Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Copy of Cheque.html

Overview

General Information

Sample name:Copy of Cheque.html
Analysis ID:1637381
MD5:703eeecd0d6f71aed85f436dfa3e6550
SHA1:542f58c89d227b5a1ab6124d5edef751cd2ac384
SHA256:e709760b7efb3336f83700732f3cbeaa80b6299c771d90bbedb8e8bf29b9129a
Infos:

Detection

KnowBe4
Score:60
Range:0 - 100
Confidence:100%

Signatures

Antivirus detection for URL or domain
Yara detected KnowBe4 simulated phishing
AI detected suspicious Javascript
Creates files inside the system directory
Deletes files inside the Windows folder

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 6936 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument C:\Users\user\Desktop\Copy of Cheque.html MD5: E81F54E6C1129887AEA47E7D092680BF)
    • chrome.exe (PID: 7152 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2024,i,17372622530745834036,6535926025712335353,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2196 /prefetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
  • cleanup
SourceRuleDescriptionAuthorStrings
2.1.pages.csvJoeSecurity_KnowBe4Yara detected KnowBe4 simulated phishingJoe Security
    No Sigma rule has matched
    No Suricata rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: https://online.login-secured.co.uk/pages/2acd09218b4dc0f8fad40ebd835b2d80/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0=Avira URL Cloud: Label: phishing
    Source: https://online.account-activity.com/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0=?cid=7886749Avira URL Cloud: Label: phishing
    Source: https://online.login-secured.co.uk/assets/landing-watermark-8487e36eef1bec74f06631f19fea0aa171c208e2976373cda5bd0a4b9e230903.cssAvira URL Cloud: Label: phishing
    Source: https://online.login-secured.co.uk/assets/sei-styles-1837e0b6e1baaf1af90438028a176241b70a365a8a09ff4bf668cf3bf9e3c759.cssAvira URL Cloud: Label: phishing
    Source: https://online.login-secured.co.uk/assets/application-237cb5c4f318687625f8ccf2f42de3fc20238bfe267384653491a6bba8c8f6f5.jsAvira URL Cloud: Label: phishing
    Source: https://online.login-secured.co.uk/assets/sei-flag-90af55d793544fe1893f26677661a4252761afbe811fab0eced85c67bc82f984.pngAvira URL Cloud: Label: phishing
    Source: https://online.login-secured.co.uk/favicon.icoAvira URL Cloud: Label: phishing

    Phishing

    barindex
    Source: Yara matchFile source: 2.1.pages.csv, type: HTML
    Source: 1.0..script.csvJoe Sandbox AI: Detected suspicious JavaScript with source url: https://online.account-activity.com/XOGhzSkErZlJUV... This script exhibits high-risk behavior by redirecting the user to a suspicious and obfuscated URL, which is a common tactic used in phishing attacks. The URL appears to be heavily encoded, indicating an attempt to hide the true destination. This type of behavior is often associated with malicious activities such as credential theft or other forms of user data exfiltration.
    Source: Copy of Cheque.htmlHTTP Parser: No favicon
    Source: file:///C:/Users/user/Desktop/Copy%20of%20Cheque.htmlHTTP Parser: No favicon
    Source: https://online.login-secured.co.uk/pages/2acd09218b4dc0f8fad40ebd835b2d80/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0=HTTP Parser: No favicon
    Source: chrome.exeMemory has grown: Private usage: 11MB later: 32MB
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
    Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
    Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
    Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
    Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
    Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
    Source: unknownTCP traffic detected without corresponding DNS query: 4.245.163.56
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
    Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
    Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
    Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
    Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
    Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
    Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
    Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownTCP traffic detected without corresponding DNS query: 52.182.143.211
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.68
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: global trafficHTTP traffic detected: GET /XVFpXQU5LUEt3dHpERkI2eUg0OERBQUJzalZ2TkowYXpsSUZ0T2V1YjVMT2FKUm1OQTBseHBkdkxsZmtWbXcwRTA4YXEyUEdNdGVVQ1NkcjMwbXJvN25RUGNhektYaVNMZnc3YWxDV3hrb0taL2RyYjlDZEotLXJrcnUrUlRYbU94a0I5UXctLW1sNnB3dURHU29mb1lWd3ArK0pFY1E9PQ==?cid=7886749 HTTP/1.1Host: online.account-activity.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0=?cid=7886749 HTTP/1.1Host: online.account-activity.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /pages/2acd09218b4dc0f8fad40ebd835b2d80/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0= HTTP/1.1Host: online.login-secured.co.ukConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://online.account-activity.com/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0=?cid=7886749Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /assets/landing-watermark-8487e36eef1bec74f06631f19fea0aa171c208e2976373cda5bd0a4b9e230903.css HTTP/1.1Host: online.login-secured.co.ukConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://online.login-secured.co.uk/pages/2acd09218b4dc0f8fad40ebd835b2d80/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0=Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /landing_pages/oops/styles.css HTTP/1.1Host: helpimg.s3.amazonaws.