Windows Analysis Report https://alloverhaulage-my.sharepoint.com/:u:/g/personal/office_nlls_com_au/Ebi3MkfuJ2pLrppTTXXF_10ByRNMkVVs2ifkr322sjryVQ?download=1

Overview

General Information

Sample URL: https://alloverhaulage-my.sharepoint.com/:u:/g/personal/office_nlls_com_au/Ebi3MkfuJ2pLrppTTXXF_10ByRNMkVVs2ifkr322sjryVQ?download=1
Analysis ID: 491037
Infos:

Most interesting Screenshot:

Detection

HTMLPhisher
Score: 60
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Yara detected HtmlPhish10
Antivirus detection for URL or domain
Phishing site detected (based on logo template match)
Queries the volume information (name, serial number etc) of a device
Invalid 'forgot password' link found
Uses code obfuscation techniques (call, push, ret)
No HTML title found
HTML body contains low number of good links
Sigma detected: Windows PowerShell Web Request

Classification

AV Detection:

barindex
Antivirus detection for URL or domain
Source: https://bucket-api.restoreniaer.au-syd1.upcloudobjects.com/regooop.html SlashNext: Label: Fake Login Page type: Phishing & Social Engineering

Phishing:

barindex
Yara detected HtmlPhish10
Source: Yara match File source: 89955.0.pages.csv, type: HTML
Phishing site detected (based on logo template match)
Source: https://bucket-api.restoreniaer.au-syd1.upcloudobjects.com/regooop.html Matcher: Template: microsoft matched
Invalid 'forgot password' link found
Source: https://bucket-api.restoreniaer.au-syd1.upcloudobjects.com/regooop.html HTTP Parser: Invalid link: Forgot Password?
Source: https://bucket-api.restoreniaer.au-syd1.upcloudobjects.com/regooop.html HTTP Parser: Invalid link: Forgot Password?
No HTML title found
Source: https://bucket-api.restoreniaer.au-syd1.upcloudobjects.com/regooop.html HTTP Parser: HTML title missing
Source: https://bucket-api.restoreniaer.au-syd1.upcloudobjects.com/regooop.html HTTP Parser: HTML title missing
HTML body contains low number of good links
Source: https://bucket-api.restoreniaer.au-syd1.upcloudobjects.com/regooop.html HTTP Parser: Number of links: 0
Source: https://bucket-api.restoreniaer.au-syd1.upcloudobjects.com/regooop.html HTTP Parser: Number of links: 0
Source: https://bucket-api.restoreniaer.au-syd1.upcloudobjects.com/regooop.html HTTP Parser: No <meta name="author".. found
Source: https://bucket-api.restoreniaer.au-syd1.upcloudobjects.com/regooop.html HTTP Parser: No <meta name="author".. found
Source: https://bucket-api.restoreniaer.au-syd1.upcloudobjects.com/regooop.html HTTP Parser: No <meta name="copyright".. found
Source: https://bucket-api.restoreniaer.au-syd1.upcloudobjects.com/regooop.html HTTP Parser: No <meta name="copyright".. found
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic Jump to behavior
Source: unknown Network traffic detected: HTTP traffic on port 49733 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49733
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49744
Source: unknown Network traffic detected: HTTP traffic on port 49734 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49752
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49750
Source: unknown Network traffic detected: HTTP traffic on port 49748 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49749 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49746 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49747 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49744 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49752 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49750 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49749
Source: unknown Network traffic detected: HTTP traffic on port 49736 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49737
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49748
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49736
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49747
Source: unknown Network traffic detected: HTTP traffic on port 49737 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49746
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49734
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Mon, 27 Sep 2021 03:21:52 GMTContent-Type: application/xmlContent-Length: 334Connection: closeAccept-Ranges: bytesContent-Security-Policy: block-all-mixed-contentStrict-Transport-Security: max-age=31536000; includeSubDomainsVary: OriginX-Amz-Bucket-Region: au-syd1X-Amz-Request-Id: 16A88FBE60744176X-Content-Type-Options: nosniffX-Frame-Options: denyX-Xss-Protection: 1; mode=blockStrict-Transport-Security: max-age=31536000; includeSubDomains
Source: wget.exe, 00000003.00000003.236282290.0000000002C24000.00000004.00000001.sdmp String found in binary or memory: http://crl.globalsign.net/root-r2.crl
Source: wget.exe, 00000003.00000003.236282290.0000000002C24000.00000004.00000001.sdmp String found in binary or memory: http://crl.globalsign.net/root-r2.crl0
Source: Reporting and NEL.7.dr String found in binary or memory: https://a.nel.cloudflare.com/report/v3?s=WlMrcP45svZ2rr816UnTkC37FyCSEZc4Mf6EZNvdHe1ZjWMBEVfZ4%2BsV3
Source: 8b112260-365b-4180-a7f6-5f35840517ad.tmp.7.dr, manifest.json0.6.dr, f2ddcea8-52be-4aea-b5a6-4cdaa631bff3.tmp.7.dr String found in binary or memory: https://accounts.google.com
Source: 8b112260-365b-4180-a7f6-5f35840517ad.tmp.7.dr String found in binary or memory: https://ajax.googleapis.com
Source: 28a003971055812a_0.6.dr String found in binary or memory: https://ajax.googleapis.com/ajax/libs/jquery/2.2.4/jquery.min.js
Source: wget.exe, 00000003.00000002.236627515.00000000012C0000.00000004.00000040.sdmp, wget.exe, 00000003.00000002.236631549.00000000012C6000.00000004.00000040.sdmp, cmdline.out.3.dr String found in binary or memory: https://alloverhaulage-my.sharepoint.com/:u:/g/personal/office_nlls_com_au/Ebi3MkfuJ2pLrppTTXXF_10By
Source: wget.exe, 00000003.00000003.236314962.0000000002C75000.00000004.00000001.sdmp, wget.exe, 00000003.00000003.236266685.0000000002C6A000.00000004.00000001.sdmp, cmdline.out.3.dr String found in binary or memory: https://alloverhaulage-my.sharepoint.com/personal/office_nlls_com_au/Documents/PAYMENT-PROCESSING%20
Source: 8b112260-365b-4180-a7f6-5f35840517ad.tmp.7.dr, manifest.json0.6.dr, f2ddcea8-52be-4aea-b5a6-4cdaa631bff3.tmp.7.dr String found in binary or memory: https://apis.google.com
Source: Current Session.6.dr, PAYMENT-PROCESSING FILE.html.3.dr String found in binary or memory: https://bucket-api.restoreniaer.au-syd1.upcloudobjects.com/regooop.html
Source: History.6.dr String found in binary or memory: https://bucket-api.restoreniaer.au-syd1.upcloudobjects.com/regooop.htmlOffice
Source: 9bb83c42521feb47_0.6.dr String found in binary or memory: https://cdnjs.cloudflare.com/ajax/libs/popper.js/1.12.9/umd/popper.min.js
Source: 8b112260-365b-4180-a7f6-5f35840517ad.tmp.7.dr, f2ddcea8-52be-4aea-b5a6-4cdaa631bff3.tmp.7.dr String found in binary or memory: https://clients2.google.com
Source: manifest.json0.6.dr String found in binary or memory: https://clients2.google.com/service/update2/crx
Source: 8b112260-365b-4180-a7f6-5f35840517ad.tmp.7.dr, f2ddcea8-52be-4aea-b5a6-4cdaa631bff3.tmp.7.dr String found in binary or memory: https://clients2.googleusercontent.com
Source: e5508e1875f34ee1_0.6.dr String found in binary or memory: https://code.jquery.com/jquery-3.2.1.slim.min.js
Source: 8b112260-365b-4180-a7f6-5f35840517ad.tmp.7.dr String found in binary or memory: https://content-autofill.googleapis.com
Source: manifest.json0.6.dr String found in binary or memory: https://content.googleapis.com
Source: Reporting and NEL.7.dr String found in binary or memory: https://csp.withgoogle.com/csp/report-to/hosted-libraries-pushers
