Analysis Report http://www.fema.gov/disasters/coronavirus/economic/funeral-assistance

Overview

General Information

Sample URL: http://www.fema.gov/disasters/coronavirus/economic/funeral-assistance
Analysis ID: 389168
Infos:

Most interesting Screenshot:

Detection

Score: 0
Range: 0 - 100
Whitelisted: false
Confidence: 80%

Signatures

No high impact signatures.

Classification

There are no high impact signatures.

Source: C:\Program Files (x86)\Internet Explorer\iexplore.exe File opened: C:\Program Files (x86)\Java\jre1.8.0_211\bin\msvcr100.dll Jump to behavior
Source: unknown HTTPS traffic detected: 13.32.25.62:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.32.25.62:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknown HTTPS traffic detected: 74.125.140.154:443 -> 192.168.2.4:49754 version: TLS 1.2
Source: unknown HTTPS traffic detected: 74.125.140.154:443 -> 192.168.2.4:49753 version: TLS 1.2
Source: unknown HTTPS traffic detected: 162.247.242.19:443 -> 192.168.2.4:49755 version: TLS 1.2
Source: unknown HTTPS traffic detected: 162.247.242.19:443 -> 192.168.2.4:49756 version: TLS 1.2
Source: unknown HTTPS traffic detected: 162.247.242.19:443 -> 192.168.2.4:49755 version: TLS 1.2
Source: unknown HTTPS traffic detected: 162.247.242.19:443 -> 192.168.2.4:49780 version: TLS 1.2
Source: unknown HTTPS traffic detected: 162.247.242.19:443 -> 192.168.2.4:49779 version: TLS 1.2
Source: funeral-assistance[1].htm2.2.dr String found in binary or memory: <a target="_blank" href="https://www.facebook.com/FEMA/?ref=bookmarks"><img src="/profiles/femad8_gov/themes/fema_uswds/images/social-icons/facebook_white.svg" alt="Facebook Logo" /></a> equals www.facebook.com (Facebook)
Source: funeral-assistance[1].htm2.2.dr String found in binary or memory: <a target="_blank" href="https://www.linkedin.com/company/fema/"><img src="/profiles/femad8_gov/themes/fema_uswds/images/social-icons/linkedin_white.svg" alt="LinkedIn Logo" /></a> equals www.linkedin.com (Linkedin)
Source: funeral-assistance[1].htm2.2.dr String found in binary or memory: <a target="_blank" href="https://www.youtube.com/fema"><img src="/profiles/femad8_gov/themes/fema_uswds/images/social-icons/youtube_white.svg" alt="YouTube Logo" /></a> equals www.youtube.com (Youtube)
Source: msapplication.xml0.1.dr String found in binary or memory: <browserconfig><msapplication><config><site src="http://www.facebook.com/"/><date>0x5b8cace6,0x01d732ae</date><accdate>0x5b8cace6,0x01d732ae</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig> equals www.facebook.com (Facebook)
Source: msapplication.xml0.1.dr String found in binary or memory: <browserconfig><msapplication><config><site src="http://www.facebook.com/"/><date>0x5b8cace6,0x01d732ae</date><accdate>0x5b8cace6,0x01d732ae</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Facebook.url"/></tile></msapplication></browserconfig> equals www.facebook.com (Facebook)
Source: msapplication.xml5.1.dr String found in binary or memory: <browserconfig><msapplication><config><site src="http://www.twitter.com/"/><date>0x5b93d414,0x01d732ae</date><accdate>0x5b93d414,0x01d732ae</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig> equals www.twitter.com (Twitter)
Source: msapplication.xml5.1.dr String found in binary or memory: <browserconfig><msapplication><config><site src="http://www.twitter.com/"/><date>0x5b93d414,0x01d732ae</date><accdate>0x5b93d414,0x01d732ae</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Twitter.url"/></tile></msapplication></browserconfig> equals www.twitter.com (Twitter)
Source: msapplication.xml7.1.dr String found in binary or memory: <browserconfig><msapplication><config><site src="http://www.youtube.com/"/><date>0x5b963661,0x01d732ae</date><accdate>0x5b963661,0x01d732ae</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig> equals www.youtube.com (Youtube)
Source: msapplication.xml7.1.dr String found in binary or memory: <browserconfig><msapplication><config><site src="http://www.youtube.com/"/><date>0x5b963661,0x01d732ae</date><accdate>0x5b9898aa,0x01d732ae</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Youtube.url"/></tile></msapplication></browserconfig> equals www.youtube.com (Youtube)
