Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://ctlinks.wolterskluwer.com/ls/click?upn=-2F-2B5hLiYrr13mMklQzkilNPvE-2BPYo5nhRLT6V-2BqlTi7kpM0RT6onBJ28bgBSAYUbh60t9W3P21gRRyVbLtnTe39-2BUKFAdWE-2F9utgRuUM1WI-2BwvijlKoyye8-2F1lXNbNuywkr9VSIrlzgGsSObiegBJS7X-2FNFxP3asb5ksx5hiqiOe5DLDhLyynO864YG8-2FdOxYumDCcKOeWQMWv-2FQeYeHkTA-3D-3DUnvt_imVlhaP

Overview

General Information

Sample URL:http://ctlinks.wolterskluwer.com/ls/click?upn=-2F-2B5hLiYrr13mMklQzkilNPvE-2BPYo5nhRLT6V-2BqlTi7kpM0RT6onBJ28bgBSAYUbh60t9W3P21gRRyVbLtnTe39-2BUKFAdWE-2F9utgRuUM1WI-2BwvijlKoyye8-2F1lXNbNuywkr9VSIrlzg
Analysis ID:736953

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Found iframes
No HTML title found

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 5772 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://ctlinks.wolterskluwer.com/ls/click?upn=-2F-2B5hLiYrr13mMklQzkilNPvE-2BPYo5nhRLT6V-2BqlTi7kpM0RT6onBJ28bgBSAYUbh60t9W3P21gRRyVbLtnTe39-2BUKFAdWE-2F9utgRuUM1WI-2BwvijlKoyye8-2F1lXNbNuywkr9VSIrlzgGsSObiegBJS7X-2FNFxP3asb5ksx5hiqiOe5DLDhLyynO864YG8-2FdOxYumDCcKOeWQMWv-2FQeYeHkTA-3D-3DUnvt_imVlhaP3FR-2Fe8ZExGsY6oQnx74nFuNOYPIfTRZidYsSMUOIzqg41MG5lgxasfcocJXJlKP6nRrhJbqXW3TA3nKdUaLxbQjJC-2FDVePYnSDJKtiphyPueYo5ZY-2F0ieEa8XGjp3pPCxqMJsumRw6ImKVm4OnRppS3lvqZxyzCICvozrLe-2Betq383F1LTJph1fLBwzFDHgOFB-2FlTvCP7fRXbrIJeGENSJi0V56PSsw1X1rcEOEPlF5iP-2BzgFTMSSNTG3eeJ-2FbKI8KZKasdXSI2rXfoUo8hHe-2FI7uQI9ad38-2Ba4bT3Kg5ljsL0aLwRuzzcs0r2UfbAjEtrENgw8bLKnWY6SnnAu-2FcRqPhuVM-2B1V0tJ-2F5-2B3Whx9q5ivCEPorDEmuh7Ykb0Ri6lDrppCPN6TiSATQ-3D-3D MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
    • chrome.exe (PID: 4116 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=1864,i,1159066534976410925,8171802982352021328,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
  • cleanup
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://ct.wolterskluwer.com/accept-tc/EBC13E8E-0DE0-4BB7-89EA-93FAC3ADACA9?utm_source=sendgrid.com&utm_medium=email&utm_campaign=websiteHTTP Parser: Iframe src: https://www.googletagmanager.com/ns.html?id=GTM-5L2BMNS
Source: https://ct.wolterskluwer.com/accept-tc/EBC13E8E-0DE0-4BB7-89EA-93FAC3ADACA9?utm_source=sendgrid.com&utm_medium=email&utm_campaign=websiteHTTP Parser: Iframe src: https://vars.hotjar.com/box-0feefa1930c964ac6aa4db4e99e8f25f.html
Source: https://ct.wolterskluwer.com/accept-tc/EBC13E8E-0DE0-4BB7-89EA-93FAC3ADACA9?utm_source=sendgrid.com&utm_medium=email&utm_campaign=websiteHTTP Parser: Iframe src: https://www.googletagmanager.com/ns.html?id=GTM-5L2BMNS
Source: https://ct.wolterskluwer.com/accept-tc/EBC13E8E-0DE0-4BB7-89EA-93FAC3ADACA9?utm_source=sendgrid.com&utm_medium=email&utm_campaign=websiteHTTP Parser: Iframe src: https://vars.hotjar.com/box-0feefa1930c964ac6aa4db4e99e8f25f.html
Source: https://ct.wolterskluwer.com/accept-tc/EBC13E8E-0DE0-4BB7-89EA-93FAC3ADACA9?utm_source=sendgrid.com&utm_medium=email&utm_campaign=websiteHTTP Parser: Iframe src: https://www.googletagmanager.com/ns.html?id=GTM-5L2BMNS
Source: https://ct.wolterskluwer.com/accept-tc/EBC13E8E-0DE0-4BB7-89EA-93FAC3ADACA9?utm_source=sendgrid.com&utm_medium=email&utm_campaign=websiteHTTP Parser: Iframe src: https://vars.hotjar.com/box-0feefa1930c964ac6aa4db4e99e8f25f.html
Source: https://ct.wolterskluwer.com/accept-tc/EBC13E8E-0DE0-4BB7-89EA-93FAC3ADACA9?utm_source=sendgrid.com&utm_medium=email&utm_campaign=websiteHTTP Parser: Iframe src: https://www.googletagmanager.com/ns.html?id=GTM-5L2BMNS
Source: https://ct.wolterskluwer.com/accept-tc/EBC13E8E-0DE0-4BB7-89EA-93FAC3ADACA9?utm_source=sendgrid.com&utm_medium=email&utm_campaign=websiteHTTP Parser: Iframe src: https://vars.hotjar.com/box-0feefa1930c964ac6aa4db4e99e8f25f.html
Source: https://ct.wolterskluwer.com/accept-tc/EBC13E8E-0DE0-4BB7-89EA-93FAC3ADACA9?utm_source=sendgrid.com&utm_medium=email&utm_campaign=websiteHTTP Parser: HTML title missing
Source: https://ct.wolterskluwer.com/accept-tc/EBC13E8E-0DE0-4BB7-89EA-93FAC3ADACA9?utm_source=sendgrid.com&utm_medium=email&utm_campaign=websiteHTTP Parser: HTML title missing
Source: https://ct.wolterskluwer.com/accept-tc/EBC13E8E-0DE0-4BB7-89EA-93FAC3ADACA9?utm_source=sendgrid.com&utm_medium=email&utm_campaign=websiteHTTP Parser: HTML title missing
Source: https://ct.wolterskluwer.com/accept-tc/EBC13E8E-0DE0-4BB7-89EA-93FAC3ADACA9?utm_source=sendgrid.com&utm_medium=email&utm_campaign=websiteHTTP Parser: HTML title missing
Source: https://ct.wolterskluwer.com/accept-tc/EBC13E8E-0DE0-4BB7-89EA-93FAC3ADACA9?utm_source=sendgrid.com&utm_medium=email&utm_campaign=websiteHTTP Parser: No <meta name="author".. found
Source: https://ct.wolterskluwer.com/accept-tc/EBC13E8E-0DE0-4BB7-89EA-93FAC3ADACA9?utm_source=sendgrid.com&utm_medium=email&utm_campaign=websiteHTTP Parser: No <meta name="author".. found
Source: https://ct.wolterskluwer.com/accept-tc/EBC13E8E-0DE0-4BB7-89EA-93FAC3ADACA9?utm_source=sendgrid.com&utm_medium=email&utm_campaign=websiteHTTP Parser: No <meta name="author".. found
Source: https://ct.wolterskluwer.com/accept-tc/EBC13E8E-0DE0-4BB7-89EA-93FAC3ADACA9?utm_source=sendgrid.com&utm_medium=email&utm_campaign=websiteHTTP Parser: No <meta name="author".. found
Source: https://ct.wolterskluwer.com/accept-tc/EBC13E8E-0DE0-4BB7-89EA-93FAC3ADACA9?utm_source=sendgrid.com&utm_medium=email&utm_campaign=websiteHTTP Parser: No <meta name="copyright".. found
Source: https://ct.wolterskluwer.com/accept-tc/EBC13E8E-0DE0-4BB7-89EA-93FAC3ADACA9?utm_source=sendgrid.com&utm_medium=email&utm_campaign=websiteHTTP Parser: No <meta name="copyright".. found
Source: https://ct.wolterskluwer.com/accept-tc/EBC13E8E-0DE0-4BB7-89EA-93FAC3ADACA9?utm_source=sendgrid.com&utm_medium=email&utm_campaign=websiteHTTP Parser: No <meta name="copyright".. found
Source: https://ct.wolterskluwer.com/accept-tc/EBC13E8E-0DE0-4BB7-89EA-93FAC3ADACA9?utm_source=sendgrid.com&utm_medium=email&utm_campaign=websiteHTTP Parser: No <meta name="copyright".. found
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdater
Source: unknownDNS traffic detected: queries for: ctlinks.wolterskluwer.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49700
Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49864
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49780
Source: unknownNetwork traffic detected: HTTP traffic on port 49691 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49858
Source: unknownNetwork traffic detected: HTTP traffic on port 49868 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49881 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49699
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49691
Source: unknownNetwork traffic detected: HTTP traffic on port 49858 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49780 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49689 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 49777 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49689
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49881
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49831 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49831
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 49864 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49870
Source: unknownNetwork traffic detected: HTTP traffic on port 49870 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49868
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.181.227
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.181.227
Source: global trafficHTTP traffic detected: GET /ls/click?upn=-2F-2B5hLiYrr13mMklQzkilNPvE-2BPYo5nhRLT6V-2BqlTi7kpM0RT6onBJ28bgBSAYUbh60t9W3P21gRRyVbLtnTe39-2BUKFAdWE-2F9utgRuUM1WI-2BwvijlKoyye8-2F1lXNbNuywkr9VSIrlzgGsSObiegBJS7X-2FNFxP3asb5ksx5hiqiOe5DLDhLyynO864YG8-2FdOxYumDCcKOeWQMWv-2FQeYeHkTA-3D-3DUnvt_imVlhaP3FR-2Fe8ZExGsY6oQnx74nFuNOYPIfTRZidYsSMUOIzqg41MG5lgxasfcocJXJlKP6nRrhJbqXW3TA3nKdUaLxbQjJC-2FDVePYnSDJKtiphyPueYo5ZY-2F0ieEa8XGjp3pPCxqMJsumRw6ImKVm4OnRppS3lvqZxyzCICvozrLe-2Betq383F1LTJph1fLBwzFDHgOFB-2FlTvCP7fRXbrIJeGENSJi0V56PSsw1X1rcEOEPlF5iP-2BzgFTMSSNTG3eeJ-2FbKI8KZKasdXSI2rXfoUo8hHe-2FI7uQI9ad38-2Ba4bT3Kg5ljsL0aLwRuzzcs0r2UfbAjEtrENgw8bLKnWY6SnnAu-2FcRqPhuVM-2B1V0tJ-2F5-2B3Whx9q5ivCEPorDEmuh7Ykb0Ri6lDrppCPN6TiSATQ-3D-3D HTTP/1.1Host: ctlinks.wolterskluwer.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: classification engineClassification label: clean1.win@25/0@32/348
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://ctlinks.wolterskluwer.com/ls/click?upn=-2F-2B5hLiYrr13mMklQzkilNPvE-2BPYo5nhRLT6V-2BqlTi7kpM0RT6onBJ28bgBSAYUbh60t9W3P21gRRyVbLtnTe39-2BUKFAdWE-2F9utgRuUM1WI-2BwvijlKoyye8-2F1lXNbNuywkr9VSIrlzgGsSObiegBJS7X-2FNFxP3asb5ksx5hiqiOe5DLDhLyynO864YG8-2FdOxYumDCcKOeWQMWv-2FQeYeHkTA-3D-3DUnvt_imVlhaP3FR-2Fe8ZExGsY6oQnx74nFuNOYPIfTRZidYsSMUOIzqg41MG5lgxasfcocJXJlKP6nRrhJbqXW3TA3nKdUaLxbQjJC-2FDVePYnSDJKtiphyPueYo5ZY-2F0ieEa8XGjp3pPCxqMJsumRw6ImKVm4OnRppS3lvqZxyzCICvozrLe-2Betq383F1LTJph1fLBwzFDHgOFB-2FlTvCP7fRXbrIJeGENSJi0V56PSsw1X1rcEOEPlF5iP-2BzgFTMSSNTG3eeJ-2FbKI8KZKasdXSI2rXfoUo8hHe-2FI7uQI9ad38-2Ba4bT3Kg5ljsL0aLwRuzzcs0r2UfbAjEtrENgw8bLKnWY6SnnAu-2FcRqPhuVM-2B1V0tJ-2F5-2B3Whx9q5ivCEPorDEmuh7Ykb0Ri6lDrppCPN6TiSATQ-3D-3D
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=1864,i,1159066534976410925,8171802982352021328,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=1864,i,1159066534976410925,8171802982352021328,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdater
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdater
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
1
Drive-by Compromise
Windows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium2
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth2
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration3
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://ctlinks.wolterskluwer.com/ls/click?upn=-2F-2B5hLiYrr13mMklQzkilNPvE-2BPYo5nhRLT6V-2BqlTi7kpM0RT6onBJ28bgBSAYUbh60t9W3P21gRRyVbLtnTe39-2BUKFAdWE-2F9utgRuUM1WI-2BwvijlKoyye8-2F1lXNbNuywkr9VSIrlzgGsSObiegBJS7X-2FNFxP3asb5ksx5hiqiOe5DLDhLyynO864YG8-2FdOxYumDCcKOeWQMWv-2FQeYeHkTA-3D-3DUnvt_imVlhaP3FR-2Fe8ZExGsY6oQnx74nFuNOYPIfTRZidYsSMUOIzqg41MG5lgxasfcocJXJlKP6nRrhJbqXW3TA3nKdUaLxbQjJC-2FDVePYnSDJKtiphyPueYo5ZY-2F0ieEa8XGjp3pPCxqMJsumRw6ImKVm4OnRppS3lvqZxyzCICvozrLe-2Betq383F1LTJph1fLBwzFDHgOFB-2FlTvCP7fRXbrIJeGENSJi0V56PSsw1X1rcEOEPlF5iP-2BzgFTMSSNTG3eeJ-2FbKI8KZKasdXSI2rXfoUo8hHe-2FI7uQI9ad38-2Ba4bT3Kg5ljsL0aLwRuzzcs0r2UfbAjEtrENgw8bLKnWY6SnnAu-2FcRqPhuVM-2B1V0tJ-2F5-2B3Whx9q5ivCEPorDEmuh7Ykb0Ri6lDrppCPN6TiSATQ-3D-3D0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
star-mini.c10r.facebook.com
157.240.20.35
truefalse
    high
    p01f.t.eloqua.com
    142.0.173.26
    truefalse
      high
      vc-live-cf.hotjar.io
      65.9.66.34
      truefalse
        unknown
        accounts.google.com
        142.250.185.173
        truefalse
          high
          sendgrid.net
          167.89.118.52
          truefalse
            high
            st1.dialogtech.com
            107.22.63.100
            truefalse
              high
              stats.g.doubleclick.net
              74.125.140.156
              truefalse
                high
                vars.hotjar.com
                13.227.219.93
                truefalse
                  high
                  adobetarget.data.adobedc.net
                  13.36.218.177
                  truefalse
                    unknown
                    duerzc3hf5let.cloudfront.net
                    99.86.240.71
                    truefalse
                      high
                      scontent.xx.fbcdn.net
                      185.60.216.19
                      truefalse
                        high
                        in-live.live.eks.hotjar.com
                        52.17.231.22
                        truefalse
                          high
                          script.hotjar.com
                          52.222.236.74
                          truefalse
                            high
                            googleads.g.doubleclick.net
                            172.217.23.98
                            truefalse
                              high
                              www.google.com
                              216.58.212.132
                              truefalse
                                high
                                clients.l.google.com
                                172.217.18.14
                                truefalse
                                  high
                                  cdn.linkedin.oribi.io
                                  108.138.36.102
                                  truefalse
                                    high
                                    st2.dialogtech.com
                                    34.226.62.133
                                    truefalse
                                      high
                                      www.google.ch
                                      142.250.185.99
                                      truefalse
                                        high
                                        d31y97ze264gaa.cloudfront.net
                                        13.225.84.38
                                        truefalse
                                          high
                                          wolterskluwer.com.102.122.2o7.net
                                          15.188.95.229
                                          truefalse
                                            high
                                            static-cdn.hotjar.com
                                            108.157.4.21
                                            truefalse
                                              high
                                              wolterskluwer.tt.omtrdc.net
                                              unknown
                                              unknownfalse
                                                unknown
                                                in.hotjar.com
                                                unknown
                                                unknownfalse
                                                  high
                                                  ct.wolterskluwer.com
                                                  unknown
                                                  unknownfalse
                                                    high
                                                    cdn.tt.omtrdc.net
                                                    unknown
                                                    unknownfalse
                                                      unknown
                                                      ctlinks.wolterskluwer.com
                                                      unknown
                                                      unknownfalse
                                                        high
                                                        vc.hotjar.io
                                                        unknown
                                                        unknownfalse
                                                          unknown
                                                          clients2.google.com
                                                          unknown
                                                          unknownfalse
                                                            high
                                                            static.hotjar.com
                                                            unknown
                                                            unknownfalse
                                                              high
                                                              s676.t.eloqua.com
                                                              unknown
                                                              unknownfalse
                                                                high
                                                                www.facebook.com
                                                                unknown
                                                                unknownfalse
                                                                  high
                                                                  assets.adobedtm.com
                                                                  unknown
                                                                  unknownfalse
                                                                    high
                                                                    smetrics.wolterskluwer.com
                                                                    unknown
                                                                    unknownfalse
                                                                      high
                                                                      www.linkedin.com
                                                                      unknown
                                                                      unknownfalse
                                                                        high
                                                                        img.en25.com
                                                                        unknown
                                                                        unknownfalse
                                                                          high
                                                                          js-agent.newrelic.com
                                                                          unknown
                                                                          unknownfalse
                                                                            high
                                                                            connect.facebook.net
                                                                            unknown
                                                                            unknownfalse
                                                                              high
                                                                              px.ads.linkedin.com
                                                                              unknown
                                                                              unknownfalse
                                                                                high
                                                                                bam.nr-data.net
                                                                                unknown
                                                                                unknownfalse
                                                                                  unknown
                                                                                  snap.licdn.com
                                                                                  unknown
                                                                                  unknownfalse
                                                                                    high
                                                                                    NameMaliciousAntivirus DetectionReputation
                                                                                    https://ct.wolterskluwer.com/accept-tc/EBC13E8E-0DE0-4BB7-89EA-93FAC3ADACA9?utm_source=sendgrid.com&utm_medium=email&utm_campaign=websitefalse
                                                                                      high
                                                                                      https://vars.hotjar.com/box-0feefa1930c964ac6aa4db4e99e8f25f.htmlfalse
                                                                                        high
                                                                                        • No. of IPs < 25%
                                                                                        • 25% < No. of IPs < 50%
                                                                                        • 50% < No. of IPs < 75%
                                                                                        • 75% < No. of IPs
                                                                                        IPDomainCountryFlagASNASN NameMalicious
                                                                                        142.250.185.99
                                                                                        www.google.chUnited States
                                                                                        15169GOOGLEUSfalse
                                                                                        167.89.118.52
                                                                                        sendgrid.netUnited States
                                                                                        11377SENDGRIDUSfalse
                                                                                        107.22.63.100
                                                                                        st1.dialogtech.comUnited States
                                                                                        14618AMAZON-AESUSfalse
                                                                                        23.197.8.158
                                                                                        unknownUnited States
                                                                                        16625AKAMAI-ASUSfalse
                                                                                        172.217.18.14
                                                                                        clients.l.google.comUnited States
                                                                                        15169GOOGLEUSfalse
                                                                                        142.0.173.26
