Analysis Report http://www.ztzusl.vibz.co.uk./#jrschnell.com.br/site/z1/bGFtQHNwYXJub3JkLmRr

Overview

General Information

Sample URL: http://www.ztzusl.vibz.co.uk./#jrschnell.com.br/site/z1/bGFtQHNwYXJub3JkLmRr
Analysis ID: 383856
Infos:

Most interesting Screenshot:

Detection

HTMLPhisher
Score: 56
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Yara detected HtmlPhish10
Phishing site detected (based on image similarity)
Phishing site detected (based on logo template match)
HTML body contains low number of good links
HTML title does not match URL
Invalid 'forgot password' link found

Classification

Phishing:

barindex
Yara detected HtmlPhish10
Source: Yara match File source: 36770.pages.csv, type: HTML
Phishing site detected (based on image similarity)
Source: https://jrschnell.com.br/site/z1/y5t4SCIjdufwm3DlF0B6gHz9h7YcZW/ptmkYZg0csRd3hfLVODo/mf6H3wg59JYA4MiDNIy.php Matcher: Found strong image similarity, brand: Microsoft image: 36770.img.2.gfk.csv EE5C8D9FB6248C938FD0DC19370E90BD
Phishing site detected (based on logo template match)
Source: https://jrschnell.com.br/site/z1/y5t4SCIjdufwm3DlF0B6gHz9h7YcZW/ptmkYZg0csRd3hfLVODo/mf6H3wg59JYA4MiDNIy.php Matcher: Template: microsoft matched
HTML body contains low number of good links
Source: https://jrschnell.com.br/site/z1/y5t4SCIjdufwm3DlF0B6gHz9h7YcZW/ptmkYZg0csRd3hfLVODo/mf6H3wg59JYA4MiDNIy.php HTTP Parser: Number of links: 0
Source: https://jrschnell.com.br/site/z1/y5t4SCIjdufwm3DlF0B6gHz9h7YcZW/ptmkYZg0csRd3hfLVODo/mf6H3wg59JYA4MiDNIy.php HTTP Parser: Number of links: 0
HTML title does not match URL
Source: https://jrschnell.com.br/site/z1/y5t4SCIjdufwm3DlF0B6gHz9h7YcZW/ptmkYZg0csRd3hfLVODo/mf6H3wg59JYA4MiDNIy.php HTTP Parser: Title: Sign in to your account does not match URL
Source: https://jrschnell.com.br/site/z1/y5t4SCIjdufwm3DlF0B6gHz9h7YcZW/ptmkYZg0csRd3hfLVODo/mf6H3wg59JYA4MiDNIy.php HTTP Parser: Title: Sign in to your account does not match URL
Invalid 'forgot password' link found
Source: https://jrschnell.com.br/site/z1/y5t4SCIjdufwm3DlF0B6gHz9h7YcZW/ptmkYZg0csRd3hfLVODo/mf6H3wg59JYA4MiDNIy.php HTTP Parser: Invalid link: Forgot my password
Source: https://jrschnell.com.br/site/z1/y5t4SCIjdufwm3DlF0B6gHz9h7YcZW/ptmkYZg0csRd3hfLVODo/mf6H3wg59JYA4MiDNIy.php HTTP Parser: Invalid link: Forgot my password
Source: https://jrschnell.com.br/site/z1/y5t4SCIjdufwm3DlF0B6gHz9h7YcZW/ptmkYZg0csRd3hfLVODo/mf6H3wg59JYA4MiDNIy.php HTTP Parser: No <meta name="author".. found
Source: https://jrschnell.com.br/site/z1/y5t4SCIjdufwm3DlF0B6gHz9h7YcZW/ptmkYZg0csRd3hfLVODo/mf6H3wg59JYA4MiDNIy.php HTTP Parser: No <meta name="author".. found
Source: https://jrschnell.com.br/site/z1/y5t4SCIjdufwm3DlF0B6gHz9h7YcZW/ptmkYZg0csRd3hfLVODo/mf6H3wg59JYA4MiDNIy.php HTTP Parser: No <meta name="copyright".. found
Source: https://jrschnell.com.br/site/z1/y5t4SCIjdufwm3DlF0B6gHz9h7YcZW/ptmkYZg0csRd3hfLVODo/mf6H3wg59JYA4MiDNIy.php HTTP Parser: No <meta name="copyright".. found
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic Jump to behavior
Source: unknown HTTPS traffic detected: 172.67.192.199:443 -> 192.168.2.3:49738 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.21.69.231:443 -> 192.168.2.3:49739 version: TLS 1.2
Source: unknown HTTPS traffic detected: 152.199.23.37:443 -> 192.168.2.3:49740 version: TLS 1.2
Source: unknown HTTPS traffic detected: 152.199.23.37:443 -> 192.168.2.3:49741 version: TLS 1.2
Source: unknown HTTPS traffic detected: 152.199.23.37:443 -> 192.168.2.3:49742 version: TLS 1.2
Source: unknown HTTPS traffic detected: 152.199.23.37:443 -> 192.168.2.3:49743 version: TLS 1.2
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKdate: Thu, 08 Apr 2021 09:20:33 GMTserver: Apachex-powered-by: PHP/7.3.27vary: Accept-Encodingcontent-encoding: gzipcontent-length: 364content-type: text/html; charset=UTF-8Data Raw: 1f 8b 08 00 00 00 00 00 00 03 4d 51 4d 6f c2 30 0c bd 4f e2 3f 74 ec 90 44 0d 69 61 1b fb 28 e1 b6 f3 a6 ed b0 03 30 29 a4 06 32 ba 12 b5 81 32 35 f9 ef 4b 60 20 a2 c8 7a 7e b6 9f 2d bb 73 d5 b9 1a ad cc 4f 31 8e 02 00 91 07 10 f9 37 32 ca 14 30 7e 2b 40 d4 10 7d 0a 65 18 63 a3 e4 c8 86 e4 5a 56 4a 9b c8 fc 6a e0 5d 03 7b 93 7c 8b 9d 38 b2 dd 71 c7 0b c3 4e 14 78 b1 2d a5 51 9b 12 6b 2a a8 a4 6b 0a 34 27 2d f0 33 2f 49 5b 81 d9 56 65 24 5d a6 16 f8 1a 21 56 81 2e 84 04 9c 7c 25 f4 c3 54 aa 5c 12 d2 36 2b 55 00 96 bd 1e 69 f3 89 9c f1 b5 37 d6 4a b7 e6 93 b3 18 9c c5 f2 09 cc dc 2c bb 68 74 0a a1 e9 b4 89 91 cb 24 ef bb ec 42 d4 f7 0e 92 a4 d5 5c 9f 27 28 a1 89 de 61 f9 b2 d7 d8 d7 cd 51 ec 93 49 7c 80 14 2d 11 a1 87 12 e7 fe bb 6a 87 d1 30 4a f9 3d bb 63 b7 d9 30 1a f0 94 3d e1 94 3d e2 29 ba 99 22 12 f7 49 76 88 f1 ee c3 73 92 74 e3 41 86 68 3f 0d 1f d5 a6 b2 d6 9b be 5d 55 b0 b0 c5 46 8a 30 b7 6d 54 99 6f 1a bb 13 95 5d 19 a3 6b eb 7d d8 bf 2e 6c bd 9d d7 87 e5 20 56 eb 42 19 8c ac 1f 28 a5 ad 23 24 ec df 1f 29 39 de 63 7c 74 4e f7 f5 28 9c 3c 90 7f d3 8a 66 42 01 02 00 00 Data Ascii: MQMo0O?tDia(0)225K` z~-sO1720~+@}ecZVJj]{|8qNx-Qk*k4'-3/I[Ve$]!V.|%T\6+Ui7J,ht$B\'(aQI|-j0J=c0==)"IvstAh?]UF0mTo]k}.l VB(#$)9c|tN(<fB
Source: global traffic HTTP traffic detected: GET / HTTP/1.1Host: www.ztzusl.vibz.co.uk.Connection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknown DNS traffic detected: queries for: www.ztzusl.vibz.co.uk
Source: Favicons.0.dr String found in binary or memory: http://www.ztzusl.vibz.co.uk./#jrschnell.com.br/site/z1/bGFtQHNwYXJub3JkLmRr
Source: History Provider Cache.0.dr String found in binary or memory: http://www.ztzusl.vibz.co.uk./#jrschnell.com.br/site/z1/bGFtQHNwYXJub3JkLmRr2
Source: History.0.dr String found in binary or memory: http://www.ztzusl.vibz.co.uk./#jrschnell.com.br/site/z1/bGFtQHNwYXJub3JkLmRrPlease
Source: Reporting and NEL.1.dr String found in binary or memory: https://a.nel.cloudflare.com/report?s=%2Brkvlk2spclXqK6yTmx2usbGOs8A629aLK1Dqd3p0H0JYWQO71VtF1WOEgDU
Source: Reporting and NEL.1.dr String found in binary or memory: https://a.nel.cloudflare.com/report?s=x%2Fk503X%2FQhaDDfvDnSBp0jVUjYJ98bFOUyn9O3pstJJ87ASzqPO11BiOuN
Source: manifest.json0.0.dr, 6c452b1a-6acf-4bcf-809d-623812ae33de.tmp.1.dr String found in binary or memory: https://accounts.google.com
Source: manifest.json0.0.dr, 6c452b1a-6acf-4bcf-809d-623812ae33de.tmp.1.dr String found in binary or memory: https://apis.google.com
Source: 6c452b1a-6acf-4bcf-809d-623812ae33de.tmp.1.dr String found in binary or memory: https://clients2.google.com
Source: manifest.json1.0.dr String found in binary or memory: https://clients2.google.com/service/update2/crx
Source: 6c452b1a-6acf-4bcf-809d-623812ae33de.tmp.1.dr String found in binary or memory: https://clients2.googleusercontent.com
Source: manifest.json0.0.dr String found in binary or memory: https://content.googleapis.com
Source: 85f45a16-0382-45af-b147-50395de217b0.tmp.1.dr, 468071a4-6c7d-4327-9229-b9c7ff9f8d37.tmp.1.dr, 6c452b1a-6acf-4bcf-809d-623812ae33de.tmp.1.dr String found in binary or memory: https://dns.google
Source: manifest.json0.0.dr String found in binary or memory: https://feedback.googleusercontent.com
Source: 6c452b1a-6acf-4bcf-809d-623812ae33de.tmp.1.dr String found in binary or memory: https://fonts.googleapis.com
Source: manifest.json0.0.dr String found in binary or memory: https://fonts.googleapis.com;
Source: 6c452b1a-6acf-4bcf-809d-623812ae33de.tmp.1.dr String found in binary or memory: https://fonts.gstatic.com
Source: manifest.json0.0.dr String found in binary or memory: https://fonts.gstatic.com;
Source: manifest.json0.0.dr String found in binary or memory: https://hangouts.google.com/
Source: Current Session.0.dr String found in binary or memory: https://jrschnell.com.br
Source: Favicons.0.dr String found in binary or memory: https://jrschnell.com.br/favicon.ico
Source: Current Session.0.dr String found in binary or memory: https://jrschnell.com.br/site/z1/bGFtQHNwYXJub3JkLmRr