Source: 8b112260-365b-4180-a7f6-5f35840517ad.tmp.7.dr, 4266caff-4fff-44b5-a35f-e8f8c4ebc865.tmp.7.dr, d5e46756-d7e7-4391-82ea-d60701e74801.tmp.7.dr, f2ddcea8-52be-4aea-b5a6-4cdaa631bff3.tmp.7.dr String found in binary or memory: https://dns.google
Source: manifest.json0.6.dr String found in binary or memory: https://feedback.googleusercontent.com
Source: 8b112260-365b-4180-a7f6-5f35840517ad.tmp.7.dr, f2ddcea8-52be-4aea-b5a6-4cdaa631bff3.tmp.7.dr String found in binary or memory: https://fonts.googleapis.com
Source: manifest.json0.6.dr String found in binary or memory: https://fonts.googleapis.com;
Source: 8b112260-365b-4180-a7f6-5f35840517ad.tmp.7.dr, f2ddcea8-52be-4aea-b5a6-4cdaa631bff3.tmp.7.dr String found in binary or memory: https://fonts.gstatic.com
Source: manifest.json0.6.dr String found in binary or memory: https://fonts.gstatic.com;
Source: manifest.json0.6.dr String found in binary or memory: https://hangouts.google.com/
Source: 2594a7bff7c32443_0.6.dr String found in binary or memory: https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/js/bootstrap.min.js
Source: 8b112260-365b-4180-a7f6-5f35840517ad.tmp.7.dr, f2ddcea8-52be-4aea-b5a6-4cdaa631bff3.tmp.7.dr String found in binary or memory: https://ogs.google.com
Source: manifest.json.6.dr String found in binary or memory: https://payments.google.com/payments/v4/js/integrator.js
Source: 8b112260-365b-4180-a7f6-5f35840517ad.tmp.7.dr String found in binary or memory: https://r5---sn-1gieen7e.gvt1.com
Source: 8b112260-365b-4180-a7f6-5f35840517ad.tmp.7.dr String found in binary or memory: https://redirector.gvt1.com
Source: manifest.json.6.dr String found in binary or memory: https://sandbox.google.com/payments/v4/js/integrator.js
Source: wget.exe, 00000003.00000003.236314962.0000000002C75000.00000004.00000001.sdmp String found in binary or memory: https://spo.nel.measure.office.net/api/report?tenantId=41b7aef6-4ea4-4ad7-b4ec-55715d2e26e3&destinat
Source: 8b112260-365b-4180-a7f6-5f35840517ad.tmp.7.dr, f2ddcea8-52be-4aea-b5a6-4cdaa631bff3.tmp.7.dr String found in binary or memory: https://ssl.gstatic.com
Source: 54b72c159e367103_0.6.dr String found in binary or memory: https://stackpath.bootstrapcdn.com/bootstrap/4.1.3/js/bootstrap.min.js
Source: messages.json72.6.dr String found in binary or memory: https://support.google.com/chromecast/answer/2998456
Source: messages.json72.6.dr String found in binary or memory: https://support.google.com/chromecast/troubleshooter/2995236
Source: 9bb83c42521feb47_0.6.dr String found in binary or memory: https://upcloudobjects.com/
Source: 54b72c159e367103_0.6.dr String found in binary or memory: https://upcloudobjects.com/Q
Source: e5508e1875f34ee1_0.6.dr String found in binary or memory: https://upcloudobjects.com/W
Source: 8b112260-365b-4180-a7f6-5f35840517ad.tmp.7.dr, manifest.json0.6.dr, f2ddcea8-52be-4aea-b5a6-4cdaa631bff3.tmp.7.dr String found in binary or memory: https://www.google.com
Source: manifest.json.6.dr String found in binary or memory: https://www.google.com/
Source: manifest.json0.6.dr String found in binary or memory: https://www.google.com;
Source: 8b112260-365b-4180-a7f6-5f35840517ad.tmp.7.dr, f2ddcea8-52be-4aea-b5a6-4cdaa631bff3.tmp.7.dr String found in binary or memory: https://www.googleapis.com
Source: manifest.json.6.dr String found in binary or memory: https://www.googleapis.com/
Source: manifest.json0.6.dr String found in binary or memory: https://www.googleapis.com/auth/calendar.readonly
Source: manifest.json0.6.dr String found in binary or memory: https://www.googleapis.com/auth/cast-edu-messaging
Source: manifest.json.6.dr String found in binary or memory: https://www.googleapis.com/auth/chromewebstore
Source: manifest.json.6.dr String found in binary or memory: https://www.googleapis.com/auth/chromewebstore.readonly
Source: manifest.json0.6.dr String found in binary or memory: https://www.googleapis.com/auth/clouddevices