Source: funeral-assistance[1].htm.2.dr String found in binary or memory: <p><a href="https://www.youtube.com/watch?v=DgvN_9m58Z0">VIDEO: Providing Financial Assistance for COVID-19-Related Funeral Expenses</a></p> equals www.youtube.com (Youtube)
Source: funeral-assistance[1].htm0.2.dr String found in binary or memory: <p><a href="https://www.youtube.com/watch?v=NGaWq_Hg87I">Proporcionando asistencia econ equals www.youtube.com (Youtube)
Source: Universal-Federated-Analytics-Min[1].js.2.dr String found in binary or memory: if(oCONFIG.YOUTUBE){var videoArray_fed=[],playerArray_fed=[],_f33=!1,_f66=!1,_f90=!1,tag=document.createElement("script");tag.src="https://www.youtube.com/iframe_api";var firstScriptTag=document.getElementsByTagName("script")[0];firstScriptTag.parentNode.insertBefore(tag,firstScriptTag);var youtube_parser_fed=function(a){if((a=a.match(/^(https?:)?(\/\/)?(www\.)?(youtu\.be\/|youtube(\-nocookie)?\.([A-Za-z]{2,4}|[A-Za-z]{2,3}\.[A-Za-z]{2})\/)(watch|embed\/|vi?\/)?(\?vi?=)?([^#&\?\/]{11}).*$/))&&11=== equals www.youtube.com (Youtube)
Source: unknown DNS traffic detected: queries for: www.fema.gov
Source: json3.min[1].js.2.dr String found in binary or memory: http://bestiejs.github.io/json3
Source: datatables.min[1].js.2.dr String found in binary or memory: http://datatables.net/license
Source: datatables.min[1].js.2.dr String found in binary or memory: http://datatables.net/license/mit
Source: datatables.min[1].js.2.dr String found in binary or memory: http://datatables.net/tn/
Source: jquery.once.min[1].js.2.dr String found in binary or memory: http://github.com/robloach/jquery-once
Source: stacktable[1].js.2.dr String found in binary or memory: http://johnpolacek.github.com/stacktable.js
Source: effect-min[1].js.2.dr String found in binary or memory: http://jqueryui.com
Source: json3.min[1].js.2.dr String found in binary or memory: http://kit.mit-license.org
Source: jquery.once.min[1].js.2.dr String found in binary or memory: http://opensource.org/licenses/GPL-2.0
Source: jquery.once.min[1].js.2.dr String found in binary or memory: http://opensource.org/licenses/MIT
Source: wcm_survey[1].js.2.dr String found in binary or memory: http://stackoverflow.com/questions/2308134/trim-in-javascript-not-working-in-ie
Source: query_string.min[1].js.2.dr String found in binary or memory: http://w3.org/TR/2012/WD-url-20120524/#collect-url-parameters
Source: msapplication.xml.1.dr String found in binary or memory: http://www.amazon.com/
Source: datatables.min[1].js.2.dr String found in binary or memory: http://www.datatables.net
Source: msapplication.xml1.1.dr String found in binary or memory: http://www.google.com/
Source: jquery.colorbox-min[1].js.2.dr String found in binary or memory: http://www.jacklmoore.com/colorbox
Source: msapplication.xml2.1.dr String found in binary or memory: http://www.live.com/
Source: msapplication.xml3.1.dr String found in binary or memory: http://www.nytimes.com/
Source: msapplication.xml4.1.dr String found in binary or memory: http://www.reddit.com/
Source: msapplication.xml5.1.dr String found in binary or memory: http://www.twitter.com/
Source: msapplication.xml6.1.dr String found in binary or memory: http://www.wikipedia.com/
Source: msapplication.xml7.1.dr String found in binary or memory: http://www.youtube.com/
Source: gtm[1].js.2.dr String found in binary or memory: https://adservice.google.com/ddm/regclk
Source: gtm[1].js.2.dr String found in binary or memory: https://adservice.google.com/pagead/regclk
Source: analytics[1].js.2.dr String found in binary or memory: https://ampcid.google.com/v1/publisher:getClientId
Source: gtm[1].js.2.dr String found in binary or memory: https://cct.google/taggy/agent.js
Source: funeral-assistance[1].htm2.2.dr String found in binary or memory: https://dap.digitalgov.gov/Universal-Federated-Analytics-Min.js?agency=DHS&amp;subagency=FEMA&amp;pu
Source: datatables.min[1].js.2.dr String found in binary or memory: https://datatables.net/download
Source: datatables.min[1].js.2.dr String found in binary or memory: https://datatables.net/download/#dt/dt-1.10.20/af-2.3.4/sp-1.0.1
Source: datatables.min[1].js.2.dr String found in binary or memory: https://datatables.net/tn/11
