Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Payslip 28.11.22.html

Overview

General Information

Sample Name:Payslip 28.11.22.html
Analysis ID:756113
MD5:b10534ae0a0f1898d66dc74203e858a1
SHA1:aaf347a354f63f7192bbe436401f4228251a1b82
SHA256:808131c12aff58fce72de031c64535333f0b6a171bfcebd45732587487447cfd
Tags:html
Infos:

Detection

Score:21
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Phishing site detected (based on image similarity)
JA3 SSL client fingerprint seen in connection with other malware
IP address seen in connection with other malware

Classification

  • System is w10x64
  • chrome.exe (PID: 4796 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 6036 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1960 --field-trial-handle=1748,i,843581558575697743,11274918621816804293,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 1504 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "C:\Users\user\Desktop\Payslip 28.11.22.html MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

Phishing

barindex
Source: embeddedMatcher: Found strong image similarity, brand: Microsoft image: 30718.1.img.1.gfk.csv EE5C8D9FB6248C938FD0DC19370E90BD
Source: embeddedMatcher: Found strong image similarity, brand: Microsoft image: 73035.2.img.1.gfk.csv EE5C8D9FB6248C938FD0DC19370E90BD
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownHTTPS traffic detected: 13.107.219.60:443 -> 192.168.2.3:49728 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.219.60:443 -> 192.168.2.3:49729 version: TLS 1.2
Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
Source: Joe Sandbox ViewIP Address: 13.107.219.60 13.107.219.60
Source: unknownDNS traffic detected: queries for: clients2.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49702 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /tech/host9/admin/js/mj.php?ar=d29yZA== HTTP/1.1Host: socialgrow.co.inConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /font-awesome/4.7.0/css/font-awesome.min.css HTTP/1.1Host: maxcdn.bootstrapcdn.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/microsoft_logo_ee5c8d9fb6248c938fd0dc19370e90bd.svg HTTP/1.1Host: logincdn.msauth.netConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /font-awesome/4.7.0/fonts/fontawesome-webfont.woff2?v=4.7.0 HTTP/1.1Host: maxcdn.bootstrapcdn.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"Origin: nullsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://maxcdn.bootstrapcdn.com/font-awesome/4.7.0/css/font-awesome.min.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ajax/libs/font-awesome/4.7.0/css/font-awesome.css HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"Origin: nullsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: styleAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/picker_verify_call_fe87496cc7a44412f7893a72099c120a.svg HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/picker_verify_sms_27a6d18b56f46818420e60a773c36d4e.svg HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/picker_verify_fluent_authenticator_b59c16ca9bf156438a8a96d45e33db64.svg HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/picker_verify_fluent_authenticator_b59c16ca9bf156438a8a96d45e33db64.svg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: aadcdn.msauth.net
Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/picker_verify_call_fe87496cc7a44412f7893a72099c120a.svg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: aadcdn.msauth.net
Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/picker_verify_sms_27a6d18b56f46818420e60a773c36d4e.svg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: aadcdn.msauth.net
Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/picker_verify_call_fe87496cc7a44412f7893a72099c120a.svg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: aadcdn.msauth.netIf-Modified-Since: Fri, 17 Jan 2020 19:28:39 GMTIf-None-Match: 0x8D79B83749623C9
Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/picker_verify_sms_27a6d18b56f46818420e60a773c36d4e.svg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: aadcdn.msauth.netIf-Modified-Since: Fri, 17 Jan 2020 19:28:39 GMTIf-None-Match: 0x8D79B8374CE7F93
Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/picker_verify_fluent_authenticator_b59c16ca9bf156438a8a96d45e33db64.svg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: aadcdn.msauth.netIf-Modified-Since: Fri, 11 Mar 2022 11:11:29 GMTIf-None-Match: 0x8DA034FE445C10D
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=PENDING+904; AEC=AakniGO7HqlHWlnoY-P22_SwwnNSfVGxlF1NgK5nuj5WLe313NyJi16g7z4; SOCS=CAISHAgCEhJnd3NfMjAyMjA4MDgtMF9SQzEaAmVuIAEaBgiAvOuXBg; NID=511=nUT82hOv6CVwMNqDg-sTtCMJJ6SQ1v_cCpfCpf5nt8EolEbal01GWFyjG01tqWQgh9ciRU880J6nLd2gdbhAJs44PsHAZaVQAFIbrqe2FmFgjrAAK7W9Z8u5LDvwsuZRng98jP6E23SJ4fsPIs326YmnuCwa92dRRCcB6MNeI_o
Source: unknownHTTPS traffic detected: 13.107.219.60:443 -> 192.168.2.3:49728 version: TLS 1.2
Source: unknownHTTPS traffic detected: 13.107.219.60:443 -> 192.168.2.3:49729 version: TLS 1.2
Source: classification engineClassification label: sus21.phis.winHTML@28/0@9/11
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1960 --field-trial-handle=1748,i,843581558575697743,11274918621816804293,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "C:\Users\user\Desktop\Payslip 28.11.22.html
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1960 --field-trial-handle=1748,i,843581558575697743,11274918621816804293,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
Payslip 28.11.22.html2%ReversingLabs
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
socialgrow.co.in0%VirustotalBrowse
cs1227.wpc.alphacdn.net0%VirustotalBrowse
part-0032.t-0009.fbs1-t-msedge.net0%VirustotalBrowse
SourceDetectionScannerLabelLink
https://socialgrow.co.in/tech/host9/admin/js/mj.php?ar=d29yZA==0%Avira URL Cloudsafe
https://socialgrow.co.in/tech/host9/9c80cd4.php0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
socialgrow.co.in
65.21.127.94
truefalseunknown
accounts.google.com
172.217.168.45
truefalse
    high
    cdnjs.cloudflare.com
    104.17.25.14
    truefalse
      high
      maxcdn.bootstrapcdn.com
      104.18.10.207
      truefalse
        high
        www.google.com
        172.217.168.36
        truefalse
          high
          cs1227.wpc.alphacdn.net
          192.229.221.185
          truefalseunknown
          clients.l.google.com
          142.250.203.110
          truefalse
            high
            part-0032.t-0009.fbs1-t-msedge.net
            13.107.219.60
            truefalseunknown
            clients2.google.com
            unknown
            unknownfalse
              high
              code.jquery.com
              unknown
              unknownfalse
                high
                cdn.jsdelivr.net
                unknown
                unknownfalse
                  high
                  NameMaliciousAntivirus DetectionReputation
                  https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                    high
                    https://maxcdn.bootstrapcdn.com/font-awesome/4.7.0/css/font-awesome.min.cssfalse
                      high
                      https://cdnjs.cloudflare.com/ajax/libs/font-awesome/4.7.0/css/font-awesome.cssfalse
                        high
                        https://maxcdn.bootstrapcdn.com/font-awesome/4.7.0/fonts/fontawesome-webfont.woff2?v=4.7.0false
                          high
                          file:///C:/Users/user/Desktop/Payslip%2028.11.22.htmlfalse
                            low
                            https://socialgrow.co.in/tech/host9/admin/js/mj.php?ar=d29yZA==false
                            • Avira URL Cloud: safe
                            unknown
                            https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                              high
                              https://socialgrow.co.in/tech/host9/9c80cd4.phpfalse
                              • Avira URL Cloud: safe
                              unknown
                              • No. of IPs < 25%
                              • 25% < No. of IPs < 50%
                              • 50% < No. of IPs < 75%
                              • 75% < No. of IPs
                              IPDomainCountryFlagASNASN NameMalicious
                              65.21.127.94
                              socialgrow.co.inUnited States
                              199592CP-ASDEfalse
                              13.107.219.60
                              part-0032.t-0009.fbs1-t-msedge.netUnited States
                              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                              104.18.10.207
                              maxcdn.bootstrapcdn.comUnited States
