Analysis Report http://bkbizwwqfqstgcsbkbizwwqfqstgcs.lk8ftr.com/e/am9hbm5hLmthaW0ta2VydGhAaWcuY29t

Overview

General Information

Sample URL: http://bkbizwwqfqstgcsbkbizwwqfqstgcs.lk8ftr.com/e/am9hbm5hLmthaW0ta2VydGhAaWcuY29t
Analysis ID: 344868

Most interesting Screenshot:

Detection

HTMLPhisher
Score: 80
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Phishing site detected (based on favicon image match)
Yara detected HtmlPhish_10
Phishing site detected (based on image similarity)
Phishing site detected (based on logo template match)
HTML body contains low number of good links
HTML title does not match URL
Invalid T&C link found

Classification

AV Detection:

barindex
Antivirus / Scanner detection for submitted sample
Source: http://bkbizwwqfqstgcsbkbizwwqfqstgcs.lk8ftr.com/e/am9hbm5hLmthaW0ta2VydGhAaWcuY29t SlashNext: detection malicious, Label: Fake Login Page type: Phishing & Social Engineering
Source: http://bkbizwwqfqstgcsbkbizwwqfqstgcs.lk8ftr.com/e/am9hbm5hLmthaW0ta2VydGhAaWcuY29t UrlScan: detection malicious, Label: phishing brand: onedrive microsoft Perma Link
Antivirus detection for URL or domain
Source: https://mydocushare.docushareportal657.xyz/O365/home?MTYxMTc0MTcyMTc4MmI1OWM1YjgzM2ZhNDhjMWY4YjI4MGRhYzk4YmEwZWE4MmU5N2I5MGQzNDMwNDIxNjdlMzM5MzkwZDczMmMwZDBiYzkyMg==&data=am9hbm5hLmthaW0ta2VydGhAaWcuY29t&email=joanna.kaim-kerth@ig.com&MTYxMTc0MTcyMWExZTE4OGY1ZTFlNTA0ZjViN2NkMDRhNzdhODlhMWY1NzRkZDE3OGE5OGUyZGZhMTFlMDgzZTJjYmFjMzYzMjM3NjNhOTc5MA==%3D SlashNext: Label: Fake Login Page type: Phishing & Social Engineering
Source: https://mydocushare.docushareportal657.xyz/O365/home?MTYxMTc0MTcyMTc4MmI1OWM1YjgzM2ZhNDhjMWY4YjI4MGRhYzk4YmEwZWE4MmU5N2I5MGQzNDMwNDIxNjdlMzM5MzkwZDczMmMwZDBiYzkyMg==&data=am9hbm5hLmthaW0ta2VydGhAaWcuY29t&email=joanna.kaim-kerth@ig.com&MTYxMTc0MTcyMWExZTE4OGY1ZTFlNTA0ZjViN2NkMDRhNzdhODlhMWY1NzRkZDE3OGE5OGUyZGZhMTFlMDgzZTJjYmFjMzYzMjM3NjNhOTc5MA==%3D UrlScan: Label: phishing brand: onedrive microsoft Perma Link

Phishing:

barindex
Phishing site detected (based on favicon image match)
Source: https://mydocushare.docushareportal657.xyz/O365/home?MTYxMTc0MTcyMTc4MmI1OWM1YjgzM2ZhNDhjMWY4YjI4MGRhYzk4YmEwZWE4MmU5N2I5MGQzNDMwNDIxNjdlMzM5MzkwZDczMmMwZDBiYzkyMg==&data=am9hbm5hLmthaW0ta2VydGhAaWcuY29t&email=joanna.kaim-kerth@ig.com&MTYxMTc0MTcyMWExZTE4OGY1ZTFlNTA0ZjViN2NkMDRhNzdhODlhMWY1NzRkZDE3OGE5OGUyZGZhMTFlMDgzZTJjYmFjMzYzMjM3NjNhOTc5MA==%3D Matcher: Template: microsoft matched with high similarity
Yara detected HtmlPhish_10
Source: Yara match File source: 96078.pages.csv, type: HTML
Phishing site detected (based on image similarity)
Source: https://mydocushare.docushareportal657.xyz/O365/home?MTYxMTc0MTcyMTc4MmI1OWM1YjgzM2ZhNDhjMWY4YjI4MGRhYzk4YmEwZWE4MmU5N2I5MGQzNDMwNDIxNjdlMzM5MzkwZDczMmMwZDBiYzkyMg==&data=am9hbm5hLmthaW0ta2VydGhAaWcuY29t&email=joanna.kaim-kerth@ig.com&MTYxMTc0MTcyMWExZTE4OGY1ZTFlNTA0ZjViN2NkMDRhNzdhODlhMWY1NzRkZDE3OGE5OGUyZGZhMTFlMDgzZTJjYmFjMzYzMjM3NjNhOTc5MA==%3D Matcher: Found strong image similarity, brand: Microsoft image: 96078.img.2.gfk.csv EE5C8D9FB6248C938FD0DC19370E90BD
Phishing site detected (based on logo template match)
Source: https://mydocushare.docushareportal657.xyz/O365/home?MTYxMTc0MTcyMTc4MmI1OWM1YjgzM2ZhNDhjMWY4YjI4MGRhYzk4YmEwZWE4MmU5N2I5MGQzNDMwNDIxNjdlMzM5MzkwZDczMmMwZDBiYzkyMg==&data=am9hbm5hLmthaW0ta2VydGhAaWcuY29t&email=joanna.kaim-kerth@ig.com&MTYxMTc0MTcyMWExZTE4OGY1ZTFlNTA0ZjViN2NkMDRhNzdhODlhMWY1NzRkZDE3OGE5OGUyZGZhMTFlMDgzZTJjYmFjMzYzMjM3NjNhOTc5MA==%3D Matcher: Template: microsoft matched
HTML body contains low number of good links
Source: https://mydocushare.docushareportal657.xyz/O365/home?MTYxMTc0MTcyMTc4MmI1OWM1YjgzM2ZhNDhjMWY4YjI4MGRhYzk4YmEwZWE4MmU5N2I5MGQzNDMwNDIxNjdlMzM5MzkwZDczMmMwZDBiYzkyMg==&data=am9hbm5hLmthaW0ta2VydGhAaWcuY29t&email=joanna.kaim-kerth@ig.com&MTYxMTc0MTcyMWExZTE4OGY1ZTFlNTA0ZjViN2NkMDRhNzdhODlhMWY1NzRkZDE3OGE5OGUyZGZhMTFlMDgzZTJjYmFjMzYzMjM3NjNhOTc5MA==%3D HTTP Parser: Number of links: 0
Source: https://mydocushare.docushareportal657.xyz/O365/home?MTYxMTc0MTcyMTc4MmI1OWM1YjgzM2ZhNDhjMWY4YjI4MGRhYzk4YmEwZWE4MmU5N2I5MGQzNDMwNDIxNjdlMzM5MzkwZDczMmMwZDBiYzkyMg==&data=am9hbm5hLmthaW0ta2VydGhAaWcuY29t&email=joanna.kaim-kerth@ig.com&MTYxMTc0MTcyMWExZTE4OGY1ZTFlNTA0ZjViN2NkMDRhNzdhODlhMWY1NzRkZDE3OGE5OGUyZGZhMTFlMDgzZTJjYmFjMzYzMjM3NjNhOTc5MA==%3D HTTP Parser: Number of links: 0
HTML title does not match URL
Source: https://mydocushare.docushareportal657.xyz/O365/home?MTYxMTc0MTcyMTc4MmI1OWM1YjgzM2ZhNDhjMWY4YjI4MGRhYzk4YmEwZWE4MmU5N2I5MGQzNDMwNDIxNjdlMzM5MzkwZDczMmMwZDBiYzkyMg==&data=am9hbm5hLmthaW0ta2VydGhAaWcuY29t&email=joanna.kaim-kerth@ig.com&MTYxMTc0MTcyMWExZTE4OGY1ZTFlNTA0ZjViN2NkMDRhNzdhODlhMWY1NzRkZDE3OGE5OGUyZGZhMTFlMDgzZTJjYmFjMzYzMjM3NjNhOTc5MA==%3D HTTP Parser: Title: Sign in to your account does not match URL
Source: https://mydocushare.docushareportal657.xyz/O365/home?MTYxMTc0MTcyMTc4MmI1OWM1YjgzM2ZhNDhjMWY4YjI4MGRhYzk4YmEwZWE4MmU5N2I5MGQzNDMwNDIxNjdlMzM5MzkwZDczMmMwZDBiYzkyMg==&data=am9hbm5hLmthaW0ta2VydGhAaWcuY29t&email=joanna.kaim-kerth@ig.com&MTYxMTc0MTcyMWExZTE4OGY1ZTFlNTA0ZjViN2NkMDRhNzdhODlhMWY1NzRkZDE3OGE5OGUyZGZhMTFlMDgzZTJjYmFjMzYzMjM3NjNhOTc5MA==%3D HTTP Parser: Title: Sign in to your account does not match URL
Invalid T&C link found
Source: https://mydocushare.docushareportal657.xyz/O365/home?MTYxMTc0MTcyMTc4MmI1OWM1YjgzM2ZhNDhjMWY4YjI4MGRhYzk4YmEwZWE4MmU5N2I5MGQzNDMwNDIxNjdlMzM5MzkwZDczMmMwZDBiYzkyMg==&data=am9hbm5hLmthaW0ta2VydGhAaWcuY29t&email=joanna.kaim-kerth@ig.com&MTYxMTc0MTcyMWExZTE4OGY1ZTFlNTA0ZjViN2NkMDRhNzdhODlhMWY1NzRkZDE3OGE5OGUyZGZhMTFlMDgzZTJjYmFjMzYzMjM3NjNhOTc5MA==%3D HTTP Parser: Invalid link: Terms of use
Source: https://mydocushare.docushareportal657.xyz/O365/home?MTYxMTc0MTcyMTc4MmI1OWM1YjgzM2ZhNDhjMWY4YjI4MGRhYzk4YmEwZWE4MmU5N2I5MGQzNDMwNDIxNjdlMzM5MzkwZDczMmMwZDBiYzkyMg==&data=am9hbm5hLmthaW0ta2VydGhAaWcuY29t&email=joanna.kaim-kerth@ig.com&MTYxMTc0MTcyMWExZTE4OGY1ZTFlNTA0ZjViN2NkMDRhNzdhODlhMWY1NzRkZDE3OGE5OGUyZGZhMTFlMDgzZTJjYmFjMzYzMjM3NjNhOTc5MA==%3D HTTP Parser: Invalid link: Terms of use
Source: https://mydocushare.docushareportal657.xyz/O365/home?MTYxMTc0MTcyMTc4MmI1OWM1YjgzM2ZhNDhjMWY4YjI4MGRhYzk4YmEwZWE4MmU5N2I5MGQzNDMwNDIxNjdlMzM5MzkwZDczMmMwZDBiYzkyMg==&data=am9hbm5hLmthaW0ta2VydGhAaWcuY29t&email=joanna.kaim-kerth@ig.com&MTYxMTc0MTcyMWExZTE4OGY1ZTFlNTA0ZjViN2NkMDRhNzdhODlhMWY1NzRkZDE3OGE5OGUyZGZhMTFlMDgzZTJjYmFjMzYzMjM3NjNhOTc5MA==%3D HTTP Parser: No <meta name="author".. found
Source: https://mydocushare.docushareportal657.xyz/O365/home?MTYxMTc0MTcyMTc4MmI1OWM1YjgzM2ZhNDhjMWY4YjI4MGRhYzk4YmEwZWE4MmU5N2I5MGQzNDMwNDIxNjdlMzM5MzkwZDczMmMwZDBiYzkyMg==&data=am9hbm5hLmthaW0ta2VydGhAaWcuY29t&email=joanna.kaim-kerth@ig.com&MTYxMTc0MTcyMWExZTE4OGY1ZTFlNTA0ZjViN2NkMDRhNzdhODlhMWY1NzRkZDE3OGE5OGUyZGZhMTFlMDgzZTJjYmFjMzYzMjM3NjNhOTc5MA==%3D HTTP Parser: No <meta name="author".. found
Source: https://mydocushare.docushareportal657.xyz/O365/home?MTYxMTc0MTcyMTc4MmI1OWM1YjgzM2ZhNDhjMWY4YjI4MGRhYzk4YmEwZWE4MmU5N2I5MGQzNDMwNDIxNjdlMzM5MzkwZDczMmMwZDBiYzkyMg==&data=am9hbm5hLmthaW0ta2VydGhAaWcuY29t&email=joanna.kaim-kerth@ig.com&MTYxMTc0MTcyMWExZTE4OGY1ZTFlNTA0ZjViN2NkMDRhNzdhODlhMWY1NzRkZDE3OGE5OGUyZGZhMTFlMDgzZTJjYmFjMzYzMjM3NjNhOTc5MA==%3D HTTP Parser: No <meta name="copyright".. found
Source: https://mydocushare.docushareportal657.xyz/O365/home?MTYxMTc0MTcyMTc4MmI1OWM1YjgzM2ZhNDhjMWY4YjI4MGRhYzk4YmEwZWE4MmU5N2I5MGQzNDMwNDIxNjdlMzM5MzkwZDczMmMwZDBiYzkyMg==&data=am9hbm5hLmthaW0ta2VydGhAaWcuY29t&email=joanna.kaim-kerth@ig.com&MTYxMTc0MTcyMWExZTE4OGY1ZTFlNTA0ZjViN2NkMDRhNzdhODlhMWY1NzRkZDE3OGE5OGUyZGZhMTFlMDgzZTJjYmFjMzYzMjM3NjNhOTc5MA==%3D HTTP Parser: No <meta name="copyright".. found

Compliance:

barindex
Creates a directory in C:\Program Files
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic Jump to behavior
Uses secure TLS version for HTTPS connections
Source: unknown HTTPS traffic detected: 52.188.166.242:443 -> 192.168.2.3:49754 version: TLS 1.2
Source: unknown HTTPS traffic detected: 52.188.166.242:443 -> 192.168.2.3:49755 version: TLS 1.2
Source: global traffic HTTP traffic detected: GET /e/am9hbm5hLmthaW0ta2VydGhAaWcuY29t HTTP/1.1Host: bkbizwwqfqstgcsbkbizwwqfqstgcs.lk8ftr.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ZeroSSLRSADomainSecureSiteCA.crt HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Microsoft-CryptoAPI/10.0Host: zerossl.crt.sectigo.com
Source: unknown DNS traffic detected: queries for: bkbizwwqfqstgcsbkbizwwqfqstgcs.lk8ftr.com
Source: Current Session.0.dr String found in binary or memory: http://bkbizwwqfqstgcsbkbizwwqfqstgcs.lk8ftr.com
Source: Current Session.0.dr, Favicons.0.dr String found in binary or memory: http://bkbizwwqfqstgcsbkbizwwqfqstgcs.lk8ftr.com/e/am9hbm5hLmthaW0ta2VydGhAaWcuY29t
Source: History Provider Cache.0.dr String found in binary or memory: http://bkbizwwqfqstgcsbkbizwwqfqstgcs.lk8ftr.com/e/am9hbm5hLmthaW0ta2VydGhAaWcuY29t23S
Source: History.0.dr String found in binary or memory: http://bkbizwwqfqstgcsbkbizwwqfqstgcs.lk8ftr.com/e/am9hbm5hLmthaW0ta2VydGhAaWcuY29tS
Source: 10BDC45B4A27319429BBC4F08A4E8A10.1.dr String found in binary or memory: http://zerossl.crt.sectigo.com/ZeroSSLRSADomainSecureSiteCA.crt
Source: manifest.json0.0.dr, 4d17712d-d8aa-4e1c-accd-8c3693b5068c.tmp.1.dr String found in binary or memory: https://accounts.google.com
Source: manifest.json0.0.dr, 4d17712d-d8aa-4e1c-accd-8c3693b5068c.tmp.1.dr String found in binary or memory: https://apis.google.com
Source: 4d17712d-d8aa-4e1c-accd-8c3693b5068c.tmp.1.dr String found in binary or memory: https://clients2.google.com
Source: manifest.json0.0.dr String found in binary or memory: https://clients2.google.com/service/update2/crx
Source: 4d17712d-d8aa-4e1c-accd-8c3693b5068c.tmp.1.dr String found in binary or memory: https://clients2.googleusercontent.com
Source: manifest.json0.0.dr String found in binary or memory: https://content.googleapis.com
Source: 71a93ce5-c5db-43e1-9b45-27c90a52ea2b.tmp.1.dr, 5920a891-a4d7-4969-ac23-7026941eaf9f.tmp.1.dr, 4d17712d-d8aa-4e1c-accd-8c3693b5068c.tmp.1.dr String found in binary or memory: https://dns.google
Source: manifest.json0.0.dr String found in binary or memory: https://feedback.googleusercontent.com
Source: 4d17712d-d8aa-4e1c-accd-8c3693b5068c.tmp.1.dr String found in binary or memory: https://fonts.googleapis.com
Source: manifest.json0.0.dr String found in binary or memory: https://fonts.googleapis.com;
Source: 4d17712d-d8aa-4e1c-accd-8c3693b5068c.tmp.1.dr String found in binary or memory: https://fonts.gstatic.com
Source: manifest.json0.0.dr String found in binary or memory: https://fonts.gstatic.com;
Source: manifest.json0.0.dr String found in binary or memory: https://hangouts.google.com/
Source: Favicons.0.dr, History.0.dr String found in binary or memory: https://mydocushare.docushareportal657.xyz/O365/?joanna.kaim-kerth
Source: Current Session.0.dr, Favicons.0.dr, History.0.dr String found in binary or memory: https://mydocushare.docushareportal657.xyz/O365/home?MTYxMTc0MTcyMTc4MmI1OWM1YjgzM2ZhNDhjMWY4YjI4MGR
Source: Favicons.0.dr String found in binary or memory: https://mydocushare.docushareportal657.xyz/O365/lib/img/favicon.ico
Source: Favicons.0.dr, History.0.dr String found in binary or memory: https://mydocushare.docushareportal657.xyz/O365/proceed?email=joanna.kaim-kerth
Source: 4d17712d-d8aa-4e1c-accd-8c3693b5068c.tmp.1.dr String found in binary or memory: https://ogs.google.com
Source: manifest.json.0.dr String found in binary or memory: https://payments.google.com/payments/v4/js/integrator.js
Source: 4d17712d-d8aa-4e1c-accd-8c3693b5068c.tmp.1.dr String found in binary or memory: https://play.google.com
Source: manifest.json.0.dr String found in binary or memory: https://sandbox.google.com/payments/v4/js/integrator.js
Source: 4d17712d-d8aa-4e1c-accd-8c3693b5068c.tmp.1.dr String found in binary or memory: https://ssl.gstatic.com
Source: messages.json41.0.dr String found in binary or memory: https://support.google.com/chromecast/answer/2998456
Source: messages.json41.0.dr String found in binary or memory: https://support.google.com/chromecast/troubleshooter/2995236
Source: manifest.json0.0.dr, 4d17712d-d8aa-4e1c-accd-8c3693b5068c.tmp.1.dr String found in binary or memory: https://www.google.com
Source: manifest.json.0.dr String found in binary or memory: https://www.google.com/
Source: manifest.json0.0.dr String found in binary or memory: https://www.google.com;
Source: 4d17712d-d8aa-4e1c-accd-8c3693b5068c.tmp.1.dr String found in binary or memory: https://www.googleapis.com
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/calendar.readonly
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/cast-edu-messaging
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/chromewebstore
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/chromewebstore.readonly
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/clouddevices
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/hangouts
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/hangouts.readonly
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/meetings
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/plus.peopleapi.readwrite
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/sierra
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/sierrasandbox
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/userinfo.email
Source: 4d17712d-d8aa-4e1c-accd-8c3693b5068c.tmp.1.dr String found in binary or memory: https://www.gstatic.com
Source: manifest.json0.0.dr String found in binary or memory: https://www.gstatic.com;
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49744
Source: unknown Network traffic detected: HTTP traffic on port 49733 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49743
Source: unknown Network traffic detected: HTTP traffic on port 49758 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49760
Source: unknown Network traffic detected: HTTP traffic on port 49743 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49760 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49746 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49745 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49759
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49758
Source: unknown Network traffic detected: HTTP traffic on port 49759 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49757
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49734
Source: unknown Network traffic detected: HTTP traffic on port 49755 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49733
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49755
Source: unknown Network traffic detected: HTTP traffic on port 49757 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49754
Source: unknown Network traffic detected: HTTP traffic on port 49734 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49744 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49754 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49746
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49745
Source: unknown HTTPS traffic detected: 52.188.166.242:443 -> 192.168.2.3:49754 version: TLS 1.2
Source: unknown HTTPS traffic detected: 52.188.166.242:443 -> 192.168.2.3:49755 version: TLS 1.2
Source: classification engine Classification label: mal80.phis.win@29/164@5/7
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-6011B8A2-1678.pma Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Local\Temp\59e48edb-4a38-4908-bb87-233755c51147.tmp Jump to behavior
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --start-maximized 'http://bkbizwwqfqstgcsbkbizwwqfqstgcs.lk8ftr.com/e/am9hbm5hLmthaW0ta2VydGhAaWcuY29t'
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1532,15419587561947641969,2247414398812328316,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1724 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1532,15419587561947641969,2247414398812328316,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1724 /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic Jump to behavior
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 344868 URL: http://bkbizwwqfqstgcsbkbiz... Startdate: 27/01/2021 Architecture: WINDOWS Score: 80 13 mydocushare.docushareportal657.xyz 2->13 25 Antivirus detection for URL or domain 2->25 27 Antivirus / Scanner detection for submitted sample 2->27 29 Phishing site detected (based on favicon image match) 2->29 31 3 other signatures 2->31 7 chrome.exe 14 384 2->7         started        signatures3 process4 dnsIp5 15 192.168.2.1 unknown unknown 7->15 17 239.255.255.250 unknown Reserved 7->17 10 chrome.exe 1 20 7->10         started        process6 dnsIp7 19 crt.sectigo.com 91.199.212.52, 49735, 80 SECTIGOGB United Kingdom 10->19 21 bkbizwwqfqstgcsbkbizwwqfqstgcs.lk8ftr.com 40.76.49.205, 49724, 49725, 80 MICROSOFT-CORP-MSN-AS-BLOCKUS United States 10->21 23 5 other IPs or domains 10->23
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs

Contacted Public IPs

IP Domain Country Flag ASN ASN Name Malicious
172.217.22.225
unknown United States
15169 GOOGLEUS false
91.199.212.52
unknown United Kingdom
48447 SECTIGOGB false
239.255.255.250
unknown Reserved
unknown unknown false
40.76.49.205
unknown United States
8075 MICROSOFT-CORP-MSN-AS-BLOCKUS false
52.188.166.242
unknown United States
8075 MICROSOFT-CORP-MSN-AS-BLOCKUS false

Private

IP
192.168.2.1
127.0.0.1

Contacted Domains

Name IP Active
bkbizwwqfqstgcsbkbizwwqfqstgcs.lk8ftr.com 40.76.49.205 true
mydocushare.docushareportal657.xyz 52.188.166.242 true
crt.sectigo.com 91.199.212.52 true
googlehosted.l.googleusercontent.com 172.217.22.225 true
clients2.googleusercontent.com unknown unknown
zerossl.crt.sectigo.com unknown unknown

Contacted URLs

Name Malicious Antivirus Detection Reputation
http://bkbizwwqfqstgcsbkbizwwqfqstgcs.lk8ftr.com/e/am9hbm5hLmthaW0ta2VydGhAaWcuY29t true
    unknown
    https://mydocushare.docushareportal657.xyz/O365/home?MTYxMTc0MTcyMTc4MmI1OWM1YjgzM2ZhNDhjMWY4YjI4MGRhYzk4YmEwZWE4MmU5N2I5MGQzNDMwNDIxNjdlMzM5MzkwZDczMmMwZDBiYzkyMg==&data=am9hbm5hLmthaW0ta2VydGhAaWcuY29t&email=joanna.kaim-kerth@ig.com&MTYxMTc0MTcyMWExZTE4OGY1ZTFlNTA0ZjViN2NkMDRhNzdhODlhMWY1NzRkZDE3OGE5OGUyZGZhMTFlMDgzZTJjYmFjMzYzMjM3NjNhOTc5MA==%3D true
    • 100%, UrlScan, Browse
    • SlashNext: Fake Login Page type: Phishing & Social Engineering
    unknown
    http://zerossl.crt.sectigo.com/ZeroSSLRSADomainSecureSiteCA.crt false
    • Avira URL Cloud: safe
    unknown