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleSec-Fetch-Storage-Access: activeReferer: https://online.login-secured.co.uk/pages/2acd09218b4dc0f8fad40ebd835b2d80/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0=Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /assets/sei-styles-1837e0b6e1baaf1af90438028a176241b70a365a8a09ff4bf668cf3bf9e3c759.css HTTP/1.1Host: online.login-secured.co.ukConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://online.login-secured.co.uk/pages/2acd09218b4dc0f8fad40ebd835b2d80/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0=Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /assets/application-237cb5c4f318687625f8ccf2f42de3fc20238bfe267384653491a6bba8c8f6f5.js HTTP/1.1Host: online.login-secured.co.ukConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://online.login-secured.co.uk/pages/2acd09218b4dc0f8fad40ebd835b2d80/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0=Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /landing_pages/sei.css HTTP/1.1Host: helpimg.s3.amazonaws.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleSec-Fetch-Storage-Access: activeReferer: https://online.login-secured.co.uk/pages/2acd09218b4dc0f8fad40ebd835b2d80/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0=Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /petite-vue HTTP/1.1Host: unpkg.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://online.login-secured.co.uk/pages/2acd09218b4dc0f8fad40ebd835b2d80/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0=Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /petite-vue@0.4.1 HTTP/1.1Host: unpkg.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://online.login-secured.co.uk/pages/2acd09218b4dc0f8fad40ebd835b2d80/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0=Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /petite-vue@0.4.1/dist/petite-vue.iife.js HTTP/1.1Host: unpkg.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://online.login-secured.co.uk/pages/2acd09218b4dc0f8fad40ebd835b2d80/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0=Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /assets/sei-flag-90af55d793544fe1893f26677661a4252761afbe811fab0eced85c67bc82f984.png HTTP/1.1Host: online.login-secured.co.ukConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://online.login-secured.co.uk/assets/sei-styles-1837e0b6e1baaf1af90438028a176241b70a365a8a09ff4bf668cf3bf9e3c759.cssAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /assets/sei-flag-90af55d793544fe1893f26677661a4252761afbe811fab0eced85c67bc82f984.png HTTP/1.1Host: online.login-secured.co.ukConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: online.login-secured.co.ukConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://online.login-secured.co.uk/pages/2acd09218b4dc0f8fad40ebd835b2d80/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0=Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: online.login-secured.co.ukConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
    Source: global trafficDNS traffic detected: DNS query: online.account-activity.com
    Source: global trafficDNS traffic detected: DNS query: www.google.com
    Source: global trafficDNS traffic detected: DNS query: online.login-secured.co.uk
    Source: global trafficDNS traffic detected: DNS query: helpimg.s3.amazonaws.com
    Source: global trafficDNS traffic detected: DNS query: training.knowbe4.com
    Source: global trafficDNS traffic detected: DNS query: unpkg.com
    Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
    Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49699
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
    Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
    Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49694
    Source: unknownNetwork traffic detected: HTTP traffic on port 49679 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
    Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
    Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
    Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
    Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49694 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
    Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\scoped_dir6936_1811131488
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile deleted: C:\Windows\SystemTemp\scoped_dir6936_1811131488
    Source: classification engineClassification label: mal60.phis.winHTML@21/11@20/147
    Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument C:\Users\user\Desktop\Copy of Cheque.html
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2024,i,17372622530745834036,6535926025712335353,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2196 /prefetch:3
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2024,i,17372622530745834036,6535926025712335353,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2196 /prefetch:3
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: Window RecorderWindow detected: More than 3 window changes detected
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
    Browser Extensions
    1
    Process Injection
    1
    Masquerading
    OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
    Encrypted Channel
    Exfiltration Over Other Network MediumAbuse Accessibility Features
    CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
    Extra Window Memory Injection
    1
    Process Injection
    LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
    Non-Application Layer Protocol
    Exfiltration Over BluetoothNetwork Denial of Service
    Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
    File Deletion
    Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
    Application Layer Protocol
    Automated ExfiltrationData Encrypted for Impact
    Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
    Extra Window Memory Injection
    NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
    Ingress Tool Transfer
    Traffic DuplicationData Destruction

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.


