Analysis Report https://www.we-make-you-digital.com/de/safe-exam-browser

Overview

General Information

Sample URL: https://www.we-make-you-digital.com/de/safe-exam-browser
Analysis ID: 326329

Most interesting Screenshot:

Detection

Score: 1
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Drops PE files
Form action URLs do not match main URL
HTML body contains low number of good links

Classification

Phishing:

barindex
Form action URLs do not match main URL
Source: https://www.we-make-you-digital.com/de/digitales-arbeiten/ HTTP Parser: Form action: https://www.tuev-nord.de/locationfinder we-make-you-digital tuev-nord
Source: https://www.we-make-you-digital.com/de/digitales-arbeiten/ HTTP Parser: Form action: https://www.tuev-nord.de/locationfinder we-make-you-digital tuev-nord
HTML body contains low number of good links
Source: https://www.instagram.com/accounts/login/?next=/da_tng/ HTTP Parser: Number of links: 0
Source: https://www.instagram.com/accounts/login/?next=/da_tng/ HTTP Parser: Number of links: 0
Source: https://www.instagram.com/accounts/login/?next=/da_tng/ HTTP Parser: No <meta name="author".. found
Source: https://www.instagram.com/accounts/login/?next=/da_tng/ HTTP Parser: No <meta name="author".. found
Source: https://www.linkedin.com/showcase/tng-digital-academy/ HTTP Parser: No <meta name="author".. found
Source: https://www.linkedin.com/showcase/tng-digital-academy/ HTTP Parser: No <meta name="author".. found
Source: https://www.we-make-you-digital.com/de/digitales-arbeiten/ HTTP Parser: No <meta name="author".. found
Source: https://www.we-make-you-digital.com/de/digitales-arbeiten/ HTTP Parser: No <meta name="author".. found
Source: https://www.instagram.com/accounts/login/?next=/da_tng/ HTTP Parser: No <meta name="copyright".. found
Source: https://www.instagram.com/accounts/login/?next=/da_tng/ HTTP Parser: No <meta name="copyright".. found
Source: https://www.linkedin.com/showcase/tng-digital-academy/ HTTP Parser: No <meta name="copyright".. found
Source: https://www.linkedin.com/showcase/tng-digital-academy/ HTTP Parser: No <meta name="copyright".. found
Source: https://www.we-make-you-digital.com/de/digitales-arbeiten/ HTTP Parser: No <meta name="copyright".. found
Source: https://www.we-make-you-digital.com/de/digitales-arbeiten/ HTTP Parser: No <meta name="copyright".. found
Source: videos[1].htm.2.dr String found in binary or memory: <div data-youtubeiframe="https://www.youtube.com/embed/3r2IPmEcc1U" data-youtubeiframe-cookie="thirdparty"> equals www.youtube.com (Youtube)
Source: videos[1].htm.2.dr String found in binary or memory: <div data-youtubeiframe="https://www.youtube.com/embed/7Xdzgwvqjrw" data-youtubeiframe-cookie="thirdparty"> equals www.youtube.com (Youtube)
Source: videos[1].htm.2.dr String found in binary or memory: <div data-youtubeiframe="https://www.youtube.com/embed/EgVBgb1YhVU" data-youtubeiframe-cookie="thirdparty"> equals www.youtube.com (Youtube)
Source: videos[1].htm.2.dr String found in binary or memory: <div data-youtubeiframe="https://www.youtube.com/embed/Ww247f9-c5Q" data-youtubeiframe-cookie="thirdparty"> equals www.youtube.com (Youtube)
Source: videos[1].htm.2.dr String found in binary or memory: <div data-youtubeiframe="https://www.youtube.com/embed/YKXdP6DEEIU" data-youtubeiframe-cookie="thirdparty"> equals www.youtube.com (Youtube)
Source: videos[1].htm.2.dr String found in binary or memory: <div data-youtubeiframe="https://www.youtube.com/embed/ZVB5dJmZyYY" data-youtubeiframe-cookie="thirdparty"> equals www.youtube.com (Youtube)
Source: videos[1].htm.2.dr String found in binary or memory: <div data-youtubeiframe="https://www.youtube.com/embed/ePyWAVb0h0E" data-youtubeiframe-cookie="thirdparty"> equals www.youtube.com (Youtube)
Source: videos[1].htm.2.dr String found in binary or memory: <div data-youtubeiframe="https://www.youtube.com/embed/h5kBe0ZEUbA" data-youtubeiframe-cookie="thirdparty"> equals www.youtube.com (Youtube)
Source: videos[1].htm.2.dr String found in binary or memory: <div data-youtubeiframe="https://www.youtube.com/embed/uqbTTmOigMs" data-youtubeiframe-cookie="thirdparty"> equals www.youtube.com (Youtube)
Source: videos[1].htm.2.dr String found in binary or memory: <a class="c-wemakeyoudigital__social-link" href="https://www.linkedin.com/showcase/tng-digital-academy/" title="Die Digital Academy auf Linkedin" target="_blank"><span class="c-wemakeyoudigital__social-icon icon">brand_linkedin</span></a> equals www.linkedin.com (Linkedin)
