Windows
Analysis Report
http://zeit-zu-investieren.cc/crp/gfh53g4h54j4h/a3ccg4n2/?affsub2=es2
Overview
General Information
Detection
Score: | 64 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Classification
- System is w10x64_ra
chrome.exe (PID: 6216 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized "abou t:blank" MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 6448 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=2040,i ,382770400 1359153027 ,975987398 4629800320 ,262144 -- disable-fe atures=Opt imizationG uideModelD ownloading ,Optimizat ionHints,O ptimizatio nHintsFetc hing,Optim izationTar getPredict ion --vari ations-see d-version --mojo-pla tform-chan nel-handle =2248 /pre fetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
chrome.exe (PID: 7140 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt p://zeit-z u-investie ren.cc/crp /gfh53g4h5 4j4h/a3ccg 4n2/?affsu b2=es2" MD5: E81F54E6C1129887AEA47E7D092680BF)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | Avira URL Cloud: |
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Phishing |
---|
Source: | Joe Sandbox AI: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Memory has grown: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | File created: |
Source: | File deleted: |
Source: | Classification label: |
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: |
Source: | Window detected: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Browser Extensions | 1 Process Injection | 1 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Extra Window Memory Injection | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 File Deletion | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Extra Window Memory Injection | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
beacons3.gvt2.com | 142.250.185.67 | true | false | high | |
zeit-zu-investieren.cc | 45.11.92.141 | true | true | unknown | |
beacons-handoff.gcp.gvt2.com | 142.251.143.35 | true | false | high | |
maps.google.com | 142.250.185.110 | true | false | high | |
www.google.com | 142.250.185.68 | true | false | high | |
beacons2.gvt2.com | 142.250.179.67 | true | false | high | |
beacons.gvt2.com | 142.251.143.67 | true | false | high | |
beacons6.gvt2.com | 172.217.16.195 | true | false | high | |
beacons.gcp.gvt2.com | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true | unknown | ||
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
false |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.250.186.67 | unknown | United States | 15169 | GOOGLEUS | false | |
142.250.185.68 | www.google.com | United States | 15169 | GOOGLEUS | false | |
1.1.1.1 | unknown | Australia | 13335 | CLOUDFLARENETUS | false | |
216.58.206.74 | unknown | United States | 15169 | GOOGLEUS | false | |
142.251.5.84 | unknown | United States | 15169 | GOOGLEUS | false | |
216.58.206.78 | unknown | United States | 15169 | GOOGLEUS | false | |
142.250.185.110 | maps.google.com | United States | 15169 | GOOGLEUS | false | |
142.250.185.138 | unknown | United States | 15169 | GOOGLEUS | false | |
142.250.185.238 | unknown | United States | 15169 | GOOGLEUS | false | |
142.250.185.227 | unknown | United States | 15169 | GOOGLEUS | false | |
142.250.181.227 | unknown | United States | 15169 | GOOGLEUS | false | |
45.11.92.141 | zeit-zu-investieren.cc | Russian Federation | 40676 | AS40676US | true | |
142.250.186.164 | unknown | United States | 15169 | GOOGLEUS | false | |
142.250.186.142 | unknown | United States | 15169 | GOOGLEUS | false | |
142.250.184.227 | unknown | United States | 15169 | GOOGLEUS | false | |
216.58.212.163 | unknown | United States | 15169 | GOOGLEUS | false | |
142.250.184.234 | unknown | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.16 |
192.168.2.7 |
192.168.2.5 |
192.168.2.23 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1638223 |
Start date and time: | 2025-03-14 10:04:45 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Sample URL: | http://zeit-zu-investieren.cc/crp/gfh53g4h54j4h/a3ccg4n2/?affsub2=es2 |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 16 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | stream |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal64.phis.win@23/32@43/194 |
- Exclude process from analysis (whitelisted): svchost.exe
- Excluded IPs from analysis (whitelisted): 216.58.206.78, 216.58.212.163, 142.250.185.238, 142.251.5.84, 142.250.184.238, 142.250.181.238, 142.250.185.142, 172.217.18.14, 142.250.184.234, 142.250.186.67
- Excluded domains from analysis (whitelisted): fonts.googleapis.com, clients2.google.com, accounts.google.com, redirector.gvt1.com, fonts.gstatic.com, clientservices.googleapis.com, clients.l.google.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtOpenFile calls found.
- Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: http://zeit-zu-investieren.cc/crp/gfh53g4h54j4h/a3ccg4n2/?affsub2=es2
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 33326 |
Entropy (8bit): | 7.994185063306593 |
Encrypted: | true |
SSDEEP: | |
MD5: | 7E3C36ABCC7D4F30F28A01D719C4BC49 |
SHA1: | 519556FDD6EA712870409F347880DA8364BF751F |
SHA-256: | 404CAB205A4E4543063C9E138CCC4A9E8E2E4C022C37300348B41414F8CB9CB2 |
SHA-512: | 23C069E1BEA150DEF9C3C8F1D953C119F041479A746920A4DB077158B960F857B5DC2F73A670861CAFD8CC15BDFE1F92A9D488839D1AFD7C15CEE5C7385CB8A8 |
Malicious: | false |
Reputation: | unknown |
URL: | http://zeit-zu-investieren.cc/crp/gfh53g4h54j4h/a3ccg4n2/assets/img/user_avatar-RHta-0.webp |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2946 |
Entropy (8bit): | 5.46572521740437 |
Encrypted: | false |
SSDEEP: | |
MD5: | 2EBD2B75B06FA287B8ED7079ED471843 |
SHA1: | 2BE0B9D113659E90C147890EB4004BA9D717A1A2 |
SHA-256: | 42131E3DDBB898F7CC2BD2B13C23AB3E9CB8564570973438394B57AE30A51985 |
SHA-512: | BB8CB0D373D677EF49E47803DAA25102D210049741D1204251A6C836F6949DAD0B106CFD9BD4DE2449C2FB3186079832287063EFF2473B923279BB150B5EC45F |
Malicious: | false |
Reputation: | unknown |
URL: | https://maps.googleapis.com/maps-api-v3/api/js/60/4/geometry.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 32343 |
Entropy (8bit): | 5.576826427318878 |
Encrypted: | false |
SSDEEP: | |
MD5: | D4C56AA6504707666C864C83519E17E9 |
SHA1: | BCC60CEE4DB3AA99D9062ADCFEEBD5E835229590 |
SHA-256: | DBDC3638A12A0325B735875E40460431AC22943D072A99D0BC572E13FB57B9DE |
SHA-512: | 220025C64EC06DD50506EBF2E8CC9AF8B8BB293AB635430DF25C193830AC4D4808058226423F3CC3A1D181E9C872EAEC74F05FD3E311AD3260A0F1B7D3D4D701 |
Malicious: | false |
Reputation: | unknown |
URL: | https://maps.googleapis.com/maps-api-v3/api/js/60/4/onion.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 98255 |
Entropy (8bit): | 4.785098083739527 |
Encrypted: | false |
SSDEEP: | |
MD5: | 1D14AC4000DC4A8D3557B256248D9000 |
SHA1: | 9EE496CC9BAAAE58B98E7FC1EB46E3578DAF8143 |
SHA-256: | 4FFA6BEA4304D2EDA418683F56261685ED47BF00995039F27E5AD62D53938D2D |
SHA-512: | CB098F6EEC464B8709EC6C70097F9B089C1E79EC6DD38ED9614D873F9D9658A6E9267178FD9CDFAF6068D7D2780963D766695E56EB10F5DFFF441E5BAB444FEF |
Malicious: | false |
Reputation: | unknown |
URL: | http://zeit-zu-investieren.cc/crp/gfh53g4h54j4h/a3ccg4n2/common/style_css/bootstrap-icons.css |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 11971 |
Entropy (8bit): | 5.911974436252161 |
Encrypted: | false |
SSDEEP: | |
MD5: | 37CF506E94E304347479920DD0301870 |
SHA1: | A85481FBACFAD4D2B58FD6FC2EF8A8141A444BD8 |
SHA-256: | A32DFE2B07E7DCCBC11411B723ACF6FB9605D9C11567A6891B39553ABC92BE31 |
SHA-512: | C66A582BB3E9F5C86EB68A4C996B8C71EF51C4DC66C36630DAB6F24FA34CECC2F4CF72F2A683AB7B4D5064BC68DB283722C2261D9C2EE6847E494631F5781FF5 |
Malicious: | false |
Reputation: | unknown |
URL: | "https://maps.googleapis.com/maps/api/js?client=google-maps-embed&paint_origin=&libraries=geometry,search&v=weekly&loading=async&language=en&callback=onApiLoad" |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 70354 |
Entropy (8bit): | 7.997229701934639 |
Encrypted: | true |
SSDEEP: | |
MD5: | BB7A00E641928BA0D9CD84B2139F6F12 |
SHA1: | 18D43A6FCE0F01C49D3E274427E9EFE610AB48B4 |
SHA-256: | FC710E48B6CBDDC9294371EBC3F6E658FC3FAD829C18D686AE6D5FEF58E3B1A7 |
SHA-512: | CEED632CB4B003F3A12556F0EBCF9B4C0FDD423BAF06F5FE02579992BFB30FF9DC3ADF1CB752960886A6E26180355BE77EA01B0F5BE260C642F18A9C2FE04EBE |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 3 |
Entropy (8bit): | 1.584962500721156 |
Encrypted: | false |
SSDEEP: | |
MD5: | 8A80554C91D9FCA8ACB82F023DE02F11 |
SHA1: | 5F36B2EA290645EE34D943220A14B54EE5EA5BE5 |
SHA-256: | CA3D163BAB055381827226140568F3BEF7EAAC187CEBD76878E0B63E9E442356 |
SHA-512: | CA4B6DEFB8ADCC010050BC8B1BB8F8092C4928B8A0FBA32146ABCFB256E4D91672F88CA2CDF6210E754E5B8AC5E23FB023806CCD749AC8B701F79A691F03C87A |
Malicious: | false |
Reputation: | unknown |
URL: | https://maps.googleapis.com/maps/api/mapsjs/gen_204?csp_test=true |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 53276 |
Entropy (8bit): | 7.996327468079799 |
Encrypted: | true |
SSDEEP: | |
MD5: | B59D870BA982F8751253D064EA0582AA |
SHA1: | BAFB80DFF8E54966D3AA76D6F73D822A2070298F |
SHA-256: | 35E3062451E5EA0A1BCB136B8B1347DD40587FE590D880D040469D76017227F6 |
SHA-512: | F7CDAF2ACC68F44DB4BCB7723B9C2A1175861094B5F2870728A071FF454D5E6151D5016A4DA77CFEF158E8588A991EBC0B37AF08DB16C6570961961A46C1E206 |
Malicious: | false |
Reputation: | unknown |
URL: | http://zeit-zu-investieren.cc/crp/gfh53g4h54j4h/a3ccg4n2/posts/16_11_2024/Ventilation-real-4e222-1.webp |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 56870 |
Entropy (8bit): | 7.997299945306364 |
Encrypted: | true |
SSDEEP: | |
MD5: | 7C5FCB105F73A91199E5CA75437A6C0B |
SHA1: | 3D938A358D0CC1E114E714A427FDBE8CFCF63E8B |
SHA-256: | 3D39A72307CA5D9376591F2967D4C0CE329C047B199255E7AF8A032275C58900 |
SHA-512: | 4DFEED650F04724871814703896FC2288B8E8441C19F70A0284EB885A45C7394E20229D8D3B4878A45FA3FE370A0D5476C7FE35E96517D5CC70C5A871FB4224E |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 33480 |
Entropy (8bit): | 7.994213611229128 |
Encrypted: | true |
SSDEEP: | |
MD5: | BA1B198260152FE1CCCFC03405A4584D |
SHA1: | DDBACD54DCC7C7EFA1C5394A7EFC7D813DD80AB0 |
SHA-256: | 91D1A85790A99C064AD9C3244B2A0292140DC75968A5E12B861637232DAB80C7 |
SHA-512: | BB18ED664F81BD87BB999274E03E3C98726031C0CB2532F3C20D663759097D8B099AA82F7FCEE51C4B9C1C824CEE94CC8DE953D5D7A651C864A863D490A28E2F |
Malicious: | false |
Reputation: | unknown |
URL: | http://zeit-zu-investieren.cc/crp/gfh53g4h54j4h/a3ccg4n2/assets/img/user_avatar-RHta-2.webp |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 5772 |
Entropy (8bit): | 5.501201589462824 |
Encrypted: | false |
SSDEEP: | |
MD5: | ABBAA272304F302B51084A451FFE7DAE |
SHA1: | 4F30F97F10502F580324D269E82DA30CCFB98908 |
SHA-256: | 15A5EE82EBDA5AA1EAB84759B10AE104478212211971EC31BC3A8439B51C7104 |
SHA-512: | 28A43EED3AC0E0A0DA75E6E59300BEBB3E4F0B1062E25132E6EA044B148601E99C5E5CF45AE05E1A4D4CCB2E3FF4D3D7F94806DDF229D468E7D7A6A2E99DB43F |
Malicious: | false |
Reputation: | unknown |
URL: | https://fonts.googleapis.com/css2?family=Big+Shoulders+Stencil+Display:wght@400;500;600;700&display=swap |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 3508 |
Entropy (8bit): | 5.301121972532377 |
Encrypted: | false |
SSDEEP: | |
MD5: | 8A82A948D3AF8EDB15629C355138744F |
SHA1: | 2B0AC27E1F9C3EE0F289FABC47532D5F18D1388B |
SHA-256: | 2A4D831311E6DE00CFF32AAEA8C476E3AB77E1298B3385AB2DA36817285346E0 |
SHA-512: | 77F83B1C7A683BFB061CC6BDB455AE28ABA5628A2349E4963BFDF9611A6557F95C45BB478985FD62929681892F773CDD5C7E59E62A0A5C9AC2880AB23555443E |
Malicious: | false |
Reputation: | unknown |
URL: | https://maps.googleapis.com/maps-api-v3/api/js/60/4/search_impl.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 68253 |
Entropy (8bit): | 5.351880637556216 |
Encrypted: | false |
SSDEEP: | |
MD5: | 49A6B4D019A934BCF83F0C397EBA82D8 |
SHA1: | 6181412E73966696D08E1E5B1243A572D0F22BA6 |
SHA-256: | CADDA460CCB4C3C01BB45F3D5976F63F5ADF8DC3FF1D31CB4FBD3DED4F18E5BF |
SHA-512: | B94465F995CC06B17803019A5A611EB73ADDF89E7FF0D464580BC9C79B1B3D24AE39BD1B64BA9FFAD3B39E239B3B4D018C76BF743EE0B9BF6808630B3D01ED40 |
Malicious: | false |
Reputation: | unknown |
URL: | http://zeit-zu-investieren.cc/crp/gfh53g4h54j4h/a3ccg4n2/common/js_files/jquery.fancybox.min.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 285313 |
Entropy (8bit): | 5.053810035814701 |
Encrypted: | false |
SSDEEP: | |
MD5: | 304FD509939802B85C4FFE9D58F3498F |
SHA1: | E82D537CEB3A36761D6F9725CB8023FE4AC18655 |
SHA-256: | 126ADD89639E7AC92DFF67C061C2E32486ECCA91D0D1D1ED8F1BC5EE34596A27 |
SHA-512: | 029AC435A1FC089B7989848A337F3AE5D7DF702A052912E71941B390E5F976F359E957DF7CB1B1C9A275A3656882DEFE9509AD625644F444A1F5929A5153BE45 |
Malicious: | false |
Reputation: | unknown |
URL: | http://zeit-zu-investieren.cc/crp/gfh53g4h54j4h/a3ccg4n2/common/js_files/jquery.min.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 7743 |
Entropy (8bit): | 5.402301641320615 |
Encrypted: | false |
SSDEEP: | |
MD5: | 24A494ABD80E69BA22599CB1ABCE07FD |
SHA1: | 4D5D6F6CEE65E510ADB572E570DE70A3AF7FEC42 |
SHA-256: | AD9890C4CF6A32E393E9B21374061F4163BBD346C6DC2956E55E7E3F4C8292A5 |
SHA-512: | 00624CD1A417D4F8979A125A15FBA016B7D231E5C1A08E6C259A1E9D0C75556D8700B50A18579CE19C69F799738B75DCDE76D2FBDD418B17522B0404CF6E9C10 |
Malicious: | false |
Reputation: | unknown |
URL: | "https://fonts.googleapis.com/css2?family=Crimson+Text:ital,wght@0,400;0,600;0,700;1,400;1,600;1,700&display=swap" |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 278470 |
Entropy (8bit): | 5.423101325684964 |
Encrypted: | false |
SSDEEP: | |
MD5: | EEDBBB80231A00F3E9C48AF0618C23C6 |
SHA1: | C8B9CBFEFE7FAEEDEDCAD7928E7C6326352D2406 |
SHA-256: | 5FE0A073ACE2F50344B1222B26540AFB741B7DB359714AEEBDA229FAE7B5DB03 |
SHA-512: | C09726CADA3CA1CD549C3BA6132195D8A58EE9CA5D0EAF97A8DA7897C2C0E1AD100432BBF160CAC1097658B50ECD4A63014B9A8BE6E4FE8210C7BD729B18A312 |
Malicious: | false |
Reputation: | unknown |
URL: | https://maps.googleapis.com/maps-api-v3/api/js/60/4/common.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 85044 |
Entropy (8bit): | 7.997149031473659 |
Encrypted: | true |
SSDEEP: | |
MD5: | 316400C09C0560B3812E58B3124BBF15 |
SHA1: | 2314D4D73DD9ED7AA2F9D18D45E71CA0440AC0A9 |
SHA-256: | 856B3F9E0DF4F7061C8948021C7CC6E6263D96C48161E7FE9E4FBEFD0C69A085 |
SHA-512: | D410D293CBD3FC7198C171D72C137D3032D0D1D8C8108AAA20DD273E745EA3DF928242CFA2FE5A095AF36E43EF3883FADB3794295DBA6403F61D575E659FFB81 |
Malicious: | false |
Reputation: | unknown |
URL: | http://zeit-zu-investieren.cc/crp/gfh53g4h54j4h/a3ccg4n2/common/style_css/fonts/bootstrap-icons.woff2?dd67030699838ea613ee6dbda90effa6 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 12795 |
Entropy (8bit): | 5.023138147083958 |
Encrypted: | false |
SSDEEP: | |
MD5: | A2D42584292F64C5827E8B67B1B38726 |
SHA1: | 1BE9B79BE02A1CFC5D96C4A5E0FEB8F472BABD95 |
SHA-256: | 5736E3EEC0C34BFC288854B7B8D2A8F1E22E9E2E7DAE3C8D1AD5DFB2D4734AD0 |
SHA-512: | 1FD8EB6628A8A5476C2E983DE00DF7DC47EE9A0501A4EF4C75BC52B5D7884E8F8A10831A35F1CDBF0CA38C325BF8444F6914BA0E9C9194A6EF3D46AC348B51CB |
Malicious: | false |
Reputation: | unknown |
URL: | http://zeit-zu-investieren.cc/crp/gfh53g4h54j4h/a3ccg4n2/common/style_css/jquery.fancybox.min.css |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 179612 |
Entropy (8bit): | 5.618955961633512 |
Encrypted: | false |
SSDEEP: | |
MD5: | 582A2A4B5625BAFB0D39CE7C18E79492 |
SHA1: | FE9C5AF8C2F15E776504ABB3EBB2634515B48FCD |
SHA-256: | 2C7330D0FB6EC7FB399168B167CAFC7E1186688782C4BB8A9EE089D0AC7A6843 |
SHA-512: | 2EE46C0C09A6E50ABA689F27BBB3E5CE9A2E0F6E1242BE8A1B259D8C0E639F51E677ECC34D2991FC738C1D6F5557012DF6DE04967699332DDF342F25B8EE1B2F |
Malicious: | false |
Reputation: | unknown |
URL: | https://maps.googleapis.com/maps-api-v3/api/js/60/4/util.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 26052 |
Entropy (8bit): | 7.9912777033346245 |
Encrypted: | true |
SSDEEP: | |
MD5: | 79F4A05271DF2557331188959E000767 |
SHA1: | E72E4F7D2E58634CA69DABCFCCB2C87D92A953D0 |
SHA-256: | DED83489ADAEEC098EE0D639252E72BE7DE219F759B939BA4B2E606E5E68B272 |
SHA-512: | 4CEA6F906EB49CBD0202B049BA22694A4E6F4D05D19F62FCF2E26A5F9157ABE090F08FB5F55F0D7C676D7E133FEEE3C2DB0A59FE97EAEC5E5CD78FA580405D39 |
Malicious: | false |
Reputation: | unknown |
URL: | https://fonts.gstatic.com/s/crimsontext/v19/wlpogwHKFkZgtmSR3NB0oRJfajhRK_Y.woff2 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2673 |
Entropy (8bit): | 5.289995026181556 |
Encrypted: | false |
SSDEEP: | |
MD5: | DD4903BD251C0BE35B2A704627EE2350 |
SHA1: | 59555D96A0DB96029AEFD090F0CB14F2CCA3B9F7 |
SHA-256: | 7EAD621A451AE6F5AF9A1224EA24C0EA6A9B9B7E737AD92E3108C509D7278D83 |
SHA-512: | CA5182A00A8CDEA6BA26D1C9C182839490232AF7D006A40D0D04940DC4845570F5632E0E8BA69FB1A405CE0EB5F1D2474A77FD614E570805E89E4AAB9C7C9A2C |
Malicious: | false |
Reputation: | unknown |
URL: | https://maps.googleapis.com/maps-api-v3/api/js/60/4/search.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 3452 |
Entropy (8bit): | 5.333645885683573 |
Encrypted: | false |
SSDEEP: | |
MD5: | D7F74099180D57494A08E2DD5EEE37A1 |
SHA1: | BEA13C8E6533A1F73DE0968026F10C5C2CC89A42 |
SHA-256: | A7DE596B1913214ACDB10A1CBE33DF7C0783034A42EEB86D449E4FA6389176AF |
SHA-512: | 28DE00DFE89B0C5CCBF398DA3B270B8E2F99A1EA8B63EA01BE0D91DFAA7283D7997C1279EF4071404561D4B43FAD0E05A5FAE1CB1FEF15AE1F68E4C17264BE81 |
Malicious: | false |
Reputation: | unknown |
URL: | https://maps.googleapis.com/maps-api-v3/api/js/60/4/overlay.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 25184 |
Entropy (8bit): | 7.992071869095497 |
Encrypted: | true |
SSDEEP: | |
MD5: | 23EEC75BA54D389A0188ABBB596B7614 |
SHA1: | DAA4672AD515A108325F52116E9A49AAB8CDD5FA |
SHA-256: | 538C7067580F457DD3DD98EBAABEB19405C12BDD01674D3DB8FD9948EE73C862 |
SHA-512: | 6A50E67D032474B8DB85942578F819F804F2FE19B1629D9F53605A81C87ADFDD3064E73B395B8D79051F966654444AC99CB59BD0019C205CAC4810A54AF14042 |
Malicious: | false |
Reputation: | unknown |
URL: | https://fonts.gstatic.com/s/crimsontext/v19/wlp2gwHKFkZgtmSR3NB0oRJfbwhT.woff2 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 49044 |
Entropy (8bit): | 7.996026369858628 |
Encrypted: | true |
SSDEEP: | |
MD5: | E58DBDD32330B774D84251493C4D5BEB |
SHA1: | E614CBC5A5A2562F48AB4803A41FD94766DBDDBE |
SHA-256: | 5267DE379AC4FE3F217BD13EA4D11AF6C5D48E57DE606FDE7BD192E05852BEC3 |
SHA-512: | 4B67D18E02F083B0783742792853BBF1819E8DBBC953369E07C1959CFD33CEB2895BB90571B75F13F99EDC673CB093C14B2EE0A70486F258C4EDEE8570EDDA81 |
Malicious: | false |
Reputation: | unknown |
URL: | http://zeit-zu-investieren.cc/crp/gfh53g4h54j4h/a3ccg4n2/assets/img/gallery-EPU5.webp |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 25540 |
Entropy (8bit): | 7.991502685547295 |
Encrypted: | true |
SSDEEP: | |
MD5: | 19AB149056827F64D640FA3D65F4E536 |
SHA1: | 754C09533C5B386067E762AE85F39C345EC10915 |
SHA-256: | 60B9B9640FC716ABD752DF41F38AD81052F4905E42BE2FF3C1F78E851863AEE0 |
SHA-512: | E382CFCF784EF72503CCD007642F5B3E285DE7B5515CD76457855896034B7EE26908A1F491527B9FE7A603A6627FB3DB0FC9618CDBD52724B8F4D309F7DE33D1 |
Malicious: | false |
Reputation: | unknown |
URL: | https://fonts.gstatic.com/s/crimsontext/v19/wlppgwHKFkZgtmSR3NB0oRJX1C1GDNNQ.woff2 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2206 |
Entropy (8bit): | 5.273591375889605 |
Encrypted: | false |
SSDEEP: | |
MD5: | 0DC409ED9387901716C1A55D71E6CF50 |
SHA1: | 820183498E8A73FF5593FFACA0333A657C2580E6 |
SHA-256: | 2E460938533D3D31C6DA3964FA21CC672F9B373F7C160DDCA6EF816FA3F49113 |
SHA-512: | 8589F8EAEA369DFC8B622928B5BDCC244439EDD63DF232B4A66F5D848D250E98F8C29FCCC07E69499DE5D9055D8ECC5C6CC302F44CF48F9D4CC80F770A2C2685 |
Malicious: | false |
Reputation: | unknown |
URL: | "https://www.google.com/maps/embed?origin=mfe&pb=!1m3!2m1!1s1019,+Canterbury+Trail,+Georgetown,+78626,+United+States!6i8!3m1!1sen!5m1!1sen" |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 238767 |
Entropy (8bit): | 5.569053023110954 |
Encrypted: | false |
SSDEEP: | |
MD5: | A6A8F82C5701D25A8829EFEE1E9EADB9 |
SHA1: | C00D5265EB719D2C80BD6F64926DCEBCF4C98032 |
SHA-256: | 6E3202AF9C34699E8727B48AF5AA1DF38B10815D1A5DD49BE8176B9026321A1D |
SHA-512: | 30C94D463962A088E182D8A3EDB3C026BE6C6245A3D9A7EA66DF836105EF75D7B2E028B8432752AC5BF821AA19DD5FE29E093B8ADE87080FBCC59CEA337B98C3 |
Malicious: | false |
Reputation: | unknown |
URL: | https://maps.googleapis.com/maps-api-v3/api/js/60/4/main.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2087 |
Entropy (8bit): | 5.028903414406507 |
Encrypted: | false |
SSDEEP: | |
MD5: | 6A1B7F865D6D3E9B6ACA4E8131CC6DE7 |
SHA1: | AA3233B9AB089872097C9C0AEEC67A8D2ABF1E1D |
SHA-256: | 3B0E141D28AF87F144EA808CC6C8F906172BE3E690976DF5694BB3233A614956 |
SHA-512: | DDA1A125510C5CC41250A1C1D057A51EBF3014EB6BC7C2E848FD3448C36268D4ED5FF7BB3CBBB5CC8EC6A082B042B6662FB1E8A634881BF3A11A8862EE70BE28 |
Malicious: | false |
Reputation: | unknown |
URL: | http://zeit-zu-investieren.cc/crp/gfh53g4h54j4h/a3ccg4n2/common/js_files/script.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 248669 |
Entropy (8bit): | 5.686294869113514 |
Encrypted: | false |
SSDEEP: | |
MD5: | BCBE9096CBAF6ECA90ABFCDC069C13E2 |
SHA1: | 79FF4A339DE8CE3D99A3B5A34BCE1A51D7FD46E1 |
SHA-256: | 489B33ED727742A6091A792D3A476C9B9A703001F5B3ACE10AB4A3C502A72CA0 |
SHA-512: | CF512DE45108DA27128895340E2943644807A48EFB6493C6372852A63F440BC41222102EC8FE078FE1F14F96C9525FC267FBE2C38400C6641EC93A08440F0D16 |
Malicious: | false |
Reputation: | unknown |
URL: | https://maps.gstatic.com/maps-api-v3/embed/js/60/4/init_embed.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 123218 |
Entropy (8bit): | 7.998599689807692 |
Encrypted: | true |
SSDEEP: | |
MD5: | 15D31BE6656E3D73EB6C1F3972FD8354 |
SHA1: | 9BC196DC443A612C1BD799AD493A7A0E22A3EF9A |
SHA-256: | 6434F977C1A67500434BFCA38CAED40020C976C478562CC5C1F33FC2C78C0DE9 |
SHA-512: | 65A71CD622B302E5728556ED73F5867AF0229A6E9C89FDC14AD87B415E448A1D65A1161BB681AAAEA1BC5E2BC6319E7F270683FB21485495D1E5B6D6387BB290 |
Malicious: | false |
Reputation: | unknown |
URL: | http://zeit-zu-investieren.cc/crp/gfh53g4h54j4h/a3ccg4n2/assets/img/user_avatar-RHta-1.webp |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 13146 |
Entropy (8bit): | 7.9829792746621955 |
Encrypted: | false |
SSDEEP: | |
MD5: | 91873C6A27D0AC29926F5A0EB384E0BD |
SHA1: | 22E6FC6C9B49B98E78C6BAC882F0C07BAEC33CDE |
SHA-256: | 6906A91EC24772441B7D51758774513F6B700DA45136AE850EA9CC8B60B4C532 |
SHA-512: | 4D4CCF26AF0E1A4E5A1E0933F7AFCAC8573839159F38F8A622D4FAEAFAC7B60036DC311866B874985F667CD9402C36232C306DDED2B9FFC3F30D0FFCD9A9CFAA |
Malicious: | false |
Reputation: | unknown |
URL: | http://zeit-zu-investieren.cc/crp/gfh53g4h54j4h/a3ccg4n2/?affsub2=es2 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 470430 |
Entropy (8bit): | 7.999613624675269 |
Encrypted: | true |
SSDEEP: | |
MD5: | 46FBA8580604F76ED033FB7ABDA509A9 |
SHA1: | 45A982892C24728AC1D441A5846615713A61ADC8 |
SHA-256: | 98A0DD833D08BFB7415B47CD5E598F4F2BBC56534B398C827515DA6C7B436A25 |
SHA-512: | 9D94DFF1982DC8674145401F79A13D80A5007B2563B2145487B22234868BA9CA9AAE4448A99D95F758B0BD71040D7E459690BC4A8AEB343C6F2D7D18319DB5D1 |
Malicious: | false |
Reputation: | unknown |
Preview: |