Source: manifest.json0.6.dr String found in binary or memory: https://www.googleapis.com/auth/hangouts
Source: manifest.json0.6.dr String found in binary or memory: https://www.googleapis.com/auth/hangouts.readonly
Source: manifest.json0.6.dr String found in binary or memory: https://www.googleapis.com/auth/meetings
Source: manifest.json0.6.dr String found in binary or memory: https://www.googleapis.com/auth/plus.peopleapi.readwrite
Source: manifest.json.6.dr String found in binary or memory: https://www.googleapis.com/auth/sierra
Source: manifest.json.6.dr String found in binary or memory: https://www.googleapis.com/auth/sierrasandbox
Source: manifest.json0.6.dr String found in binary or memory: https://www.googleapis.com/auth/userinfo.email
Source: 8b112260-365b-4180-a7f6-5f35840517ad.tmp.7.dr, f2ddcea8-52be-4aea-b5a6-4cdaa631bff3.tmp.7.dr String found in binary or memory: https://www.gstatic.com
Source: manifest.json0.6.dr String found in binary or memory: https://www.gstatic.com;
Source: unknown HTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: unknown DNS traffic detected: queries for: alloverhaulage-my.sharepoint.com
Source: global traffic HTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=85.0.4183.121&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1&x=id%3Dpkedcjkdefgpdelpbcmbmeomcjbeemfm%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda,pkedcjkdefgpdelpbcmbmeomcjbeemfmX-Goog-Update-Updater: chromecrx-85.0.4183.121Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /regooop.html HTTP/1.1Host: bucket-api.restoreniaer.au-syd1.upcloudobjects.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /crx/blobs/Acy1k0bLIjHsvnKaKN_oRpVaYYvFs25d7GKYF1WXrT6yizCMksBO0c_ggE0B6tx6HPRHe6q1GOEe3_NcIbSiGG8kXeLMUY0sAKVvC6R89zvKM13s5VqoAMZSmuUgjQL5vlygJuArQghXXE_qTL7NlQ/extension_8520_615_0_5.crx HTTP/1.1Host: clients2.googleusercontent.comConnection: keep-aliveSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /cc41020ecb5162014937e0d1c83fa617.png HTTP/1.1Host: i.gyazo.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://bucket-api.restoreniaer.au-syd1.upcloudobjects.com/regooop.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /bootstrap/4.0.0/css/bootstrap.min.css HTTP/1.1Host: maxcdn.bootstrapcdn.comConnection: keep-aliveOrigin: https://bucket-api.restoreniaer.au-syd1.upcloudobjects.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: styleReferer: https://bucket-api.restoreniaer.au-syd1.upcloudobjects.com/regooop.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /bootstrap/4.0.0/js/bootstrap.min.js HTTP/1.1Host: maxcdn.bootstrapcdn.comConnection: keep-aliveOrigin: https://bucket-api.restoreniaer.au-syd1.upcloudobjects.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://bucket-api.restoreniaer.au-syd1.upcloudobjects.com/regooop.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /bootstrap/4.1.3/js/bootstrap.min.js HTTP/1.1Host: stackpath.bootstrapcdn.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://bucket-api.restoreniaer.au-syd1.upcloudobjects.com/regooop.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ajax/libs/popper.js/1.12.9/umd/popper.min.js HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-aliveOrigin: https://bucket-api.restoreniaer.au-syd1.upcloudobjects.comUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://bucket-api.restoreniaer.au-syd1.upcloudobjects.com/regooop.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /b308246805567e68aad040e42c453a7f.png HTTP/1.1Host: i.gyazo.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://bucket-api.restoreniaer.au-syd1.upcloudobjects.com/regooop.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /favicon.ico HTTP/1.1Host: bucket-api.restoreniaer.au-syd1.upcloudobjects.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://bucket-api.restoreniaer.au-syd1.upcloudobjects.com/regooop.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9