                                                                                        p01f.t.eloqua.comUnited States
                                                                                        7160NETDYNAMICSUSfalse
                                                                                        15.188.95.229
                                                                                        wolterskluwer.com.102.122.2o7.netUnited States
                                                                                        16509AMAZON-02USfalse
                                                                                        34.226.62.133
                                                                                        st2.dialogtech.comUnited States
                                                                                        14618AMAZON-AESUSfalse
                                                                                        172.217.23.98
                                                                                        googleads.g.doubleclick.netUnited States
                                                                                        15169GOOGLEUSfalse
                                                                                        65.9.66.34
                                                                                        vc-live-cf.hotjar.ioUnited States
                                                                                        16509AMAZON-02USfalse
                                                                                        95.101.54.113
                                                                                        unknownEuropean Union
                                                                                        34164AKAMAI-LONGBfalse
                                                                                        162.247.241.14
                                                                                        unknownUnited States
                                                                                        23467NEWRELIC-AS-1USfalse
                                                                                        52.167.11.129
                                                                                        unknownUnited States
                                                                                        8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                        172.217.18.99
                                                                                        unknownUnited States
                                                                                        15169GOOGLEUSfalse
                                                                                        142.250.186.136
                                                                                        unknownUnited States
                                                                                        15169GOOGLEUSfalse
                                                                                        142.250.184.200
                                                                                        unknownUnited States
                                                                                        15169GOOGLEUSfalse
                                                                                        142.250.186.99
                                                                                        unknownUnited States
                                                                                        15169GOOGLEUSfalse
                                                                                        52.17.231.22
                                                                                        in-live.live.eks.hotjar.comUnited States
                                                                                        16509AMAZON-02USfalse
                                                                                        142.250.186.78
                                                                                        unknownUnited States
                                                                                        15169GOOGLEUSfalse
                                                                                        142.250.185.68
                                                                                        unknownUnited States
                                                                                        15169GOOGLEUSfalse
                                                                                        34.104.35.123
                                                                                        unknownUnited States
                                                                                        15169GOOGLEUSfalse
                                                                                        13.225.84.38
                                                                                        d31y97ze264gaa.cloudfront.netUnited States
                                                                                        16509AMAZON-02USfalse
                                                                                        13.36.218.177
                                                                                        adobetarget.data.adobedc.netUnited States
                                                                                        7018ATT-INTERNET4USfalse
                                                                                        13.107.42.14
                                                                                        unknownUnited States
                                                                                        8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                        74.125.140.156
                                                                                        stats.g.doubleclick.netUnited States
                                                                                        15169GOOGLEUSfalse
                                                                                        142.250.186.106
                                                                                        unknownUnited States
                                                                                        15169GOOGLEUSfalse
                                                                                        151.101.2.137
                                                                                        unknownUnited States
                                                                                        54113FASTLYUSfalse
                                                                                        142.250.181.227
                                                                                        unknownUnited States
                                                                                        15169GOOGLEUSfalse
                                                                                        185.60.216.19
                                                                                        scontent.xx.fbcdn.netIreland
                                                                                        32934FACEBOOKUSfalse
                                                                                        239.255.255.250
                                                                                        unknownReserved
                                                                                        unknownunknownfalse
                                                                                        108.157.4.21
                                                                                        static-cdn.hotjar.comUnited States
                                                                                        16509AMAZON-02USfalse
                                                                                        13.227.219.93
                                                                                        vars.hotjar.comUnited States
                                                                                        16509AMAZON-02USfalse
                                                                                        108.138.36.102
                                                                                        cdn.linkedin.oribi.ioUnited States
                                                                                        16509AMAZON-02USfalse
                                                                                        142.250.185.173
                                                                                        accounts.google.comUnited States
                                                                                        15169GOOGLEUSfalse
                                                                                        52.222.236.74
                                                                                        script.hotjar.comUnited States
                                                                                        16509AMAZON-02USfalse
                                                                                        99.86.240.71
                                                                                        duerzc3hf5let.cloudfront.netUnited States
                                                                                        16509AMAZON-02USfalse
                                                                                        157.240.20.35
                                                                                        star-mini.c10r.facebook.comUnited States
                                                                                        32934FACEBOOKUSfalse
                                                                                        88.221.168.237
                                                                                        unknownEuropean Union
                                                                                        16625AKAMAI-ASUSfalse
                                                                                        142.250.185.98
                                                                                        unknownUnited States
                                                                                        15169GOOGLEUSfalse
                                                                                        IP
                                                                                        192.168.2.1
                                                                                        127.0.0.1
                                                                                        Joe Sandbox Version:36.0.0 Rainbow Opal
                                                                                        Analysis ID:736953
                                                                                        Start date and time:2022-11-03 12:25:01 +01:00
                                                                                        Joe Sandbox Product:CloudBasic
                                                                                        Overall analysis duration:
                                                                                        Hypervisor based Inspection enabled:false
                                                                                        Report type:light
                                                                                        Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                                                                        Sample URL:http://ctlinks.wolterskluwer.com/ls/click?upn=-2F-2B5hLiYrr13mMklQzkilNPvE-2BPYo5nhRLT6V-2BqlTi7kpM0RT6onBJ28bgBSAYUbh60t9W3P21gRRyVbLtnTe39-2BUKFAdWE-2F9utgRuUM1WI-2BwvijlKoyye8-2F1lXNbNuywkr9VSIrlzgGsSObiegBJS7X-2FNFxP3asb5ksx5hiqiOe5DLDhLyynO864YG8-2FdOxYumDCcKOeWQMWv-2FQeYeHkTA-3D-3DUnvt_imVlhaP3FR-2Fe8ZExGsY6oQnx74nFuNOYPIfTRZidYsSMUOIzqg41MG5lgxasfcocJXJlKP6nRrhJbqXW3TA3nKdUaLxbQjJC-2FDVePYnSDJKtiphyPueYo5ZY-2F0ieEa8XGjp3pPCxqMJsumRw6ImKVm4OnRppS3lvqZxyzCICvozrLe-2Betq383F1LTJph1fLBwzFDHgOFB-2FlTvCP7fRXbrIJeGENSJi0V56PSsw1X1rcEOEPlF5iP-2BzgFTMSSNTG3eeJ-2FbKI8KZKasdXSI2rXfoUo8hHe-2FI7uQI9ad38-2Ba4bT3Kg5ljsL0aLwRuzzcs0r2UfbAjEtrENgw8bLKnWY6SnnAu-2FcRqPhuVM-2B1V0tJ-2F5-2B3Whx9q5ivCEPorDEmuh7Ykb0Ri6lDrppCPN6TiSATQ-3D-3D
                                                                                        Analysis system description:Windows 10 64 bit version 1909 (MS Office 2019, IE 11, Chrome 104, Firefox 88, Adobe Reader DC 21, Java 8 u291, 7-Zip)
                                                                                        Number of analysed new started processes analysed:10
                                                                                        Number of new started drivers analysed:0
                                                                                        Number of existing processes analysed:0
                                                                                        Number of existing drivers analysed:0
                                                                                        Number of injected processes analysed:0
                                                                                        Technologies:
                                                                                        • EGA enabled
                                                                                        Analysis Mode:stream
                                                                                        Analysis stop reason:Timeout
                                                                                        Detection:CLEAN
                                                                                        Classification:clean1.win@25/0@32/348
                                                                                        • Exclude process from analysis (whitelisted): SgrmBroker.exe, usocoreworker.exe, svchost.exe
                                                                                        • Excluded IPs from analysis (whitelisted): 40.126.31.69, 40.126.31.73, 20.190.159.23, 20.190.159.71, 20.190.159.0, 20.190.159.73, 40.126.31.67, 20.190.159.4, 142.250.186.99, 52.167.11.129, 34.104.35.123, 88.221.168.237, 142.250.186.136, 142.250.184.200, 95.101.54.113, 95.101.54.122, 13.107.42.14, 142.250.185.98, 142.250.186.106, 142.250.186.138, 172.217.16.138, 142.250.186.42, 142.250.186.74, 172.217.18.10, 172.217.16.202, 142.250.184.202, 216.58.212.170, 172.217.23.106, 142.250.185.74, 142.250.186.170, 142.250.185.106, 142.250.184.234, 142.250.185.202, 142.250.181.234, 142.250.186.78, 151.101.2.137, 151.101.66.137, 151.101.130.137, 151.101.194.137, 23.197.8.158, 162.247.241.14
                                                                                        • Excluded domains from analysis (whitelisted): www-linkedin-com.l-0005.l-msedge.net, fs.microsoft.com, www.googleadservices.com, content-autofill.googleapis.com, wildcard.en25.com.edgekey.net, www.tm.lg.prod.aadmsa.akadns.net, cn-assets.adobedtm.com.edgekey.net, clientservices.googleapis.com, www.tm.a.prd.aadg.akadns.net, od.linkedin.edgesuite.net, k.sni.global.fastly.net, login.msa.msidentity.com, ssl.google-analytics.com, wk-grc-ct-prod-myct.trafficmanager.net, l-0005.l-msedge.net, prda.aadg.msidentity.com, edgedl.me.gvt1.com, login.live.com, e7808.dscg.akamaiedge.net, www.googletagmanager.com, e5763.g.akamaiedge.net, a1916.dscg2.akamai.net, bam.nr-data.net.cdn.cloudflare.net, www.google-analytics.com
                                                                                        • Not all processes where analyzed, report is missing behavior information
                                                                                        • Report size getting too big, too many NtWriteVirtualMemory calls found.
                                                                                        No created / dropped files found
                                                                                        No static file info