Click to jump to signature section
Source: https://online.login-secured.co.uk/pages/2acd09218b4dc0f8fad40ebd835b2d80/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0= | Avira URL Cloud: Label: phishing |
Source: https://online.account-activity.com/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0=?cid=7886749 | Avira URL Cloud: Label: phishing |
Source: https://online.login-secured.co.uk/assets/landing-watermark-8487e36eef1bec74f06631f19fea0aa171c208e2976373cda5bd0a4b9e230903.css | Avira URL Cloud: Label: phishing |
Source: https://online.login-secured.co.uk/assets/sei-styles-1837e0b6e1baaf1af90438028a176241b70a365a8a09ff4bf668cf3bf9e3c759.css | Avira URL Cloud: Label: phishing |
Source: https://online.login-secured.co.uk/assets/application-237cb5c4f318687625f8ccf2f42de3fc20238bfe267384653491a6bba8c8f6f5.js | Avira URL Cloud: Label: phishing |
Source: https://online.login-secured.co.uk/assets/sei-flag-90af55d793544fe1893f26677661a4252761afbe811fab0eced85c67bc82f984.png | Avira URL Cloud: Label: phishing |
Source: https://online.login-secured.co.uk/favicon.ico | Avira URL Cloud: Label: phishing |
Source: Yara match | File source: 2.1.pages.csv, type: HTML |
Source: 1.0..script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: https://online.account-activity.com/XOGhzSkErZlJUV... This script exhibits high-risk behavior by redirecting the user to a suspicious and obfuscated URL, which is a common tactic used in phishing attacks. The URL appears to be heavily encoded, indicating an attempt to hide the true destination. This type of behavior is often associated with malicious activities such as credential theft or other forms of user data exfiltration. |
Source: Copy of Cheque.html | HTTP Parser: No favicon |
Source: file:///C:/Users/user/Desktop/Copy%20of%20Cheque.html | HTTP Parser: No favicon |
Source: https://online.login-secured.co.uk/pages/2acd09218b4dc0f8fad40ebd835b2d80/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0= | HTTP Parser: No favicon |
Source: chrome.exe | Memory has grown: Private usage: 11MB later: 32MB |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 4.245.163.56 |
Source: unknown | TCP traffic detected without corresponding DNS query: 4.245.163.56 |
Source: unknown | TCP traffic detected without corresponding DNS query: 4.245.163.56 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.182.143.211 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.182.143.211 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.182.143.211 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.182.143.211 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.182.143.211 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.182.143.211 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.182.143.211 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.32.68 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.32.68 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.32.68 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: global traffic | HTTP traffic detected: GET /XVFpXQU5LUEt3dHpERkI2eUg0OERBQUJzalZ2TkowYXpsSUZ0T2V1YjVMT2FKUm1OQTBseHBkdkxsZmtWbXcwRTA4YXEyUEdNdGVVQ1NkcjMwbXJvN25RUGNhektYaVNMZnc3YWxDV3hrb0taL2RyYjlDZEotLXJrcnUrUlRYbU94a0I5UXctLW1sNnB3dURHU29mb1lWd3ArK0pFY1E9PQ==?cid=7886749 HTTP/1.1Host: online.account-activity.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0=?cid=7886749 HTTP/1.1Host: online.account-activity.comConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /pages/2acd09218b4dc0f8fad40ebd835b2d80/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0= HTTP/1.1Host: online.login-secured.co.ukConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://online.account-activity.com/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0=?cid=7886749Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /assets/landing-watermark-8487e36eef1bec74f06631f19fea0aa171c208e2976373cda5bd0a4b9e230903.css HTTP/1.1Host: online.login-secured.co.ukConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://online.login-secured.co.uk/pages/2acd09218b4dc0f8fad40ebd835b2d80/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0=Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /landing_pages/oops/styles.css HTTP/1.1Host: helpimg.s3.amazonaws.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleSec-Fetch-Storage-Access: activeReferer: https://online.login-secured.co.uk/pages/2acd09218b4dc0f8fad40ebd835b2d80/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0=Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /assets/sei-styles-1837e0b6e1baaf1af90438028a176241b70a365a8a09ff4bf668cf3bf9e3c759.css HTTP/1.1Host: online.login-secured.co.ukConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://online.login-secured.co.uk/pages/2acd09218b4dc0f8fad40ebd835b2d80/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0=Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /assets/application-237cb5c4f318687625f8ccf2f42de3fc20238bfe267384653491a6bba8c8f6f5.js HTTP/1.1Host: online.login-secured.co.ukConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://online.login-secured.co.uk/pages/2acd09218b4dc0f8fad40ebd835b2d80/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0=Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /landing_pages/sei.css HTTP/1.1Host: helpimg.s3.amazonaws.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleSec-Fetch-Storage-Access: activeReferer: https://online.login-secured.co.uk/pages/2acd09218b4dc0f8fad40ebd835b2d80/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0=Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /petite-vue HTTP/1.1Host: unpkg.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://online.login-secured.co.uk/pages/2acd09218b4dc0f8fad40ebd835b2d80/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0=Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /petite-vue@0.4.1 HTTP/1.1Host: unpkg.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://online.login-secured.co.uk/pages/2acd09218b4dc0f8fad40ebd835b2d80/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0=Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /petite-vue@0.4.1/dist/petite-vue.iife.js HTTP/1.1Host: unpkg.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://online.login-secured.co.uk/pages/2acd09218b4dc0f8fad40ebd835b2d80/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0=Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /assets/sei-flag-90af55d793544fe1893f26677661a4252761afbe811fab0eced85c67bc82f984.png HTTP/1.1Host: online.login-secured.co.ukConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://online.login-secured.co.uk/assets/sei-styles-1837e0b6e1baaf1af90438028a176241b70a365a8a09ff4bf668cf3bf9e3c759.cssAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /assets/sei-flag-90af55d793544fe1893f26677661a4252761afbe811fab0eced85c67bc82f984.png HTTP/1.1Host: online.login-secured.co.ukConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /favicon.ico HTTP/1.1Host: online.login-secured.co.ukConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://online.login-secured.co.uk/pages/2acd09218b4dc0f8fad40ebd835b2d80/XOGhzSkErZlJUVUJyL2FSSEttWEJqdUE0NGUrMVd3ZXc2QjMyaGRnQ3ZPMzV4L3BqK201eVJpUGJ3RFJDb2drSXRiWXBFSjZBVHlNM3l3dS9WTVArNTBEK2NNeXJGTW5BbHpJZ2xHSjNxbU5lRlAvREI2eGZDRDluWFIwWm9sbGhjRzB5N1l4UHFFZEhvd0ZEcStvNS9oc252UDYvNGRwQlhteVBqdTVPajUrVU9TcU1KcGo4SjYwTzd4VUFoV05kN3p3N3YvNG9JSXlubEl0U0hIMnJVNWc9LS05Y3VkL1RBdnNscWRYUnRxLS1yNktFeGhyZk9XMFlCRnFlRDZOdU5RPT0=Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /favicon.ico HTTP/1.1Host: online.login-secured.co.ukConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | DNS traffic detected: DNS query: online.account-activity.com |
Source: global traffic | DNS traffic detected: DNS query: www.google.com |
Source: global traffic | DNS traffic detected: DNS query: online.login-secured.co.uk |
Source: global traffic | DNS traffic detected: DNS query: helpimg.s3.amazonaws.com |
Source: global traffic | DNS traffic detected: DNS query: training.knowbe4.com |
Source: global traffic | DNS traffic detected: DNS query: unpkg.com |
Source: unknown | Network traffic detected: HTTP traffic on port 49708 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49733 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49699 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49741 |
Source: unknown | Network traffic detected: HTTP traffic on port 49704 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49713 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49717 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49736 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49736 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49735 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49734 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49733 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49732 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49699 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49731 |
Source: unknown | Network traffic detected: HTTP traffic on port 49707 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49730 |
Source: unknown | Network traffic detected: HTTP traffic on port 49732 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49694 |
Source: unknown | Network traffic detected: HTTP traffic on port 49679 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49671 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49729 |
Source: unknown | Network traffic detected: HTTP traffic on port 49714 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49726 |
Source: unknown | Network traffic detected: HTTP traffic on port 49718 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49735 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49706 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49731 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49712 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49741 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49729 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49748 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49718 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49717 |
Source: unknown | Network traffic detected: HTTP traffic on port 49715 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49716 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49715 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49714 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49713 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49712 |
Source: unknown | Network traffic detected: HTTP traffic on port 49709 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49734 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49705 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49730 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49694 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49726 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49709 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49708 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49707 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49706 |
Source: unknown | Network traffic detected: HTTP traffic on port 49716 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49705 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49704 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49748 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Windows\SystemTemp\scoped_dir6936_1811131488 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File deleted: C:\Windows\SystemTemp\scoped_dir6936_1811131488 |
Source: classification engine | Classification label: mal60.phis.winHTML@21/11@20/147 |
Source: unknown | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument C:\Users\user\Desktop\Copy of Cheque.html |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2024,i,17372622530745834036,6535926025712335353,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2196 /prefetch:3 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2024,i,17372622530745834036,6535926025712335353,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2196 /prefetch:3 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: Window Recorder | Window detected: More than 3 window changes detected |