                              13335CLOUDFLARENETUSfalse
                              142.250.203.110
                              clients.l.google.comUnited States
                              15169GOOGLEUSfalse
                              172.217.168.45
                              accounts.google.comUnited States
                              15169GOOGLEUSfalse
                              172.217.168.36
                              www.google.comUnited States
                              15169GOOGLEUSfalse
                              239.255.255.250
                              unknownReserved
                              unknownunknownfalse
                              192.229.221.185
                              cs1227.wpc.alphacdn.netUnited States
                              15133EDGECASTUSfalse
                              104.17.25.14
                              cdnjs.cloudflare.comUnited States
                              13335CLOUDFLARENETUSfalse
                              IP
                              192.168.2.1
                              127.0.0.1
                              Joe Sandbox Version:36.0.0 Rainbow Opal
                              Analysis ID:756113
                              Start date and time:2022-11-29 16:45:13 +01:00
                              Joe Sandbox Product:CloudBasic
                              Overall analysis duration:0h 7m 26s
                              Hypervisor based Inspection enabled:false
                              Report type:light
                              Sample file name:Payslip 28.11.22.html
                              Cookbook file name:defaultwindowshtmlcookbook.jbs
                              Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                              Number of analysed new started processes analysed:17
                              Number of new started drivers analysed:0
                              Number of existing processes analysed:0
                              Number of existing drivers analysed:0
                              Number of injected processes analysed:0
                              Technologies:
                              • HCA enabled
                              • EGA enabled
                              • HDC enabled
                              • AMSI enabled
                              Analysis Mode:default
                              Analysis stop reason:Timeout
                              Detection:SUS
                              Classification:sus21.phis.winHTML@28/0@9/11
                              EGA Information:Failed
                              HDC Information:Failed
                              HCA Information:
                              • Successful, ratio: 100%
                              • Number of executed functions: 0
                              • Number of non-executed functions: 0
                              Cookbook Comments:
                              • Found application associated with file extension: .html
                              • Browse: https://privacy.microsoft.com/fr/privacystatement
                              • Exclude process from analysis (whitelisted): MpCmdRun.exe, audiodg.exe, WMIADAP.exe, SgrmBroker.exe, conhost.exe, backgroundTaskHost.exe, svchost.exe
                              • TCP Packets have been reduced to 100
                              • Excluded IPs from analysis (whitelisted): 172.217.168.67, 34.104.35.123, 104.16.86.20, 104.16.85.20, 104.16.87.20, 104.16.88.20, 104.16.89.20, 69.16.175.10, 69.16.175.42
                              • Excluded domains from analysis (whitelisted): logincdn.msauth.net, cdn.jsdelivr.net.cdn.cloudflare.net, cds.s5x3j6q5.hwcdn.net, fs.microsoft.com, aadcdnoriginwus2.azureedge.net, lgincdnvzeuno.ec.azureedge.net, clientservices.googleapis.com, aadcdn.msauth.net, firstparty-azurefd-prod.trafficmanager.net, lgincdnvzeuno.azureedge.net, edgedl.me.gvt1.com, lgincdn.trafficmanager.net, update.googleapis.com, aadcdnoriginwus2.afd.azureedge.net, global-entry-afdthirdparty-fallback.trafficmanager.net
                              • Not all processes where analyzed, report is missing behavior information
                              • Report size getting too big, too many NtWriteVirtualMemory calls found.
                              No simulations
                              No context
                              No context
                              No context
                              No context
                              No context
                              No created / dropped files found
                              File type:HTML document, ASCII text, with very long lines (616), with CRLF line terminators
                              Entropy (8bit):5.41578686683262
                              TrID:
                              • HyperText Markup Language (12001/1) 66.65%
                              • HyperText Markup Language (6006/1) 33.35%
                              File name:Payslip 28.11.22.html
                              File size:1639
                              MD5:b10534ae0a0f1898d66dc74203e858a1
                              SHA1:aaf347a354f63f7192bbe436401f4228251a1b82
                              SHA256:808131c12aff58fce72de031c64535333f0b6a171bfcebd45732587487447cfd
                              SHA512:47521d043fbe5478154e27ba4289b66c5ccbd506a75d059279f968cf418ba489f8a7001715b6f72fac9b3a2ee728e6705af9ed70c98f7662df0f7bcea82fc8a1
                              SSDEEP:24:DwK1VaODNXKCQwQkpi6c9P/IwkMPtNcz4rMR5dH5kVQozr31HPSTi6fgxkW1zYMf:D7aODxtQo3MPt2ErgaeozdaN6kwzPf
                              TLSH:BD315F3590339D3188A34CB8B4C5AF2E209EC109CB0658452AE88CEB67E7C460266EE9
                              File Content Preview:<html>..<head>..</head>..<body>..<div class="form-group row" style="display:none;"><div class="col-md-3"><label for="price_per_item" class="font-weight-bold">Price<span class="badge badge-primary" id="next_discount">B 5.00 % discount</span></label><input
                              TimestampSource PortDest PortSource IPDest IP
                              Nov 29, 2022 16:46:11.793051004 CET49701443192.168.2.3172.217.168.45
                              Nov 29, 2022 16:46:11.793107986 CET44349701172.217.168.45192.168.2.3
                              Nov 29, 2022 16:46:11.793231964 CET49701443192.168.2.3172.217.168.45
                              Nov 29, 2022 16:46:11.797557116 CET49702443192.168.2.3142.250.203.110
                              Nov 29, 2022 16:46:11.797610044 CET44349702142.250.203.110192.168.2.3
                              Nov 29, 2022 16:46:11.797708988 CET49702443192.168.2.3142.250.203.110
                              Nov 29, 2022 16:46:11.799981117 CET49704443192.168.2.3172.217.168.45
                              Nov 29, 2022 16:46:11.800015926 CET44349704172.217.168.45192.168.2.3
                              Nov 29, 2022 16:46:11.800105095 CET49704443192.168.2.3172.217.168.45
                              Nov 29, 2022 16:46:11.800843954 CET49705443192.168.2.3142.250.203.110
                              Nov 29, 2022 16:46:11.800873041 CET44349705142.250.203.110192.168.2.3
                              Nov 29, 2022 16:46:11.800957918 CET49705443192.168.2.3142.250.203.110
                              Nov 29, 2022 16:46:11.802480936 CET49701443192.168.2.3172.217.168.45
                              Nov 29, 2022 16:46:11.802505016 CET44349701172.217.168.45192.168.2.3
                              Nov 29, 2022 16:46:11.803487062 CET49702443192.168.2.3142.250.203.110
                              Nov 29, 2022 16:46:11.803529024 CET44349702142.250.203.110192.168.2.3
                              Nov 29, 2022 16:46:11.858628988 CET44349701172.217.168.45192.168.2.3
                              Nov 29, 2022 16:46:11.872416019 CET44349702142.250.203.110192.168.2.3
                              Nov 29, 2022 16:46:11.903265953 CET49701443192.168.2.3172.217.168.45
                              Nov 29, 2022 16:46:11.915292978 CET49702443192.168.2.3142.250.203.110
                              Nov 29, 2022 16:46:12.126543999 CET49704443192.168.2.3172.217.168.45
                              Nov 29, 2022 16:46:12.126569986 CET44349704172.217.168.45192.168.2.3
                              Nov 29, 2022 16:46:12.126974106 CET49705443192.168.2.3142.250.203.110
                              Nov 29, 2022 16:46:12.127000093 CET44349705142.250.203.110192.168.2.3
                              Nov 29, 2022 16:46:12.127907991 CET49702443192.168.2.3142.250.203.110
                              Nov 29, 2022 16:46:12.127950907 CET44349702142.250.203.110192.168.2.3
                              Nov 29, 2022 16:46:12.128423929 CET49701443192.168.2.3172.217.168.45
                              Nov 29, 2022 16:46:12.128454924 CET44349701172.217.168.45192.168.2.3
                              Nov 29, 2022 16:46:12.129081011 CET44349702142.250.203.110192.168.2.3
                              Nov 29, 2022 16:46:12.129162073 CET49702443192.168.2.3142.250.203.110
                              Nov 29, 2022 16:46:12.131283045 CET44349701172.217.168.45192.168.2.3
                              Nov 29, 2022 16:46:12.131364107 CET49701443192.168.2.3172.217.168.45
                              Nov 29, 2022 16:46:12.131558895 CET44349702142.250.203.110192.168.2.3
                              Nov 29, 2022 16:46:12.131623030 CET49702443192.168.2.3142.250.203.110
                              Nov 29, 2022 16:46:12.213440895 CET44349705142.250.203.110192.168.2.3
                              Nov 29, 2022 16:46:12.235071898 CET44349704172.217.168.45192.168.2.3
                              Nov 29, 2022 16:46:12.303354979 CET49704443192.168.2.3172.217.168.45
                              Nov 29, 2022 16:46:12.315280914 CET49705443192.168.2.3142.250.203.110
                              Nov 29, 2022 16:46:12.956907988 CET49707443192.168.2.365.21.127.94
                              Nov 29, 2022 16:46:12.956967115 CET4434970765.21.127.94192.168.2.3
                              Nov 29, 2022 16:46:12.957055092 CET49707443192.168.2.365.21.127.94
                              Nov 29, 2022 16:46:12.957256079 CET49704443192.168.2.3172.217.168.45
                              Nov 29, 2022 16:46:12.957315922 CET44349704172.217.168.45192.168.2.3
                              Nov 29, 2022 16:46:12.958776951 CET44349704172.217.168.45192.168.2.3
                              Nov 29, 2022 16:46:12.958842993 CET44349704172.217.168.45192.168.2.3
                              Nov 29, 2022 16:46:12.958869934 CET49704443192.168.2.3172.217.168.45
                              Nov 29, 2022 16:46:12.972431898 CET49705443192.168.2.3142.250.203.110
                              Nov 29, 2022 16:46:12.972459078 CET44349705142.250.203.110192.168.2.3
                              Nov 29, 2022 16:46:12.972970963 CET44349705142.250.203.110192.168.2.3
                              Nov 29, 2022 16:46:12.972987890 CET44349705142.250.203.110192.168.2.3
                              Nov 29, 2022 16:46:12.973037004 CET49705443192.168.2.3142.250.203.110
                              Nov 29, 2022 16:46:12.973882914 CET44349705142.250.203.110192.168.2.3
                              Nov 29, 2022 16:46:12.973926067 CET49705443192.168.2.3142.250.203.110
                              Nov 29, 2022 16:46:13.000307083 CET49704443192.168.2.3172.217.168.45
                              Nov 29, 2022 16:46:13.095467091 CET49708443192.168.2.365.21.127.94
                              Nov 29, 2022 16:46:13.095529079 CET4434970865.21.127.94192.168.2.3
                              Nov 29, 2022 16:46:13.095632076 CET49708443192.168.2.365.21.127.94
                              Nov 29, 2022 16:46:13.096370935 CET49707443192.168.2.365.21.127.94
                              Nov 29, 2022 16:46:13.096390963 CET4434970765.21.127.94192.168.2.3
                              Nov 29, 2022 16:46:13.099550009 CET49708443192.168.2.365.21.127.94
                              Nov 29, 2022 16:46:13.099560976 CET4434970865.21.127.94192.168.2.3
                              Nov 29, 2022 16:46:13.186755896 CET4434970765.21.127.94192.168.2.3
                              Nov 29, 2022 16:46:13.194175005 CET4434970865.21.127.94192.168.2.3
                              Nov 29, 2022 16:46:13.315391064 CET49708443192.168.2.365.21.127.94
                              Nov 29, 2022 16:46:13.386915922 CET4434970765.21.127.94192.168.2.3
                              Nov 29, 2022 16:46:13.387162924 CET49707443192.168.2.365.21.127.94
                              Nov 29, 2022 16:46:13.536859989 CET49708443192.168.2.365.21.127.94
                              Nov 29, 2022 16:46:13.536899090 CET4434970865.21.127.94192.168.2.3
                              Nov 29, 2022 16:46:13.537621975 CET49702443192.168.2.3142.250.203.110
                              Nov 29, 2022 16:46:13.537669897 CET44349702142.250.203.110192.168.2.3
                              Nov 29, 2022 16:46:13.538238049 CET49705443192.168.2.3142.250.203.110
                              Nov 29, 2022 16:46:13.538269997 CET44349705142.250.203.110192.168.2.3
                              Nov 29, 2022 16:46:13.538443089 CET44349705142.250.203.110192.168.2.3
                              Nov 29, 2022 16:46:13.538600922 CET49707443192.168.2.365.21.127.94
                              Nov 29, 2022 16:46:13.538621902 CET4434970765.21.127.94192.168.2.3
                              Nov 29, 2022 16:46:13.538897038 CET49701443192.168.2.3172.217.168.45
                              Nov 29, 2022 16:46:13.538921118 CET44349701172.217.168.45192.168.2.3
                              Nov 29, 2022 16:46:13.539005041 CET49704443192.168.2.3172.217.168.45
                              Nov 29, 2022 16:46:13.539033890 CET44349704172.217.168.45192.168.2.3
                              Nov 29, 2022 16:46:13.539132118 CET44349701172.217.168.45192.168.2.3
                              Nov 29, 2022 16:46:13.539232969 CET44349704172.217.168.45192.168.2.3
                              Nov 29, 2022 16:46:13.539242029 CET4434970865.21.127.94192.168.2.3
                              Nov 29, 2022 16:46:13.539280891 CET4434970865.21.127.94192.168.2.3
                              Nov 29, 2022 16:46:13.539316893 CET49708443192.168.2.365.21.127.94
                              Nov 29, 2022 16:46:13.539470911 CET44349702142.250.203.110192.168.2.3
                              Nov 29, 2022 16:46:13.540003061 CET4434970765.21.127.94192.168.2.3
                              Nov 29, 2022 16:46:13.540082932 CET49707443192.168.2.365.21.127.94
                              Nov 29, 2022 16:46:13.594898939 CET49702443192.168.2.3142.250.203.110
                              Nov 29, 2022 16:46:13.594954014 CET44349702142.250.203.110192.168.2.3
                              Nov 29, 2022 16:46:13.595103025 CET49708443192.168.2.365.21.127.94
                              Nov 29, 2022 16:46:13.595149994 CET4434970865.21.127.94192.168.2.3
                              Nov 29, 2022 16:46:13.595500946 CET49707443192.168.2.365.21.127.94
                              Nov 29, 2022 16:46:13.595541954 CET4434970765.21.127.94192.168.2.3
                              Nov 29, 2022 16:46:13.595642090 CET49701443192.168.2.3172.217.168.45
                              Nov 29, 2022 16:46:13.595675945 CET44349701172.217.168.45192.168.2.3
                              Nov 29, 2022 16:46:13.595767975 CET4434970765.21.127.94192.168.2.3
                              Nov 29, 2022 16:46:13.595818996 CET4434970865.21.127.94192.168.2.3
                              Nov 29, 2022 16:46:13.596684933 CET49708443192.168.2.365.21.127.94
                              Nov 29, 2022 16:46:13.596707106 CET4434970865.21.127.94192.168.2.3
                              Nov 29, 2022 16:46:13.600385904 CET49704443192.168.2.3172.217.168.45
                              TimestampSource PortDest PortSource IPDest IP
                              Nov 29, 2022 16:46:10.590328932 CET5784053192.168.2.38.8.8.8
                              Nov 29, 2022 16:46:10.592724085 CET5238753192.168.2.38.8.8.8
                              Nov 29, 2022 16:46:10.609754086 CET53578408.8.8.8192.168.2.3
                              Nov 29, 2022 16:46:10.620765924 CET53523878.8.8.8192.168.2.3
                              Nov 29, 2022 16:46:12.063255072 CET6062553192.168.2.38.8.8.8
                              Nov 29, 2022 16:46:12.117599010 CET53606258.8.8.8192.168.2.3
                              Nov 29, 2022 16:46:13.598861933 CET5397553192.168.2.38.8.8.8
                              Nov 29, 2022 16:46:13.627137899 CET53539758.8.8.8192.168.2.3
                              Nov 29, 2022 16:46:13.939086914 CET6058253192.168.2.38.8.8.8
                              Nov 29, 2022 16:46:13.958861113 CET53605828.8.8.8192.168.2.3
                              Nov 29, 2022 16:46:13.989461899 CET5713453192.168.2.38.8.8.8
                              Nov 29, 2022 16:46:14.003297091 CET6205053192.168.2.38.8.8.8
                              Nov 29, 2022 16:46:15.197282076 CET5770453192.168.2.38.8.8.8
                              Nov 29, 2022 16:46:15.219022989 CET53577048.8.8.8192.168.2.3
                              Nov 29, 2022 16:48:13.587235928 CET5304953192.168.2.38.8.8.8
                              Nov 29, 2022 16:48:13.606765032 CET53530498.8.8.8192.168.2.3
                              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                              Nov 29, 2022 16:46:10.590328932 CET192.168.2.38.8.8.80x73dStandard query (0)clients2.google.comA (IP address)IN (0x0001)false
                              Nov 29, 2022 16:46:10.592724085 CET192.168.2.38.8.8.80xc9c5Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                              Nov 29, 2022 16:46:12.063255072 CET192.168.2.38.8.8.80xb93dStandard query (0)socialgrow.co.inA (IP address)IN (0x0001)false
                              Nov 29, 2022 16:46:13.598861933 CET192.168.2.38.8.8.80x49ecStandard query (0)www.google.comA (IP address)IN (0x0001)false
                              Nov 29, 2022 16:46:13.939086914 CET192.168.2.38.8.8.80x8257Standard query (0)maxcdn.bootstrapcdn.comA (IP address)IN (0x0001)false
                              Nov 29, 2022 16:46:13.989461899 CET192.168.2.38.8.8.80xd98dStandard query (0)cdn.jsdelivr.netA (IP address)IN (0x0001)false
                              Nov 29, 2022 16:46:14.003297091 CET192.168.2.38.8.8.80x40aeStandard query (0)code.jquery.comA (IP address)IN (0x0001)false
                              Nov 29, 2022 16:46:15.197282076 CET192.168.2.38.8.8.80xb07dStandard query (0)cdnjs.cloudflare.comA (IP address)IN (0x0001)false
                              Nov 29, 2022 16:48:13.587235928 CET192.168.2.38.8.8.80x1ee2Standard query (0)www.google.comA (IP address)IN (0x0001)false
                              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                              Nov 29, 2022 16:46:10.609754086 CET8.8.8.8192.168.2.30x73dNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                              Nov 29, 2022 16:46:10.609754086 CET8.8.8.8192.168.2.30x73dNo error (0)clients.l.google.com142.250.203.110A (IP address)IN (0x0001)false
                              Nov 29, 2022 16:46:10.620765924 CET8.8.8.8192.168.2.30xc9c5No error (0)accounts.google.com172.217.168.45A (IP address)IN (0x0001)false
                              Nov 29, 2022 16:46:12.117599010 CET8.8.8.8192.168.2.30xb93dNo error (0)socialgrow.co.in65.21.127.94A (IP address)IN (0x0001)false
                              Nov 29, 2022 16:46:13.627137899 CET8.8.8.8192.168.2.30x49ecNo error (0)www.google.com172.217.168.36A (IP address)IN (0x0001)false
                              Nov 29, 2022 16:46:13.958861113 CET8.8.8.8192.168.2.30x8257No error (0)maxcdn.bootstrapcdn.com104.18.10.207A (IP address)IN (0x0001)false
                              Nov 29, 2022 16:46:13.958861113 CET8.8.8.8192.168.2.30x8257No error (0)maxcdn.bootstrapcdn.com104.18.11.207A (IP address)IN (0x0001)false
                              Nov 29, 2022 16:46:14.009639025 CET8.8.8.8192.168.2.30xd98dNo error (0)cdn.jsdelivr.netcdn.jsdelivr.net.cdn.cloudflare.netCNAME (Canonical name)IN (0x0001)false
                              Nov 29, 2022 16:46:14.021028042 CET8.8.8.8192.168.2.30x40aeNo error (0)code.jquery.comcds.s5x3j6q5.hwcdn.netCNAME (Canonical name)IN (0x0001)false
                              Nov 29, 2022 16:46:14.286166906 CET8.8.8.8192.168.2.30x9a2fNo error (0)cs1227.wpc.alphacdn.net192.229.221.185A (IP address)IN (0x0001)false
                              Nov 29, 2022 16:46:15.219022989 CET8.8.8.8192.168.2.30xb07dNo error (0)cdnjs.cloudflare.com104.17.25.14A (IP address)IN (0x0001)false
                              Nov 29, 2022 16:46:15.219022989 CET8.8.8.8192.168.2.30xb07dNo error (0)cdnjs.cloudflare.com104.17.24.14A (IP address)IN (0x0001)false
                              Nov 29, 2022 16:46:15.250801086 CET8.8.8.8192.168.2.30x9ca0No error (0)dual.part-0032.t-0009.t-msedge.netglobal-entry-afdthirdparty-fallback.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                              Nov 29, 2022 16:46:15.250801086 CET8.8.8.8192.168.2.30x9ca0No error (0)dual.part-0032.t-0009.fbs1-t-msedge.netpart-0032.t-0009.fbs1-t-msedge.netCNAME (Canonical name)IN (0x0001)false
                              Nov 29, 2022 16:46:15.250801086 CET8.8.8.8192.168.2.30x9ca0No error (0)part-0032.t-0009.fbs1-t-msedge.net13.107.219.60A (IP address)IN (0x0001)false
                              Nov 29, 2022 16:46:15.250801086 CET8.8.8.8192.168.2.30x9ca0No error (0)part-0032.t-0009.fbs1-t-msedge.net13.107.227.60A (IP address)IN (0x0001)false
                              Nov 29, 2022 16:46:16.768930912 CET8.8.8.8192.168.2.30x1fcbNo error (0)dual.part-0032.t-0009.t-msedge.netglobal-entry-afdthirdparty-fallback.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                              Nov 29, 2022 16:46:16.768930912 CET8.8.8.8192.168.2.30x1fcbNo error (0)dual.part-0032.t-0009.fbs1-t-msedge.netpart-0032.t-0009.fbs1-t-msedge.netCNAME (Canonical name)IN (0x0001)false
                              Nov 29, 2022 16:46:16.768930912 CET8.8.8.8192.168.2.30x1fcbNo error (0)part-0032.t-0009.fbs1-t-msedge.net13.107.219.60A (IP address)IN (0x0001)false
                              Nov 29, 2022 16:46:16.768930912 CET8.8.8.8192.168.2.30x1fcbNo error (0)part-0032.t-0009.fbs1-t-msedge.net13.107.227.60A (IP address)IN (0x0001)false
                              Nov 29, 2022 16:48:13.606765032 CET8.8.8.8192.168.2.30x1ee2No error (0)www.google.com172.217.168.36A (IP address)IN (0x0001)false
                              • clients2.google.com
                              • accounts.google.com
                              • socialgrow.co.in
                              • maxcdn.bootstrapcdn.com
                              • logincdn.msauth.net
                              • https:
                              • cdnjs.cloudflare.com
                              • aadcdn.msauth.net

                              Click to jump to process

                              Target ID:0
                              Start time:16:46:06
                              Start date:29/11/2022
                              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                              Wow64 process (32bit):false
                              Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                              Imagebase:0x7ff614650000
                              File size:2851656 bytes
                              MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                              Has elevated privileges:true
                              Has administrator privileges:true
                              Programmed in:C, C++ or other language
                              Reputation:high

                              Target ID:1
                              Start time:16:46:07
                              Start date:29/11/2022
                              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                              Wow64 process (32bit):false
                              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1960 --field-trial-handle=1748,i,843581558575697743,11274918621816804293,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                              Imagebase:0x7ff614650000
                              File size:2851656 bytes
                              MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                              Has elevated privileges:true
                              Has administrator privileges:true
                              Programmed in:C, C++ or other language
                              Reputation:high

                              Target ID:2
                              Start time:16:46:08
                              Start date:29/11/2022
                              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                              Wow64 process (32bit):false
                              Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "C:\Users\user\Desktop\Payslip 28.11.22.html
                              Imagebase:0x7ff614650000
                              File size:2851656 bytes
                              MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                              Has elevated privileges:true
                              Has administrator privileges:true
                              Programmed in:C, C++ or other language
                              Reputation:high

                              No disassembly