data exfiltration, and the use of obfuscated URLs. The script appears to be redirecting users to a suspicious login page and collecting sensitive user data, which is a clear indication of malicious intent. The combination of these factors results in a high-risk score. |
Source: https://centrepatronal.blob.core.windows.net/heberhard/centrepatronal.html | HTTP Parser: Form action: https://cpatronal.cardosonettoyages.website/common/login windows cardosonettoyages |
Source: https://centrepatronal.blob.core.windows.net/heberhard/centrepatronal.html | HTTP Parser: Form action: https://cpatronal.cardosonettoyages.website/common/login windows cardosonettoyages |
Source: https://centrepatronal.blob.core.windows.net/heberhard/centrepatronal.html | HTTP Parser: Number of links: 0 |
Source: https://centrepatronal.blob.core.windows.net/heberhard/centrepatronal.html | HTTP Parser: Base64 decoded: b-ru%7D~tJ00hqoz%7D~tbu0dcse%7Ct%7Dph%7B~p%C2%82mxgt%3F%C2%84fn%7Bt%7Bm0H_t%7BD2BSQSWZ9%235.%23%7Bgsn~k%2C3/g%23jr%7Dq%C2%88%3Exbsi0~xzpu%7F%22%3D%21/bpr~%C2%865ux~%3E~bwvxozt~t%235.%23c%7D%7D%7C%C2%883q~ki%7D%7C%2C%3D%20%23bq%7D%7D%C2%870zosr~uu%23%3D-%2... |
Source: https://centrepatronal.blob.core.windows.net/heberhard/centrepatronal.html | HTTP Parser: Title: Sign in to your account does not match URL |
Source: https://centrepatronal.blob.core.windows.net/heberhard/centrepatronal.html | HTTP Parser: Iframe src: https://d50682cb-50824fa2.cardosonettoyages.website/Prefetch/Prefetch.aspx |
Source: https://centrepatronal.blob.core.windows.net/heberhard/centrepatronal.html | HTTP Parser: Iframe src: https://d50682cb-50824fa2.cardosonettoyages.website/Prefetch/Prefetch.aspx |
Source: https://centrepatronal.blob.core.windows.net/heberhard/centrepatronal.html | HTTP Parser: <input type="password" .../> found |
Source: https://centrepatronal.blob.core.windows.net/heberhard/centrepatronal.html | HTTP Parser: No favicon |
Source: https://centrepatronal.blob.core.windows.net/heberhard/centrepatronal.html | HTTP Parser: No favicon |
Source: https://centrepatronal.blob.core.windows.net/heberhard/centrepatronal.html | HTTP Parser: No favicon |
Source: https://centrepatronal.blob.core.windows.net/heberhard/centrepatronal.html | HTTP Parser: No favicon |
Source: https://centrepatronal.blob.core.windows.net/heberhard/centrepatronal.html | HTTP Parser: No favicon |
Source: https://centrepatronal.blob.core.windows.net/heberhard/centrepatronal.html | HTTP Parser: No favicon |
Source: https://centrepatronal.blob.core.windows.net/heberhard/centrepatronal.html | HTTP Parser: No <meta name="author".. found |
Source: https://centrepatronal.blob.core.windows.net/heberhard/centrepatronal.html | HTTP Parser: No <meta name="author".. found |
Source: https://centrepatronal.blob.core.windows.net/heberhard/centrepatronal.html | HTTP Parser: No <meta name="author".. found |
Source: https://centrepatronal.blob.core.windows.net/heberhard/centrepatronal.html | HTTP Parser: No <meta name="copyright".. found |
Source: https://centrepatronal.blob.core.windows.net/heberhard/centrepatronal.html | HTTP Parser: No <meta name="copyright".. found |
Source: https://centrepatronal.blob.core.windows.net/heberhard/centrepatronal.html | HTTP Parser: No <meta name="copyright".. found |
Source: chrome.exe | Memory has grown: Private usage: 8MB later: 37MB |
Source: global traffic | TCP traffic: 192.168.2.16:53253 -> 1.1.1.1:53 |
Source: global traffic | TCP traffic: 192.168.2.16:53253 -> 1.1.1.1:53 |
Source: global traffic | TCP traffic: 192.168.2.16:53253 -> 1.1.1.1:53 |
Source: global traffic | TCP traffic: 192.168.2.16:53253 -> 1.1.1.1:53 |
Source: global traffic | TCP traffic: 192.168.2.16:53253 -> 1.1.1.1:53 |
Source: global traffic | TCP traffic: 192.168.2.16:53253 -> 1.1.1.1:53 |
Source: global traffic | TCP traffic: 192.168.2.16:53253 -> 1.1.1.1:53 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.182.143.211 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.182.143.211 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.182.143.211 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.182.143.211 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.182.143.211 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.182.143.211 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.182.143.211 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 199.232.214.172 |
Source: unknown | TCP traffic detected without corresponding DNS query: 142.250.186.131 |
Source: unknown | TCP traffic detected without corresponding DNS query: 199.232.214.172 |
Source: unknown | TCP traffic detected without corresponding DNS query: 142.250.186.131 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.17.190.73 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.31.69 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.17.190.73 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.31.69 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: global traffic | DNS traffic detected: DNS query: cpatronal.cardosonettoyages.website |
Source: global traffic | DNS traffic detected: DNS query: www.google.com |
Source: global traffic | DNS traffic detected: DNS query: 72a9db00-50824fa2.cardosonettoyages.website |
Source: global traffic | DNS traffic detected: DNS query: 0a2f192d-50824fa2.cardosonettoyages.website |
Source: global traffic | DNS traffic detected: DNS query: l1ve.cardosonettoyages.website |
Source: global traffic | DNS traffic detected: DNS query: d50682cb-50824fa2.cardosonettoyages.website |
Source: global traffic | DNS traffic detected: DNS query: 6758f79f-50824fa2.cardosonettoyages.website |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49721 |
Source: unknown | Network traffic detected: HTTP traffic on port 49731 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49712 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49729 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49717 |
Source: unknown | Network traffic detected: HTTP traffic on port 49713 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49738 |
Source: unknown | Network traffic detected: HTTP traffic on port 49717 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49737 |
Source: unknown | Network traffic detected: HTTP traffic on port 53263 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49713 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49712 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49734 |
Source: unknown | Network traffic detected: HTTP traffic on port 49738 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49732 |
Source: unknown | Network traffic detected: HTTP traffic on port 49734 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49731 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49730 |
Source: unknown | Network traffic detected: HTTP traffic on port 49732 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49730 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49694 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49694 |
Source: unknown | Network traffic detected: HTTP traffic on port 49679 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 53257 |
Source: unknown | Network traffic detected: HTTP traffic on port 49724 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49671 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49728 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 53257 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49721 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49723 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 53264 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 53263 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 53262 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49729 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49728 |
Source: unknown | Network traffic detected: HTTP traffic on port 53262 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49724 |
Source: unknown | Network traffic detected: HTTP traffic on port 49737 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 53264 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49723 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Windows\SystemTemp\scoped_dir6232_2017771118 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping6232_2010104423 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping6232_2010104423\Google.Widevine.CDM.dll |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping6232_2010104423\manifest.json |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping6232_2010104423\_metadata\ |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping6232_2010104423\_metadata\verified_contents.json |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping6232_2010104423\manifest.fingerprint |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Windows\SystemTemp\scoped_dir6232_1685396563 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File deleted: C:\Windows\SystemTemp\scoped_dir6232_2017771118 |
Source: classification engine | Classification label: mal52.phis.win@24/4@18/113 |
Source: unknown | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2072,i,11883520060479385369,1920324618307650223,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2080 /prefetch:3 |
Source: unknown | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://centrepatronal.blob.core.windows.net/heberhard/centrepatronal.html" |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2072,i,11883520060479385369,1920324618307650223,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2080 /prefetch:3 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping6232_2010104423\Google.Widevine.CDM.dll | Jump to dropped file |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Windows\SystemTemp\chrome_Unpacker_BeginUnzipping6232_2010104423\Google.Widevine.CDM.dll | Jump to dropped file |