Source: funeral-assistance[1].htm2.2.dr String found in binary or memory: https://dhs.gov
Source: funeral-assistance[1].htm.2.dr String found in binary or memory: https://edit.fema.gov/disasters/coronavirus/economic/funeral-assistance
Source: funeral-assistance[1].htm1.2.dr String found in binary or memory: https://edit.fema.gov/sites/default/files/documents/fema_policy_covid-19_funeral_assistance-updated.
Source: funeral-assistance[1].htm.2.dr String found in binary or memory: https://edit.fema.gov/tl/disasters/coronavirus/economic/funeral-assistance
Source: css_VNgLk2ESUyLAlwPrEIHYtOcUpYNm6tpdh_m6hGDFMzg[1].css.2.dr, css_0TyUDkYpGET7gQtMxzdX3_eiss7Sz8jKTVr_i5zSdPc[1].css.2.dr String found in binary or memory: https://fonts.googleapis.com/css?family=Poppins:300
Source: css[2].css.2.dr String found in binary or memory: https://fonts.gstatic.com/s/merriweather/v22/u-440qyriQwlOrhSvowK_l5-fCZK.woff)
Source: css[2].css.2.dr String found in binary or memory: https://fonts.gstatic.com/s/merriweather/v22/u-4n0qyriQwlOrhSvowK_l52xwNZWMf8.woff)
Source: css[1].css.2.dr String found in binary or memory: https://fonts.gstatic.com/s/poppins/v15/pxiByp8kv8JHgFVrLCz7Z1xlEw.woff)
Source: css[1].css.2.dr String found in binary or memory: https://fonts.gstatic.com/s/poppins/v15/pxiByp8kv8JHgFVrLDz8Z1xlEw.woff)
Source: css[1].css.2.dr String found in binary or memory: https://fonts.gstatic.com/s/poppins/v15/pxiByp8kv8JHgFVrLEj6Z1xlEw.woff)
Source: css[1].css.2.dr String found in binary or memory: https://fonts.gstatic.com/s/poppins/v15/pxiByp8kv8JHgFVrLGT9Z1xlEw.woff)
Source: css[1].css.2.dr String found in binary or memory: https://fonts.gstatic.com/s/poppins/v15/pxiEyp8kv8JHgFVrJJfedA.woff)
Source: css[2].css.2.dr String found in binary or memory: https://fonts.gstatic.com/s/sourcesanspro/v14/6xK3dSBYKcSV-LCoeQqfX1RYOo3qOK7j.woff)
Source: css[2].css.2.dr String found in binary or memory: https://fonts.gstatic.com/s/sourcesanspro/v14/6xKydSBYKcSV-LCoeQqfX1RYOo3i54rwlxdo.woff)
Source: css[2].css.2.dr String found in binary or memory: https://fonts.gstatic.com/s/sourcesanspro/v14/6xKydSBYKcSV-LCoeQqfX1RYOo3i94_wlxdo.woff)
Source: css[2].css.2.dr String found in binary or memory: https://fonts.gstatic.com/s/sourcesanspro/v14/6xKydSBYKcSV-LCoeQqfX1RYOo3ig4vwlxdo.woff)
Source: jquery.cookie[1].js.2.dr String found in binary or memory: https://github.com/carhartl/jquery-cookie
Source: chosen.jquery.min[1].js.2.dr String found in binary or memory: https://github.com/harvesthq/chosen/blob/master/LICENSE.md
Source: chosen[1].js.2.dr String found in binary or memory: https://github.com/harvesthq/chosen/issues/515
Source: chosen[1].js.2.dr String found in binary or memory: https://github.com/harvesthq/chosen/issues/515#issuecomment-104602031
Source: chosen[1].js.2.dr String found in binary or memory: https://github.com/harvesthq/chosen/issues/515#issuecomment-33214050
Source: stacktable[1].js.2.dr String found in binary or memory: https://github.com/johnpolacek/stacktable.js/
Source: google_analytics[1].js.2.dr String found in binary or memory: https://mydomain.com/node/1
Source: gtm[1].js.2.dr String found in binary or memory: https://pagead2.googlesyndication.com
Source: fema_search[1].js.2.dr String found in binary or memory: https://search.usa.gov/search
Source: analytics[1].js.2.dr String found in binary or memory: https://stats.g.doubleclick.net/j/collect
Source: analytics[1].js.2.dr String found in binary or memory: https://tagassistant.google.com/
Source: funeral-assistance[1].htm2.2.dr String found in binary or memory: https://twitter.com/fema
Source: funeral-assistance[1].htm2.2.dr String found in binary or memory: https://usa.gov
Source: SQ22SSVH.htm.2.dr, coronavirus[1].htm.2.dr String found in binary or memory: https://www.cdc.gov/coronavirus/2019-ncov/index.html
Source: funeral-assistance[1].htm2.2.dr String found in binary or memory: https://www.disasterassistance.gov/
Source: funeral-assistance[1].htm2.2.dr String found in binary or memory: https://www.drupal.org)
Source: drupalSettingsLoader[1].js.2.dr String found in binary or memory: https://www.drupal.org/node/2815083
Source: {7139B2C1-9EA1-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.fema.
Source: {7139B2C1-9EA1-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.fema.Root
Source: ~DF8C0B9062984F8D35.TMP.1.dr String found in binary or memory: https://www.fema.gov/
Source: funeral-assistance[1].htm2.2.dr String found in binary or memory: https://www.fema.gov/about/newsletters
Source: funeral-assistance[1].htm2.2.dr String found in binary or memory: https://www.fema.gov/ar/disasters/coronavirus/economic/funeral-assistance
Source: funeral-assistance[1].htm2.2.dr String found in binary or memory: https://www.fema.gov/bn/disasters/coronavirus/economic/funeral-assistance
Source: {7139B2C1-9EA1-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.fema.gov/d
Source: ~DF8C0B9062984F8D35.TMP.1.dr String found in binary or memory: https://www.fema.gov/disaster-responses
Source: ~DF8C0B9062984F8D35.TMP.1.dr String found in binary or memory: https://www.fema.gov/disaster-responsesJCurrent
Source: ~DF8C0B9062984F8D35.TMP.1.dr String found in binary or memory: https://www.fema.gov/disaster-responsesad8_gov/themes/fema_uswds/images/favicon.ico
Source: ~DF8C0B9062984F8D35.TMP.1.dr String found in binary or memory: https://www.fema.gov/disaster-responsesvirus/economic/funeral-assistance
Source: {7139B2C1-9EA1-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.fema.gov/disasters/corRoot
Source: coronavirus[1].htm.2.dr String found in binary or memory: https://www.fema.gov/disasters/coronavirus
Source: funeral-assistance[1].htm.2.dr, {7139B2C1-9EA1-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.fema.gov/disasters/coronavirus/economic/funeral-assistance
Source: ~DF8C0B9062984F8D35.TMP.1.dr String found in binary or memory: https://www.fema.gov/disasters/coronavirus/economic/funeral-assistance#main-content
Source: ~DF8C0B9062984F8D35.TMP.1.dr String found in binary or memory: https://www.fema.gov/disasters/coronavirus/economic/funeral-assistance(
Source: funeral-assistance[1].htm2.2.dr, funeral-assistance[3].htm.2.dr, funeral-assistance[1].htm.2.dr, funeral-assistance[1].htm1.2.dr String found in binary or memory: https://www.fema.gov/disasters/coronavirus/economic/funeral-assistance/faq
Source: funeral-assistance[1].htm.2.dr String found in binary or memory: https://www.fema.gov/disasters/coronavirus/economic/funeral-assistance/faq#scams
Source: ~DF8C0B9062984F8D35.TMP.1.dr String found in binary or memory: https://www.fema.gov/disasters/coronavirus/economic/funeral-assistanceLCOVID-19
Source: {7139B2C1-9EA1-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.fema.gov/disasters/coronavirus/economic/funeral-assistanceRoot
Source: ~DF8C0B9062984F8D35.TMP.1.dr String found in binary or memory: https://www.fema.gov/disasters/coronavirus/economic/funeral-assistanceeance
Source: ~DF8C0B9062984F8D35.TMP.1.dr String found in binary or memory: https://www.fema.gov/disasters/coronavirus/economic/funeral-assistanceeancece
Source: ~DF8C0B9062984F8D35.TMP.1.dr String found in binary or memory: https://www.fema.gov/disasters/coronavirusTCoronavirus
Source: ~DF8C0B9062984F8D35.TMP.1.dr String found in binary or memory: https://www.fema.gov/disasters/coronavirusemad8_gov/themes/fema_uswds/images/favicon.ico
Source: ~DF8C0B9062984F8D35.TMP.1.dr String found in binary or memory: https://www.fema.gov/disasters/coronavirusv
Source: {7139B2C1-9EA1-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.fema.gov/e
Source: disaster-responses[1].htm.2.dr String found in binary or memory: https://www.fema.gov/es/disaster-responses
Source: coronavirus[1].htm.2.dr String found in binary or memory: https://www.fema.gov/es/disasters/coronavirus
Source: funeral-assistance[1].htm0.2.dr String found in binary or memory: https://www.fema.gov/es/disasters/coronavirus/economic/funeral-assistance/faq
Source: funeral-assistance[1].htm0.2.dr String found in binary or memory: https://www.fema.gov/es/disasters/coronavirus/economic/funeral-assistance/faq#scams
Source: funeral-assistance[1].htm0.2.dr String found in binary or memory: https://www.fema.gov/es/disasters/coronavirus/funeral-assistance
Source: ~DF8C0B9062984F8D35.TMP.1.dr String found in binary or memory: https://www.fema.gov/es/disasters/coronavirus/funeral-assistanceance#main-content