    windows-stand
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    SourceDetectionScannerLabelLink
    https://online.login-secured.co.uk/pages/2acd09218b4dc0f8fad40ebd835b2d80/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0=100%Avira URL Cloudphishing
    file:///C:/Users/user/Desktop/Copy%20of%20Cheque.html0%Avira URL Cloudsafe
    https://online.account-activity.com/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0=?cid=7886749100%Avira URL Cloudphishing
    https://online.login-secured.co.uk/assets/landing-watermark-8487e36eef1bec74f06631f19fea0aa171c208e2976373cda5bd0a4b9e230903.css100%Avira URL Cloudphishing
    https://online.login-secured.co.uk/assets/sei-styles-1837e0b6e1baaf1af90438028a176241b70a365a8a09ff4bf668cf3bf9e3c759.css100%Avira URL Cloudphishing
    https://online.login-secured.co.uk/assets/application-237cb5c4f318687625f8ccf2f42de3fc20238bfe267384653491a6bba8c8f6f5.js100%Avira URL Cloudphishing
    https://unpkg.com/petite-vue@0.4.10%Avira URL Cloudsafe
    https://helpimg.s3.amazonaws.com/landing_pages/sei.css0%Avira URL Cloudsafe
    https://unpkg.com/petite-vue0%Avira URL Cloudsafe
    https://helpimg.s3.amazonaws.com/landing_pages/oops/styles.css0%Avira URL Cloudsafe
    https://unpkg.com/petite-vue@0.4.1/dist/petite-vue.iife.js0%Avira URL Cloudsafe
    https://online.login-secured.co.uk/assets/sei-flag-90af55d793544fe1893f26677661a4252761afbe811fab0eced85c67bc82f984.png100%Avira URL Cloudphishing
    https://online.login-secured.co.uk/favicon.ico100%Avira URL Cloudphishing
    NameIPActiveMaliciousAntivirus DetectionReputation
    s3-w.us-east-1.amazonaws.com
    3.5.28.247
    truefalse
      high
      online.login-secured.co.uk
      18.135.59.120
      truefalse
        unknown
        www.google.com
        142.250.184.228
        truefalse
          high
          training.knowbe4.com
          18.173.205.50
          truefalse
            high
            unpkg.com
            104.17.245.203
            truefalse
              high
              online.account-activity.com
              13.41.249.232
              truetrue
                unknown
                helpimg.s3.amazonaws.com
                unknown
                unknownfalse
                  high
                  NameMaliciousAntivirus DetectionReputation
                  https://online.login-secured.co.uk/assets/sei-styles-1837e0b6e1baaf1af90438028a176241b70a365a8a09ff4bf668cf3bf9e3c759.csstrue
                  • Avira URL Cloud: phishing
                  unknown
                  https://helpimg.s3.amazonaws.com/landing_pages/sei.cssfalse
                  • Avira URL Cloud: safe
                  unknown
                  https://online.login-secured.co.uk/assets/application-237cb5c4f318687625f8ccf2f42de3fc20238bfe267384653491a6bba8c8f6f5.jstrue
                  • Avira URL Cloud: phishing
                  unknown
                  https://helpimg.s3.amazonaws.com/landing_pages/oops/styles.cssfalse
                  • Avira URL Cloud: safe
                  unknown
                  https://unpkg.com/petite-vue@0.4.1/dist/petite-vue.iife.jsfalse
                  • Avira URL Cloud: safe
                  unknown
                  https://online.account-activity.com/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0=?cid=7886749true
                  • Avira URL Cloud: phishing
                  unknown
                  https://online.login-secured.co.uk/pages/2acd09218b4dc0f8fad40ebd835b2d80/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0=true
                  • Avira URL Cloud: phishing
                  unknown
                  https://online.login-secured.co.uk/assets/sei-flag-90af55d793544fe1893f26677661a4252761afbe811fab0eced85c67bc82f984.pngtrue
                  • Avira URL Cloud: phishing
                  unknown
                  https://unpkg.com/petite-vue@0.4.1false
                  • Avira URL Cloud: safe
                  unknown
                  https://online.login-secured.co.uk/assets/landing-watermark-8487e36eef1bec74f06631f19fea0aa171c208e2976373cda5bd0a4b9e230903.csstrue
                  • Avira URL Cloud: phishing
                  unknown
                  https://unpkg.com/petite-vuefalse
                  • Avira URL Cloud: safe
                  unknown
                  https://online.login-secured.co.uk/favicon.icotrue
                  • Avira URL Cloud: phishing
                  unknown
                  file:///C:/Users/user/Desktop/Copy%20of%20Cheque.htmlfalse
                  • Avira URL Cloud: safe
                  unknown
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  142.250.186.35
                  unknownUnited States
                  15169GOOGLEUSfalse
                  142.250.185.99
                  unknownUnited States
                  15169GOOGLEUSfalse
                  142.250.186.46
                  unknownUnited States
                  15169GOOGLEUSfalse
                  13.41.249.232
                  online.account-activity.comUnited States
                  7018ATT-INTERNET4UStrue
