Windows Analysis Report
https://planninggreenfutures.co.uk/noil/

Overview

General Information

Sample URL: https://planninggreenfutures.co.uk/noil/
Analysis ID: 1665814
Infos:

Detection

Score: 20
Range: 0 - 100
Confidence: 80%

Signatures

AI detected suspicious Javascript
HTML page contains hidden javascript code

Classification

Phishing

barindex
Source: 0.0..script.csv Joe Sandbox AI: Detected suspicious JavaScript with source url: https://planninggreenfutures.co.uk/noil/... This script demonstrates several high-risk behaviors:1. Dynamic code execution using `eval()` and `decodeURIComponent()` to execute obfuscated code.2. Data exfiltration by setting a cookie with sensitive information and potentially submitting form data.3. Obfuscated code and URLs, making it difficult to analyze the script's true purpose.The script also attempts to detect various browser automation tools, which could indicate an attempt to bypass security measures. Overall, this script exhibits a high level of malicious intent and should be considered a significant security risk.
Source: https://planninggreenfutures.co.uk/noil/ HTTP Parser: Base64 decoded: (function(){ var a = function() {try{return !!window.addEventListener} catch(e) {return !1} }, b = function(b, c) {a() ? document.addEventListener("DOMContentLoaded", b, c) : document.attachEvent("onreadystatechange", b)}; b(functi...
Source: https://planninggreenfutures.co.uk/noil/ HTTP Parser: No favicon
Source: https://planninggreenfutures.co.uk/noil/ HTTP Parser: No favicon
Source: unknown HTTPS traffic detected: 74.125.138.147:443 -> 192.168.2.4:49724 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.21.32.1:443 -> 192.168.2.4:49727 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.21.32.1:443 -> 192.168.2.4:49728 version: TLS 1.2
Source: unknown TCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 2.17.190.73
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknown TCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknown TCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknown TCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknown TCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknown TCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknown TCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknown TCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknown TCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknown TCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknown TCP traffic detected without corresponding DNS query: 131.253.33.254
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknown TCP traffic detected without corresponding DNS query: 172.217.215.94
Source: unknown TCP traffic detected without corresponding DNS query: 172.217.215.94
Source: unknown TCP traffic detected without corresponding DNS query: 172.217.215.94
Source: unknown TCP traffic detected without corresponding DNS query: 172.217.215.94
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.27
Source: unknown TCP traffic detected without corresponding DNS query: 172.217.215.94
Source: unknown TCP traffic detected without corresponding DNS query: 172.217.215.94
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET /noil/ HTTP/1.1Host: planninggreenfutures.co.ukConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /favicon.ico HTTP/1.1Host: planninggreenfutures.co.ukConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://planninggreenfutures.co.uk/noil/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: jcc6Qx2Qa8K47m0GezRV3pUGC70=M9RIViqAG6IYepBuf0w_rLN-f2c; CMc2XCAX7fVppbgU-VOIqbYJOCQ=1744745764; Src9Gd_xPBWNrOvuF2DGCttyS7g=1744832164; NeNQ8RH03JIVEyjUqppBfkCIgb0=bGSC6C5b5xkNQcesxv04ABVh-lg; 9O5XFUSTRKEF4D0tNTH8i5VOalI=3-PU9Xsf7pbdMnWSiiLIvFWadsw
