Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://onedrive.live.com/download?cid=7BB5E286F12776DD&resid=7BB5E286F12776DD%21105&authkey=AMOExoSCD2ywjes

Overview

General Information

Sample URL:http://onedrive.live.com/download?cid=7BB5E286F12776DD&resid=7BB5E286F12776DD%21105&authkey=AMOExoSCD2ywjes
Analysis ID:708230

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Found iframes
No HTML title found

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 2436 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://onedrive.live.com/download?cid=7BB5E286F12776DD&resid=7BB5E286F12776DD%21105&authkey=AMOExoSCD2ywjes MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
    • chrome.exe (PID: 964 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1912 --field-trial-handle=1800,i,18321044787883545475,3443962279196911152,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
  • cleanup
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://login.live.com/login.srf?wa=wsignin1.0&wreply=https%3A%2F%2Fonedrive.live.com%2F%3Fauthkey%3D%2521AMOExoSCD2ywjes%26cid%3D7BB5E286F12776DD%26id%3D7BB5E286F12776DD%2521105%26parId%3Droot%26o%3DOneUpHTTP Parser: Iframe src: https://onedrive.live.com/preload?view=Folders.All&id=250206&mkt=EN-US
Source: https://login.live.com/login.srf?wa=wsignin1.0&wreply=https%3A%2F%2Fonedrive.live.com%2F%3Fauthkey%3D%2521AMOExoSCD2ywjes%26cid%3D7BB5E286F12776DD%26id%3D7BB5E286F12776DD%2521105%26parId%3Droot%26o%3DOneUpHTTP Parser: Iframe src: https://onedrive.live.com/preload?view=Folders.All&id=250206&mkt=EN-US
Source: https://login.live.com/login.srf?wa=wsignin1.0&wreply=https%3A%2F%2Fonedrive.live.com%2F%3Fauthkey%3D%2521AMOExoSCD2ywjes%26cid%3D7BB5E286F12776DD%26id%3D7BB5E286F12776DD%2521105%26parId%3Droot%26o%3DOneUpHTTP Parser: HTML title missing
Source: https://login.live.com/login.srf?wa=wsignin1.0&wreply=https%3A%2F%2Fonedrive.live.com%2F%3Fauthkey%3D%2521AMOExoSCD2ywjes%26cid%3D7BB5E286F12776DD%26id%3D7BB5E286F12776DD%2521105%26parId%3Droot%26o%3DOneUpHTTP Parser: HTML title missing
Source: https://login.live.com/login.srf?wa=wsignin1.0&wreply=https%3A%2F%2Fonedrive.live.com%2F%3Fauthkey%3D%2521AMOExoSCD2ywjes%26cid%3D7BB5E286F12776DD%26id%3D7BB5E286F12776DD%2521105%26parId%3Droot%26o%3DOneUpHTTP Parser: No <meta name="author".. found
Source: https://login.live.com/login.srf?wa=wsignin1.0&wreply=https%3A%2F%2Fonedrive.live.com%2F%3Fauthkey%3D%2521AMOExoSCD2ywjes%26cid%3D7BB5E286F12776DD%26id%3D7BB5E286F12776DD%2521105%26parId%3Droot%26o%3DOneUpHTTP Parser: No <meta name="author".. found
Source: https://login.live.com/login.srf?wa=wsignin1.0&wreply=https%3A%2F%2Fonedrive.live.com%2F%3Fauthkey%3D%2521AMOExoSCD2ywjes%26cid%3D7BB5E286F12776DD%26id%3D7BB5E286F12776DD%2521105%26parId%3Droot%26o%3DOneUpHTTP Parser: No <meta name="copyright".. found
Source: https://login.live.com/login.srf?wa=wsignin1.0&wreply=https%3A%2F%2Fonedrive.live.com%2F%3Fauthkey%3D%2521AMOExoSCD2ywjes%26cid%3D7BB5E286F12776DD%26id%3D7BB5E286F12776DD%2521105%26parId%3Droot%26o%3DOneUpHTTP Parser: No <meta name="copyright".. found
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdater
Source: chrome.exeMemory has grown: Private usage: 1MB later: 27MB
Source: unknownDNS traffic detected: queries for: onedrive.live.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49700
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49689
Source: unknownNetwork traffic detected: HTTP traffic on port 49890 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49688
Source: unknownNetwork traffic detected: HTTP traffic on port 49922 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49883
Source: unknownNetwork traffic detected: HTTP traffic on port 49926 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49880
Source: unknownNetwork traffic detected: HTTP traffic on port 49892 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49850 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49688 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49883 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49906 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 49921 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49891 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49925 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49923 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49850
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49892
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49891
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49890
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49880 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49689 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49906
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49926
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49925
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49923
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49922
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49921
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.163
Source: unknownTCP traffic detected without corresponding DNS query: 104.91.71.141
Source: unknownTCP traffic detected without corresponding DNS query: 104.91.71.141
Source: unknownTCP traffic detected without corresponding DNS query: 104.91.71.141
Source: unknownTCP traffic detected without corresponding DNS query: 104.91.71.141
Source: unknownTCP traffic detected without corresponding DNS query: 104.91.71.141
Source: unknownTCP traffic detected without corresponding DNS query: 104.91.71.141
Source: unknownTCP traffic detected without corresponding DNS query: 104.91.71.141
Source: classification engineClassification label: clean1.win@29/0@18/372
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://onedrive.live.com/download?cid=7BB5E286F12776DD&resid=7BB5E286F12776DD%21105&authkey=AMOExoSCD2ywjes
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1912 --field-trial-handle=1800,i,18321044787883545475,3443962279196911152,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1912 --field-trial-handle=1800,i,18321044787883545475,3443962279196911152,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdater
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdater
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
1
Drive-by Compromise
Windows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium2
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Extra Window Memory Injection
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)1
Extra Window Memory Injection
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration2
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://onedrive.live.com/download?cid=7BB5E286F12776DD&resid=7BB5E286F12776DD%21105&authkey=AMOExoSCD2ywjes0%Avira URL Cloudsafe
http://onedrive.live.com/download?cid=7BB5E286F12776DD&resid=7BB5E286F12776DD%21105&authkey=AMOExoSCD2ywjes1%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
142.250.185.173
truefalse
    high
    dual-a-0001.a-msedge.net
    204.79.197.200
    truefalse
      unknown
      l-0003.l-dc-msedge.net
      13.107.43.12
      truefalse
        unknown
        part-0017.t-0009.fbs1-t-msedge.net
        13.107.219.45
        truefalse
          unknown
          i-am3p-cor006.api.p001.1drv.com
          13.104.158.180
          truefalse
            high
            www.google.com
            142.250.186.164
            truefalse
              high
              clients.l.google.com
              142.250.185.206
              truefalse
                high
                c.live.com
                unknown
                unknownfalse
                  high
                  shellprod.msocdn.com
                  unknown
                  unknownfalse
                    unknown
                    storage.live.com
                    unknown
                    unknownfalse
                      high
                      skyapi.onedrive.live.com
                      unknown
                      unknownfalse
                        high
                        clients2.google.com
                        unknown
                        unknownfalse
                          high
                          onedrive.live.com
                          unknown
                          unknownfalse
                            high
                            wf6uzq.db.files.1drv.com
                            unknown
                            unknownfalse
                              high
                              skydrive.live.com
                              unknown
                              unknownfalse
                                high
                                api.onedrive.com
                                unknown
                                unknownfalse
                                  high
                                  p.sfx.ms
                                  unknown
                                  unknownfalse
                                    high
                                    amcdn.msftauth.net
                                    unknown
                                    unknownfalse
                                      unknown
                                      dub01pap002files.storage.live.com
                                      unknown
                                      unknownfalse
                                        high
                                        NameMaliciousAntivirus DetectionReputation
                                        https://onedrive.live.com/?cid=7bb5e286f12776dd&id=7BB5E286F12776DD%21105&authkey=%21AMOExoSCD2ywjesfalse
                                          high
                                          https://onedrive.live.com/viruswarning.aspx/po%20961691589.pdf.tar?cid=7bb5e286f12776dd&avres=Infected&resid=7BB5E286F12776DD!105&authkey=!AMOExoSCD2ywjesfalse
                                            high
                                            https://onedrive.live.com/?authkey=%21AMOExoSCD2ywjes&cid=7BB5E286F12776DD&id=7BB5E286F12776DD%21105&parId=root&o=OneUpfalse
                                              high
                                              • No. of IPs < 25%
                                              • 25% < No. of IPs < 50%
                                              • 50% < No. of IPs < 75%
                                              • 75% < No. of IPs
                                              IPDomainCountryFlagASNASN NameMalicious
                                              142.250.185.206
                                              clients.l.google.comUnited States
                                              15169GOOGLEUSfalse
                                              52.228.36.228
                                              unknownUnited States
                                              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                              204.79.197.200
                                              dual-a-0001.a-msedge.netUnited States
                                              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                              13.107.219.45
                                              part-0017.t-0009.fbs1-t-msedge.netUnited States
                                              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                              2.16.107.90
                                              unknownEuropean Union
                                              20940AKAMAI-ASN1EUfalse
                                              13.95.147.73
                                              unknownUnited States
                                              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                              51.11.192.49
                                              unknownUnited Kingdom
                                              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                              2.20.9.204
                                              unknownEuropean Union
                                              20940AKAMAI-ASN1EUfalse
                                              40.126.31.71
                                              unknownUnited States
                                              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                              13.107.43.12
                                              l-0003.l-dc-msedge.netUnited States
                                              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                              13.107.43.13
                                              unknownUnited States
                                              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                              20.189.173.14
                                              unknownUnited States
                                              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                              104.91.71.141
                                              unknownUnited States
                                              16625AKAMAI-ASUSfalse
                                              13.104.208.162
                                              unknownUnited States
                                              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                              34.104.35.123
                                              unknownUnited States
                                              15169GOOGLEUSfalse
                                              1.1.1.1
                                              unknownAustralia
                                              13335CLOUDFLARENETUSfalse
                                              184.51.105.213
                                              unknownUnited States
                                              3257GTT-BACKBONEGTTDEfalse
                                              23.54.139.180
                                              unknownUnited States
                                              20940AKAMAI-ASN1EUfalse
                                              142.250.186.163
                                              unknownUnited States
                                              15169GOOGLEUSfalse
                                              13.107.42.13
                                              unknownUnited States
                                              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                              13.107.42.12
                                              unknownUnited States
                                              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                              20.234.93.27
                                              unknownUnited States
                                              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                              23.45.102.249
                                              unknownUnited States
                                              20940AKAMAI-ASN1EUfalse
                                              239.255.255.250
                                              unknownReserved
                                              unknownunknownfalse
                                              20.190.159.2
                                              unknownUnited States
                                              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                              192.229.221.185
                                              unknownUnited States
                                              15133EDGECASTUSfalse
                                              2.20.8.220
                                              unknownEuropean Union
                                              20940AKAMAI-ASN1EUfalse
                                              142.250.185.173
                                              accounts.google.comUnited States
                                              15169GOOGLEUSfalse
                                              40.90.128.17
                                              unknownUnited States
                                              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                              88.221.169.199
                                              unknownEuropean Union
                                              16625AKAMAI-ASUSfalse
                                              142.250.186.164
                                              www.google.comUnited States
                                              15169GOOGLEUSfalse
                                              152.199.21.175
                                              unknownUnited States
                                              15133EDGECASTUSfalse
                                              23.213.164.142
                                              unknownUnited States
                                              16625AKAMAI-ASUSfalse
                                              172.217.16.195
                                              unknownUnited States
                                              15169GOOGLEUSfalse
                                              142.250.185.74
                                              unknownUnited States
                                              15169GOOGLEUSfalse
                                              20.44.10.123
                                              unknownUnited States
                                              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                              88.221.168.218
                                              unknownEuropean Union
                                              16625AKAMAI-ASUSfalse
                                              IP
                                              127.0.0.1
                                              Joe Sandbox Version:36.0.0 Rainbow Opal
                                              Analysis ID:708230
                                              Start date and time:2022-09-23 07:46:45 +02:00
                                              Joe Sandbox Product:CloudBasic
                                              Hypervisor based Inspection enabled:false
                                              Report type:full
                                              Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                              Sample URL:http://onedrive.live.com/download?cid=7BB5E286F12776DD&resid=7BB5E286F12776DD%21105&authkey=AMOExoSCD2ywjes
                                              Analysis system description:Windows 10 64 bit version 1909 (MS Office 2019, IE 11, Chrome 104, Firefox 88, Adobe Reader DC 21, Java 8 u291, 7-Zip)
                                              Number of analysed new started processes analysed:13
                                              Number of new started drivers analysed:0
                                              Number of existing processes analysed:0
                                              Number of existing drivers analysed:0
                                              Number of injected processes analysed:0
                                              Technologies:
                                              • EGA enabled
                                              Analysis Mode:stream
                                              Analysis stop reason:Timeout
                                              Detection:CLEAN
                                              Classification:clean1.win@29/0@18/372
                                              • Exclude process from analysis (whitelisted): svchost.exe
                                              • Excluded IPs from analysis (whitelisted): 20.190.159.4, 20.190.159.75, 20.190.159.23, 20.190.159.2, 20.190.159.68, 20.190.159.71, 20.190.159.64, 40.126.31.71, 172.217.16.195, 13.107.42.13, 34.104.35.123, 13.107.42.12, 52.228.36.228, 23.213.164.142, 13.95.147.73, 20.234.93.27, 2.16.107.90, 2.16.107.82, 20.189.173.14, 13.104.208.162, 23.54.139.180
                                              • Excluded domains from analysis (whitelisted): odc-web-brs.onedrive.akadns.net, odwebp.trafficmanager.net, c-msn-com-nsatc.trafficmanager.net, clientservices.googleapis.com, res-1.cdn.office.net, odc-commonafdrk-geo.onedrive.akadns.net, browser.events.data.trafficmanager.net, canadacentral1-odwebpl.cloudapp.net, l-0004.l-msedge.net, odwebpl.trafficmanager.net.l-0004.dc-msedge.net.l-0004.l-msedge.net, prda.aadg.msidentity.com, l-0003.l-msedge.net, login.live.com, common.be.1drv.com.l-0003.dc-msedge.net.l-0003.l-msedge.net, modernb.akamai.odsp.cdn.office.net-c.edgesuite.net, a1883.dscd.akamai.net, common-emea.onedrive.akadns.net, odc-db-files-geo.onedrive.akadns.net, odwebpl.trafficmanager.net, odc-db-files-brs.onedrive.akadns.net, odc-commonafdrk-brs.onedrive.akadns.net, res-1.cdn.office.net-c.edgekey.net.globalredir.akadns.net, e7695.dscg.akamaiedge.net, fs.microsoft.com, odc-web-geo.onedrive.akadns.net, onedscolprdwus13.westus.cloudapp.azure.com, westeurope1-odwebp.cloudapp.net, ctldl.windowsupdate.com, www.t
                                              • Not all processes where analyzed, report is missing behavior information
                                              No created / dropped files found
                                              No static file info