Source: 0.0..script.csv |
Joe Sandbox AI: Detected suspicious JavaScript with source url: https://planninggreenfutures.co.uk/noil/... This script demonstrates several high-risk behaviors:1. Dynamic code execution using `eval()` and `decodeURIComponent()` to execute obfuscated code.2. Data exfiltration by setting a cookie with sensitive information and potentially submitting form data.3. Obfuscated code and URLs, making it difficult to analyze the script's true purpose.The script also attempts to detect various browser automation tools, which could indicate an attempt to bypass security measures. Overall, this script exhibits a high level of malicious intent and should be considered a significant security risk. |
Source: https://planninggreenfutures.co.uk/noil/ |
HTTP Parser: Base64 decoded: (function(){ var a = function() {try{return !!window.addEventListener} catch(e) {return !1} }, b = function(b, c) {a() ? document.addEventListener("DOMContentLoaded", b, c) : document.attachEvent("onreadystatechange", b)}; b(functi... |
Source: https://planninggreenfutures.co.uk/noil/ |
HTTP Parser: No favicon |
Source: https://planninggreenfutures.co.uk/noil/ |
HTTP Parser: No favicon |
Source: unknown |
HTTPS traffic detected: 74.125.138.147:443 -> 192.168.2.4:49724 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 104.21.32.1:443 -> 192.168.2.4:49727 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 104.21.32.1:443 -> 192.168.2.4:49728 version: TLS 1.2 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.17.190.73 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 2.17.190.73 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.189.173.27 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.189.173.27 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.189.173.27 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 131.253.33.254 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 131.253.33.254 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 131.253.33.254 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 131.253.33.254 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 131.253.33.254 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 131.253.33.254 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 131.253.33.254 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 131.253.33.254 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 131.253.33.254 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 131.253.33.254 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.189.173.27 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 172.217.215.94 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 172.217.215.94 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 172.217.215.94 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 172.217.215.94 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.189.173.27 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.189.173.27 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.189.173.27 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 172.217.215.94 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 172.217.215.94 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: global traffic |
HTTP traffic detected: GET /noil/ HTTP/1.1Host: planninggreenfutures.co.ukConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9 |
Source: global traffic |
HTTP traffic detected: GET /favicon.ico HTTP/1.1Host: planninggreenfutures.co.ukConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://planninggreenfutures.co.uk/noil/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: jcc6Qx2Qa8K47m0GezRV3pUGC70=M9RIViqAG6IYepBuf0w_rLN-f2c; CMc2XCAX7fVppbgU-VOIqbYJOCQ=1744745764; Src9Gd_xPBWNrOvuF2DGCttyS7g=1744832164; NeNQ8RH03JIVEyjUqppBfkCIgb0=bGSC6C5b5xkNQcesxv04ABVh-lg; 9O5XFUSTRKEF4D0tNTH8i5VOalI=3-PU9Xsf7pbdMnWSiiLIvFWadsw |
Source: global traffic |
HTTP traffic detected: GET /noil/ HTTP/1.1Host: planninggreenfutures.co.ukConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-Dest: documentReferer: https://planninggreenfutures.co.uk/noil/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: jcc6Qx2Qa8K47m0GezRV3pUGC70=M9RIViqAG6IYepBuf0w_rLN-f2c; CMc2XCAX7fVppbgU-VOIqbYJOCQ=1744745764; Src9Gd_xPBWNrOvuF2DGCttyS7g=1744832164; NeNQ8RH03JIVEyjUqppBfkCIgb0=bGSC6C5b5xkNQcesxv04ABVh-lg; 9O5XFUSTRKEF4D0tNTH8i5VOalI=3-PU9Xsf7pbdMnWSiiLIvFWadsw; jmnfUtjDdqBcSIM0lC6CLpFKm2Q=1744745766; R330STMjPDOl6Cd9ISymkYs_nuw=1744832166; DJXqr-x-Qr2IkAQhd7S0YiNVAlE=nR771USBrWlemPVYTuXNwbMCypk |
Source: global traffic |
HTTP traffic detected: GET /favicon.ico HTTP/1.1Host: planninggreenfutures.co.ukConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://planninggreenfutures.co.uk/noil/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: jcc6Qx2Qa8K47m0GezRV3pUGC70=M9RIViqAG6IYepBuf0w_rLN-f2c; CMc2XCAX7fVppbgU-VOIqbYJOCQ=1744745764; Src9Gd_xPBWNrOvuF2DGCttyS7g=1744832164; NeNQ8RH03JIVEyjUqppBfkCIgb0=bGSC6C5b5xkNQcesxv04ABVh-lg; 9O5XFUSTRKEF4D0tNTH8i5VOalI=3-PU9Xsf7pbdMnWSiiLIvFWadsw; jmnfUtjDdqBcSIM0lC6CLpFKm2Q=1744745766; R330STMjPDOl6Cd9ISymkYs_nuw=1744832166; DJXqr-x-Qr2IkAQhd7S0YiNVAlE=nR771USBrWlemPVYTuXNwbMCypk; Tejxf_v6HPnbr1wA6K-c4ka28ng=d2cV0f4sDecz1xLHSfeOhOOBSvI; r-xLG1H1HiUoh7m7c7akYbtc3Bk=1744745767; a-vuaCHlCr2MaR58o4FNbAnhgHs=1744832167; yAfzWXZHJyocGJyXzR87YclZbOI=x0A5DWV1IG8jOukFSHvTiK59gaM |
Source: global traffic |
HTTP traffic detected: GET /r/r4.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog |
Source: global traffic |
DNS traffic detected: DNS query: www.google.com |
Source: global traffic |
DNS traffic detected: DNS query: planninggreenfutures.co.uk |
Source: unknown |
HTTP traffic detected: POST /noil/ HTTP/1.1Host: planninggreenfutures.co.ukConnection: keep-aliveContent-Length: 22sec-ch-ua-platform: "Windows"X-Requested-TimeStamp-Combination: JRAJSttIF-9Qmygfn7av7VxL2k: 34292439X-Requested-TimeStamp: sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"X-Requested-Type-Combination: GETsec-ch-ua-mobile: ?0X-Requested-with: XMLHttpRequestUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36X-Requested-Type: GETContent-type: application/x-www-form-urlencodedX-Requested-TimeStamp-Expire: Accept: */*Origin: https://planninggreenfutures.co.ukSec-Fetch-Site: same-originSec-Fetch-Mode: corsSec-Fetch-Dest: emptyReferer: https://planninggreenfutures.co.uk/noil/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9Cookie: jcc6Qx2Qa8K47m0GezRV3pUGC70=M9RIViqAG6IYepBuf0w_rLN-f2c; CMc2XCAX7fVppbgU-VOIqbYJOCQ=1744745764; Src9Gd_xPBWNrOvuF2DGCttyS7g=1744832164; NeNQ8RH03JIVEyjUqppBfkCIgb0=bGSC6C5b5xkNQcesxv04ABVh-lg; 9O5XFUSTRKEF4D0tNTH8i5VOalI=3-PU9Xsf7pbdMnWSiiLIvFWadsw |
Source: global traffic |
HTTP traffic detected: HTTP/1.1 503 Service UnavailableDate: Tue, 15 Apr 2025 19:36:05 GMTContent-Type: text/html; charset=utf-8Transfer-Encoding: chunkedConnection: closeX-Content-Type-Options: nosniffX-Content-Type-Options: nosniffX-Xss-Protection: 1; mode=blockX-Xss-Protection: 1; mode=blockX-Frame-Options: SAMEORIGINCache-Control: public, max-age=0 no-store, no-cache, must-revalidate, post-check=0, pre-check=0Pragma: no-cacheExpires: 0Cf-Cache-Status: DYNAMICServer: cloudflareSet-Cookie: jcc6Qx2Qa8K47m0GezRV3pUGC70=M9RIViqAG6IYepBuf0w_rLN-f2c; Path=/; Max-Age=86400; Expires=Wed, 16 Apr 2025 19:36:04 GMTSet-Cookie: CMc2XCAX7fVppbgU-VOIqbYJOCQ=1744745764; Path=/; Max-Age=86400; Expires=Wed, 16 Apr 2025 19:36:04 GMTSet-Cookie: Src9Gd_xPBWNrOvuF2DGCttyS7g=1744832164; Path=/; Max-Age=86400; Expires=Wed, 16 Apr 2025 19:36:04 GMTSet-Cookie: NeNQ8RH03JIVEyjUqppBfkCIgb0=bGSC6C5b5xkNQcesxv04ABVh-lg; Path=/; Max-Age=86400; Expires=Wed, 16 Apr 2025 19:36:04 GMTCF-RAY: 930de3c92c816863-NRTalt-svc: h3=":443"; ma=86400 |
Source: global traffic |
