Analysis Report https://summary.aquilaiajax.com/v3/summary?ref=email&crId=606c5ec27707d53875dac9da

Overview

General Information

Sample URL: https://summary.aquilaiajax.com/v3/summary?ref=email&crId=606c5ec27707d53875dac9da
Analysis ID: 383834
Infos:

Most interesting Screenshot:

Detection

Score: 0
Range: 0 - 100
Whitelisted: false
Confidence: 80%

Signatures

No high impact signatures.

Classification

There are no high impact signatures.

Source: C:\Program Files (x86)\Internet Explorer\iexplore.exe File opened: C:\Program Files (x86)\Java\jre1.8.0_211\bin\msvcr100.dll Jump to behavior
Source: unknown HTTPS traffic detected: 35.178.120.30:443 -> 192.168.2.6:49699 version: TLS 1.2
Source: unknown HTTPS traffic detected: 35.178.120.30:443 -> 192.168.2.6:49698 version: TLS 1.2
Source: unknown HTTPS traffic detected: 185.199.108.153:443 -> 192.168.2.6:49705 version: TLS 1.2
Source: unknown HTTPS traffic detected: 185.199.108.153:443 -> 192.168.2.6:49706 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.26.6.30:443 -> 192.168.2.6:49709 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.26.6.30:443 -> 192.168.2.6:49708 version: TLS 1.2
Source: unknown HTTPS traffic detected: 35.178.120.30:443 -> 192.168.2.6:49721 version: TLS 1.2
Source: msapplication.xml0.1.dr String found in binary or memory: <browserconfig><msapplication><config><site src="http://www.facebook.com/"/><date>0x69559cf6,0x01d72c9f</date><accdate>0x69559cf6,0x01d72c9f</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig> equals www.facebook.com (Facebook)
Source: msapplication.xml0.1.dr String found in binary or memory: <browserconfig><msapplication><config><site src="http://www.facebook.com/"/><date>0x69559cf6,0x01d72c9f</date><accdate>0x69559cf6,0x01d72c9f</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Facebook.url"/></tile></msapplication></browserconfig> equals www.facebook.com (Facebook)
Source: msapplication.xml5.1.dr String found in binary or memory: <browserconfig><msapplication><config><site src="http://www.twitter.com/"/><date>0x6976fdd8,0x01d72c9f</date><accdate>0x6976fdd8,0x01d72c9f</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig> equals www.twitter.com (Twitter)
Source: msapplication.xml5.1.dr String found in binary or memory: <browserconfig><msapplication><config><site src="http://www.twitter.com/"/><date>0x6976fdd8,0x01d72c9f</date><accdate>0x6976fdd8,0x01d72c9f</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Twitter.url"/></tile></msapplication></browserconfig> equals www.twitter.com (Twitter)
Source: msapplication.xml7.1.dr String found in binary or memory: <browserconfig><msapplication><config><site src="http://www.youtube.com/"/><date>0x6976fdd8,0x01d72c9f</date><accdate>0x6976fdd8,0x01d72c9f</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig> equals www.youtube.com (Youtube)
Source: msapplication.xml7.1.dr String found in binary or memory: <browserconfig><msapplication><config><site src="http://www.youtube.com/"/><date>0x6976fdd8,0x01d72c9f</date><accdate>0x69796033,0x01d72c9f</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Youtube.url"/></tile></msapplication></browserconfig> equals www.youtube.com (Youtube)
Source: unknown DNS traffic detected: queries for: summary.aquilaiajax.com
Source: msapplication.xml.1.dr String found in binary or memory: http://www.amazon.com/
Source: msapplication.xml1.1.dr String found in binary or memory: http://www.google.com/
Source: msapplication.xml2.1.dr String found in binary or memory: http://www.live.com/
Source: msapplication.xml3.1.dr String found in binary or memory: http://www.nytimes.com/
Source: msapplication.xml4.1.dr String found in binary or memory: http://www.reddit.com/
Source: msapplication.xml5.1.dr String found in binary or memory: http://www.twitter.com/
Source: msapplication.xml6.1.dr String found in binary or memory: http://www.wikipedia.com/
Source: msapplication.xml7.1.dr String found in binary or memory: http://www.youtube.com/
Source: js[1].js.2.dr String found in binary or memory: https://ade.googlesyndication.com/ddm/activity
Source: js[1].js.2.dr String found in binary or memory: https://adservice.google.com/ddm/regclk
Source: js[1].js.2.dr String found in binary or memory: https://adservice.google.com/pagead/regclk
Source: analytics[1].js.2.dr String found in binary or memory: https://ampcid.google.com/v1/publisher:getClientId
Source: summary[1].htm.2.dr String found in binary or memory: https://bernii.github.io/gauge.js/dist/gauge.min.js
Source: js[1].js.2.dr String found in binary or memory: https://cct.google/taggy/agent.js
Source: summary[1].htm.2.dr String found in binary or memory: https://code.jquery.com/jquery-3.5.1.min.js
Source: d3.v5.min[1].js.2.dr String found in binary or memory: https://d3js.org
Source: summary[1].htm.2.dr String found in binary or memory: https://d3js.org/d3.v5.min.js
Source: summary[1].htm.2.dr String found in binary or memory: https://fonts.googleapis.com/css?family=Roboto:regular
Source: summary[1].htm.2.dr String found in binary or memory: https://fonts.googleapis.com/icon?family=Material
Source: icon[1].css.2.dr String found in binary or memory: https://fonts.gstatic.com/s/materialicons/v83/flUhRq6tzZclQEJ-Vdg-IuiaDsNa.woff)
Source: css[1].css.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v27/KFOjCnqEu92Fr1Mu51TzBic6CsI.woff)
Source: css[1].css.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v27/KFOkCnqEu92Fr1MmgVxIIzQ.woff)
Source: css[1].css.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v27/KFOkCnqEu92Fr1Mu51xIIzQ.woff)
Source: css[1].css.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v27/KFOlCnqEu92Fr1MmEU9fBBc-.woff)
Source: css[1].css.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v27/KFOlCnqEu92Fr1MmSU5fBBc-.woff)
Source: css[1].css.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v27/KFOlCnqEu92Fr1MmWUlfBBc-.woff)
Source: css[1].css.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v27/KFOlCnqEu92Fr1MmYUtfBBc-.woff)
Source: css[1].css.2.dr String found in binary or memory: https://fonts.gstatic.com/s/roboto/v27/KFOmCnqEu92Fr1Mu4mxM.woff)
Source: js[1].js.2.dr String found in binary or memory: https://pagead2.googlesyndication.com
Source: js[1].js.2.dr String found in binary or memory: https://pagead2.googlesyndication.com/
Source: analytics[1].js.2.dr String found in binary or memory: https://stats.g.doubleclick.net/j/collect
Source: ~DF03EBC80C459E6306.TMP.1.dr String found in binary or memory: https://summary.aquilaiajax.com/v3/summary?ref=email&crId=606c5ec27707d53875dac9da
Source: {92EDE2C2-9892-11EB-90E5-ECF4BB2D2496}.dat.1.dr String found in binary or memory: https://summary.aquilaiajax.com/v3/summary?ref=email&crId=606c5ec27707d53875dac9daRoot
Source: analytics[1].js.2.dr String found in binary or memory: https://tagassistant.google.com/
Source: js[1].js.2.dr String found in binary or memory: https://www.google-analytics.com/analytics.js
Source: analytics[1].js.2.dr String found in binary or memory: https://www.google-analytics.com/debug/bootstrap
Source: analytics[1].js.2.dr String found in binary or memory: https://www.google-analytics.com/gtm/js?id=
Source: analytics[1].js.2.dr String found in binary or memory: https://www.google.%/ads/ga-audiences
Source: js[1].js.2.dr String found in binary or memory: https://www.google.com
Source: js[1].js.2.dr String found in binary or memory: https://www.googletagmanager.com/debug/bootstrap
Source: analytics[1].js.2.dr String found in binary or memory: https://www.googletagmanager.com/gtag/js?id=
Source: summary[1].htm.2.dr String found in binary or memory: https://www.googletagmanager.com/gtag/js?id=UA-165596162-2
Source: unknown Network traffic detected: HTTP traffic on port 49698 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49708 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49699 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49699
Source: unknown Network traffic detected: HTTP traffic on port 49709 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49721
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49698
Source: unknown Network traffic detected: HTTP traffic on port 49706 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49705 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49721 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49709
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49708
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49706
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49705
Source: unknown HTTPS traffic detected: 35.178.120.30:443 -> 192.168.2.6:49699 version: TLS 1.2
Source: unknown HTTPS traffic detected: 35.178.120.30:443 -> 192.168.2.6:49698 version: TLS 1.2
Source: unknown HTTPS traffic detected: 185.199.108.153:443 -> 192.168.2.6:49705 version: TLS 1.2
Source: unknown HTTPS traffic detected: 185.199.108.153:443 -> 192.168.2.6:49706 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.26.6.30:443 -> 192.168.2.6:49709 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.26.6.30:443 -> 192.168.2.6:49708 version: TLS 1.2
Source: unknown HTTPS traffic detected: 35.178.120.30:443 -> 192.168.2.6:49721 version: TLS 1.2
Source: classification engine Classification label: clean0.win@3/25@5/3
Source: C:\Program Files\internet explorer\iexplore.exe File created: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{92EDE2C0-9892-11EB-90E5-ECF4BB2D2496}.dat Jump to behavior
Source: C:\Program Files\internet explorer\iexplore.exe File created: C:\Users\user\AppData\Local\Temp\~DF22D8D2F9858A4A01.TMP Jump to behavior
Source: C:\Program Files\internet explorer\iexplore.exe File read: C:\Users\desktop.ini Jump to behavior
Source: unknown Process created: C:\Program Files\internet explorer\iexplore.exe 'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding
Source: C:\Program Files\internet explorer\iexplore.exe Process created: C:\Program Files (x86)\Internet Explorer\iexplore.exe 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:2680 CREDAT:17410 /prefetch:2
Source: C:\Program Files\internet explorer\iexplore.exe Process created: C:\Program Files (x86)\Internet Explorer\iexplore.exe 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:2680 CREDAT:17410 /prefetch:2 Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Internet Explorer\iexplore.exe File opened: C:\Program Files (x86)\Java\jre1.8.0_211\bin\msvcr100.dll Jump to behavior
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 383834 URL: https://summary.aquilaiajax... Startdate: 08/04/2021 Architecture: WINDOWS Score: 0 11 summary.aquilaiajax.com 2->11 13 london-sentry-email-summary-1161567812.eu-west-2.elb.amazonaws.com 2->13 6 iexplore.exe 1 73 2->6         started        process3 process4 8 iexplore.exe 2 44 6->8         started        dnsIp5 15 bernii.github.io 185.199.108.153, 443, 49705, 49706 FASTLYUS Netherlands 8->15 17 d3js.org 104.26.6.30, 443, 49708, 49709 CLOUDFLARENETUS United States 8->17 19 3 other IPs or domains 8->19
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs

Contacted Public IPs

IP Domain Country Flag ASN ASN Name Malicious
104.26.6.30
d3js.org United States
13335 CLOUDFLARENETUS false
35.178.120.30
london-sentry-email-summary-1161567812.eu-west-2.elb.amazonaws.com United States
16509 AMAZON-02US false
185.199.108.153
bernii.github.io Netherlands
54113 FASTLYUS false

Contacted Domains

Name IP Active
bernii.github.io 185.199.108.153 true
london-sentry-email-summary-1161567812.eu-west-2.elb.amazonaws.com 35.178.120.30 true
d3js.org 104.26.6.30 true
summary.aquilaiajax.com unknown unknown
code.jquery.com unknown unknown

Contacted URLs

Name Malicious Antivirus Detection Reputation
https://summary.aquilaiajax.com/v3/summary?ref=email&crId=606c5ec27707d53875dac9da false
    unknown