Source: ~DF8C0B9062984F8D35.TMP.1.dr String found in binary or memory: https://www.fema.gov/es/disasters/coronavirus/funeral-assistanceance#main-contents://www.fema.gov/di
Source: ~DF8C0B9062984F8D35.TMP.1.dr String found in binary or memory: https://www.fema.gov/es/disasters/coronavirus/funeral-assistancenAsistencia
Source: funeral-assistance[1].htm0.2.dr String found in binary or memory: https://www.fema.gov/es/node/613038
Source: {7139B2C1-9EA1-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.fema.gov/f
Source: {7139B2C1-9EA1-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.fema.gov/fRoot
Source: funeral-assistance[2].htm0.2.dr String found in binary or memory: https://www.fema.gov/fr/disasters/coronavirus/economic/funeral-assistance
Source: ~DF8C0B9062984F8D35.TMP.1.dr String found in binary or memory: https://www.fema.gov/fr/disasters/coronavirus/economic/funeral-assistanceTCOVID-19
Source: ~DF8C0B9062984F8D35.TMP.1.dr String found in binary or memory: https://www.fema.gov/fr/disasters/coronavirus/economic/funeral-assistanceance
Source: funeral-assistance[2].htm0.2.dr String found in binary or memory: https://www.fema.gov/fr/node/613038
Source: {7139B2C1-9EA1-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.fema.gov/h
Source: funeral-assistance[1].htm2.2.dr String found in binary or memory: https://www.fema.gov/hi/disasters/coronavirus/economic/funeral-assistance
Source: ~DF8C0B9062984F8D35.TMP.1.dr String found in binary or memory: https://www.fema.gov/ht/disasters/coronavirus/economic/funeral-assistance
Source: ~DF8C0B9062984F8D35.TMP.1.dr String found in binary or memory: https://www.fema.gov/ht/disasters/coronavirus/economic/funeral-assistanceFAsistans
Source: funeral-assistance[1].htm2.2.dr String found in binary or memory: https://www.fema.gov/ht/node/613038
Source: {7139B2C1-9EA1-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.fema.gov/k
Source: ~DF8C0B9062984F8D35.TMP.1.dr String found in binary or memory: https://www.fema.gov/ko/disasters/coronavirus/economic/funeral-assistance
Source: {7139B2C1-9EA1-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.fema.gov/ko/disasters/coronavirus/economic/funeral-assistance2COV
Source: ~DF8C0B9062984F8D35.TMP.1.dr String found in binary or memory: https://www.fema.gov/ko/disasters/coronavirus/economic/funeral-assistance2COVID-19
Source: funeral-assistance[3].htm.2.dr String found in binary or memory: https://www.fema.gov/ko/node/613038
Source: coronavirus[1].htm.2.dr String found in binary or memory: https://www.fema.gov/node/481051
Source: disaster-responses[1].htm.2.dr String found in binary or memory: https://www.fema.gov/node/575622
Source: funeral-assistance[1].htm.2.dr String found in binary or memory: https://www.fema.gov/node/613038
Source: ~DF8C0B9062984F8D35.TMP.1.dr String found in binary or memory: https://www.fema.gov/o/disasters/coronavirus/economic/funeral-assistance
Source: imagestore.dat.2.dr String found in binary or memory: https://www.fema.gov/profiles/femad8_gov/themes/fema_uswds/images/favicon.ico~
Source: funeral-assistance[1].htm2.2.dr String found in binary or memory: https://www.fema.gov/pt-br/disasters/coronavirus/economic/funeral-assistance
Source: funeral-assistance[1].htm2.2.dr String found in binary or memory: https://www.fema.gov/ru/disasters/coronavirus/economic/funeral-assistance
Source: coronavirus[1].htm.2.dr String found in binary or memory: https://www.fema.gov/sites/default/files/2020-07/illustration_hero_disasters_corona_2.png
Source: funeral-assistance[1].htm2.2.dr String found in binary or memory: https://www.fema.gov/sites/default/files/email_white.svg
Source: funeral-assistance[1].htm2.2.dr String found in binary or memory: https://www.fema.gov/tl/disasters/coronavirus/economic/funeral-assistance
Source: {7139B2C1-9EA1-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.fema.gov/v
Source: funeral-assistance[2].htm.2.dr String found in binary or memory: https://www.fema.gov/vi/disasters/coronavirus/economic/funeral-assistance
Source: ~DF8C0B9062984F8D35.TMP.1.dr String found in binary or memory: https://www.fema.gov/vi/disasters/coronavirus/economic/funeral-assistanceDH