HTTP traffic detected: HTTP/1.1 503 Service UnavailableDate: Tue, 15 Apr 2025 19:36:08 GMTContent-Type: text/html; charset=utf-8Transfer-Encoding: chunkedConnection: closeServer: cloudflareX-Content-Type-Options: nosniffX-Content-Type-Options: nosniffX-Xss-Protection: 1; mode=blockX-Xss-Protection: 1; mode=blockCache-Control: public, max-age=0 no-store, no-cache, must-revalidate, post-check=0, pre-check=0Pragma: no-cacheX-Frame-Options: SAMEORIGINExpires: 0Cf-Cache-Status: BYPASSSet-Cookie: Tejxf_v6HPnbr1wA6K-c4ka28ng=d2cV0f4sDecz1xLHSfeOhOOBSvI; Path=/; Max-Age=86400; Expires=Wed, 16 Apr 2025 19:36:07 GMTSet-Cookie: r-xLG1H1HiUoh7m7c7akYbtc3Bk=1744745767; Path=/; Max-Age=86400; Expires=Wed, 16 Apr 2025 19:36:07 GMTSet-Cookie: a-vuaCHlCr2MaR58o4FNbAnhgHs=1744832167; Path=/; Max-Age=86400; Expires=Wed, 16 Apr 2025 19:36:07 GMTSet-Cookie: yAfzWXZHJyocGJyXzR87YclZbOI=x0A5DWV1IG8jOukFSHvTiK59gaM; Path=/; Max-Age=86400; Expires=Wed, 16 Apr 2025 19:36:07 GMTCF-RAY: 930de3d4fd7ce7c2-SYDalt-svc: h3=":443"; ma=86400 |
Source: global traffic |
HTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 15 Apr 2025 19:36:09 GMTContent-Type: text/htmlTransfer-Encoding: chunkedConnection: closeVary: Accept-EncodingX-Content-Type-Options: nosniffX-Content-Type-Options: nosniffX-Xss-Protection: 1; mode=blockX-Xss-Protection: 1; mode=blockCf-Cache-Status: DYNAMICServer: cloudflareCF-RAY: 930de3dba8c5fcbd-NRTalt-svc: h3=":443"; ma=86400 |
Source: global traffic |
HTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 15 Apr 2025 19:36:10 GMTContent-Type: text/htmlTransfer-Encoding: chunkedConnection: closeServer: cloudflareVary: Accept-EncodingX-Content-Type-Options: nosniffX-Content-Type-Options: nosniffX-Xss-Protection: 1; mode=blockX-Xss-Protection: 1; mode=blockCache-Control: public, max-age=315360000, stale-while-revalidate=315360000, stale-if-error=315360000, immutablePragma: publicCf-Cache-Status: MISSCF-RAY: 930de3e90817a93b-SYDalt-svc: h3=":443"; ma=86400 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49733 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49733 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49744 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49734 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49709 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49678 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49727 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49671 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49724 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49729 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49728 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49744 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49709 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49729 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49728 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49727 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49724 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49734 |
Source: unknown |
HTTPS traffic detected: 74.125.138.147:443 -> 192.168.2.4:49724 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 104.21.32.1:443 -> 192.168.2.4:49727 version: TLS 1.2 |
Source: unknown |
HTTPS traffic detected: 104.21.32.1:443 -> 192.168.2.4:49728 version: TLS 1.2 |
Source: classification engine |
Classification label: sus20.win@21/4@4/3 |
Source: unknown |
Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" |
|
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2012,i,14331022784213342634,139238066655825086,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2568 /prefetch:3 |
|
Source: unknown |
Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://planninggreenfutures.co.uk/noil/" |
|
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2012,i,14331022784213342634,139238066655825086,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2568 /prefetch:3 |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe |
Process created: unknown unknown |
Jump to behavior |
Source: Window Recorder |
Window detected: More than 3 window changes detected |