Click to jump to signature section
Source: https://dspr.fokmsumz.ru/awrgihmhaysnufhcxsmugmxaoaqjkzm8h2rjgv69z9snabi7ugqt5?HWGBQAIFGTYIPPDDHZHQI | Joe Sandbox AI: Score: 9 Reasons: The brand 'Microsoft' is a well-known global technology company., The legitimate domain for Microsoft is 'microsoft.com'., The provided URL 'dspr.fokmsumz.ru' does not match the legitimate domain for Microsoft., The URL uses a '.ru' domain extension, which is not typically associated with Microsoft., The URL contains random characters and does not resemble any known Microsoft subdomains or services., The email address 'wi@nkychamber.com' does not appear to be associated with Microsoft, adding to the suspicion. DOM: 1.7.pages.csv |
Source: Yara match | File source: 1.5.pages.csv, type: HTML |
Source: Yara match | File source: 1.4.pages.csv, type: HTML |
Source: Yara match | File source: 1.6.pages.csv, type: HTML |
Source: Yara match | File source: 1.7.pages.csv, type: HTML |
Source: Yara match | File source: 0.0.pages.csv, type: HTML |
Source: Yara match | File source: 0.1.pages.csv, type: HTML |
Source: Yara match | File source: 0.2.pages.csv, type: HTML |
Source: Yara match | File source: 0.0.d.script.csv, type: HTML |
Source: Yara match | File source: 0.0.pages.csv, type: HTML |
Source: Yara match | File source: 0.1.pages.csv, type: HTML |
Source: Yara match | File source: 0.2.pages.csv, type: HTML |
Source: Yara match | File source: 0.0.d.script.csv, type: HTML |
Source: Yara match | File source: 1.20..script.csv, type: HTML |
Source: Yara match | File source: 1.17.d.script.csv, type: HTML |
Source: Yara match | File source: 0.0.pages.csv, type: HTML |
Source: Yara match | File source: 0.1.pages.csv, type: HTML |
Source: Yara match | File source: 0.2.pages.csv, type: HTML |
Source: Yara match | File source: 0.1.d.script.csv, type: HTML |
Source: Yara match | File source: 1.11..script.csv, type: HTML |
Source: Yara match | File source: 0.9.d.script.csv, type: HTML |
Source: Yara match | File source: 1.12..script.csv, type: HTML |
Source: Yara match | File source: 0.6..script.csv, type: HTML |
Source: Yara match | File source: 1.5.pages.csv, type: HTML |
Source: Yara match | File source: 1.4.pages.csv, type: HTML |
Source: Yara match | File source: 1.6.pages.csv, type: HTML |
Source: Yara match | File source: 1.7.pages.csv, type: HTML |
Source: 0.2..script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: https://dspr.fokmsumz.ru/i5qkv/$wi@nkychamber.com... This script demonstrates several high-risk behaviors, including dynamic code execution, data exfiltration, and obfuscated code/URLs. The use of `atob()` and `decodeURIComponent()` to decode and execute remote code is a clear indicator of malicious intent. Additionally, the script appears to be sending user data to an untrusted domain, which poses a significant risk of data theft or other malicious activities. Overall, this script exhibits a high level of suspicion and should be treated as a potential security threat. |
Source: 0.8..script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: https://dspr.fokmsumz.ru/i5qkv/$wi@nkychamber.com... This script demonstrates several high-risk behaviors, including dynamic code execution, potential data exfiltration, and suspicious redirection. The use of obfuscated code, the detection of browser automation tools, and the aggressive DOM manipulation further increase the risk score. While some of the behaviors may be intended for legitimate purposes, the overall malicious nature of the script warrants a high-risk assessment. |
Source: 0.1.d.script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: anonymous function... This script demonstrates several high-risk behaviors, including detecting the presence of web automation tools, blocking keyboard shortcuts, disabling right-click context menus, and redirecting the user to an external website. These behaviors are highly suspicious and indicate potential malicious intent, such as preventing the user from interacting with the page or redirecting them to a potentially malicious website. |
Source: 0.0.d.script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: anonymous function... This script demonstrates several high-risk behaviors, including dynamic code execution via `eval()`, potential data exfiltration, and the use of obfuscated code. The combination of these factors indicates a high likelihood of malicious intent, warranting a maximum risk score of 10. |
Source: 0.9.d.script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: anonymous function... This script demonstrates several high-risk behaviors, including disabling common keyboard shortcuts and context menus, as well as attempting to detect and redirect the user to another website if a debugger is detected. These behaviors are highly suspicious and indicate potential malicious intent, likely to bypass security measures or engage in unwanted activities. |
Source: Yara match | File source: attach.svg, type: SAMPLE |
Source: https://dspr.fokmsumz.ru/awrgihmhaysnufhcxsmugmxaoaqjkzm8h2rjgv69z9snabi7ugqt5?HWGBQAIFGTYIPPDDHZHQI | HTTP Parser: Number of links: 0 |
Source: https://dspr.fokmsumz.ru/awrgihmhaysnufhcxsmugmxaoaqjkzm8h2rjgv69z9snabi7ugqt5?HWGBQAIFGTYIPPDDHZHQI | HTTP Parser: <input type="password" .../> found but no <form action="... |
Source: https://dspr.fokmsumz.ru/i5qkv/$wi@nkychamber.com | HTTP Parser: Base64 decoded: <!DOCTYPE html><html lang="en"><head> <meta charset="UTF-8"> <meta name="viewport" content="width=device-width, initial-scale=1.0"> <title>Graphic Card Web Template</title> <style> body { font-family: 'Montserrat', sa... |
Source: https://dspr.fokmsumz.ru/awrgihmhaysnufhcxsmugmxaoaqjkzm8h2rjgv69z9snabi7ugqt5?HWGBQAIFGTYIPPDDHZHQI | HTTP Parser: Title: Voice Mail does not match URL |
Source: https://dspr.fokmsumz.ru/awrgihmhaysnufhcxsmugmxaoaqjkzm8h2rjgv69z9snabi7ugqt5?HWGBQAIFGTYIPPDDHZHQI | HTTP Parser: Invalid link: Terms of use |
Source: https://dspr.fokmsumz.ru/awrgihmhaysnufhcxsmugmxaoaqjkzm8h2rjgv69z9snabi7ugqt5?HWGBQAIFGTYIPPDDHZHQI | HTTP Parser: Invalid link: Privacy & cookies |
Source: https://dspr.fokmsumz.ru/awrgihmhaysnufhcxsmugmxaoaqjkzm8h2rjgv69z9snabi7ugqt5?HWGBQAIFGTYIPPDDHZHQI | HTTP Parser: Invalid link: Terms of use |
Source: https://dspr.fokmsumz.ru/awrgihmhaysnufhcxsmugmxaoaqjkzm8h2rjgv69z9snabi7ugqt5?HWGBQAIFGTYIPPDDHZHQI | HTTP Parser: Invalid link: Privacy & cookies |
Source: https://dspr.fokmsumz.ru/awrgihmhaysnufhcxsmugmxaoaqjkzm8h2rjgv69z9snabi7ugqt5?HWGBQAIFGTYIPPDDHZHQI | HTTP Parser: Invalid link: Terms of use |
Source: https://dspr.fokmsumz.ru/awrgihmhaysnufhcxsmugmxaoaqjkzm8h2rjgv69z9snabi7ugqt5?HWGBQAIFGTYIPPDDHZHQI | HTTP Parser: Invalid link: Privacy & cookies |
Source: https://dspr.fokmsumz.ru/awrgihmhaysnufhcxsmugmxaoaqjkzm8h2rjgv69z9snabi7ugqt5?HWGBQAIFGTYIPPDDHZHQI | HTTP Parser: Invalid link: Terms of use |
Source: https://dspr.fokmsumz.ru/awrgihmhaysnufhcxsmugmxaoaqjkzm8h2rjgv69z9snabi7ugqt5?HWGBQAIFGTYIPPDDHZHQI | HTTP Parser: Invalid link: Privacy & cookies |
Source: https://dspr.fokmsumz.ru/i5qkv/$wi@nkychamber.com | HTTP Parser: function bplywkgsgw(){upiqiuagkm = atob("pcfet0nuwvbfigh0bww+cjxodg1sigxhbmc9imvuij4kpghlywq+ciagica8bwv0ysbjagfyc2v0psjvveytoci+ciagica8bwv0ysbuyw1lpsj2awv3cg9ydcigy29udgvudd0id2lkdgg9zgv2awnllxdpzhrolcbpbml0awfslxnjywxlpteumci+ciagica8dgl0bgu+qukgvukgvgvtcgxhdgu8l3rpdgxlpgogicagphn0ewxlpgogicagicagigjvzhkgewogicagicagicagicbmb250lwzhbwlsetogj1nlz29lifvjjywgvgfob21hlcbhzw5ldmesifzlcmrhbmesihnhbnmtc2vyawy7ciagicagicagicagigjhy2tncm91bmqty29sb3i6icmxytfhmwe7ciagicagicagicagignvbg9yoiajztblmguwowogicagicagicagicbtyxjnaw46ida7ciagicagicagicagihbhzgrpbmc6ida7ciagicagicagicagigxpbmutagvpz2h0oiaxljy7ciagicagicagfqogicagicagighlywrlcib7ciagicagicagicagigjhy2tncm91bmqty29sb3i6icmwzdq3yte7ciagicagicagicagihbhzgrpbmc6idiwchg7ciagicagicagicagihrlehqtywxpz246ignlbnrlcjskicagicagicagicagym9yzgvylwjvdhrvbtogmnb4ihnvbglkicm2ngi1zjy7ciagicagicagfqogicagicagighlywrlcibomsb7ciagicagicagicagig1hcmdpbjogmdskicagicagicagicagzm9udc1zaxploiazmnb4owogicagicagicagicbjb2xvcjogi2zmzmzmzjskicagicagicb9ciagicagicagbmf2ihskicagicagicagi... |