Source: global traffic HTTP traffic detected: GET /noil/ HTTP/1.1Host: planninggreenfutures.co.ukConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://planninggreenfutures.co.uk/noil/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: jcc6Qx2Qa8K47m0GezRV3pUGC70=M9RIViqAG6IYepBuf0w_rLN-f2c; CMc2XCAX7fVppbgU-VOIqbYJOCQ=1744745764; Src9Gd_xPBWNrOvuF2DGCttyS7g=1744832164; NeNQ8RH03JIVEyjUqppBfkCIgb0=bGSC6C5b5xkNQcesxv04ABVh-lg; 9O5XFUSTRKEF4D0tNTH8i5VOalI=3-PU9Xsf7pbdMnWSiiLIvFWadsw; jmnfUtjDdqBcSIM0lC6CLpFKm2Q=1744745766; R330STMjPDOl6Cd9ISymkYs_nuw=1744832166; DJXqr-x-Qr2IkAQhd7S0YiNVAlE=nR771USBrWlemPVYTuXNwbMCypk
Source: global traffic HTTP traffic detected: GET /favicon.ico HTTP/1.1Host: planninggreenfutures.co.ukConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://planninggreenfutures.co.uk/noil/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: jcc6Qx2Qa8K47m0GezRV3pUGC70=M9RIViqAG6IYepBuf0w_rLN-f2c; CMc2XCAX7fVppbgU-VOIqbYJOCQ=1744745764; Src9Gd_xPBWNrOvuF2DGCttyS7g=1744832164; NeNQ8RH03JIVEyjUqppBfkCIgb0=bGSC6C5b5xkNQcesxv04ABVh-lg; 9O5XFUSTRKEF4D0tNTH8i5VOalI=3-PU9Xsf7pbdMnWSiiLIvFWadsw; jmnfUtjDdqBcSIM0lC6CLpFKm2Q=1744745766; R330STMjPDOl6Cd9ISymkYs_nuw=1744832166; DJXqr-x-Qr2IkAQhd7S0YiNVAlE=nR771USBrWlemPVYTuXNwbMCypk; Tejxf_v6HPnbr1wA6K-c4ka28ng=d2cV0f4sDecz1xLHSfeOhOOBSvI; r-xLG1H1HiUoh7m7c7akYbtc3Bk=1744745767; a-vuaCHlCr2MaR58o4FNbAnhgHs=1744832167; yAfzWXZHJyocGJyXzR87YclZbOI=x0A5DWV1IG8jOukFSHvTiK59gaM
Source: global traffic HTTP traffic detected: GET /r/r4.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: global traffic DNS traffic detected: DNS query: planninggreenfutures.co.uk
Source: unknown HTTP traffic detected: POST /noil/ HTTP/1.1Host: planninggreenfutures.co.ukConnection: keep-aliveContent-Length: 22sec-ch-ua-platform: "Windows"X-Requested-TimeStamp-Combination: JRAJSttIF-9Qmygfn7av7VxL2k: 34292439X-Requested-TimeStamp: sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"X-Requested-Type-Combination: GETsec-ch-ua-mobile: ?0X-Requested-with: XMLHttpRequestUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36X-Requested-Type: GETContent-type: application/x-www-form-urlencodedX-Requested-TimeStamp-Expire: Accept: */*Origin: https://planninggreenfutures.co.ukSec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://planninggreenfutures.co.uk/noil/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: jcc6Qx2Qa8K47m0GezRV3pUGC70=M9RIViqAG6IYepBuf0w_rLN-f2c; CMc2XCAX7fVppbgU-VOIqbYJOCQ=1744745764; Src9Gd_xPBWNrOvuF2DGCttyS7g=1744832164; NeNQ8RH03JIVEyjUqppBfkCIgb0=bGSC6C5b5xkNQcesxv04ABVh-lg; 9O5XFUSTRKEF4D0tNTH8i5VOalI=3-PU9Xsf7pbdMnWSiiLIvFWadsw
Source: global traffic HTTP traffic detected: HTTP/1.1 503 Service UnavailableDate: Tue, 15 Apr 2025 19:36:05 GMTContent-Type: text/html; charset=utf-8Transfer-Encoding: chunkedConnection: closeX-Content-Type-Options: nosniffX-Content-Type-Options: nosniffX-Xss-Protection: 1; mode=blockX-Xss-Protection: 1; mode=blockX-Frame-Options: SAMEORIGINCache-Control: public, max-age=0 no-store, no-cache, must-revalidate, post-check=0, pre-check=0Pragma: no-cacheExpires: 0Cf-Cache-Status: DYNAMICServer: cloudflareSet-Cookie: jcc6Qx2Qa8K47m0GezRV3pUGC70=M9RIViqAG6IYepBuf0w_rLN-f2c; Path=/; Max-Age=86400; Expires=Wed, 16 Apr 2025 19:36:04 GMTSet-Cookie: CMc2XCAX7fVppbgU-VOIqbYJOCQ=1744745764; Path=/; Max-Age=86400; Expires=Wed, 16 Apr 2025 19:36:04 GMTSet-Cookie: Src9Gd_xPBWNrOvuF2DGCttyS7g=1744832164; Path=/; Max-Age=86400; Expires=Wed, 16 Apr 2025 19:36:04 GMTSet-Cookie: NeNQ8RH03JIVEyjUqppBfkCIgb0=bGSC6C5b5xkNQcesxv04ABVh-lg; Path=/; Max-Age=86400; Expires=Wed, 16 Apr 2025 19:36:04 GMTCF-RAY: 930de3c92c816863-NRTalt-svc: h3=":443"; ma=86400