Source: videos[1].htm.2.dr String found in binary or memory: <a class="o-layout__item u-1/6-portable u-1/4-desk u-mb" href="https://www.linkedin.com/showcase/tng-digital-academy/" title="Die Digital Academy auf Linkedin" target="_blank"><span class="c-circle icon icon-size--l">brand_linkedin</span></a> equals www.linkedin.com (Linkedin)
Source: suggest_controller[1].js.2.dr String found in binary or memory: if (suggestion.data.link.indexOf('https://www.youtube.com') === 0) { equals www.youtube.com (Youtube)
Source: body.min[1].js0.2.dr String found in binary or memory: "},shareUrl:"https://www.facebook.com/sharer/sharer.php?u="+t+e.getReferrerTrack()}}},{}],8:[function(e,t,i){"use strict";t.exports=function(e){var t=encodeURIComponent(e.getURL());return{popup:!0,shareText:"+1",name:"googleplus",faName:"fa-google-plus",title:{bg:" equals www.facebook.com (Facebook)
Source: body.min[1].js0.2.dr String found in binary or memory: "},shareUrl:"https://www.linkedin.com/cws/share?url="+t+e.getReferrerTrack()}}},{}],11:[function(e,t,i){"use strict";t.exports=function(e){var t=e.getOption("mailUrl");return 0===t.indexOf("mailto:")&&(t+="?subject="+encodeURIComponent(e.getOption("mailSubject")),t+="&body="+encodeURIComponent(e.getOption("mailBody"))),{blank:0===t.indexOf("http"),popup:!1,shareText:"mail",name:"mail",faName:"fa-envelope",title:{bg:" equals www.linkedin.com (Linkedin)
Source: ea1d49fd9094[1].js.2.dr String found in binary or memory: __d(function(g,r,i,a,m,e,d){"use strict";function t(){return window.navigator&&window.navigator.share&&!r(d[0]).isIgLite()}Object.defineProperty(e,'__esModule',{value:!0}),e.hasNativeShare=t,e.getShareDescription=function(t,n){switch(n){case'guide':return r(d[1])(942,{username:t});case'photo':return r(d[1])(3553,{username:t});case'video':return r(d[1])(2e3,{username:t});case'sidecar':default:return r(d[1])(2702,{username:t})}},e.shareWithNative=function(n,o,u){return t()||i(d[2])(0),window.navigator.share({title:r(d[1])(1444),text:n,url:new(i(d[3]))(o).addQueryData('utm_source',u)})},e.getShareToFBURL=function(t){return new(i(d[3]))('https://www.facebook.com/sharer/sharer.php').addQueryData({app_id:r(d[4]).instagramWebFBAppId,u:t}).toString()},e.getShareToMessengerURL=function(t){var n;return r(d[0]).isMobile()?(n=new(i(d[3]))('fb-messenger://share')).addQueryData({app_id:r(d[4]).instagramWebFBAppId,link:t}):(n=new(i(d[3]))('https://www.facebook.com/dialog/send')).addQueryData({app_id:r(d[4]).instagramWebFBAppId,link:t,redirect_uri:t}),n.toString()},e.getShareToWhatsAppURL=function(t,n){return new(i(d[3]))('whatsapp://send').addQueryData({text:n+": "+t}).toString()},e.getShareToTwitterURL=function(t,n){return new(i(d[3]))('https://twitter.com/share').addQueryData({text:n,url:t}).toString()},e.getShareToEmailURL=function(t,n){var o=n+": "+t;return"mailto:?subject="+encodeURIComponent(n)+"&body="+encodeURIComponent(o)}},15532040,[9699341,9699332,9502828,9962060,9961605]); equals www.facebook.com (Facebook)
Source: ea1d49fd9094[1].js.2.dr String found in binary or memory: __d(function(g,r,i,a,m,e,d){"use strict";function t(){return window.navigator&&window.navigator.share&&!r(d[0]).isIgLite()}Object.defineProperty(e,'__esModule',{value:!0}),e.hasNativeShare=t,e.getShareDescription=function(t,n){switch(n){case'guide':return r(d[1])(942,{username:t});case'photo':return r(d[1])(3553,{username:t});case'video':return r(d[1])(2e3,{username:t});case'sidecar':default:return r(d[1])(2702,{username:t})}},e.shareWithNative=function(n,o,u){return t()||i(d[2])(0),window.navigator.share({title:r(d[1])(1444),text:n,url:new(i(d[3]))(o).addQueryData('utm_source',u)})},e.getShareToFBURL=function(t){return new(i(d[3]))('https://www.facebook.com/sharer/sharer.php').addQueryData({app_id:r(d[4]).instagramWebFBAppId,u:t}).toString()},e.getShareToMessengerURL=function(t){var n;return r(d[0]).isMobile()?(n=new(i(d[3]))('fb-messenger://share')).addQueryData({app_id:r(d[4]).instagramWebFBAppId,link:t}):(n=new(i(d[3]))('https://www.facebook.com/dialog/send')).addQueryData({app_id:r(d[4]).instagramWebFBAppId,link:t,redirect_uri:t}),n.toString()},e.getShareToWhatsAppURL=function(t,n){return new(i(d[3]))('whatsapp://send').addQueryData({text:n+": "+t}).toString()},e.getShareToTwitterURL=function(t,n){return new(i(d[3]))('https://twitter.com/share').addQueryData({text:n,url:t}).toString()},e.getShareToEmailURL=function(t,n){var o=n+": "+t;return"mailto:?subject="+encodeURIComponent(n)+"&body="+encodeURIComponent(o)}},15532040,[9699341,9699332,9502828,9962060,9961605]); equals www.twitter.com (Twitter)
Source: body.min[1].js0.2.dr String found in binary or memory: http://api.addthis.com/oexchange/0.8/offer?url=
Source: SEB_3.0.0.118_SetupBundle[1].exe.2.dr String found in binary or memory: http://appsyndication.org/2006/appsynapplicationapuputil.cppupgradeexclusivetrueenclosuredigestalgor
Source: SEB_3.0.0.118_SetupBundle[1].exe.2.dr String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
Source: SEB_3.0.0.118_SetupBundle[1].exe.2.dr String found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDCodeSigningCA.crt0
Source: SEB_3.0.0.118_SetupBundle[1].exe.2.dr String found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0
Source: SEB_3.0.0.118_SetupBundle[1].exe.2.dr String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0O
Source: SEB_3.0.0.118_SetupBundle[1].exe.2.dr String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P
Source: SEB_3.0.0.118_SetupBundle[1].exe.2.dr String found in binary or memory: http://crl3.digicert.com/sha2-assured-cs-g1.crl05
Source: SEB_3.0.0.118_SetupBundle[1].exe.2.dr String found in binary or memory: http://crl3.digicert.com/sha2-assured-ts.crl02
Source: SEB_3.0.0.118_SetupBundle[1].exe.2.dr String found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
Source: SEB_3.0.0.118_SetupBundle[1].exe.2.dr String found in binary or memory: http://crl4.digicert.com/sha2-assured-cs-g1.crl0L
Source: SEB_3.0.0.118_SetupBundle[1].exe.2.dr String found in binary or memory: http://crl4.digicert.com/sha2-assured-ts.crl0
Source: fontawesome-webfont[1].eot.2.dr, font-awesome.min[1].css.2.dr String found in binary or memory: http://fontawesome.io
Source: font-awesome.min[1].css.2.dr String found in binary or memory: http://fontawesome.io/license
Source: fontawesome-webfont[1].eot.2.dr String found in binary or memory: http://fontawesome.io/license/
Source: fontawesome-webfont[1].eot.2.dr String found in binary or memory: http://fontawesome.iohttp://fontawesome.iohttp://fontawesome.io/license/http://fontawesome.io/licens
Source: SEB_3.0.0.118_SetupBundle[1].exe.2.dr String found in binary or memory: http://ocsp.digicert.com0C
Source: SEB_3.0.0.118_SetupBundle[1].exe.2.dr String found in binary or memory: http://ocsp.digicert.com0N
Source: SEB_3.0.0.118_SetupBundle[1].exe.2.dr String found in binary or memory: http://ocsp.digicert.com0O
Source: ea1d49fd9094[1].js.2.dr String found in binary or memory: http://www.aboutads.info
Source: ea1d49fd9094[1].js.2.dr String found in binary or memory: http://www.networkadvertising.org/managing/opt_out.asp
Source: home[1].htm.2.dr String found in binary or memory: http://www.we-make-you-digital.com
Source: ea1d49fd9094[1].js.2.dr String found in binary or memory: http://youronlinechoices.eu
Source: da_tng[1].htm.2.dr String found in binary or memory: https://abs.twimg.com/responsive-web/client-web-legacy/i18n/en.af6d8bb5.js
Source: da_tng[1].htm.2.dr String found in binary or memory: https://abs.twimg.com/responsive-web/client-web-legacy/icon-ios.8ea219d5.png
Source: da_tng[1].htm.2.dr String found in binary or memory: https://abs.twimg.com/responsive-web/client-web-legacy/icon-svg.9e211f65.svg
Source: da_tng[1].htm.2.dr String found in binary or memory: https://abs.twimg.com/responsive-web/client-web-legacy/main.bc9b0305.js
Source: da_tng[1].htm.2.dr String found in binary or memory: https://abs.twimg.com/responsive-web/client-web-legacy/polyfills.e49ae9f5.js
Source: da_tng[1].htm.2.dr String found in binary or memory: https://abs.twimg.com/responsive-web/client-web-legacy/vendors~main.2ee92315.js
Source: ea1d49fd9094[1].js.2.dr String found in binary or memory: https://api.instagram.com/oembed/?url=https://www.instagram.com/
Source: ea1d49fd9094[1].js.2.dr String found in binary or memory: https://applink.instagram.com
Source: videos[1].htm.2.dr String found in binary or memory: https://cdn.consentmanager.mgr.consensu.org/delivery/cmp.min.css
Source: ea1d49fd9094[1].js.2.dr String found in binary or memory: https://help.instagram.com/1006568999411025
Source: ea1d49fd9094[1].js.2.dr String found in binary or memory: https://help.instagram.com/1009785806132609
Source: ea1d49fd9094[1].js.2.dr String found in binary or memory: https://help.instagram.com/1731078377046291
Source: da_tng[1].htm.2.dr String found in binary or memory: https://mobile.twitter.com/i/nojs_router?path=%2Fda_tng
Source: body.min[1].js0.2.dr String found in binary or memory: https://plus.google.com/share?url=
Source: ea1d49fd9094[1].js.2.dr String found in binary or memory: https://support.google.com/chrome/answer/95647
Source: da_tng[1].htm.2.dr String found in binary or memory: https://ton.twitter.com/responsive-web-internal/sourcemaps/client-web-legacy/runtime.28dc8215.js.map
Source: videos[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;ar
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;bg
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;bn
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;ca
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;cs
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;da
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;de
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;el
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;en
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;en-GB
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;es
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;eu
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;fa
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;fi
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;fr
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;ga
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;gl
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;gu
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;he
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;hi
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;hr
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;hu
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;id
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;it
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;ja
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;kn
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;ko
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;mr
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;ms
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;nb
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;nl
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;pl
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;pt
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;ro
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;ru
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;sk
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;sr
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;sv
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;ta
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;th
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;tl
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;tr
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;uk
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;ur
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;vi
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;zh
Source: da_tng[1].htm.2.dr String found in binary or memory: https://twitter.com/da_tng?lang&#x3D;zh-Hant
Source: body.min[1].js0.2.dr String found in binary or memory: https://twitter.com/intent/tweet
Source: videos[1].htm.2.dr String found in binary or memory: https://typo3.org/
Source: SEB_3.0.0.118_SetupBundle[1].exe.2.dr String found in binary or memory: https://www.digicert.com/CPS0
Source: home[1].htm.2.dr String found in binary or memory: https://www.eccelerate.com
Source: ea1d49fd9094[1].js.2.dr String found in binary or memory: https://www.fbsbx.com/captcha/recaptcha/iframe/
Source: videos[1].htm.2.dr String found in binary or memory: https://www.googletagmanager.com/gtag/js?id=AW-975834537
Source: videos[1].htm.2.dr String found in binary or memory: https://www.googletagmanager.com/gtm.js?id=
Source: videos[1].htm.2.dr String found in binary or memory: https://www.googletagmanager.com/ns.html?id=GTM-ML9G2LP
Source: ea1d49fd9094[1].js.2.dr String found in binary or memory: https://www.instagram.com
Source: ea1d49fd9094[1].js.2.dr String found in binary or memory: https://www.instagram.com/browser/closeWindow
Source: videos[1].htm.2.dr String found in binary or memory: https://www.instagram.com/da_tng/
Source: body.min[1].js0.2.dr String found in binary or memory: https://www.linkedin.com/cws/share?url=
Source: videos[1].htm.2.dr String found in binary or memory: https://www.linkedin.com/showcase/tng-digital-academy/
Source: body.min[1].js0.2.dr String found in binary or memory: https://www.pinterest.com/pin/create/link/
Source: home[1].htm.2.dr String found in binary or memory: https://www.steinbeis-sibe.de/
Source: videos[1].htm.2.dr String found in binary or memory: https://www.tuev-nord-group.com/de/datenschutz/
Source: videos[1].htm.2.dr String found in binary or memory: https://www.tuev-nord-group.com/de/meta/impressum/
Source: home[1].htm.2.dr String found in binary or memory: https://www.tuev-nord-group.com/de/startseite/
Source: videos[1].htm.2.dr String found in binary or memory: https://www.tuev-nord.de/locationfinder
Source: home[1].htm.2.dr String found in binary or memory: https://www.we-make-you-digital.com/de/home/
Source: videos[1].htm.2.dr String found in binary or memory: https://www.we-make-you-digital.com/de/videos/
Source: home[1].htm.2.dr String found in binary or memory: https://www.we-make-you-digital.com/en/home/
Source: home[1].htm.2.dr String found in binary or memory: https://www.we-make-you-digital.com/fileadmin/Content/TUEV_NORD_GROUP_LEUCHTTURM/pics/Digital_Academ
Source: home[1].htm.2.dr String found in binary or memory: https://www.we-make-you-digital.com/fileadmin/_processed_/2/e/csm_EP-Top2-Transformation-2020_5a1118
Source: home[1].htm.2.dr String found in binary or memory: https://www.we-make-you-digital.com/fileadmin/_processed_/2/e/csm_EP-Top2-Transformation-2020_67fa9a
Source: OpenWith.exe, 00000004.00000002.836315802.000001CADCD5B000.00000004.00000001.sdmp String found in binary or memory: https://www.we-make-you-digital.com/fileadmin/user_upload/SafeExamBrowser-2.1.4.dmg
Source: suggest_controller[1].js.2.dr String found in binary or memory: https://www.youtube.com
Source: videos[1].htm.2.dr String found in binary or memory: https://www.youtube.com/embed/3r2IPmEcc1U
Source: videos[1].htm.2.dr String found in binary or memory: https://www.youtube.com/embed/7Xdzgwvqjrw
Source: videos[1].htm.2.dr String found in binary or memory: https://www.youtube.com/embed/EgVBgb1YhVU
Source: videos[1].htm.2.dr String found in binary or memory: https://www.youtube.com/embed/Ww247f9-c5Q
Source: videos[1].htm.2.dr String found in binary or memory: https://www.youtube.com/embed/YKXdP6DEEIU
Source: videos[1].htm.2.dr String found in binary or memory: https://www.youtube.com/embed/ZVB5dJmZyYY
Source: videos[1].htm.2.dr String found in binary or memory: https://www.youtube.com/embed/ePyWAVb0h0E
Source: videos[1].htm.2.dr String found in binary or memory: https://www.youtube.com/embed/h5kBe0ZEUbA
Source: videos[1].htm.2.dr String found in binary or memory: https://www.youtube.com/embed/uqbTTmOigMs
Source: classification engine Classification label: clean1.win@4/203@0/16
Source: C:\Program Files\internet explorer\iexplore.exe File created: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{A050342B-3545-11EB-90EB-ECF4BBEA1588}.dat Jump to behavior
Source: C:\Program Files\internet explorer\iexplore.exe File created: C:\Users\user\AppData\Local\Temp\~DF4800B8EB439C0D67.TMP Jump to behavior
Source: C:\Program Files\internet explorer\iexplore.exe File read: C:\Users\desktop.ini Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: unknown Process created: C:\Program Files\internet explorer\iexplore.exe 'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding
Source: unknown Process created: C:\Program Files (x86)\Internet Explorer\iexplore.exe 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:5816 CREDAT:17410 /prefetch:2
Source: unknown Process created: C:\Windows\System32\OpenWith.exe C:\Windows\system32\OpenWith.exe -Embedding
Source: C:\Program Files\internet explorer\iexplore.exe Process created: C:\Program Files (x86)\Internet Explorer\iexplore.exe 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:5816 CREDAT:17410 /prefetch:2 Jump to behavior
Source: C:\Windows\System32\OpenWith.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32 Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Internet Explorer\iexplore.exe File opened: C:\Program Files (x86)\Java\jre1.8.0_211\bin\msvcr100.dll Jump to behavior
Source: Binary string: C:\agent\_work\8\s\build\ship\x86\burn.pdb source: SEB_3.0.0.118_SetupBundle[1].exe.2.dr

Persistence and Installation Behavior:

barindex
Drops PE files
Source: C:\Program Files (x86)\Internet Explorer\iexplore.exe File created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\SEB_3.0.0.118_SetupBundle[1].exe Jump to dropped file
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 326329 URL: https://www.we-make-you-dig... Startdate: 03/12/2020 Architecture: WINDOWS Score: 1 5 iexplore.exe 3 64 2->5         started        8 OpenWith.exe 2->8         started        dnsIp3 13 8.8.8.8 GOOGLEUS United States 5->13 15 192.168.2.1 unknown unknown 5->15 10 iexplore.exe 10 255 5->10         started        process4 dnsIp5 17 104.244.42.2 TWITTERUS United States 10->17 19 104.244.42.65 TWITTERUS United States 10->19 21 12 other IPs or domains 10->21
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs

Contacted Public IPs

IP Domain Country Flag ASN ASN Name Malicious
104.244.42.65
unknown United States
13414 TWITTERUS false
104.244.42.2
unknown United States
13414 TWITTERUS false
152.199.21.118
unknown United States
15133 EDGECASTUS false
31.13.92.14
unknown Ireland
32934 FACEBOOKUS false
31.13.92.36
unknown Ireland
32934 FACEBOOKUS false
192.229.233.50
unknown United States
15133 EDGECASTUS false
92.122.213.192
unknown European Union
20940 AKAMAI-ASN1EU false
13.107.42.14
unknown United States
8068 MICROSOFT-CORP-MSN-AS-BLOCKUS false
8.8.8.8
unknown United States
15169 GOOGLEUS false
87.230.98.69
unknown Germany
61157 PLUSSERVER-ASN1DE false
172.217.22.46
unknown United States
15169 GOOGLEUS false
185.39.104.87
unknown Germany
200003 DE-TUEVNORD-HDE false
89.187.165.8
unknown Czech Republic
60068 CDN77GB false
152.199.21.141
unknown United States
15133 EDGECASTUS false
31.13.92.174
unknown Ireland
32934 FACEBOOKUS false

Private

IP
192.168.2.1

Contacted URLs

Name Malicious Antivirus Detection Reputation
https://www.instagram.com/accounts/login/?next=/da_tng/ false
    high
    https://www.we-make-you-digital.com/de/safe-exam-browser false unknown
    https://www.we-make-you-digital.com/de/videos/ false
      unknown
      https://www.we-make-you-digital.com/de/digitales-arbeiten/ false
        unknown
        https://www.we-make-you-digital.com/de/newsfeed/ false
          unknown
          https://www.we-make-you-digital.com/de/da-toolbox/ false
            unknown
            https://www.we-make-you-digital.com/de/safe-exam-browser#off-canvas-navigation false
              unknown
              https://www.linkedin.com/showcase/tng-digital-academy/ false
                high
                https://twitter.com/da_tng false
                  high
                  https://www.we-make-you-digital.com/de/home/ false
                    unknown