                  142.250.185.206
                  unknownUnited States
                  15169GOOGLEUSfalse
                  1.1.1.1
                  unknownAustralia
                  13335CLOUDFLARENETUSfalse
                  3.5.28.247
                  s3-w.us-east-1.amazonaws.comUnited States
                  14618AMAZON-AESUSfalse
                  142.250.186.163
                  unknownUnited States
                  15169GOOGLEUSfalse
                  18.173.205.50
                  training.knowbe4.comUnited States
                  3MIT-GATEWAYSUSfalse
                  142.251.168.84
                  unknownUnited States
                  15169GOOGLEUSfalse
                  104.17.245.203
                  unpkg.comUnited States
                  13335CLOUDFLARENETUSfalse
                  142.250.185.142
                  unknownUnited States
                  15169GOOGLEUSfalse
                  18.135.59.120
                  online.login-secured.co.ukUnited States
                  16509AMAZON-02USfalse
                  142.250.184.228
                  www.google.comUnited States
                  15169GOOGLEUSfalse
                  IP
                  192.168.2.16
                  192.168.2.7
                  Joe Sandbox version:42.0.0 Malachite
                  Analysis ID:1637381
                  Start date and time:2025-03-13 15:32:17 +01:00
                  Joe Sandbox product:CloudBasic
                  Overall analysis duration:
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:defaultwindowsinteractivecookbook.jbs
                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                  Number of analysed new started processes analysed:15
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • EGA enabled
                  Analysis Mode:stream
                  Analysis stop reason:Timeout
                  Sample name:Copy of Cheque.html
                  Detection:MAL
                  Classification:mal60.phis.winHTML@21/11@20/147
                  Cookbook Comments:
                  • Found application associated with file extension: .html
                  • Exclude process from analysis (whitelisted): svchost.exe
                  • Excluded IPs from analysis (whitelisted): 142.250.186.35, 142.250.185.206, 142.250.185.142, 142.251.168.84
                  • Excluded domains from analysis (whitelisted): clients2.google.com, accounts.google.com, clientservices.googleapis.com, clients.l.google.com
                  • Not all processes where analyzed, report is missing behavior information
                  • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                  • VT rate limit hit for: online.account-activity.com
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:HTML document, ASCII text, with very long lines (472)
                  Category:downloaded
                  Size (bytes):526
                  Entropy (8bit):5.8932088034716905
                  Encrypted:false
                  SSDEEP:
                  MD5:B6D24ED036F948756D7CF486A0BE79A7
                  SHA1:61AC8C50F9EC03A6506F48F38B122F7FC4F7224F
                  SHA-256:D1FE53206519DC2BC9A132000202DF5C828DF16D75EB9E8C54B1BB132C057AC5
                  SHA-512:8F90D596B89D45D0778E8AC5AA6795E3E6A2239FF62D751709AD3AAA21546C1DABD820C299F48FEA43FBDD13D35C67DF78598508DE2354596D1AEF2DE2464432
                  Malicious:false
                  Reputation:unknown
                  URL:https://online.account-activity.com/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0=?cid=7886749
                  Preview:<html>. <head>. <script>window.location.href = 'https://online.login-secured.co.uk/pages/2acd09218b4dc0f8fad40ebd835b2d80/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0=';</script>. </head>. <body>. </body>.</html>.
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:ASCII text
                  Category:downloaded
                  Size (bytes):5934
                  Entropy (8bit):4.931906350831601
                  Encrypted:false
                  SSDEEP:
                  MD5:134D934420B13974981A9634B7380865
                  SHA1:18C01D3711CF8C21C1CD0CF544002358C1C929C6
                  SHA-256:B3C447F15FCE33DFA869B9D2190364509EDE3937AE05B51BA394A78E28C244BA
                  SHA-512:7FAE93AD1895DCF7CC58FC2C477BA51D3EB7D7B2884FE117E21C0A7E0160981EB53D23A6ACDA07DA594AF6984F52E1B57B6F157F84220729C7EEBF9AE062C092
                  Malicious:false
                  Reputation:unknown
                  URL:https://online.login-secured.co.uk/assets/sei-styles-1837e0b6e1baaf1af90438028a176241b70a365a8a09ff4bf668cf3bf9e3c759.css
                  Preview:/* line 2, app/assets/stylesheets/sei-styles.scss */.x-sei.sei-flag {. border-bottom: 2px solid tomato;. padding-left: 3px;.}../* line 6, app/assets/stylesheets/sei-styles.scss */.x-sei.sei-flag::before {. content: ' ';. display: inline-block;. background: url(/assets/sei-flag-90af55d793544fe1893f26677661a4252761afbe811fab0eced85c67bc82f984.png) no-repeat;. background-size: contain;. height: 12px;. width: 12px;. margin: 0 .1rem;.}../* line 16, app/assets/stylesheets/sei-styles.scss */.x-sei.sei-flag[generic='true'] {. display: block;. border-bottom: 0px;.}../* line 21, app/assets/stylesheets/sei-styles.scss */.x-sei.sei-flag[generic='true']::after {. font-family: "Courier New", Courier, monospace;. line-height: 1.8;. color: #b65555;. font-weight: bold;. content: attr(data-original-title);.}../* line 29, app/assets/stylesheets/sei-styles.scss */.x-sei.sei-flag[generic='true']::before {. content: ' ';. display: inline-block;. background: url(/assets/dark-flag-2846d82c5
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:gzip compressed data, from Unix, original size modulo 2^32 51364
                  Category:downloaded
                  Size (bytes):15794
                  Entropy (8bit):7.988903293841564
                  Encrypted:false
                  SSDEEP:
                  MD5:1CF731481C968C93A0349960E14949A9
                  SHA1:637B4AB483B25273FE40B690B1461C1F0A3587BC
                  SHA-256:4410C51FA6B83BCDEA5394014F40E7784672C4CCDBD477899E5DED97F00CF938
                  SHA-512:1684885D3C20F61ADEFB69CD00BCCD8A0C12ED44EFC3C84F6A1D78EAE2C78C077EABE0C647E21B2F80ED09D99993808DDFB13428B6F11A162B9992D892DA0743
                  Malicious:false
                  Reputation:unknown
                  URL:https://training.knowbe4.com/assets/modernizr-79e0181ec91aff04bb01d87cba546535ede843f75d19f5c60f66b8dd6546971f.js
                  Preview:................[{s.F...b...C..e[..%+.....\..o..Z..!...h. ...>.....H..c%29......4F......E..2O?...at....r...n<..9.i.y.X..tV.~<..dY_..J..M.8/S=...L.Ku[.9-:..i&..u....)...y"..D..*.J..o;..F.3.wo...0v..X..x&rY.7J<..<`....x.XL...Ri!K%.G$e.....K.W.3^5..L......YT.bU.X+.e!.r.....bQ..UV)....b..c.....?U\.y..3........j..$T...&.W.Tc.IQ.A...b.......@P..l%T>.y.p...9..eZ...R.u&K.)L..D.E^......P..>U...sn0..]..bAX..~^T@,..D%..........Y!....@[%......C1.....j..y.Z.W.....~@...BLU.2.u.%.V.....@v...y<+...S.g..#-...0..~.K]R,s.9..8..YQja?.(.......W..J."..g*....`/..{F..OE.R.1q./..H..&..."M..,......R78b..&a9.=V...<..~.....?..kme.X.......A. ..!K.)..\.m..J ...g.....Z.7o. .uLvtE.}..}...KK..$.;..v....X*...BWN....yd..Z..8...n....y[.U...v.e..a8uk"M...M\L.E]y...8....x.....]..n....=.+."X.F.....`mE .z.f.n..1..pm..T.%$.rA..._..H\.y.F...5e..%....1/@.3I..{.......[e-..\.j#wZ..A.,..U.&.........B..R...jW..O.[.7.+z.^d)X$z..&l.XR..|U.Q&>.E.....ZA.....=H'i,X2BG!.{.8....O..Q}V....e...M#
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:HTML document, Unicode text, UTF-8 text, with very long lines (461)
                  Category:downloaded
                  Size (bytes):72401
                  Entropy (8bit):6.08796783630505
                  Encrypted:false
                  SSDEEP:
                  MD5:10648E92BEE5B56A806CE68BBB26B001
                  SHA1:28F69C7C85225A61A8F32E54AF13996913C8AE3C
                  SHA-256:9F0BC2AC2C5A704391F3265777C55281E0BF111BB002B6A4D96D5B3D0FD4317B
                  SHA-512:2952AAB35945470DC4242A852E8A040F4F1C122E3294ACDADCF69717BBCC02AFFD4327AF27E22A8C0B2722813BE9749A7CCCE21A6A86940215BB7D611A764ED7
                  Malicious:false
                  Reputation:unknown
                  URL:https://online.login-secured.co.uk/pages/2acd09218b4dc0f8fad40ebd835b2d80/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0=
                  Preview:<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN". "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">..<html xmlns="http://www.w3.org/1999/xhtml">. <meta name="IMPORTANT" content="This page is part of a simulated phishing attack initiated by KnowBe4 on behalf of its customers." />. <meta name="IMPORTANT" content="If you have any questions please contact support@knowbe4.com." />. <meta content="IE=edge,chrome=1" http-equiv="X-UA-Compatible"/>. <meta name="robots" content="noindex, nofollow" />.. <head>. <script src="/assets/application-237cb5c4f318687625f8ccf2f42de3fc20238bfe267384653491a6bba8c8f6f5.js"></script>.. <link rel="stylesheet" href="/assets/landing-watermark-8487e36eef1bec74f06631f19fea0aa171c208e2976373cda5bd0a4b9e230903.css" media="all" />. <link rel="stylesheet" href="/assets/sei-styles-1837e0b6e1baaf1af90438028a176241b70a365a8a09ff4bf668cf3bf9e3c759.css" media="all" />.. <script>.//<![CDATA[.. $(document).ready(function() {.
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:ASCII text
                  Category:downloaded
                  Size (bytes):1471
                  Entropy (8bit):4.754611179426391
                  Encrypted:false
                  SSDEEP:
                  MD5:15E89F9684B18EC43EE51F8D62A787C3
                  SHA1:9CBAAACEAE96845ECD3497F41EE3B02588ABEC11
                  SHA-256:16F13E16A7EF02FB6F94250AA1931DED83DBEE5D9FAD278E33DD5792D085194F
                  SHA-512:79E0110A045F28437D192290AC9789270CB0D4E676A985564746DB439992D867BA89639D7738E2A7F7D83BBF37D9A02CAA2AE1DC4E0EE2519797E5840A47FABE
                  Malicious:false
                  Reputation:unknown
                  URL:https://online.login-secured.co.uk/assets/landing-watermark-8487e36eef1bec74f06631f19fea0aa171c208e2976373cda5bd0a4b9e230903.css
                  Preview:/* line 1, app/assets/stylesheets/landing-watermark.scss */..watermark {. -webkit-writing-mode: vertical-rl;. -ms-writing-mode: tb-rl;. writing-mode: vertical-rl;. text-orientation: sideways;.}../* line 4, app/assets/stylesheets/landing-watermark.scss */..watermark.left {. left: 0;.}../* line 7, app/assets/stylesheets/landing-watermark.scss */..watermark.right {. right: 0;.}../* line 10, app/assets/stylesheets/landing-watermark.scss */..watermark.top {. text-align: center;. -webkit-writing-mode: horizontal-tb;. -ms-writing-mode: lr-tb;. writing-mode: horizontal-tb;. top: -38px;.}../* line 15, app/assets/stylesheets/landing-watermark.scss */..watermark h1 {. -webkit-user-select: none;. -moz-user-select: none;. -ms-user-select: none;. user-select: none;. font-size: 15px;. color: #fdfdfa;. font-weight: bold;.}../* line 24, app/assets/stylesheets/landing-watermark.scss */.#template_sei .watermark.left {. margin-left: -10px;.}../* li
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:PNG image data, 240 x 240, 8-bit/color RGBA, non-interlaced
                  Category:dropped
                  Size (bytes):3168
                  Entropy (8bit):7.704911325185365
                  Encrypted:false
                  SSDEEP:
                  MD5:A907E6E737788176B026FA71DFE8AFFE
                  SHA1:6844236F638CEDCD652EB0A805476A1A13376CF5
                  SHA-256:FC5E7621BA0E98C5C6728E3B2BDF802311C0A0953A05E60A7551CB0C7BED00A9
                  SHA-512:3A17E66931A15B5C6553DAE241C5A7BB40240699F0608F92ED940CB203CBEA3031CB0FAC23F9C962F50D573F56DB27A3369F1A38ED1AEA0168D7E707803CA27A
                  Malicious:false
                  Reputation:unknown
                  Preview:.PNG........IHDR.............>U....'IDATx..].\...e.!.H..B/J."""R..R....E)"../..".H..3s......&.O....d.QJ.L......P.m.U..u.Q..$.....}.5..M.....{.y.!A...|.|...3{.-M....m..~~....0.a...0..`...0........C...!`...0.a...0..<.z......w.tt<X.f..f.O.f./.(QK&s.t.{..z+.T..J..r.....3.....<r..../..Z.}.`..^.gGF6....p%.y^.,.R.....dr.c6/....w_[^........#G.j.7x...?.N.l..k.}...0< a..'.M...XO&g.....to......B..q~.......{....:...^H*QT..m..x.'..K}}.eu.&a........a..{...o..8.".-`Yi.p..zs........l........X-..tt<..=N&...H....&^...eE^M.9...U..gd..D;....gw.xL{.E.1..}}.+Q..U.......x.rO....V.8.,.n.p{...+............m...V.8.|~``.\.........[.......>s...r......v$.+ctq...B{.A....L...j..T..K...b.V.y.M.Z....7T..8...e-.>...u...&`)..|...... .....2...d....=:.N.~.....g%..x..5...7..-.l.e.........Y.u..=..l-...s.&.......r.vx.....{..e....).<1S(.\{>j.....+5.....kO...|"Q-.r.k.I..........]i..!...W..._...=7[.[uo....sk....t[..B.a....\...X......7..\.96...F..]..]...M{.6..!..lv...V..C..p5..q.f
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:ASCII text, with very long lines (16900)
                  Category:downloaded
                  Size (bytes):16901
                  Entropy (8bit):5.207509946311759
                  Encrypted:false
                  SSDEEP:
                  MD5:A7DB3244C9A6704A3159A38C82207F66
                  SHA1:CC3B2BF9D2FCC718C86B1ED2AC7D9CD5BA12EF43
                  SHA-256:774BB8E88B09936246A57F0DFED88A375258A8235B893561C96880411DABC4D5
                  SHA-512:3197FFB1055735A329D122D6C8EDFA9C12FCCD54E8F22F579A4E79B3C6AE0163391E790429A3F680434309AAECCE1572941EA47DEE321AC080FEAADA2DE3F3B6
                  Malicious:false
                  Reputation:unknown
                  URL:https://unpkg.com/petite-vue@0.4.1/dist/petite-vue.iife.js
                  Preview:var pn=Object.defineProperty,hn=(e,t,n)=>t in e?pn(e,t,{enumerable:!0,configurable:!0,writable:!0,value:n}):e[t]=n,C=(e,t,n)=>(hn(e,"symbol"!=typeof t?t+"":t,n),n),PetiteVue=function(e){"use strict";function t(e){if(a(e)){const n={};for(let s=0;s<e.length;s++){const i=e[s],o=d(i)?r(i):t(i);if(o)for(const e in o)n[e]=o[e]}return n}return d(e)||g(e)?e:void 0}const n=/;(?![^(]*\))/g,s=/:(.+)/;function r(e){const t={};return e.split(n).forEach((e=>{if(e){const n=e.split(s);n.length>1&&(t[n[0].trim()]=n[1].trim())}})),t}function i(e){let t="";if(d(e))t=e;else if(a(e))for(let n=0;n<e.length;n++){const s=i(e[n]);s&&(t+=s+" ")}else if(g(e))for(const n in e)e[n]&&(t+=n+" ");return t.trim()}function o(e,t){if(e===t)return!0;let n=h(e),s=h(t);if(n||s)return!(!n||!s)&&e.getTime()===t.getTime();if(n=a(e),s=a(t),n||s)return!(!n||!s)&&function(e,t){if(e.length!==t.length)return!1;let n=!0;for(let s=0;n&&s<e.length;s++)n=o(e[s],t[s]);return n}(e,t);if(n=g(e),s=g(t),n||s){if(!n||!s)return!1;if(Object.k
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:Unicode text, UTF-8 text
                  Category:downloaded
                  Size (bytes):5649
                  Entropy (8bit):5.250605215538956
                  Encrypted:false
                  SSDEEP:
                  MD5:B13B4F098D80AC49DCC6BED4E459D560
                  SHA1:81FFB3DD594A82F9453D1C45DA812DFC008CAA65
                  SHA-256:5FC2013E8D4F5A97667A0A5BFEF9A2E148363D89A46BE49F14CB2C60B1461CA9