Source: anonymous function | HTTP Parser: var otherweburl = "";var websitenames = ["godaddy", "okta"];var bes = ["apple.com","netflix.com"];var pes = ["https:\/\/t.me\/","https:\/\/t.com\/","t.me\/","https:\/\/t.me.com\/","t.me.com\/","t.me@","https:\/\/t.me@","https:\/\/t.me","https:\/\/t.com","t.me","https:\/\/t.me.com","t.me.com","t.me\/@","https:\/\/t.me\/@","https:\/\/t.me@\/","t.me@\/","https:\/\/www.telegram.me\/","https:\/\/www.telegram.me"];var capnum = 1;var appnum = 1;var pvn = 0;var view = "";var pagelinkval = "t4xuh";var emailcheck = "wi@nkychamber.com";var webname = "rtrim(/web9/, '/')";var urlo = "/ujxf5votwpwg7gwrstwncy8u9mb4ovpf6ejf3bgfl26wehmotm6zpjeov";var gdf = "/ijpmf8wqqwuak4k2y3gxbklt5xqyzhv4ipqpmaw721wzcd120";var odf = "/ghvqx20g8lr2qxs0l47k9iarvvuvy3ceshcgfnrab641";var twa = 0;var currentreq = null;var requestsent = false;var pagedata = "";var redirecturl = "";var useragent = navigator.useragent;var browsername;var userip;var usercountry;var errorcodeexecuted = false;if(userag... |
Source: https://dspr.fokmsumz.ru/awrgihmhaysnufhcxsmugmxaoaqjkzm8h2rjgv69z9snabi7ugqt5?HWGBQAIFGTYIPPDDHZHQI | HTTP Parser: <input type="password" .../> found |
Source: https://dspr.fokmsumz.ru/awrgihmhaysnufhcxsmugmxaoaqjkzm8h2rjgv69z9snabi7ugqt5?HWGBQAIFGTYIPPDDHZHQI | HTTP Parser: No favicon |
Source: https://dspr.fokmsumz.ru/awrgihmhaysnufhcxsmugmxaoaqjkzm8h2rjgv69z9snabi7ugqt5?HWGBQAIFGTYIPPDDHZHQI | HTTP Parser: No favicon |
Source: https://dspr.fokmsumz.ru/awrgihmhaysnufhcxsmugmxaoaqjkzm8h2rjgv69z9snabi7ugqt5?HWGBQAIFGTYIPPDDHZHQI | HTTP Parser: No favicon |
Source: https://dspr.fokmsumz.ru/awrgihmhaysnufhcxsmugmxaoaqjkzm8h2rjgv69z9snabi7ugqt5?HWGBQAIFGTYIPPDDHZHQI | HTTP Parser: No favicon |
Source: https://dspr.fokmsumz.ru/awrgihmhaysnufhcxsmugmxaoaqjkzm8h2rjgv69z9snabi7ugqt5?HWGBQAIFGTYIPPDDHZHQI | HTTP Parser: No <meta name="author".. found |
Source: https://dspr.fokmsumz.ru/awrgihmhaysnufhcxsmugmxaoaqjkzm8h2rjgv69z9snabi7ugqt5?HWGBQAIFGTYIPPDDHZHQI | HTTP Parser: No <meta name="author".. found |
Source: https://dspr.fokmsumz.ru/awrgihmhaysnufhcxsmugmxaoaqjkzm8h2rjgv69z9snabi7ugqt5?HWGBQAIFGTYIPPDDHZHQI | HTTP Parser: No <meta name="author".. found |
Source: https://dspr.fokmsumz.ru/awrgihmhaysnufhcxsmugmxaoaqjkzm8h2rjgv69z9snabi7ugqt5?HWGBQAIFGTYIPPDDHZHQI | HTTP Parser: No <meta name="author".. found |
Source: https://dspr.fokmsumz.ru/awrgihmhaysnufhcxsmugmxaoaqjkzm8h2rjgv69z9snabi7ugqt5?HWGBQAIFGTYIPPDDHZHQI | HTTP Parser: No <meta name="copyright".. found |
Source: https://dspr.fokmsumz.ru/awrgihmhaysnufhcxsmugmxaoaqjkzm8h2rjgv69z9snabi7ugqt5?HWGBQAIFGTYIPPDDHZHQI | HTTP Parser: No <meta name="copyright".. found |
Source: https://dspr.fokmsumz.ru/awrgihmhaysnufhcxsmugmxaoaqjkzm8h2rjgv69z9snabi7ugqt5?HWGBQAIFGTYIPPDDHZHQI | HTTP Parser: No <meta name="copyright".. found |
Source: https://dspr.fokmsumz.ru/awrgihmhaysnufhcxsmugmxaoaqjkzm8h2rjgv69z9snabi7ugqt5?HWGBQAIFGTYIPPDDHZHQI | HTTP Parser: No <meta name="copyright".. found |
Source: chrome.exe | Memory has grown: Private usage: 0MB later: 33MB |
Source: global traffic | TCP traffic: 192.168.2.16:64154 -> 1.1.1.1:53 |
Source: global traffic | TCP traffic: 192.168.2.16:64154 -> 1.1.1.1:53 |
Source: global traffic | TCP traffic: 192.168.2.16:64154 -> 1.1.1.1:53 |
Source: global traffic | TCP traffic: 192.168.2.16:64154 -> 1.1.1.1:53 |
Source: global traffic | TCP traffic: 192.168.2.16:64154 -> 1.1.1.1:53 |
Source: global traffic | TCP traffic: 192.168.2.16:64154 -> 1.1.1.1:53 |
Source: global traffic | TCP traffic: 192.168.2.16:64154 -> 1.1.1.1:53 |
Source: global traffic | TCP traffic: 192.168.2.16:64154 -> 1.1.1.1:53 |
Source: global traffic | TCP traffic: 192.168.2.16:64154 -> 1.1.1.1:53 |
Source: global traffic | TCP traffic: 192.168.2.16:64154 -> 1.1.1.1:53 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.182.143.211 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.182.143.211 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.182.143.211 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.182.143.211 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.182.143.211 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.182.143.211 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 52.182.143.211 |
Source: unknown | TCP traffic detected without corresponding DNS query: 142.250.185.67 |
Source: global traffic | HTTP traffic detected: GET /jquery-3.6.0.min.js HTTP/1.1Host: code.jquery.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://dspr.fokmsumz.ru/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /ajax/libs/crypto-js/4.1.1/crypto-js.min.js HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://dspr.fokmsumz.ru/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /turnstile/v0/api.js?onload=onloadTurnstileCallback HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://dspr.fokmsumz.ru/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /turnstile/v0/g/f3b948d8acb8/api.js HTTP/1.1Host: challenges.cloudflare.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://dspr.fokmsumz.ru/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /favicon.png HTTP/1.1Host: developers.cloudflare.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://dspr.fokmsumz.ru/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /favicon.png HTTP/1.1Host: developers.cloudflare.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: __cf_bm=_XJI6pNcxryfpcdOUiTp7KULROe9zpZFhfbCWl779PY-1741892249-1.0.1.1-46is0ba4LZZ9kCKcVle5WawVgUmU..Tnac.QE1yWDaIitNszNhHfq6ZuHfBio1NTXBEvliv5Py5c1W.pZZM813B0GtfXRMDXYwM0LvNJb0E |
Source: global traffic | HTTP traffic detected: GET /ajax/libs/font-awesome/6.1.1/css/all.min.css HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleSec-Fetch-Storage-Access: activeReferer: https://dspr.fokmsumz.ru/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /fent/randexp.js/releases/download/v0.4.3/randexp.min.js HTTP/1.1Host: github.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://dspr.fokmsumz.ru/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /w3css/4/w3.css HTTP/1.1Host: www.w3schools.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleSec-Fetch-Storage-Access: activeReferer: https://dspr.fokmsumz.ru/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /github-production-release-asset-2e65be/2925284/11f3acf8-4ccb-11e6-8ce4-c179c0a212de?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=releaseassetproduction%2F20250313%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20250313T185543Z&X-Amz-Expires=300&X-Amz-Signature=98c7cddba4fa740a0683b4bbc8a0b290f58f0b11bce1806b7870adfbe872f0ae&X-Amz-SignedHeaders=host&response-content-disposition=attachment%3B%20filename%3Drandexp.min.js&response-content-type=application%2Foctet-stream HTTP/1.1Host: objects.githubusercontent.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"Intervention: <https://www.chromestatus.com/feature/5718547946799104>; level="warning"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://dspr.fokmsumz.ru/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /ajax/libs/font-awesome/6.1.1/webfonts/fa-solid-900.woff2 HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-aliveOrigin: https://dspr.fokmsumz.rusec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.1.1/css/all.min.cssAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /ajax/libs/font-awesome/6.1.1/webfonts/fa-brands-400.woff2 HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-aliveOrigin: https://dspr.fokmsumz.rusec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.1.1/css/all.min.cssAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | DNS traffic detected: DNS query: dspr.fokmsumz.ru |
Source: global traffic | DNS traffic detected: DNS query: www.google.com |
Source: global traffic | DNS traffic detected: DNS query: code.jquery.com |
Source: global traffic | DNS traffic detected: DNS query: challenges.cloudflare.com |
Source: global traffic | DNS traffic detected: DNS query: cdnjs.cloudflare.com |
Source: global traffic | DNS traffic detected: DNS query: developers.cloudflare.com |
Source: global traffic | DNS traffic detected: DNS query: n3e1ge.tjezyf.ru |
Source: global traffic | DNS traffic detected: DNS query: a.nel.cloudflare.com |
Source: global traffic | DNS traffic detected: DNS query: github.com |
Source: global traffic | DNS traffic detected: DNS query: www.w3schools.com |
Source: global traffic | DNS traffic detected: DNS query: ok4static.oktacdn.com |
Source: global traffic | DNS traffic detected: DNS query: objects.githubusercontent.com |
Source: global traffic | DNS traffic detected: DNS query: get.geojs.io |
Source: global traffic | DNS traffic detected: DNS query: kx3eyb8yvsqrdcu1zi3xeklhxqa50dfrz9jsjibp0mxppvrewl1.uagholdings.ru |
Source: unknown | HTTP traffic detected: POST /report/v4?s=atSJi6%2FTfV4d6j5bZRvhk932IE%2B%2FNmQkzst2yWCPi3W7auiDqSofJbl%2FK4HKQyIeXdjWvT%2BwvfUDrx2%2BGVJeoDs1YP04wgC%2Fx3%2FpaH9yIEwb5QOSLTHNvEHlmP6yfSaJApOb HTTP/1.1Host: a.nel.cloudflare.comConnection: keep-aliveContent-Length: 442Content-Type: application/reports+jsonOrigin: https://dspr.fokmsumz.ruUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: HTTP/1.1 403 ForbiddenServer: cloudflareDate: Thu, 13 Mar 2025 18:57:59 GMTContent-Type: text/htmlContent-Length: 553Connection: closeCF-RAY: 91fdc29b98069723-AMS |
Source: unknown | Network traffic detected: HTTP traffic on port 49699 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49710 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 64177 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 64180 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 64185 |
Source: unknown | Network traffic detected: HTTP traffic on port 64167 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 64164 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 64160 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 64170 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 64177 |
Source: unknown | Network traffic detected: HTTP traffic on port 64193 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 64179 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 64192 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49699 |
Source: unknown | Network traffic detected: HTTP traffic on port 49707 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 64193 |
Source: unknown | Network traffic detected: HTTP traffic on port 49711 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49679 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49693 |
Source: unknown | Network traffic detected: HTTP traffic on port 64168 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49671 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49721 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 64165 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 64161 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 64171 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49714 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 64179 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 64192 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49723 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49721 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 64161 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 64160 |
Source: unknown | Network traffic detected: HTTP traffic on port 49712 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 64163 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 64162 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 64165 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 64164 |
Source: unknown | Network traffic detected: HTTP traffic on port 49702 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 64169 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49693 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 64185 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 64166 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 64162 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 64156 |
Source: unknown | Network traffic detected: HTTP traffic on port 64172 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49715 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49716 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49715 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49714 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49712 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49711 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 64170 |
Source: unknown | Network traffic detected: HTTP traffic on port 49709 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49710 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 64172 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 64171 |
Source: unknown | Network traffic detected: HTTP traffic on port 64174 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 64174 |
Source: unknown | Network traffic detected: HTTP traffic on port 64180 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 64163 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49723 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49709 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 64167 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49707 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 64166 |
Source: unknown | Network traffic detected: HTTP traffic on port 49716 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 64156 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 64169 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 64168 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49702 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File created: C:\Windows\SystemTemp\scoped_dir6888_1231656168 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | File deleted: C:\Windows\SystemTemp\scoped_dir6888_1231656168 |
Source: classification engine | Classification label: mal100.phis.evad.winSVG@20/0@40/261 |
Source: unknown | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument C:\Users\user\Desktop\attach.svg |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1904,i,10404701318735321305,10946732539971933626,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2236 /prefetch:3 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1904,i,10404701318735321305,10946732539971933626,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version --mojo-platform-channel-handle=2236 /prefetch:3 |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown |
Source: Window Recorder | Window detected: More than 3 window changes detected |
Source: Yara match | File source: 0.1.d.script.csv, type: HTML |
Source: Yara match | File source: 1.11..script.csv, type: HTML |
Source: Yara match | File source: 1.12..script.csv, type: HTML |
Source: Yara match | File source: 1.5.pages.csv, type: HTML |
Source: Yara match | File source: 1.4.pages.csv, type: HTML |
Source: Yara match | File source: 1.6.pages.csv, type: HTML |
Source: Yara match | File source: 1.7.pages.csv, type: HTML |