Source: ~DF8C0B9062984F8D35.TMP.1.dr String found in binary or memory: https://www.fema.gov/vi/disasters/coronavirus/economic/funeral-assistanceance
Source: funeral-assistance[2].htm.2.dr String found in binary or memory: https://www.fema.gov/vi/node/613038
Source: {7139B2C1-9EA1-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.fema.gov/z
Source: {7139B2C1-9EA1-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.fema.gov/zh-hans/disasters/coronavirus/eRoot
Source: funeral-assistance[1].htm1.2.dr, {7139B2C1-9EA1-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.fema.gov/zh-hans/disasters/coronavirus/economic/funeral-assistance
Source: ~DF8C0B9062984F8D35.TMP.1.dr String found in binary or memory: https://www.fema.gov/zh-hans/disasters/coronavirus/economic/funeral-assistance0COVID-19
Source: ~DF8C0B9062984F8D35.TMP.1.dr String found in binary or memory: https://www.fema.gov/zh-hans/disasters/coronavirus/economic/funeral-assistanceent
Source: funeral-assistance[1].htm1.2.dr String found in binary or memory: https://www.fema.gov/zh-hans/node/613038
Source: {7139B2C1-9EA1-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.fema.h-hans/disasters/coronavirus/economic/funeral-assistanceRoot
Source: {7139B2C1-9EA1-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.fema.i/disasters/coronavirus/economic/funeral-assistanceanceRoot
Source: {7139B2C1-9EA1-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.fema.isaster-responsesRoot
Source: {7139B2C1-9EA1-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.fema.isasters/coronavirus/economic/funeral-assistance#main-contentRoot
Source: {7139B2C1-9EA1-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.fema.isasters/coronavirus/economic/funeral-assistanceeanceRoot
Source: {7139B2C1-9EA1-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.fema.isasters/coronavirusRoot
Source: {7139B2C1-9EA1-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.fema.o/disasters/coronavirus/economic/funeral-assistanceRoot
Source: {7139B2C1-9EA1-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.fema.r/disasters/coronavirus/economic/funeral-assistanceRoot
Source: {7139B2C1-9EA1-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.fema.s/disasters/coronavirus/funeral-assistanceance#main-contentRoot
Source: {7139B2C1-9EA1-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.fema.t/disasters/coronavirus/economic/funeral-assistanceRoot
Source: {7139B2C1-9EA1-11EB-90EB-ECF4BBEA1588}.dat.1.dr String found in binary or memory: https://www.fema.ttps://www.fema.gov/
Source: funeral-assistance[1].htm2.2.dr String found in binary or memory: https://www.floodsmart.gov/
Source: funeral-assistance[1].htm2.2.dr, Universal-Federated-Analytics-Min[1].js.2.dr String found in binary or memory: https://www.google-analytics.com/analytics.js
Source: analytics[1].js.2.dr String found in binary or memory: https://www.google-analytics.com/debug/bootstrap
Source: analytics[1].js.2.dr String found in binary or memory: https://www.google-analytics.com/gtm/js?id=
Source: analytics[1].js.2.dr String found in binary or memory: https://www.google.%/ads/ga-audiences
Source: gtm[1].js.2.dr String found in binary or memory: https://www.google.com
Source: gtm[1].js.2.dr String found in binary or memory: https://www.googletagmanager.com/debug/bootstrap
Source: analytics[1].js.2.dr String found in binary or memory: https://www.googletagmanager.com/gtag/js?id=
Source: funeral-assistance[1].htm2.2.dr String found in binary or memory: https://www.googletagmanager.com/gtm.js?id=
Source: funeral-assistance[1].htm2.2.dr String found in binary or memory: https://www.googletagmanager.com/ns.html?id=GTM-PNFPGG3
Source: funeral-assistance[1].htm2.2.dr String found in binary or memory: https://www.instagram.com/fema
Source: funeral-assistance[1].htm2.2.dr String found in binary or memory: https://www.linkedin.com/company/fema/
Source: funeral-assistance[1].htm2.2.dr, funeral-assistance[3].htm.2.dr, disaster-responses[1].htm.2.dr, funeral-assistance[2].htm.2.dr String found in binary or memory: https://www.oig.dhs.gov/
Source: funeral-assistance[1].htm2.2.dr String found in binary or memory: https://www.ready.gov/
Source: funeral-assistance[1].htm2.2.dr String found in binary or memory: https://www.ready.gov/cert
Source: funeral-assistance[1].htm2.2.dr String found in binary or memory: https://www.ready.gov/preparedness-research
Source: funeral-assistance[1].htm2.2.dr String found in binary or memory: https://www.youtube.com/fema
Source: Universal-Federated-Analytics-Min[1].js.2.dr String found in binary or memory: https://www.youtube.com/iframe_api
Source: funeral-assistance[1].htm.2.dr String found in binary or memory: https://www.youtube.com/watch?v=DgvN_9m58Z0
Source: funeral-assistance[1].htm0.2.dr String found in binary or memory: https://www.youtube.com/watch?v=NGaWq_Hg87I
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49755
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49754
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49742
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49753
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49741
Source: unknown Network traffic detected: HTTP traffic on port 49779 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49780
Source: unknown Network traffic detected: HTTP traffic on port 49741 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49742 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49780 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49754 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49753 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49779
Source: unknown Network traffic detected: HTTP traffic on port 49756 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49755 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49756
Source: unknown HTTPS traffic detected: 13.32.25.62:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.32.25.62:443 -> 192.168.2.4:49742 version: TLS 1.2
Source: unknown HTTPS traffic detected: 74.125.140.154:443 -> 192.168.2.4:49754 version: TLS 1.2
Source: unknown HTTPS traffic detected: 74.125.140.154:443 -> 192.168.2.4:49753 version: TLS 1.2
Source: unknown HTTPS traffic detected: 162.247.242.19:443 -> 192.168.2.4:49755 version: TLS 1.2
Source: unknown HTTPS traffic detected: 162.247.242.19:443 -> 192.168.2.4:49756 version: TLS 1.2
Source: unknown HTTPS traffic detected: 162.247.242.19:443 -> 192.168.2.4:49755 version: TLS 1.2
Source: unknown HTTPS traffic detected: 162.247.242.19:443 -> 192.168.2.4:49780 version: TLS 1.2
Source: unknown HTTPS traffic detected: 162.247.242.19:443 -> 192.168.2.4:49779 version: TLS 1.2
Source: classification engine Classification label: clean0.win@3/159@7/3
Source: C:\Program Files\internet explorer\iexplore.exe File created: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{7139B2BF-9EA1-11EB-90EB-ECF4BBEA1588}.dat Jump to behavior
Source: C:\Program Files\internet explorer\iexplore.exe File created: C:\Users\user\AppData\Local\Temp\~DFEF6F7E374662853A.TMP Jump to behavior
Source: C:\Program Files\internet explorer\iexplore.exe File read: C:\Users\desktop.ini Jump to behavior
Source: unknown Process created: C:\Program Files\internet explorer\iexplore.exe 'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding
Source: C:\Program Files\internet explorer\iexplore.exe Process created: C:\Program Files (x86)\Internet Explorer\iexplore.exe 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:5964 CREDAT:17410 /prefetch:2
Source: C:\Program Files\internet explorer\iexplore.exe Process created: C:\Program Files (x86)\Internet Explorer\iexplore.exe 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:5964 CREDAT:17410 /prefetch:2 Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Internet Explorer\iexplore.exe File opened: C:\Program Files (x86)\Java\jre1.8.0_211\bin\msvcr100.dll Jump to behavior
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 389168 URL: http://www.fema.gov/disaste... Startdate: 16/04/2021 Architecture: WINDOWS Score: 0 11 www.fema.gov 2->11 6 iexplore.exe 2 80 2->6         started        process3 process4 8 iexplore.exe 2 195 6->8         started        dnsIp5 13 bam.nr-data.net 162.247.242.19, 443, 49755, 49756 NEWRELIC-AS-1US United States 8->13 15 stats.l.doubleclick.net 74.125.140.154, 443, 49753, 49754 GOOGLEUS United States 8->15 17 6 other IPs or domains 8->17
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs

Contacted Public IPs

IP Domain Country Flag ASN ASN Name Malicious
74.125.140.154
stats.l.doubleclick.net United States
15169 GOOGLEUS false
162.247.242.19
bam.nr-data.net United States
23467 NEWRELIC-AS-1US false
13.32.25.62
d27f3qgc9anoq2.cloudfront.net United States
7018 ATT-INTERNET4US false

Contacted Domains

Name IP Active
www.google.de 172.217.19.99 true
stats.l.doubleclick.net 74.125.140.154 true
d27f3qgc9anoq2.cloudfront.net 13.32.25.62 true
bam.nr-data.net 162.247.242.19 true
dap.digitalgov.gov unknown unknown
www.fema.gov unknown unknown
js-agent.newrelic.com unknown unknown
stats.g.doubleclick.net unknown unknown

Contacted URLs

Name Malicious Antivirus Detection Reputation
https://www.fema.gov/disasters/coronavirus false
    high
    https://www.fema.gov/disasters/coronavirus/economic/funeral-assistance#main-content false
      high
      https://www.fema.gov/ko/disasters/coronavirus/economic/funeral-assistance false
        high
        https://www.fema.gov/fr/disasters/coronavirus/economic/funeral-assistance false
          high
          https://www.fema.gov/es/disasters/coronavirus/funeral-assistance false
            high
            https://www.fema.gov/ht/disasters/coronavirus/economic/funeral-assistance false
              high
              https://www.fema.gov/disasters/coronavirus/economic/funeral-assistance false
                high
                https://www.fema.gov/vi/disasters/coronavirus/economic/funeral-assistance false
                  high