                  SHA-512:4FEAEA5336B3E1B7B1D26C5D576C655208955D4C7657B967D11A9D58A3086EB0D087DE53606E0AC4E0F3AEFD9993E616BD7B9B343AE23DEB20477BD7EFD75ECC
                  Malicious:false
                  Reputation:unknown
                  URL:https://helpimg.s3.amazonaws.com/landing_pages/oops/styles.css
                  Preview::root {..--clr-neutral-100: #ffffff;..--clr-neutral-200: #f5f5f5;..--clr-neutral-300: #d5d5d5;..--clr-neutral-400: #ababab;..--clr-neutral-500: #707070;..--clr-neutral-600: #2c2c2c;.../* Padding */..--padding-xs: clamp(0.5rem, 1.5%, 0.75rem);..--padding-sm: clamp(1rem, 3%, 1.5rem);..--padding-md: clamp(1.5rem, 6%, 3rem);..--padding-lg: clamp(3rem, 12%, 6rem);.../* Margin */..--block-flow-xs: min(1rem, 2vh);..--block-flow-sm: min(2rem, 4vh);..--block-flow-md: min(4rem, 8vh);..--block-flow-lg: min(8rem, 16vh);.../* Font Sizes */.../* @link https://utopia.fyi/type/calculator?c=320,18,1.2,1240,20,1.25,5,2,&s=0.75|0.5|0.25,1.5|2|3|4|6,s-l&g=s,l,xl,12 */.../* Step -1: 15px . 12.003px */..--step--1: clamp(0.7502rem, 1.0027rem + -0.3258vi, 0.9375rem);../* Step 0: 18px . 16px */..--step-0: clamp(1rem, 1.1685rem + -0.2174vi, 1.125rem);../* Step 1: 21.6px . 21.328px */..--step-1: clamp(1.333rem, 1.3559rem + -0.0296vi, 1.35rem);../* Step 2: 25.92px . 28.4302px */..--step-2: clamp(1.62rem,
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:ASCII text, with very long lines (65447)
                  Category:downloaded
                  Size (bytes):380848
                  Entropy (8bit):5.202109831427653
                  Encrypted:false
                  SSDEEP:
                  MD5:67A0C4DBD69561F3226243034423F1ED
                  SHA1:88C1B5C7EBBFA24D8196290206BF544F28EEB406
                  SHA-256:74B9F1CFE7CAD31AE1C1901200890B76676E6D92AC817641F5EF9BFD552F2110
                  SHA-512:D5326C46E2FC443AA0C75DB573B39957514BD025235ADB5F16797133394E1AFD0A6458B38DA8220BF7558333E8F2334532FBCC4CD9DD4DD5811AAC403B498542
                  Malicious:false
                  Reputation:unknown
                  URL:https://online.login-secured.co.uk/assets/application-237cb5c4f318687625f8ccf2f42de3fc20238bfe267384653491a6bba8c8f6f5.js
                  Preview:/*! jQuery v3.7.1 | (c) OpenJS Foundation and other contributors | jquery.org/license */.!function(e,t){"use strict";"object"==typeof module&&"object"==typeof module.exports?module.exports=e.document?t(e,!0):function(e){if(!e.document)throw new Error("jQuery requires a window with a document");return t(e)}:t(e)}("undefined"!=typeof window?window:this,function(ie,e){"use strict";var oe=[],r=Object.getPrototypeOf,ae=oe.slice,g=oe.flat?function(e){return oe.flat.call(e)}:function(e){return oe.concat.apply([],e)},s=oe.push,se=oe.indexOf,n={},i=n.toString,ue=n.hasOwnProperty,o=ue.toString,a=o.call(Object),le={},v=function(e){return"function"==typeof e&&"number"!=typeof e.nodeType&&"function"!=typeof e.item},y=function(e){return null!=e&&e===e.window},C=ie.document,u={type:!0,src:!0,nonce:!0,noModule:!0};function m(e,t,n){var r,i,o=(n=n||C).createElement("script");if(o.text=e,t)for(r in u)(i=t[r]||t.getAttribute&&t.getAttribute(r))&&o.setAttribute(r,i);n.head.appendChild(o).parentNode.remove
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:gzip compressed data, from Unix, original size modulo 2^32 3205083
                  Category:downloaded
                  Size (bytes):772952
                  Entropy (8bit):7.999264670065835
                  Encrypted:true
                  SSDEEP:
                  MD5:612BD243FD7FA6A4492BE2F5BA9B398D
                  SHA1:6B0DF2B83CB1F1C41C9B7255246E1543186A9BE0
                  SHA-256:A80B4DDA8A3A2D9D731B7950337FD2ABEBC0DE52F66EBF1D31D0903D3D9BEF13
                  SHA-512:005473CDC21415231B443BB6B9C586213579CF89DEEE4552E09BD49F3246D102038EBE150C77E739931516B489EF850FC599359FB2D83A1C8D7DA33AA94E3A53
                  Malicious:false
                  Reputation:unknown
                  URL:https://training.knowbe4.com/assets/application-b8fb25919f68be551e6730684a8ed34bc7dd2dac142e7cc51ebf7b09c48546d5.js
                  Preview:...........[{s.F.....#z+.%>$9..T....J.vb9.....D.I. .`.QJ.......`@Q..U..m.,b0..~.0..i.]u.S..[.}x..M.xY....<......p.%M...r4.^.Ns..l1.(.8M'I.i...?.H...x...]....ly..y..~..i..q..0.TV.u.&YZ..eYd9o.^':4:R.....~PI<...!...~I._..............?.|5:..?.j.n..2.....%.e...4...[.U...x..U..u6U.,*.....U'.........v.o.Y^..,....q...X,...3..{.'.G.tz..Y..)vX..Z.j.gK\..U.F..7.(6....{J..IYhF.....i..A}z.b..*.T..j.^.i.....9=G...........6...]:...Z[.n6.a..0.....)JP.0..u...v.k.. 4TxH*...z0...0w\t.Y..q....@....8.@M<..l<:......E....4.}7ig.a..cR.^.f."/5h;..#.,.[.<;.z...U..l....I.gy.:.:.2@..[8:.=.LG.......SU..........BGn....m`.....@.@k...qD..q....}.X6.Sv..I&yJG=w/F.......a....$YD.rI.....4.Q._....0}\.K".2.....I....:..I|.pY...L.8.q......N4m@.d.p.Q]....c..(L.....".N.bM...Y..nU...hU.......=.d........'O.v..t.&>......F.W..Gm.u,ql.S1..`H..m.|.C.5..$,..e.NX.f.|M#.%N.7...v....1......-.3..8?.&...4..U."c?.*+n......<.n..T..L.P..E..bf.,$....,oIO..[.B.Y..v..=.+...Z]..v:D.b...$..4..Q.....MK.
                  Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                  File Type:ASCII text
                  Category:downloaded
                  Size (bytes):2508
                  Entropy (8bit):5.179323417990473
                  Encrypted:false
                  SSDEEP:
                  MD5:692BD85875571661EF543E40D70685F5
                  SHA1:3B42EC0CF90579BE7B85E96549217FA9260933A4
                  SHA-256:56ED46CCEE20887F8E7AD18C2FCACB721210D959FA293C6252426F4A5F5100FB
                  SHA-512:8FCE74DDA1FFC4A871667AFD05252F613DD85047CFF0DB85C66BCD2B33D23AB9216BA4648D0C130DCF097DBE3FDAD3D06632B17F8AA7F7BFC643F9253D12EF33
                  Malicious:false
                  Reputation:unknown
                  URL:https://helpimg.s3.amazonaws.com/landing_pages/sei.css
                  Preview::root {../* Padding */..--padding-xs: clamp(0.5rem, 1.5%, 0.75rem);..--padding-sm: clamp(1rem, 3%, 1.5rem);..--padding-md: clamp(1.5rem, 6%, 3rem);..--padding-lg: clamp(3rem, 12%, 6rem);.../* Margin */..--block-flow-xs: min(1rem, 2vh);..--block-flow-sm: min(2rem, 4vh);..--block-flow-md: min(4rem, 8vh);..--block-flow-lg: min(8rem, 16vh);.}...red-flags {..width: 100%;..padding: 0 var(--padding-sm) var(--padding-md) var(--padding-sm);...h2 {...font-weight: 600;...margin-block-start: 0;..}.}...sei-template {..text-align: center;.}...modal-body .tooltip {..position: absolute;..font-size: 0.875rem;.}...modal-body {..overflow: visible;.}..tooltip-inner {..font-size: 0.875rem;.}...placeholder {..margin: var(--block-flow-sm) auto 0 auto;..box-shadow: 0 0.1875rem 0.5625rem rgba(0, 0, 0, 0.5);..border-radius: 0.375rem;..max-width: 60rem;.}...title-bar {..border-radius: 0.375rem 0.375rem 0 0;..background-color: #555;..border-bottom: none;..display: flex;..padding: 0 0.75rem;..align-items: center;.
                  File type:HTML document, ASCII text, with very long lines (449), with CRLF line terminators
                  Entropy (8bit):5.274393107698646
                  TrID:
                  • HyperText Markup Language (11501/1) 33.82%
                  • HyperText Markup Language (11501/1) 33.82%
                  • HyperText Markup Language (11001/1) 32.35%
                  File name:Copy of Cheque.html
                  File size:2'035 bytes
                  MD5:703eeecd0d6f71aed85f436dfa3e6550
                  SHA1:542f58c89d227b5a1ab6124d5edef751cd2ac384
                  SHA256:e709760b7efb3336f83700732f3cbeaa80b6299c771d90bbedb8e8bf29b9129a
                  SHA512:b9b79caa822b35ada2fd41a25a6edf9e95cde6e6ee191f8854b73ed2b5179ae943033af13f0b0d019c6d028fcc37ca6ca5b7bdffd969f02dae30e0c091e41a8f
                  SSDEEP:48:0WMqobjTGbTW18tbdCxxzEV3jlSfEgkcH1JXdz4CnS:+qvbT7OSKf5hc
                  TLSH:8741922D00D18909C832D7309BD2B214FA96644373036131BECC72A76FBAA58A177FCC
                  File Content Preview:<!doctype html>..<html lang="en">..<head>.. This html attachment is a part of a KnowBe4 Simulated Phishing Test -->.. <meta charset="utf-8">.. <title>Page Not Found</title>.. <meta name="viewport" content="width=device-width, initial-scal
                  Icon Hash:1270ce868a8686b8