Source: History.0.dr String found in binary or memory: https://jrschnell.com.br/site/z1/bGFtQHNwYXJub3JkLmRr/
Source: History Provider Cache.0.dr String found in binary or memory: https://jrschnell.com.br/site/z1/bGFtQHNwYXJub3JkLmRr2
Source: History Provider Cache.0.dr String found in binary or memory: https://jrschnell.com.br/site/z1/bGFtQHNwYXJub3JkLmRr2:
Source: Favicons.0.dr String found in binary or memory: https://jrschnell.com.br/site/z1/bGFtQHNwYXJub3JkLmRrQ
Source: History.0.dr String found in binary or memory: https://jrschnell.com.br/site/z1/y5t4SCIjdufwm3DlF0B6gHz9h7YcZW/ptmkYZg0csRd3hfLVODo/mf6H3wg59JYA4Mi
Source: 6c452b1a-6acf-4bcf-809d-623812ae33de.tmp.1.dr String found in binary or memory: https://ogs.google.com
Source: manifest.json1.0.dr String found in binary or memory: https://payments.google.com/payments/v4/js/integrator.js
Source: 6c452b1a-6acf-4bcf-809d-623812ae33de.tmp.1.dr String found in binary or memory: https://play.google.com
Source: manifest.json1.0.dr String found in binary or memory: https://sandbox.google.com/payments/v4/js/integrator.js
Source: 6c452b1a-6acf-4bcf-809d-623812ae33de.tmp.1.dr String found in binary or memory: https://ssl.gstatic.com
Source: messages.json41.0.dr String found in binary or memory: https://support.google.com/chromecast/answer/2998456
Source: messages.json41.0.dr String found in binary or memory: https://support.google.com/chromecast/troubleshooter/2995236
Source: manifest.json0.0.dr, 6c452b1a-6acf-4bcf-809d-623812ae33de.tmp.1.dr String found in binary or memory: https://www.google.com
Source: manifest.json1.0.dr String found in binary or memory: https://www.google.com/
Source: manifest.json0.0.dr String found in binary or memory: https://www.google.com;
Source: 6c452b1a-6acf-4bcf-809d-623812ae33de.tmp.1.dr String found in binary or memory: https://www.googleapis.com
Source: manifest.json1.0.dr String found in binary or memory: https://www.googleapis.com/
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/calendar.readonly
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/cast-edu-messaging
Source: manifest.json1.0.dr String found in binary or memory: https://www.googleapis.com/auth/chromewebstore
Source: manifest.json1.0.dr String found in binary or memory: https://www.googleapis.com/auth/chromewebstore.readonly
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/clouddevices
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/hangouts
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/hangouts.readonly
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/meetings
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/plus.peopleapi.readwrite
Source: manifest.json1.0.dr String found in binary or memory: https://www.googleapis.com/auth/sierra
Source: manifest.json1.0.dr String found in binary or memory: https://www.googleapis.com/auth/sierrasandbox
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/userinfo.email
Source: 6c452b1a-6acf-4bcf-809d-623812ae33de.tmp.1.dr String found in binary or memory: https://www.gstatic.com
Source: manifest.json0.0.dr String found in binary or memory: https://www.gstatic.com;
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49743
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49742
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49741
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49740
Source: unknown Network traffic detected: HTTP traffic on port 49727 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49725 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49741 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49743 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49739
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49716
Source: unknown Network traffic detected: HTTP traffic on port 49715 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49738
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49715
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49737
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49714
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49735
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49734
Source: unknown Network traffic detected: HTTP traffic on port 49738 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49734 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49754
Source: unknown Network traffic detected: HTTP traffic on port 49726 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49740 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49724 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49742 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49723 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49716 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49727
Source: unknown Network traffic detected: HTTP traffic on port 49714 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49726
Source: unknown Network traffic detected: HTTP traffic on port 49754 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49725
Source: unknown Network traffic detected: HTTP traffic on port 49735 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49724
Source: unknown Network traffic detected: HTTP traffic on port 49737 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49723
Source: unknown Network traffic detected: HTTP traffic on port 49739 -> 443
Source: unknown HTTPS traffic detected: 172.67.192.199:443 -> 192.168.2.3:49738 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.21.69.231:443 -> 192.168.2.3:49739 version: TLS 1.2
Source: unknown HTTPS traffic detected: 152.199.23.37:443 -> 192.168.2.3:49740 version: TLS 1.2
Source: unknown HTTPS traffic detected: 152.199.23.37:443 -> 192.168.2.3:49741 version: TLS 1.2
Source: unknown HTTPS traffic detected: 152.199.23.37:443 -> 192.168.2.3:49742 version: TLS 1.2
Source: unknown HTTPS traffic detected: 152.199.23.37:443 -> 192.168.2.3:49743 version: TLS 1.2
Source: classification engine Classification label: mal56.phis.win@34/214@11/11
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-606F496D-F28.pma Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Local\Temp\a98c1461-7371-4b8f-9438-8e4a0b6c4795.tmp Jump to behavior
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --start-maximized 'http://www.ztzusl.vibz.co.uk./#jrschnell.com.br/site/z1/bGFtQHNwYXJub3JkLmRr'
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1540,11347640063778282216,12771895532885012560,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1688 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1540,11347640063778282216,12771895532885012560,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1688 /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Automated click: agree
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Automated click: agree
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Automated click: agree
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Automated click: agree
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic Jump to behavior
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 383856 URL: http://www.ztzusl.vibz.co.u... Startdate: 08/04/2021 Architecture: WINDOWS Score: 56 13 cs1100.wpc.omegacdn.net 2->13 15 clipartkind.com 2->15 17 2 other IPs or domains 2->17 29 Yara detected HtmlPhish10 2->29 31 Phishing site detected (based on image similarity) 2->31 33 Phishing site detected (based on logo template match) 2->33 7 chrome.exe 14 501 2->7         started        signatures3 process4 dnsIp5 19 192.168.2.1 unknown unknown 7->19 21 239.255.255.250 unknown Reserved 7->21 10 chrome.exe 16 7->10         started        process6 dnsIp7 23 jrschnell.com.br 216.172.172.184, 443, 49714, 49715 UNIFIEDLAYER-AS-1US United States 10->23 25 www.ztzusl.vibz.co.uk 198.54.125.197, 49708, 49709, 80 NAMECHEAP-NETUS United States 10->25 27 10 other IPs or domains 10->27
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs

Contacted Public IPs

IP Domain Country Flag ASN ASN Name Malicious
104.21.69.231
clipartkind.com United States
13335 CLOUDFLARENETUS false
198.54.125.197
www.ztzusl.vibz.co.uk United States
22612 NAMECHEAP-NETUS false
216.172.172.184
jrschnell.com.br United States
46606 UNIFIEDLAYER-AS-1US false
239.255.255.250
unknown Reserved
unknown unknown false
172.217.168.33
googlehosted.l.googleusercontent.com United States
15169 GOOGLEUS false
172.67.192.199
cdn.clipart.email United States
13335 CLOUDFLARENETUS false
35.190.80.1
a.nel.cloudflare.com United States
15169 GOOGLEUS false
152.199.23.37
cs1100.wpc.omegacdn.net United States
15133 EDGECASTUS false

Private

IP
192.168.2.1
192.168.2.6
127.0.0.1

Contacted Domains

Name IP Active
cdn.clipart.email 172.67.192.199 true
clipartkind.com 104.21.69.231 true
a.nel.cloudflare.com 35.190.80.1 true
cs1100.wpc.omegacdn.net 152.199.23.37 true
www.ztzusl.vibz.co.uk 198.54.125.197 true
jrschnell.com.br 216.172.172.184 true
googlehosted.l.googleusercontent.com 172.217.168.33 true
clients2.googleusercontent.com unknown unknown
aadcdn.msftauth.net unknown unknown
aadcdn.msauth.net unknown unknown

Contacted URLs

Name Malicious Antivirus Detection Reputation
https://jrschnell.com.br/site/z1/y5t4SCIjdufwm3DlF0B6gHz9h7YcZW/ptmkYZg0csRd3hfLVODo/mf6H3wg59JYA4MiDNIy.php true
    unknown
    http://www.ztzusl.vibz.co.uk./ false
    • Avira URL Cloud: safe
    unknown