Analysis Report https://u8957694.ct.sendgrid.net/wf/open/?upn=f-2BtuTds4OlaE72NlzrEa3uxJETxyb6un73XO0J20j4W67hX4XeSZGP8bQE-2F72bB5gGmtBk-2B8kk3LzUVm74RZkfuLWT0igaq9d4s3Bo67o6wO0-2BngtKUDfKbt-2B-2BeNG0XTn9wa22CNxUIfaLs2FOpsJWJMHbRTwp20PphKNvLUuBAgV7Od-2Fd4XDEcnppvc6fLgXWSVfaZwI2Fu65J8tOw2TqpSeBe-2FGcg-2BNeG3nPbVYZi2Lfb6DqmCbUrLcuFarTAI


General Information

Sample URL:https://u8957694.ct.sendgrid.net/wf/open/?upn=f-2BtuTds4OlaE72NlzrEa3uxJETxyb6un73XO0J20j4W67hX4XeSZGP8bQE-2F72bB5gGmtBk-2B8kk3LzUVm74RZkfuLWT0igaq9d4s3Bo67o6wO0-2BngtKUDfKbt-2B-2BeNG0XTn9wa22CNxUIfaLs2FOpsJWJMHbRTwp20PphKNvLUuBAgV7Od-2Fd4XDEcnppvc6fLgXWSVfaZwI2Fu65J8tOw2TqpSeBe-2FGcg-2BNeG3nPbVYZi2Lfb6DqmCbUrLcuFarTAI
Analysis ID:286569

Most interesting Screenshot:

  • URL not reachable


Range:0 - 100


No high impact signatures.


Analysis Advice

Joe Sandbox was unable to browse the URL (domain or webserver down or HTTPS issue), try to browse the URL again later
Uses HTTPS for network communication, use the 'Proxy HTTPS (port 443) to read its encrypted data' cookbook for further analysis


  • System is w10x64
  • iexplore.exe (PID: 2692 cmdline: 'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding MD5: 6465CB92B25A7BC1DF8E01D8AC5E7596)
    • iexplore.exe (PID: 2708 cmdline: 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:2692 CREDAT:17410 /prefetch:2 MD5: 071277CC2E3DF41EEEA8013E2AB58D5A)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

No yara matches

Sigma Overview

No Sigma rule has matched

Signature Overview

Source: unknownDNS traffic detected: queries for: u8957694.ct.sendgrid.net
Source: {4C485858-F897-11EA-90E2-ECF4BB862DED}.dat.1.dr, ~DF10ACF8A7A2DC150E.TMP.1.drString found in binary or memory: https://u8957694.ct.sendgrid.net/wf/open/?upn=f-2BtuTds4OlaE72NlzrEa3uxJETxyb6un73XO0J20j4W67hX4XeSZ
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: classification engineClassification label: unknown0.win@3/14@1/1
Source: C:\Program Files\internet explorer\iexplore.exeFile created: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\HighJump to behavior
Source: C:\Program Files\internet explorer\iexplore.exeFile created: C:\Users\user\AppData\Local\Temp\LowJump to behavior
Source: C:\Program Files\internet explorer\iexplore.exeFile read: C:\Users\desktop.iniJump to behavior
Source: unknownProcess created: C:\Program Files\internet explorer\iexplore.exe 'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding
Source: unknownProcess created: C:\Program Files (x86)\Internet Explorer\iexplore.exe 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:2692 CREDAT:17410 /prefetch:2
Source: C:\Program Files\internet explorer\iexplore.exeProcess created: C:\Program Files (x86)\Internet Explorer\iexplore.exe 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:2692 CREDAT:17410 /prefetch:2Jump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Internet Explorer\iexplore.exeFile opened: C:\Program Files (x86)\Java\jre1.8.0_211\bin\msvcr100.dllJump to behavior

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath InterceptionProcess Injection1Masquerading1OS Credential DumpingFile and Directory Discovery1Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel2Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsProcess Injection1LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Application Layer Protocol1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol2Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

Behavior Graph