Source: global traffic HTTP traffic detected: HTTP/1.1 503 Service UnavailableDate: Tue, 15 Apr 2025 19:36:08 GMTContent-Type: text/html; charset=utf-8Transfer-Encoding: chunkedConnection: closeServer: cloudflareX-Content-Type-Options: nosniffX-Content-Type-Options: nosniffX-Xss-Protection: 1; mode=blockX-Xss-Protection: 1; mode=blockCache-Control: public, max-age=0 no-store, no-cache, must-revalidate, post-check=0, pre-check=0Pragma: no-cacheX-Frame-Options: SAMEORIGINExpires: 0Cf-Cache-Status: BYPASSSet-Cookie: Tejxf_v6HPnbr1wA6K-c4ka28ng=d2cV0f4sDecz1xLHSfeOhOOBSvI; Path=/; Max-Age=86400; Expires=Wed, 16 Apr 2025 19:36:07 GMTSet-Cookie: r-xLG1H1HiUoh7m7c7akYbtc3Bk=1744745767; Path=/; Max-Age=86400; Expires=Wed, 16 Apr 2025 19:36:07 GMTSet-Cookie: a-vuaCHlCr2MaR58o4FNbAnhgHs=1744832167; Path=/; Max-Age=86400; Expires=Wed, 16 Apr 2025 19:36:07 GMTSet-Cookie: yAfzWXZHJyocGJyXzR87YclZbOI=x0A5DWV1IG8jOukFSHvTiK59gaM; Path=/; Max-Age=86400; Expires=Wed, 16 Apr 2025 19:36:07 GMTCF-RAY: 930de3d4fd7ce7c2-SYDalt-svc: h3=":443"; ma=86400
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 15 Apr 2025 19:36:09 GMTContent-Type: text/htmlTransfer-Encoding: chunkedConnection: closeVary: Accept-EncodingX-Content-Type-Options: nosniffX-Content-Type-Options: nosniffX-Xss-Protection: 1; mode=blockX-Xss-Protection: 1; mode=blockCf-Cache-Status: DYNAMICServer: cloudflareCF-RAY: 930de3dba8c5fcbd-NRTalt-svc: h3=":443"; ma=86400
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 15 Apr 2025 19:36:10 GMTContent-Type: text/htmlTransfer-Encoding: chunkedConnection: closeServer: cloudflareVary: Accept-EncodingX-Content-Type-Options: nosniffX-Content-Type-Options: nosniffX-Xss-Protection: 1; mode=blockX-Xss-Protection: 1; mode=blockCache-Control: public, max-age=315360000, stale-while-revalidate=315360000, stale-if-error=315360000, immutablePragma: publicCf-Cache-Status: MISSCF-RAY: 930de3e90817a93b-SYDalt-svc: h3=":443"; ma=86400
Source: unknown Network traffic detected: HTTP traffic on port 49733 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49733
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49744
Source: unknown Network traffic detected: HTTP traffic on port 49734 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49709 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49678 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49727 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49671 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49724 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49729 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49728 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49744 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49709
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49729
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49728
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49727
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49724
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49734
Source: unknown HTTPS traffic detected: 74.125.138.147:443 -> 192.168.2.4:49724 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.21.32.1:443 -> 192.168.2.4:49727 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.21.32.1:443 -> 192.168.2.4:49728 version: TLS 1.2
Source: classification engine Classification label: sus20.win@21/4@4/3
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2012,i,14331022784213342634,139238066655825086,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2568 /prefetch:3
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://planninggreenfutures.co.uk/noil/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2012,i,14331022784213342634,139238066655825086,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2568 /prefetch:3 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs