Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://www.anovis.com.br/

Overview

General Information

Sample URL:http://www.anovis.com.br/
Analysis ID:736963
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 4520 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 2148 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1960 --field-trial-handle=1772,i,1740651327127756512,7249462608667158532,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 1812 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.anovis.com.br/ MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /html5shiv/3.7.2/html5shiv.min.js HTTP/1.1Host: oss.maxcdn.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: http://www.anovis.com.br/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /respond/1.4.2/respond.min.js HTTP/1.1Host: oss.maxcdn.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: http://www.anovis.com.br/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /bootstrap/js/bootstrap.min.js HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: */*Referer: http://www.anovis.com.br/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /bootstrap/css/bootstrap.min.css HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://www.anovis.com.br/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ilightbox/src/css/ilightbox.css HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://www.anovis.com.br/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ilightbox/src/js/jquery.requestAnimationFrame.js HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: */*Referer: http://www.anovis.com.br/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ilightbox/src/js/jquery.mousewheel.js HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: */*Referer: http://www.anovis.com.br/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ilightbox/src/js/ilightbox.packed.js HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: */*Referer: http://www.anovis.com.br/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /stellar.js HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: */*Referer: http://www.anovis.com.br/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /respond.src.js HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: */*Referer: http://www.anovis.com.br/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /images/logo-anovis.png HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.anovis.com.br/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /images/band_br.gif HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.anovis.com.br/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ilightbox/src/dark-skin/skin.css HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://www.anovis.com.br/ilightbox/src/css/ilightbox.cssAccept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ilightbox/src/light-skin/skin.css HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://www.anovis.com.br/ilightbox/src/css/ilightbox.cssAccept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ilightbox/src/parade-skin/skin.css HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://www.anovis.com.br/ilightbox/src/css/ilightbox.cssAccept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ilightbox/src/metro-black-skin/skin.css HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://www.anovis.com.br/ilightbox/src/css/ilightbox.cssAccept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ilightbox/src/metro-white-skin/skin.css HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://www.anovis.com.br/ilightbox/src/css/ilightbox.cssAccept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ilightbox/src/mac-skin/skin.css HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://www.anovis.com.br/ilightbox/src/css/ilightbox.cssAccept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ilightbox/src/smooth-skin/skin.css HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/css,*/*;q=0.1Referer: http://www.anovis.com.br/ilightbox/src/css/ilightbox.cssAccept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /images/band_en.gif HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.anovis.com.br/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /images/seta-naveg-baixo-2.png HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.anovis.com.br/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /images/icone-solidos-orais.png HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.anovis.com.br/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /images/icone-liquidos-orais.png HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.anovis.com.br/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /images/icone-semi-solidos.png HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.anovis.com.br/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /images/galeria-1.jpg HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.anovis.com.br/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /images/galeria-2.jpg HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.anovis.com.br/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /images/home1.jpg HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.anovis.com.br/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /images/galeria-4.jpg HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.anovis.com.br/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /images/unidade-taboao.jpg HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.anovis.com.br/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /images/unidade-brasilia-2.jpg HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.anovis.com.br/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /images/unidade-embu.jpg HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.anovis.com.br/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: _ga=GA1.3.1628746560.1667504316; _gid=GA1.3.1910068985.1667504316; _gat=1
Source: global trafficHTTP traffic detected: GET /images/unidade-pouso.jpg HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.anovis.com.br/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: _ga=GA1.3.1628746560.1667504316; _gid=GA1.3.1910068985.1667504316; _gat=1
Source: global trafficHTTP traffic detected: GET /images/rodape-site-anovis.jpg HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.anovis.com.br/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: _ga=GA1.3.1628746560.1667504316; _gid=GA1.3.1910068985.1667504316; _gat=1
Source: global trafficHTTP traffic detected: GET /images/rodape-site-anovis-mobile.jpg HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.anovis.com.br/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: _ga=GA1.3.1628746560.1667504316; _gid=GA1.3.1910068985.1667504316; _gat=1
Source: global trafficHTTP traffic detected: GET /images/novo-logo-uniao5.png HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.anovis.com.br/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: _ga=GA1.3.1628746560.1667504316; _gid=GA1.3.1910068985.1667504316; _gat=1
Source: global trafficHTTP traffic detected: GET /images/slide-footer-1.jpg HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.anovis.com.br/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: _ga=GA1.3.1628746560.1667504316; _gid=GA1.3.1910068985.1667504316; _gat=1
Source: global trafficHTTP traffic detected: GET /images/band_en.gif HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: www.anovis.com.br
Source: global trafficHTTP traffic detected: GET /images/logo-anovis.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: www.anovis.com.br
Source: global trafficHTTP traffic detected: GET /images/band_br.gif HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: www.anovis.com.br
Source: global trafficHTTP traffic detected: GET /images/seta-naveg-baixo-2.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: www.anovis.com.br
Source: global trafficHTTP traffic detected: GET /images/icone-solidos-orais.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: www.anovis.com.br
Source: global trafficHTTP traffic detected: GET /images/icone-liquidos-orais.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: www.anovis.com.br
Source: global trafficHTTP traffic detected: GET /images/icone-semi-solidos.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: www.anovis.com.br
Source: global trafficHTTP traffic detected: GET /images/galeria-1.jpg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: www.anovis.com.br
Source: global trafficHTTP traffic detected: GET /images/galeria-2.jpg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: www.anovis.com.br
Source: global trafficHTTP traffic detected: GET /images/galeria-4.jpg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: www.anovis.com.br
Source: global trafficHTTP traffic detected: GET /images/unidade-taboao.jpg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: www.anovis.com.br
Source: global trafficHTTP traffic detected: GET /images/unidade-brasilia-2.jpg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: www.anovis.com.br
Source: global trafficHTTP traffic detected: GET /images/unidade-embu.jpg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: www.anovis.com.br
Source: global trafficHTTP traffic detected: GET /images/unidade-pouso.jpg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: www.anovis.com.br
Source: global trafficHTTP traffic detected: GET /images/rodape-site-anovis.jpg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: www.anovis.com.br
Source: global trafficHTTP traffic detected: GET /images/rodape-site-anovis-mobile.jpg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: www.anovis.com.br
Source: global trafficHTTP traffic detected: GET /images/novo-logo-uniao5.png HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: www.anovis.com.br
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.anovis.com.br/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: _ga=GA1.3.1628746560.1667504316; _gid=GA1.3.1910068985.1667504316; _gat=1
Source: global trafficHTTP traffic detected: GET /index.php HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: _ga=GA1.3.1628746560.1667504316; _gid=GA1.3.1910068985.1667504316; _gat=1
Source: global trafficHTTP traffic detected: GET /images/slide-footer-2.jpg HTTP/1.1Host: www.anovis.com.brConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://www.anovis.com.br/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: _ga=GA1.3.1628746560.1667504316; _gid=GA1.3.1910068985.1667504316; _gat=1
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Thu, 03 Nov 2022 11:39:07 GMTServer: ApacheContent-Length: 209Keep-Alive: timeout=5, max=100Connection: Keep-AliveContent-Type: text/html; charset=iso-8859-1Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 2f 66 61 76 69 63 6f 6e 2e 69 63 6f 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL /favicon.ico was not found on this server.</p></body></html>
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49700
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49699
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49784
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: classification engineClassification label: clean0.win@25/0@7/9
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1960 --field-trial-handle=1772,i,1740651327127756512,7249462608667158532,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.anovis.com.br/
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1960 --field-trial-handle=1772,i,1740651327127756512,7249462608667158532,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth4
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration5
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer3
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://www.anovis.com.br/0%Avira URL Cloudsafe
http://www.anovis.com.br/0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://www.anovis.com.br/images/galeria-2.jpg0%Avira URL Cloudsafe
http://www.anovis.com.br/images/unidade-embu.jpg0%Avira URL Cloudsafe
http://www.anovis.com.br/ilightbox/src/js/jquery.requestAnimationFrame.js0%Avira URL Cloudsafe
http://www.anovis.com.br/bootstrap/css/bootstrap.min.css0%Avira URL Cloudsafe
http://www.anovis.com.br/images/icone-liquidos-orais.png0%Avira URL Cloudsafe
http://www.anovis.com.br/stellar.js0%Avira URL Cloudsafe
http://www.anovis.com.br/images/rodape-site-anovis.jpg0%Avira URL Cloudsafe
http://www.anovis.com.br/ilightbox/src/light-skin/skin.css0%Avira URL Cloudsafe
http://www.anovis.com.br/images/novo-logo-uniao5.png0%Avira URL Cloudsafe
http://www.anovis.com.br/bootstrap/js/bootstrap.min.js0%Avira URL Cloudsafe
http://www.anovis.com.br/images/rodape-site-anovis-mobile.jpg0%Avira URL Cloudsafe
http://www.anovis.com.br/images/band_en.gif0%Avira URL Cloudsafe
http://www.anovis.com.br/ilightbox/src/metro-black-skin/skin.css0%Avira URL Cloudsafe
http://www.anovis.com.br/images/seta-naveg-baixo-2.png0%Avira URL Cloudsafe
http://www.anovis.com.br/ilightbox/src/metro-white-skin/skin.css0%Avira URL Cloudsafe
http://www.anovis.com.br/ilightbox/src/mac-skin/skin.css0%Avira URL Cloudsafe
http://www.anovis.com.br/images/icone-solidos-orais.png0%Avira URL Cloudsafe
http://www.anovis.com.br/ilightbox/src/js/ilightbox.packed.js0%Avira URL Cloudsafe
http://www.anovis.com.br/ilightbox/src/css/ilightbox.css0%Avira URL Cloudsafe
http://www.anovis.com.br/images/home1.jpg0%Avira URL Cloudsafe
http://www.anovis.com.br/images/slide-footer-2.jpg0%Avira URL Cloudsafe
http://www.anovis.com.br/ilightbox/src/smooth-skin/skin.css0%Avira URL Cloudsafe
http://www.anovis.com.br/ilightbox/src/dark-skin/skin.css0%Avira URL Cloudsafe
http://www.anovis.com.br/images/galeria-4.jpg0%Avira URL Cloudsafe
http://www.anovis.com.br/respond.src.js0%Avira URL Cloudsafe
http://www.anovis.com.br/images/band_br.gif0%Avira URL Cloudsafe
http://www.anovis.com.br/ilightbox/src/js/jquery.mousewheel.js0%Avira URL Cloudsafe
http://www.anovis.com.br/images/logo-anovis.png0%Avira URL Cloudsafe
http://www.anovis.com.br/images/unidade-brasilia-2.jpg0%Avira URL Cloudsafe
http://www.anovis.com.br/images/unidade-taboao.jpg0%Avira URL Cloudsafe
http://www.anovis.com.br/images/unidade-pouso.jpg0%Avira URL Cloudsafe
http://www.anovis.com.br/images/slide-footer-1.jpg0%Avira URL Cloudsafe
http://www.anovis.com.br/ilightbox/src/parade-skin/skin.css0%Avira URL Cloudsafe
http://www.anovis.com.br/favicon.ico0%Avira URL Cloudsafe
http://www.anovis.com.br/images/icone-semi-solidos.png0%Avira URL Cloudsafe
http://www.anovis.com.br/images/galeria-1.jpg0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
anovis.websiteseguro.com
186.202.188.90
truefalse
    high
    accounts.google.com
    142.251.143.141
    truefalse
      high
      www.anovis.com.br
      179.188.52.129
      truefalse
        unknown
        www.google.com
        142.251.143.132
        truefalse
          high
          clients.l.google.com
          142.251.143.174
          truefalse
            high
            osscdn.netdnasa9.netdna-cdn.com
            23.111.8.154
            truefalse
              high
              clients2.google.com
              unknown
              unknownfalse
                high
                oss.maxcdn.com
                unknown
                unknownfalse
                  high
                  NameMaliciousAntivirus DetectionReputation
                  http://www.anovis.com.br/images/icone-liquidos-orais.pngfalse
                  • Avira URL Cloud: safe
                  unknown
                  http://www.anovis.com.br/images/galeria-2.jpgfalse
                  • Avira URL Cloud: safe
                  unknown
                  https://oss.maxcdn.com/html5shiv/3.7.2/html5shiv.min.jsfalse
                    high
                    http://www.anovis.com.br/ilightbox/src/js/jquery.requestAnimationFrame.jsfalse
                    • Avira URL Cloud: safe
                    unknown
                    http://www.anovis.com.br/bootstrap/css/bootstrap.min.cssfalse
                    • Avira URL Cloud: safe
                    unknown
                    http://www.anovis.com.br/images/unidade-embu.jpgfalse
                    • Avira URL Cloud: safe
                    unknown
                    http://www.anovis.com.br/images/rodape-site-anovis.jpgfalse
                    • Avira URL Cloud: safe
                    unknown
                    http://www.anovis.com.br/stellar.jsfalse
                    • Avira URL Cloud: safe
                    unknown
                    http://www.anovis.com.br/ilightbox/src/light-skin/skin.cssfalse
                    • Avira URL Cloud: safe
                    unknown
                    http://www.anovis.com.br/images/novo-logo-uniao5.pngfalse
                    • Avira URL Cloud: safe
                    unknown
                    http://www.anovis.com.br/bootstrap/js/bootstrap.min.jsfalse
                    • Avira URL Cloud: safe
                    unknown
                    http://www.anovis.com.br/images/rodape-site-anovis-mobile.jpgfalse
                    • Avira URL Cloud: safe
                    unknown
                    https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                      high
                      http://www.anovis.com.br/index.phpfalse
                        unknown
                        http://www.anovis.com.br/images/band_en.giffalse
                        • Avira URL Cloud: safe
                        unknown
                        http://www.anovis.com.br/false
                          unknown
                          http://www.anovis.com.br/false
                            unknown
                            http://www.anovis.com.br/ilightbox/src/metro-black-skin/skin.cssfalse
                            • Avira URL Cloud: safe
                            unknown
                            http://www.anovis.com.br/images/seta-naveg-baixo-2.pngfalse
                            • Avira URL Cloud: safe
                            unknown
                            http://www.anovis.com.br/ilightbox/src/metro-white-skin/skin.cssfalse
                            • Avira URL Cloud: safe
                            unknown
                            http://www.anovis.com.br/ilightbox/src/mac-skin/skin.cssfalse
                            • Avira URL Cloud: safe
                            unknown
                            https://oss.maxcdn.com/respond/1.4.2/respond.min.jsfalse
                              high
                              http://www.anovis.com.br/ilightbox/src/js/ilightbox.packed.jsfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://www.anovis.com.br/ilightbox/src/css/ilightbox.cssfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://www.anovis.com.br/images/icone-solidos-orais.pngfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://www.anovis.com.br/images/home1.jpgfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://www.anovis.com.br/images/slide-footer-2.jpgfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://www.anovis.com.br/ilightbox/src/smooth-skin/skin.cssfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://www.anovis.com.br/ilightbox/src/dark-skin/skin.cssfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://www.anovis.com.br/images/galeria-4.jpgfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://www.anovis.com.br/respond.src.jsfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://www.anovis.com.br/images/band_br.giffalse
                              • Avira URL Cloud: safe
                              unknown
                              http://www.anovis.com.br/ilightbox/src/js/jquery.mousewheel.jsfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://www.anovis.com.br/images/logo-anovis.pngfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://www.anovis.com.br/images/unidade-brasilia-2.jpgfalse
                              • Avira URL Cloud: safe
                              unknown
                              https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                                high
                                http://www.anovis.com.br/images/unidade-taboao.jpgfalse
                                • Avira URL Cloud: safe
                                unknown
                                http://www.anovis.com.br/images/unidade-pouso.jpgfalse
                                • Avira URL Cloud: safe
                                unknown
                                http://www.anovis.com.br/index.phpfalse
                                  unknown
                                  http://www.anovis.com.br/images/slide-footer-1.jpgfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  http://www.anovis.com.br/ilightbox/src/parade-skin/skin.cssfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  http://www.anovis.com.br/favicon.icofalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  http://www.anovis.com.br/images/icone-semi-solidos.pngfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  http://www.anovis.com.br/images/galeria-1.jpgfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  • No. of IPs < 25%
                                  • 25% < No. of IPs < 50%
                                  • 50% < No. of IPs < 75%
                                  • 75% < No. of IPs
                                  IPDomainCountryFlagASNASN NameMalicious
                                  186.202.188.90
                                  anovis.websiteseguro.comBrazil
                                  27715LocawebServicosdeInternetSABRfalse
                                  179.188.52.129
                                  www.anovis.com.brBrazil
                                  27715LocawebServicosdeInternetSABRfalse
                                  23.111.8.154
                                  osscdn.netdnasa9.netdna-cdn.comUnited States
                                  33438HIGHWINDS2USfalse
                                  239.255.255.250
                                  unknownReserved
                                  unknownunknownfalse
                                  142.251.143.132
                                  www.google.comUnited States
                                  15169GOOGLEUSfalse
                                  142.251.143.141
                                  accounts.google.comUnited States
                                  15169GOOGLEUSfalse
                                  142.251.143.174
                                  clients.l.google.comUnited States
                                  15169GOOGLEUSfalse
                                  IP
                                  192.168.2.1
                                  127.0.0.1
                                  Joe Sandbox Version:36.0.0 Rainbow Opal
                                  Analysis ID:736963
                                  Start date and time:2022-11-03 12:37:29 +01:00
                                  Joe Sandbox Product:CloudBasic
                                  Overall analysis duration:0h 6m 20s
                                  Hypervisor based Inspection enabled:false
                                  Report type:light
                                  Cookbook file name:browseurl.jbs
                                  Sample URL:http://www.anovis.com.br/
                                  Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                  Number of analysed new started processes analysed:5
                                  Number of new started drivers analysed:0
                                  Number of existing processes analysed:0
                                  Number of existing drivers analysed:0
                                  Number of injected processes analysed:0
                                  Technologies:
                                  • HCA enabled
                                  • EGA enabled
                                  • HDC enabled
                                  • AMSI enabled
                                  Analysis Mode:default
                                  Analysis stop reason:Timeout
                                  Detection:CLEAN
                                  Classification:clean0.win@25/0@7/9
                                  EGA Information:Failed
                                  HDC Information:Failed
                                  HCA Information:
                                  • Successful, ratio: 100%
                                  • Number of executed functions: 0
                                  • Number of non-executed functions: 0
                                  Cookbook Comments:
                                  • Browse: http://www.anovis.com.br/index.php
                                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, conhost.exe
                                  • HTTP Packets have been reduced
                                  • TCP Packets have been reduced to 100
                                  • Excluded IPs from analysis (whitelisted): 142.251.143.131, 142.251.143.202, 34.104.35.123, 142.251.143.163, 142.251.143.142
                                  • Excluded domains from analysis (whitelisted): fonts.googleapis.com, edgedl.me.gvt1.com, ajax.googleapis.com, fonts.gstatic.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, www.google-analytics.com
                                  • Not all processes where analyzed, report is missing behavior information
                                  • Report size getting too big, too many NtWriteVirtualMemory calls found.
                                  No simulations
                                  No context
                                  No context
                                  No context
                                  No context
                                  No context
                                  No created / dropped files found
                                  No static file info
                                  TimestampSource PortDest PortSource IPDest IP
                                  Nov 3, 2022 12:38:33.693859100 CET49699443192.168.2.5142.251.143.141
                                  Nov 3, 2022 12:38:33.693908930 CET44349699142.251.143.141192.168.2.5
                                  Nov 3, 2022 12:38:33.694014072 CET49699443192.168.2.5142.251.143.141
                                  Nov 3, 2022 12:38:33.694293976 CET49700443192.168.2.5142.251.143.174
                                  Nov 3, 2022 12:38:33.694377899 CET44349700142.251.143.174192.168.2.5
                                  Nov 3, 2022 12:38:33.694511890 CET49700443192.168.2.5142.251.143.174
                                  Nov 3, 2022 12:38:33.698904991 CET49699443192.168.2.5142.251.143.141
                                  Nov 3, 2022 12:38:33.698947906 CET44349699142.251.143.141192.168.2.5
                                  Nov 3, 2022 12:38:33.699203968 CET49700443192.168.2.5142.251.143.174
                                  Nov 3, 2022 12:38:33.699235916 CET44349700142.251.143.174192.168.2.5
                                  Nov 3, 2022 12:38:33.745382071 CET4970180192.168.2.5179.188.52.129
                                  Nov 3, 2022 12:38:33.746265888 CET4970280192.168.2.5179.188.52.129
                                  Nov 3, 2022 12:38:33.846199989 CET44349699142.251.143.141192.168.2.5
                                  Nov 3, 2022 12:38:33.848047018 CET49699443192.168.2.5142.251.143.141
                                  Nov 3, 2022 12:38:33.848097086 CET44349699142.251.143.141192.168.2.5
                                  Nov 3, 2022 12:38:33.851237059 CET44349700142.251.143.174192.168.2.5
                                  Nov 3, 2022 12:38:33.851816893 CET49700443192.168.2.5142.251.143.174
                                  Nov 3, 2022 12:38:33.851876020 CET44349700142.251.143.174192.168.2.5
                                  Nov 3, 2022 12:38:33.852222919 CET44349699142.251.143.141192.168.2.5
                                  Nov 3, 2022 12:38:33.852304935 CET49699443192.168.2.5142.251.143.141
                                  Nov 3, 2022 12:38:33.852569103 CET44349700142.251.143.174192.168.2.5
                                  Nov 3, 2022 12:38:33.852643013 CET49700443192.168.2.5142.251.143.174
                                  Nov 3, 2022 12:38:33.853524923 CET44349700142.251.143.174192.168.2.5
                                  Nov 3, 2022 12:38:33.853601933 CET49700443192.168.2.5142.251.143.174
                                  Nov 3, 2022 12:38:33.888387918 CET4970380192.168.2.5179.188.52.129
                                  Nov 3, 2022 12:38:33.959619045 CET8049701179.188.52.129192.168.2.5
                                  Nov 3, 2022 12:38:33.959717035 CET8049702179.188.52.129192.168.2.5
                                  Nov 3, 2022 12:38:33.959871054 CET4970180192.168.2.5179.188.52.129
                                  Nov 3, 2022 12:38:33.959950924 CET4970280192.168.2.5179.188.52.129
                                  Nov 3, 2022 12:38:33.962268114 CET4970280192.168.2.5179.188.52.129
                                  Nov 3, 2022 12:38:34.103055000 CET8049703179.188.52.129192.168.2.5
                                  Nov 3, 2022 12:38:34.103153944 CET4970380192.168.2.5179.188.52.129
                                  Nov 3, 2022 12:38:34.147751093 CET49704443192.168.2.5142.251.143.132
                                  Nov 3, 2022 12:38:34.147810936 CET44349704142.251.143.132192.168.2.5
                                  Nov 3, 2022 12:38:34.147881031 CET49704443192.168.2.5142.251.143.132
                                  Nov 3, 2022 12:38:34.148160934 CET49704443192.168.2.5142.251.143.132
                                  Nov 3, 2022 12:38:34.148178101 CET44349704142.251.143.132192.168.2.5
                                  Nov 3, 2022 12:38:34.177541971 CET8049702179.188.52.129192.168.2.5
                                  Nov 3, 2022 12:38:34.177606106 CET8049702179.188.52.129192.168.2.5
                                  Nov 3, 2022 12:38:34.177650928 CET8049702179.188.52.129192.168.2.5
                                  Nov 3, 2022 12:38:34.177692890 CET8049702179.188.52.129192.168.2.5
                                  Nov 3, 2022 12:38:34.177736044 CET8049702179.188.52.129192.168.2.5
                                  Nov 3, 2022 12:38:34.177755117 CET4970280192.168.2.5179.188.52.129
                                  Nov 3, 2022 12:38:34.177778959 CET8049702179.188.52.129192.168.2.5
                                  Nov 3, 2022 12:38:34.177819967 CET8049702179.188.52.129192.168.2.5
                                  Nov 3, 2022 12:38:34.177824974 CET4970280192.168.2.5179.188.52.129
                                  Nov 3, 2022 12:38:34.177865028 CET8049702179.188.52.129192.168.2.5
                                  Nov 3, 2022 12:38:34.177902937 CET4970280192.168.2.5179.188.52.129
                                  Nov 3, 2022 12:38:34.177913904 CET8049702179.188.52.129192.168.2.5
                                  Nov 3, 2022 12:38:34.177958965 CET8049702179.188.52.129192.168.2.5
                                  Nov 3, 2022 12:38:34.177966118 CET4970280192.168.2.5179.188.52.129
                                  Nov 3, 2022 12:38:34.178134918 CET8049702179.188.52.129192.168.2.5
                                  Nov 3, 2022 12:38:34.178186893 CET4970280192.168.2.5179.188.52.129
                                  Nov 3, 2022 12:38:34.187979937 CET49699443192.168.2.5142.251.143.141
                                  Nov 3, 2022 12:38:34.188047886 CET44349699142.251.143.141192.168.2.5
                                  Nov 3, 2022 12:38:34.188265085 CET49699443192.168.2.5142.251.143.141
                                  Nov 3, 2022 12:38:34.188281059 CET44349699142.251.143.141192.168.2.5
                                  Nov 3, 2022 12:38:34.188441038 CET44349699142.251.143.141192.168.2.5
                                  Nov 3, 2022 12:38:34.188930988 CET49700443192.168.2.5142.251.143.174
                                  Nov 3, 2022 12:38:34.189042091 CET44349700142.251.143.174192.168.2.5
                                  Nov 3, 2022 12:38:34.189285994 CET44349700142.251.143.174192.168.2.5
                                  Nov 3, 2022 12:38:34.189333916 CET49700443192.168.2.5142.251.143.174
                                  Nov 3, 2022 12:38:34.189358950 CET44349700142.251.143.174192.168.2.5
                                  Nov 3, 2022 12:38:34.236529112 CET44349704142.251.143.132192.168.2.5
                                  Nov 3, 2022 12:38:34.240012884 CET49704443192.168.2.5142.251.143.132
                                  Nov 3, 2022 12:38:34.240048885 CET44349704142.251.143.132192.168.2.5
                                  Nov 3, 2022 12:38:34.242371082 CET44349704142.251.143.132192.168.2.5
                                  Nov 3, 2022 12:38:34.242554903 CET49704443192.168.2.5142.251.143.132
                                  Nov 3, 2022 12:38:34.245021105 CET44349700142.251.143.174192.168.2.5
                                  Nov 3, 2022 12:38:34.245167017 CET49700443192.168.2.5142.251.143.174
                                  Nov 3, 2022 12:38:34.245196104 CET44349700142.251.143.174192.168.2.5
                                  Nov 3, 2022 12:38:34.245342016 CET44349700142.251.143.174192.168.2.5
                                  Nov 3, 2022 12:38:34.245424032 CET49700443192.168.2.5142.251.143.174
                                  Nov 3, 2022 12:38:34.245528936 CET49704443192.168.2.5142.251.143.132
                                  Nov 3, 2022 12:38:34.245543003 CET44349704142.251.143.132192.168.2.5
                                  Nov 3, 2022 12:38:34.245763063 CET44349704142.251.143.132192.168.2.5
                                  Nov 3, 2022 12:38:34.247982025 CET49700443192.168.2.5142.251.143.174
                                  Nov 3, 2022 12:38:34.248004913 CET44349700142.251.143.174192.168.2.5
                                  Nov 3, 2022 12:38:34.262506008 CET44349699142.251.143.141192.168.2.5
                                  Nov 3, 2022 12:38:34.262643099 CET49699443192.168.2.5142.251.143.141
                                  Nov 3, 2022 12:38:34.262686014 CET44349699142.251.143.141192.168.2.5
                                  Nov 3, 2022 12:38:34.263084888 CET44349699142.251.143.141192.168.2.5
                                  Nov 3, 2022 12:38:34.263211966 CET49699443192.168.2.5142.251.143.141
                                  Nov 3, 2022 12:38:34.267077923 CET49699443192.168.2.5142.251.143.141
                                  Nov 3, 2022 12:38:34.267132044 CET44349699142.251.143.141192.168.2.5
                                  Nov 3, 2022 12:38:34.285434961 CET4970180192.168.2.5179.188.52.129
                                  Nov 3, 2022 12:38:34.286411047 CET4970380192.168.2.5179.188.52.129
                                  Nov 3, 2022 12:38:34.288014889 CET4970580192.168.2.5179.188.52.129
                                  Nov 3, 2022 12:38:34.289190054 CET4970680192.168.2.5179.188.52.129
                                  Nov 3, 2022 12:38:34.290496111 CET4970780192.168.2.5179.188.52.129
                                  Nov 3, 2022 12:38:34.316392899 CET49704443192.168.2.5142.251.143.132
                                  Nov 3, 2022 12:38:34.316420078 CET44349704142.251.143.132192.168.2.5
                                  Nov 3, 2022 12:38:34.368261099 CET49710443192.168.2.523.111.8.154
                                  Nov 3, 2022 12:38:34.368325949 CET4434971023.111.8.154192.168.2.5
                                  Nov 3, 2022 12:38:34.368432999 CET49710443192.168.2.523.111.8.154
                                  Nov 3, 2022 12:38:34.368568897 CET49711443192.168.2.523.111.8.154
                                  Nov 3, 2022 12:38:34.368634939 CET4434971123.111.8.154192.168.2.5
                                  Nov 3, 2022 12:38:34.368694067 CET49711443192.168.2.523.111.8.154
                                  Nov 3, 2022 12:38:34.369052887 CET49710443192.168.2.523.111.8.154
                                  Nov 3, 2022 12:38:34.369082928 CET4434971023.111.8.154192.168.2.5
                                  TimestampSource PortDest PortSource IPDest IP
                                  Nov 3, 2022 12:38:33.492523909 CET6064953192.168.2.58.8.8.8
                                  Nov 3, 2022 12:38:33.502151966 CET5144153192.168.2.58.8.8.8
                                  Nov 3, 2022 12:38:33.504219055 CET4917753192.168.2.58.8.8.8
                                  Nov 3, 2022 12:38:33.520628929 CET53606498.8.8.8192.168.2.5
                                  Nov 3, 2022 12:38:33.521831036 CET53491778.8.8.8192.168.2.5
                                  Nov 3, 2022 12:38:33.739866972 CET53514418.8.8.8192.168.2.5
                                  Nov 3, 2022 12:38:34.083246946 CET6145253192.168.2.58.8.8.8
                                  Nov 3, 2022 12:38:34.103108883 CET53614528.8.8.8192.168.2.5
                                  Nov 3, 2022 12:38:34.301270962 CET5675153192.168.2.58.8.8.8
                                  Nov 3, 2022 12:38:34.321058035 CET53567518.8.8.8192.168.2.5
                                  Nov 3, 2022 12:38:35.970410109 CET5506853192.168.2.58.8.8.8
                                  Nov 3, 2022 12:38:36.215053082 CET53550688.8.8.8192.168.2.5
                                  Nov 3, 2022 12:38:41.266324997 CET6551353192.168.2.58.8.8.8
                                  Nov 3, 2022 12:38:41.532474041 CET53655138.8.8.8192.168.2.5
                                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                  Nov 3, 2022 12:38:33.492523909 CET192.168.2.58.8.8.80x397aStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
                                  Nov 3, 2022 12:38:33.502151966 CET192.168.2.58.8.8.80xe735Standard query (0)www.anovis.com.brA (IP address)IN (0x0001)false
                                  Nov 3, 2022 12:38:33.504219055 CET192.168.2.58.8.8.80xa996Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                                  Nov 3, 2022 12:38:34.083246946 CET192.168.2.58.8.8.80xaf99Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                  Nov 3, 2022 12:38:34.301270962 CET192.168.2.58.8.8.80x3c91Standard query (0)oss.maxcdn.comA (IP address)IN (0x0001)false
                                  Nov 3, 2022 12:38:35.970410109 CET192.168.2.58.8.8.80x38caStandard query (0)anovis.websiteseguro.comA (IP address)IN (0x0001)false
                                  Nov 3, 2022 12:38:41.266324997 CET192.168.2.58.8.8.80x609eStandard query (0)www.anovis.com.brA (IP address)IN (0x0001)false
                                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                  Nov 3, 2022 12:38:33.520628929 CET8.8.8.8192.168.2.50x397aNo error (0)accounts.google.com142.251.143.141A (IP address)IN (0x0001)false
                                  Nov 3, 2022 12:38:33.521831036 CET8.8.8.8192.168.2.50xa996No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                                  Nov 3, 2022 12:38:33.521831036 CET8.8.8.8192.168.2.50xa996No error (0)clients.l.google.com142.251.143.174A (IP address)IN (0x0001)false
                                  Nov 3, 2022 12:38:33.739866972 CET8.8.8.8192.168.2.50xe735No error (0)www.anovis.com.br179.188.52.129A (IP address)IN (0x0001)false
                                  Nov 3, 2022 12:38:34.103108883 CET8.8.8.8192.168.2.50xaf99No error (0)www.google.com142.251.143.132A (IP address)IN (0x0001)false
                                  Nov 3, 2022 12:38:34.321058035 CET8.8.8.8192.168.2.50x3c91No error (0)oss.maxcdn.comosscdn.netdnasa9.netdna-cdn.comCNAME (Canonical name)IN (0x0001)false
                                  Nov 3, 2022 12:38:34.321058035 CET8.8.8.8192.168.2.50x3c91No error (0)osscdn.netdnasa9.netdna-cdn.com23.111.8.154A (IP address)IN (0x0001)false
                                  Nov 3, 2022 12:38:36.215053082 CET8.8.8.8192.168.2.50x38caNo error (0)anovis.websiteseguro.com186.202.188.90A (IP address)IN (0x0001)false
                                  Nov 3, 2022 12:38:41.532474041 CET8.8.8.8192.168.2.50x609eNo error (0)www.anovis.com.br179.188.52.129A (IP address)IN (0x0001)false
                                  • accounts.google.com
                                  • clients2.google.com
                                  • www.anovis.com.br
                                    • oss.maxcdn.com

                                  Click to jump to process

                                  Target ID:0
                                  Start time:12:38:27
                                  Start date:03/11/2022
                                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                                  Imagebase:0x7ff7d31b0000
                                  File size:2851656 bytes
                                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:low

                                  Target ID:1
                                  Start time:12:38:28
                                  Start date:03/11/2022
                                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                  Wow64 process (32bit):false
                                  Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1960 --field-trial-handle=1772,i,1740651327127756512,7249462608667158532,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                                  Imagebase:0x7ff7d31b0000
                                  File size:2851656 bytes
                                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:low

                                  Target ID:2
                                  Start time:12:38:29
                                  Start date:03/11/2022
                                  Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.anovis.com.br/
                                  Imagebase:0x7ff7d31b0000
                                  File size:2851656 bytes
                                  MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:low

                                  No disassembly