Source: https://boawd.com/cgi-inc/new/s/?signin=d41d8cd98f00b204e9800998ecf8427e&auth=875dea8150642da2c39cd31a7e0474fda47bea7f8b87125553305f0662243590ed7af3d6 | SlashNext: Label: Fake Login Page type: Phishing & Social Engineering |
Source: https://app.8b.io/app/themes/webamp/projects/agency/assets/images/logo.pngn | Avira URL Cloud: Label: phishing |
Source: https://app.8b.io/app/themes/webamp/projects/agency/assets/images/logo.png | Avira URL Cloud: Label: phishing |
Source: Yara match | File source: 818225.0.links.csv, type: HTML |
Source: Yara match | File source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\s[1].htm, type: DROPPED |
Source: https://boawd.com/cgi-inc/new/s/files/logo.png | Matcher: Found strong image similarity, brand: Microsoft | Jump to dropped file |
Source: https://boawd.com/cgi-inc/new/s/?signin=d41d8cd98f00b204e9800998ecf8427e&auth=875dea8150642da2c39cd31a7e0474fda47bea7f8b87125553305f0662243590ed7af3d6 | Matcher: Template: microsoft matched |
Source: https://boawd.com/cgi-inc/new/s/?signin=d41d8cd98f00b204e9800998ecf8427e&auth=875dea8150642da2c39cd31a7e0474fda47bea7f8b87125553305f0662243590ed7af3d6 | HTTP Parser: Number of links: 0 |
Source: https://boawd.com/cgi-inc/new/s/?signin=d41d8cd98f00b204e9800998ecf8427e&auth=875dea8150642da2c39cd31a7e0474fda47bea7f8b87125553305f0662243590ed7af3d6 | HTTP Parser: Number of links: 0 |
Source: https://boawd.com/cgi-inc/new/s/?signin=d41d8cd98f00b204e9800998ecf8427e&auth=875dea8150642da2c39cd31a7e0474fda47bea7f8b87125553305f0662243590ed7af3d6 | HTTP Parser: Title: Validation does not match URL |
Source: https://boawd.com/cgi-inc/new/s/?signin=d41d8cd98f00b204e9800998ecf8427e&auth=875dea8150642da2c39cd31a7e0474fda47bea7f8b87125553305f0662243590ed7af3d6 | HTTP Parser: Title: Validation does not match URL |
Source: https://boawd.com/cgi-inc/new/s/?signin=d41d8cd98f00b204e9800998ecf8427e&auth=875dea8150642da2c39cd31a7e0474fda47bea7f8b87125553305f0662243590ed7af3d6 | HTTP Parser: No <meta name="author".. found |
Source: https://boawd.com/cgi-inc/new/s/?signin=d41d8cd98f00b204e9800998ecf8427e&auth=875dea8150642da2c39cd31a7e0474fda47bea7f8b87125553305f0662243590ed7af3d6 | HTTP Parser: No <meta name="author".. found |
Source: https://boawd.com/cgi-inc/new/s/?signin=d41d8cd98f00b204e9800998ecf8427e&auth=875dea8150642da2c39cd31a7e0474fda47bea7f8b87125553305f0662243590ed7af3d6 | HTTP Parser: No <meta name="copyright".. found |
Source: https://boawd.com/cgi-inc/new/s/?signin=d41d8cd98f00b204e9800998ecf8427e&auth=875dea8150642da2c39cd31a7e0474fda47bea7f8b87125553305f0662243590ed7af3d6 | HTTP Parser: No <meta name="copyright".. found |
Source: C:\Program Files (x86)\Internet Explorer\iexplore.exe | File opened: C:\Program Files (x86)\Java\jre1.8.0_211\bin\msvcr100.dll | Jump to behavior |
Source: unknown | HTTPS traffic detected: 52.201.120.251:443 -> 192.168.2.3:49686 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 52.201.120.251:443 -> 192.168.2.3:49687 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 108.177.119.132:443 -> 192.168.2.3:49690 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 108.177.119.132:443 -> 192.168.2.3:49692 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 108.177.119.132:443 -> 192.168.2.3:49691 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.24.105.39:443 -> 192.168.2.3:49693 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.24.105.39:443 -> 192.168.2.3:49694 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.24.104.39:443 -> 192.168.2.3:49695 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.24.104.39:443 -> 192.168.2.3:49696 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.24.105.39:443 -> 192.168.2.3:49702 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 5.188.108.191:443 -> 192.168.2.3:49707 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 5.188.108.191:443 -> 192.168.2.3:49708 version: TLS 1.2 |
Source: unknown | DNS traffic detected: queries for: 217181.8b.io |
Source: amp-mustache-0.2[1].js.2.dr | String found in binary or memory: http://github.com/janl/mustache.js |
Source: AEU170SU.htm.2.dr, {F464A1CA-5607-11EB-90E4-ECF4BB862DED}.dat.1.dr | String found in binary or memory: https://217181.8b.io/ |
Source: {F464A1CA-5607-11EB-90E4-ECF4BB862DED}.dat.1.dr | String found in binary or memory: https://217181.8b.io/L |
Source: {F464A1CA-5607-11EB-90E4-ECF4BB862DED}.dat.1.dr | String found in binary or memory: https://217181.8b.io/Root |
Source: amp-mustache-0.2[1].js.2.dr, amp-analytics-0.1[1].js.2.dr, v0[1].js.2.dr | String found in binary or memory: https://3p.ampproject.net |
Source: AEU170SU.htm.2.dr | String found in binary or memory: https://8b.com |
Source: v0[1].js.2.dr | String found in binary or memory: https://amp.dev/documentation/guides-and-tutorials/develop/style_and_layout/control_layout |
Source: v0[1].js.2.dr | String found in binary or memory: https://amp.dev/documentation/guides-and-tutorials/learn/experimental |
Source: v0[1].js.2.dr | String found in binary or memory: https://ampcid.google.com/v1/cache:getClientId?key=AIzaSyDKtqGxnoeIqVM33Uf7hRSa3GJxuzR7mLc |
Source: v0[1].js.2.dr | String found in binary or memory: https://ampcid.google.com/v1/publisher:getClientId?key= |
Source: AEU170SU.htm.2.dr | String found in binary or memory: https://app.8b.io/app/themes/webamp/projects/agency/assets/images/logo.png |
Source: imagestore.dat.2.dr | String found in binary or memory: https://app.8b.io/app/themes/webamp/projects/agency/assets/images/logo.pngn |
Source: {F464A1CA-5607-11EB-90E4-ECF4BB862DED}.dat.1.dr | String found in binary or memory: https://boawd.com/cgi- |
Source: {F464A1CA-5607-11EB-90E4-ECF4BB862DED}.dat.1.dr | String found in binary or memory: https://boawd.com/cgi-L |
Source: AEU170SU.htm.2.dr | String found in binary or memory: https://boawd.com/cgi-inc/new |
Source: new[1].htm.2.dr | String found in binary or memory: https://boawd.com/cgi-inc/new/ |
Source: {F464A1CA-5607-11EB-90E4-ECF4BB862DED}.dat.1.dr | String found in binary or memory: https://boawd.com/cgi-inc/new/s/?signin=d41d8cd98f00b204e9800998ecf8427e&auth=875dea8150642da2c39cd3 |
Source: amp-mustache-0.2[1].js.2.dr, amp-analytics-0.1[1].js.2.dr, v0[1].js.2.dr | String found in binary or memory: https://cdn.ampproject.org |
Source: AEU170SU.htm.2.dr | String found in binary or memory: https://cdn.ampproject.org/v0.js |
Source: AEU170SU.htm.2.dr | String found in binary or memory: https://cdn.ampproject.org/v0/amp-analytics-0.1.js |
Source: AEU170SU.htm.2.dr | String found in binary or memory: https://cdn.ampproject.org/v0/amp-mustache-0.2.js |
Source: v0[1].js.2.dr | String found in binary or memory: https://developers.google.com/open-source/licenses/bsd |
Source: AEU170SU.htm.2.dr | String found in binary or memory: https://fonts.googleapis.com/css?family=Roboto:100 |
Source: css[1].css0.2.dr | String found in binary or memory: https://fonts.gstatic.com/s/opensans/v18/mem5YaGs126MiZpBA-UNirkOUuhv.woff) |
Source: css[1].css.2.dr | String found in binary or memory: https://fonts.gstatic.com/s/roboto/v20/KFOiCnqEu92Fr1Mu51QrEzAdKQ.woff) |
Source: css[1].css.2.dr | String found in binary or memory: https://fonts.gstatic.com/s/roboto/v20/KFOjCnqEu92Fr1Mu51S7ACc6CsI.woff) |
Source: css[1].css.2.dr | String found in binary or memory: https://fonts.gstatic.com/s/roboto/v20/KFOjCnqEu92Fr1Mu51TLBCc6CsI.woff) |
Source: css[1].css.2.dr | String found in binary or memory: https://fonts.gstatic.com/s/roboto/v20/KFOjCnqEu92Fr1Mu51TjASc6CsI.woff) |
Source: css[1].css.2.dr | String found in binary or memory: https://fonts.gstatic.com/s/roboto/v20/KFOjCnqEu92Fr1Mu51TzBic6CsI.woff) |
Source: css[1].css.2.dr | String found in binary or memory: https://fonts.gstatic.com/s/roboto/v20/KFOkCnqEu92Fr1MmgVxIIzQ.woff) |
Source: css[1].css.2.dr | String found in binary or memory: https://fonts.gstatic.com/s/roboto/v20/KFOkCnqEu92Fr1Mu51xIIzQ.woff) |
Source: css[1].css.2.dr | String found in binary or memory: https://fonts.gstatic.com/s/roboto/v20/KFOlCnqEu92Fr1MmEU9fBBc-.woff) |
Source: css[1].css.2.dr | String found in binary or memory: https://fonts.gstatic.com/s/roboto/v20/KFOlCnqEu92Fr1MmSU5fBBc-.woff) |
Source: css[1].css.2.dr | String found in binary or memory: https://fonts.gstatic.com/s/roboto/v20/KFOlCnqEu92Fr1MmWUlfBBc-.woff) |
Source: css[1].css.2.dr | String found in binary or memory: https://fonts.gstatic.com/s/roboto/v20/KFOlCnqEu92Fr1MmYUtfBBc-.woff) |
Source: css[1].css.2.dr | String found in binary or memory: https://fonts.gstatic.com/s/roboto/v20/KFOmCnqEu92Fr1Mu4mxM.woff) |
Source: amp-analytics-0.1[1].js.2.dr | String found in binary or memory: https://github.com/ampproject/amphtml/blob/master/spec/amp-iframe-origin-policy.md |
Source: v0[1].js.2.dr | String found in binary or memory: https://log.amp.dev/?v=012012301722000&id= |
Source: amp-loader-0.1[1].js.2.dr | String found in binary or memory: https://mths.be/cssescape |
Source: AEU170SU.htm.2.dr | String found in binary or memory: https://r.8b.io/217181/images/background5-h_kjv9je6u.jpg |
Source: amp-mustache-0.2[1].js.2.dr, amp-analytics-0.1[1].js.2.dr, v0[1].js.2.dr | String found in binary or memory: https://us-central1-amp-error-reporting.cloudfunctions.net/r |
Source: amp-mustache-0.2[1].js.2.dr, amp-analytics-0.1[1].js.2.dr, v0[1].js.2.dr | String found in binary or memory: https://us-central1-amp-error-reporting.cloudfunctions.net/r-beta |
Source: unknown | Network traffic detected: HTTP traffic on port 49708 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49710 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49687 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49686 |
Source: unknown | Network traffic detected: HTTP traffic on port 49695 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49693 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49702 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49691 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49686 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 49690 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49710 |
Source: unknown | Network traffic detected: HTTP traffic on port 49707 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49696 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49695 |
Source: unknown | Network traffic detected: HTTP traffic on port 49694 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49694 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49693 |
Source: unknown | Network traffic detected: HTTP traffic on port 49696 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49692 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49691 |
Source: unknown | Network traffic detected: HTTP traffic on port 49692 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49690 |
Source: unknown | Network traffic detected: HTTP traffic on port 49687 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49708 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49707 |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 49702 |
Source: unknown | HTTPS traffic detected: 52.201.120.251:443 -> 192.168.2.3:49686 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 52.201.120.251:443 -> 192.168.2.3:49687 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 108.177.119.132:443 -> 192.168.2.3:49690 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 108.177.119.132:443 -> 192.168.2.3:49692 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 108.177.119.132:443 -> 192.168.2.3:49691 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.24.105.39:443 -> 192.168.2.3:49693 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.24.105.39:443 -> 192.168.2.3:49694 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.24.104.39:443 -> 192.168.2.3:49695 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.24.104.39:443 -> 192.168.2.3:49696 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 104.24.105.39:443 -> 192.168.2.3:49702 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 5.188.108.191:443 -> 192.168.2.3:49707 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 5.188.108.191:443 -> 192.168.2.3:49708 version: TLS 1.2 |
Source: classification engine | Classification label: mal64.phis.win@3/25@6/5 |
Source: C:\Program Files\internet explorer\iexplore.exe | File created: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High | Jump to behavior |
Source: C:\Program Files\internet explorer\iexplore.exe | File created: C:\Users\user\AppData\Local\Temp\~DFE8C735A3CF508A06.TMP | Jump to behavior |
Source: unknown | Process created: C:\Program Files\internet explorer\iexplore.exe 'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding | |
Source: unknown | Process created: C:\Program Files (x86)\Internet Explorer\iexplore.exe 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:6052 CREDAT:17410 /prefetch:2 | |
Source: C:\Program Files\internet explorer\iexplore.exe | Process created: C:\Program Files (x86)\Internet Explorer\iexplore.exe 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:6052 CREDAT:17410 /prefetch:2 | Jump to behavior |
Source: Window Recorder | Window detected: More than 3 window changes detected |
Source: C:\Program Files (x86)\Internet Explorer\iexplore.exe | File opened: C:\Program Files (x86)\Java\jre1.8.0_211\bin\msvcr100.dll | Jump to behavior |
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.