System Summary:

barindex
Source: C:\Windows\SysWOW64\wget.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: unknown Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P 'C:\Users\user\Desktop\download' --no-check-certificate --content-disposition --user-agent='Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko' 'https://alloverhaulage-my.sharepoint.com/:u:/g/personal/office_nlls_com_au/Ebi3MkfuJ2pLrppTTXXF_10ByRNMkVVs2ifkr322sjryVQ?download=1' > cmdline.out 2>&1
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\wget.exe wget -t 2 -v -T 60 -P 'C:\Users\user\Desktop\download' --no-check-certificate --content-disposition --user-agent='Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko' 'https://alloverhaulage-my.sharepoint.com/:u:/g/personal/office_nlls_com_au/Ebi3MkfuJ2pLrppTTXXF_10ByRNMkVVs2ifkr322sjryVQ?download=1'
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --start-maximized --enable-automation -- 'C:\Users\user\Desktop\download\PAYMENT-PROCESSING FILE.html'
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1588,2656585222973028929,10747540034743749709,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1716 /prefetch:8
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\wget.exe wget -t 2 -v -T 60 -P 'C:\Users\user\Desktop\download' --no-check-certificate --content-disposition --user-agent='Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko' 'https://alloverhaulage-my.sharepoint.com/:u:/g/personal/office_nlls_com_au/Ebi3MkfuJ2pLrppTTXXF_10ByRNMkVVs2ifkr322sjryVQ?download=1' Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1588,2656585222973028929,10747540034743749709,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1716 /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:768:120:WilError_01
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe File created: C:\Users\user\Desktop\cmdline.out Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Local\Temp\1e75c513-7e54-4d81-bc51-8f92f5775c64.tmp Jump to behavior
Source: classification engine Classification label: mal60.phis.win@36/210@10/13
Source: C:\Windows\SysWOW64\wget.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: C:\Windows\SysWOW64\wget.exe File read: C:\Windows\System32\drivers\etc\hosts Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic Jump to behavior

Data Obfuscation:

barindex
Uses code obfuscation techniques (call, push, ret)
Source: C:\Windows\SysWOW64\wget.exe Code function: 3_2_02C2265D push ss; ret 3_2_02C2268E
Source: C:\Windows\SysWOW64\wget.exe Code function: 3_2_02C2207B push eax; iretd 3_2_02C2209D
Source: C:\Windows\SysWOW64\wget.exe Code function: 3_2_02C23F81 pushfd ; retf 3_2_02C23F82
Source: C:\Windows\SysWOW64\wget.exe Code function: 3_2_02C2268F push ss; ret 3_2_02C226AE
Source: C:\Windows\SysWOW64\cmd.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\conhost.exe Process information set: NOOPENFILEERRORBOX Jump to behavior

Language, Device and Operating System Detection:

barindex
Queries the volume information (name, serial number etc) of a device
Source: C:\Windows\SysWOW64\wget.exe Queries volume information: C:\Users\user\Desktop\download VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\wget.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs