Windows Analysis Report
http://xm.b82mx.switchon.pk./#.aHR0cHM6Ly9sb2dpbi1taWNyb3NvZnRvbmxpbmUtY29tLmh1Z3Voc2luZ3MuY29tLz91c2VybmFtZT1haGFuc3NvbkBxaWEucWE=

Overview

General Information

Sample URL: http://xm.b82mx.switchon.pk./#.aHR0cHM6Ly9sb2dpbi1taWNyb3NvZnRvbmxpbmUtY29tLmh1Z3Voc2luZ3MuY29tLz91c2VybmFtZT1haGFuc3NvbkBxaWEucWE=
Analysis ID: 652378

Detection

Score: 48
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Multi AV Scanner detection for domain / URL

Classification

AV Detection

barindex
Source: login-microsoftonline-com.huguhsings.com Virustotal: Detection: 5% Perma Link
Source: chrome.exe Memory has grown: Private usage: 1MB later: 28MB
Source: global traffic HTTP traffic detected: GET / HTTP/1.1Host: xm.b82mx.switchon.pk.Connection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknown DNS traffic detected: queries for: accounts.google.com
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 51504
Source: unknown Network traffic detected: HTTP traffic on port 51931 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 51931
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50680
Source: unknown Network traffic detected: HTTP traffic on port 58201 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 51504 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 55152 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53006
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58201
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 55152
Source: unknown Network traffic detected: HTTP traffic on port 53006 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50680 -> 443
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknown TCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknown TCP traffic detected without corresponding DNS query: 216.58.212.138
Source: unknown TCP traffic detected without corresponding DNS query: 216.58.212.138
Source: unknown TCP traffic detected without corresponding DNS query: 216.58.212.138
Source: unknown TCP traffic detected without corresponding DNS query: 216.58.212.138
Source: unknown TCP traffic detected without corresponding DNS query: 216.58.212.138
Source: unknown TCP traffic detected without corresponding DNS query: 216.58.212.138
Source: unknown TCP traffic detected without corresponding DNS query: 216.58.212.138
Source: unknown TCP traffic detected without corresponding DNS query: 216.58.212.138
Source: unknown TCP traffic detected without corresponding DNS query: 216.58.212.138
Source: unknown TCP traffic detected without corresponding DNS query: 216.58.212.138
Source: unknown TCP traffic detected without corresponding DNS query: 216.58.212.138
Source: unknown TCP traffic detected without corresponding DNS query: 216.58.212.138
Source: unknown TCP traffic detected without corresponding DNS query: 216.58.212.138
Source: unknown TCP traffic detected without corresponding DNS query: 216.58.212.138
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\alfredo\AppData\Local\Temp\a0cc4d00-4a14-40d9-a38f-f962074026c6.tmp
Source: classification engine Classification label: mal48.win@27/69@4/117
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --enable-automation --single-argument http://xm.b82mx.switchon.pk./#.aHR0cHM6Ly9sb2dpbi1taWNyb3NvZnRvbmxpbmUtY29tLmh1Z3Voc2luZ3MuY29tLz91c2VybmFtZT1haGFuc3NvbkBxaWEucWE=
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1680,17312869768865709007,5265568345248204262,131072 --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2088 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1680,17312869768865709007,5265568345248204262,131072 --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2088 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-62B886FB-1E18.pma
Source: Window Recorder Window detected: More than 3 window changes detected
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs