Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://storageapi.fleek.co/9db0d41e-e2fe-4afc-b36b-6d83510d030c-bucket/indexx.html

Overview

General Information

Sample URL:https://storageapi.fleek.co/9db0d41e-e2fe-4afc-b36b-6d83510d030c-bucket/indexx.html
Analysis ID:756169
Infos:

Detection

HTMLPhisher
Score:88
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Phishing site detected (based on favicon image match)
Multi AV Scanner detection for domain / URL
Yara detected HtmlPhish10
Multi AV Scanner detection for submitted file
Phishing site detected (based on logo template match)
Phishing site detected (based on image similarity)
HTML body contains low number of good links
No HTML title found

Classification

  • System is w10x64
  • chrome.exe (PID: 6052 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 4536 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1932 --field-trial-handle=1796,i,15701762142637122687,14432371106928829043,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 1408 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "https://storageapi.fleek.co/9db0d41e-e2fe-4afc-b36b-6d83510d030c-bucket/indexx.html MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
81822.0.pages.csvJoeSecurity_HtmlPhish_10Yara detected HtmlPhish_10Joe Security
    No Sigma rule has matched
    No Snort rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: https://storageapi.fleek.co/9db0d41e-e2fe-4afc-b36b-6d83510d030c-bucket/indexx.htmlAvira URL Cloud: detection malicious, Label: phishing
    Source: https://storageapi.fleek.co/9db0d41e-e2fe-4afc-b36b-6d83510d030c-bucket/indexx.htmlSlashNext: detection malicious, Label: Credential Stealing type: Phishing & Social Engineering
    Source: https://storageapi.fleek.co/9db0d41e-e2fe-4afc-b36b-6d83510d030c-bucket/indexx.htmlVirustotal: Detection: 21%Perma Link
    Source: https://storageapi.fleek.co/9db0d41e-e2fe-4afc-b36b-6d83510d030c-bucket/indexx.htmlVirustotal: Detection: 21%Perma Link

    Phishing

    barindex
    Source: https://storageapi.fleek.co/9db0d41e-e2fe-4afc-b36b-6d83510d030c-bucket/indexx.htmlMatcher: Template: microsoft matched with high similarity
    Source: Yara matchFile source: 81822.0.pages.csv, type: HTML
    Source: https://storageapi.fleek.co/9db0d41e-e2fe-4afc-b36b-6d83510d030c-bucket/indexx.htmlMatcher: Template: microsoft matched
    Source: https://storageapi.fleek.co/9db0d41e-e2fe-4afc-b36b-6d83510d030c-bucket/indexx.htmlMatcher: Found strong image similarity, brand: Microsoft image: 81822.0.img.2.gfk.csv EE5C8D9FB6248C938FD0DC19370E90BD
    Source: https://storageapi.fleek.co/9db0d41e-e2fe-4afc-b36b-6d83510d030c-bucket/indexx.htmlMatcher: Found strong image similarity, brand: Microsoft image: 59827.1.img.2.gfk.csv EE5C8D9FB6248C938FD0DC19370E90BD
    Source: https://storageapi.fleek.co/9db0d41e-e2fe-4afc-b36b-6d83510d030c-bucket/indexx.htmlMatcher: Found strong image similarity, brand: Microsoft image: 35950.2.img.2.gfk.csv EE5C8D9FB6248C938FD0DC19370E90BD
    Source: https://storageapi.fleek.co/9db0d41e-e2fe-4afc-b36b-6d83510d030c-bucket/indexx.htmlMatcher: Found strong image similarity, brand: Microsoft image: 19276.3.img.2.gfk.csv EE5C8D9FB6248C938FD0DC19370E90BD
    Source: https://storageapi.fleek.co/9db0d41e-e2fe-4afc-b36b-6d83510d030c-bucket/indexx.htmlHTTP Parser: Number of links: 0
    Source: https://storageapi.fleek.co/9db0d41e-e2fe-4afc-b36b-6d83510d030c-bucket/indexx.htmlHTTP Parser: Number of links: 0
    Source: https://storageapi.fleek.co/9db0d41e-e2fe-4afc-b36b-6d83510d030c-bucket/indexx.htmlHTTP Parser: HTML title missing
    Source: https://storageapi.fleek.co/9db0d41e-e2fe-4afc-b36b-6d83510d030c-bucket/indexx.htmlHTTP Parser: HTML title missing
    Source: https://storageapi.fleek.co/9db0d41e-e2fe-4afc-b36b-6d83510d030c-bucket/indexx.htmlHTTP Parser: No <meta name="author".. found
    Source: https://storageapi.fleek.co/9db0d41e-e2fe-4afc-b36b-6d83510d030c-bucket/indexx.htmlHTTP Parser: No <meta name="author".. found
    Source: https://storageapi.fleek.co/9db0d41e-e2fe-4afc-b36b-6d83510d030c-bucket/indexx.htmlHTTP Parser: No <meta name="copyright".. found
    Source: https://storageapi.fleek.co/9db0d41e-e2fe-4afc-b36b-6d83510d030c-bucket/indexx.htmlHTTP Parser: No <meta name="copyright".. found
    Source: unknownDNS traffic detected: queries for: accounts.google.com
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49700
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
    Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49702 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
    Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
    Source: global trafficHTTP traffic detected: GET /9db0d41e-e2fe-4afc-b36b-6d83510d030c-bucket/indexx.html HTTP/1.1Host: storageapi.fleek.coConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /bootstrap/4.3.1/js/bootstrap.min.js HTTP/1.1Host: stackpath.bootstrapcdn.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://storageapi.fleek.co/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /bootstrap/4.3.1/js/bootstrap.bundle.min.js HTTP/1.1Host: stackpath.bootstrapcdn.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://storageapi.fleek.co/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /bootstrap/4.1.3/js/bootstrap.min.js HTTP/1.1Host: stackpath.bootstrapcdn.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://storageapi.fleek.co/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /ajax/libs/jquery/3.3.1/jquery.min.js HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://storageapi.fleek.co/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
    Source: global trafficHTTP traffic detected: GET /9db0d41e-e2fe-4afc-b36b-6d83510d030c-bucket/indexx.html HTTP/1.1Host: storageapi.fleek.coConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentReferer: https://storageapi.fleek.co/9db0d41e-e2fe-4afc-b36b-6d83510d030c-bucket/indexx.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9If-Modified-Since: Mon, 28 Nov 2022 14:20:15 GMT
    Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=PENDING+904; AEC=AakniGO7HqlHWlnoY-P22_SwwnNSfVGxlF1NgK5nuj5WLe313NyJi16g7z4; SOCS=CAISHAgCEhJnd3NfMjAyMjA4MDgtMF9SQzEaAmVuIAEaBgiAvOuXBg; NID=511=nUT82hOv6CVwMNqDg-sTtCMJJ6SQ1v_cCpfCpf5nt8EolEbal01GWFyjG01tqWQgh9ciRU880J6nLd2gdbhAJs44PsHAZaVQAFIbrqe2FmFgjrAAK7W9Z8u5LDvwsuZRng98jP6E23SJ4fsPIs326YmnuCwa92dRRCcB6MNeI_o
    Source: classification engineClassification label: mal88.phis.win@24/0@6/9
    Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1932 --field-trial-handle=1796,i,15701762142637122687,14432371106928829043,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
    Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "https://storageapi.fleek.co/9db0d41e-e2fe-4afc-b36b-6d83510d030c-bucket/indexx.html
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1932 --field-trial-handle=1796,i,15701762142637122687,14432371106928829043,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsWindows Management InstrumentationPath Interception1
    Process Injection
    1
    Process Injection
    OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
    Encrypted Channel
    Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
    Non-Application Layer Protocol
    Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
    Application Layer Protocol
    Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
    Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
    Ingress Tool Transfer
    SIM Card SwapCarrier Billing Fraud
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Is Windows Process
    • Number of created Registry Values
    • Number of created Files
    • Visual Basic
    • Delphi
    • Java
    • .Net C# or VB.NET
    • C, C++ or other language
    • Is malicious
    • Internet

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.


    windows-stand
    SourceDetectionScannerLabelLink
    https://storageapi.fleek.co/9db0d41e-e2fe-4afc-b36b-6d83510d030c-bucket/indexx.html22%VirustotalBrowse
    https://storageapi.fleek.co/9db0d41e-e2fe-4afc-b36b-6d83510d030c-bucket/indexx.html100%Avira URL Cloudphishing
    https://storageapi.fleek.co/9db0d41e-e2fe-4afc-b36b-6d83510d030c-bucket/indexx.html100%SlashNextCredential Stealing type: Phishing & Social Engineering
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    SourceDetectionScannerLabelLink
    https://storageapi.fleek.co/9db0d41e-e2fe-4afc-b36b-6d83510d030c-bucket/indexx.html22%VirustotalBrowse
    NameIPActiveMaliciousAntivirus DetectionReputation
    stackpath.bootstrapcdn.com
    104.18.10.207
    truefalse
      high
      accounts.google.com
      172.217.168.45
      truefalse
        high
        cdnjs.cloudflare.com
        104.17.24.14
        truefalse
          high
          storageapi.fleek.co
          104.18.6.145
          truefalse
            unknown
            www.google.com
            172.217.168.36
            truefalse
              high
              clients.l.google.com
              142.250.203.110
              truefalse
                high
                clients2.google.com
                unknown
                unknownfalse
                  high
                  NameMaliciousAntivirus DetectionReputation
                  https://stackpath.bootstrapcdn.com/bootstrap/4.3.1/js/bootstrap.min.jsfalse
                    high
                    https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                      high
                      https://stackpath.bootstrapcdn.com/bootstrap/4.1.3/js/bootstrap.min.jsfalse
                        high
                        https://storageapi.fleek.co/9db0d41e-e2fe-4afc-b36b-6d83510d030c-bucket/indexx.htmltrueunknown
                        https://storageapi.fleek.co/9db0d41e-e2fe-4afc-b36b-6d83510d030c-bucket/indexx.htmltrueunknown
                        https://stackpath.bootstrapcdn.com/bootstrap/4.3.1/js/bootstrap.bundle.min.jsfalse
                          high
                          https://cdnjs.cloudflare.com/ajax/libs/jquery/3.3.1/jquery.min.jsfalse
                            high
                            https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                              high
                              • No. of IPs < 25%
                              • 25% < No. of IPs < 50%
                              • 50% < No. of IPs < 75%
                              • 75% < No. of IPs
                              IPDomainCountryFlagASNASN NameMalicious
                              104.17.24.14
                              cdnjs.cloudflare.comUnited States
                              13335CLOUDFLARENETUSfalse
                              104.18.10.207
                              stackpath.bootstrapcdn.comUnited States
                              13335CLOUDFLARENETUSfalse
                              142.250.203.110
                              clients.l.google.comUnited States
                              15169GOOGLEUSfalse
                              104.18.6.145
                              storageapi.fleek.coUnited States
                              13335CLOUDFLARENETUSfalse
                              172.217.168.45
                              accounts.google.comUnited States
                              15169GOOGLEUSfalse
                              172.217.168.36
                              www.google.comUnited States
                              15169GOOGLEUSfalse
                              239.255.255.250
                              unknownReserved
                              unknownunknownfalse
                              IP
                              192.168.2.1
                              127.0.0.1
                              Joe Sandbox Version:36.0.0 Rainbow Opal
                              Analysis ID:756169
                              Start date and time:2022-11-29 19:01:18 +01:00
                              Joe Sandbox Product:CloudBasic
                              Overall analysis duration:0h 3m 19s
                              Hypervisor based Inspection enabled:false
                              Report type:light
                              Cookbook file name:browseurl.jbs
                              Sample URL:https://storageapi.fleek.co/9db0d41e-e2fe-4afc-b36b-6d83510d030c-bucket/indexx.html
                              Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                              Number of analysed new started processes analysed:12
                              Number of new started drivers analysed:0
                              Number of existing processes analysed:0
                              Number of existing drivers analysed:0
                              Number of injected processes analysed:0
                              Technologies:
                              • HCA enabled
                              • EGA enabled
                              • HDC enabled
                              • AMSI enabled
                              Analysis Mode:default
                              Analysis stop reason:Timeout
                              Detection:MAL
                              Classification:mal88.phis.win@24/0@6/9
                              EGA Information:Failed
                              HDC Information:Failed
                              HCA Information:
                              • Successful, ratio: 100%
                              • Number of executed functions: 0
                              • Number of non-executed functions: 0
                              • Exclude process from analysis (whitelisted): SgrmBroker.exe, svchost.exe
                              • TCP Packets have been reduced to 100
                              • Excluded IPs from analysis (whitelisted): 172.217.168.67, 34.104.35.123, 142.250.203.106, 172.217.168.10, 172.217.168.42, 172.217.168.74, 216.58.215.234
                              • Excluded domains from analysis (whitelisted): fs.microsoft.com, edgedl.me.gvt1.com, content-autofill.googleapis.com, ajax.googleapis.com, clientservices.googleapis.com, firebasestorage.googleapis.com
                              • Not all processes where analyzed, report is missing behavior information
                              • Report size getting too big, too many NtWriteVirtualMemory calls found.
                              No simulations
                              No context
                              No context
                              No context
                              No context
                              No context
                              No created / dropped files found
                              No static file info
                              TimestampSource PortDest PortSource IPDest IP
                              Nov 29, 2022 19:02:13.055984020 CET49700443192.168.2.3104.18.6.145
                              Nov 29, 2022 19:02:13.056051970 CET44349700104.18.6.145192.168.2.3
                              Nov 29, 2022 19:02:13.056153059 CET49700443192.168.2.3104.18.6.145
                              Nov 29, 2022 19:02:13.057007074 CET49700443192.168.2.3104.18.6.145
                              Nov 29, 2022 19:02:13.057068110 CET44349700104.18.6.145192.168.2.3
                              Nov 29, 2022 19:02:13.057486057 CET49701443192.168.2.3142.250.203.110
                              Nov 29, 2022 19:02:13.057537079 CET44349701142.250.203.110192.168.2.3
                              Nov 29, 2022 19:02:13.057624102 CET49701443192.168.2.3142.250.203.110
                              Nov 29, 2022 19:02:13.057898998 CET49702443192.168.2.3172.217.168.45
                              Nov 29, 2022 19:02:13.057986021 CET44349702172.217.168.45192.168.2.3
                              Nov 29, 2022 19:02:13.058100939 CET49702443192.168.2.3172.217.168.45
                              Nov 29, 2022 19:02:13.058134079 CET49701443192.168.2.3142.250.203.110
                              Nov 29, 2022 19:02:13.058151007 CET44349701142.250.203.110192.168.2.3
                              Nov 29, 2022 19:02:13.058423996 CET49702443192.168.2.3172.217.168.45
                              Nov 29, 2022 19:02:13.058443069 CET44349702172.217.168.45192.168.2.3
                              Nov 29, 2022 19:02:13.210355043 CET44349700104.18.6.145192.168.2.3
                              Nov 29, 2022 19:02:13.229434013 CET44349702172.217.168.45192.168.2.3
                              Nov 29, 2022 19:02:13.229537010 CET44349701142.250.203.110192.168.2.3
                              Nov 29, 2022 19:02:13.251533985 CET49700443192.168.2.3104.18.6.145
                              Nov 29, 2022 19:02:13.269536018 CET49702443192.168.2.3172.217.168.45
                              Nov 29, 2022 19:02:13.273617029 CET49701443192.168.2.3142.250.203.110
                              Nov 29, 2022 19:02:13.273654938 CET44349701142.250.203.110192.168.2.3
                              Nov 29, 2022 19:02:13.273929119 CET49702443192.168.2.3172.217.168.45
                              Nov 29, 2022 19:02:13.273963928 CET44349702172.217.168.45192.168.2.3
                              Nov 29, 2022 19:02:13.275038958 CET49700443192.168.2.3104.18.6.145
                              Nov 29, 2022 19:02:13.275084019 CET44349700104.18.6.145192.168.2.3
                              Nov 29, 2022 19:02:13.275188923 CET44349701142.250.203.110192.168.2.3
                              Nov 29, 2022 19:02:13.275288105 CET49701443192.168.2.3142.250.203.110
                              Nov 29, 2022 19:02:13.278841019 CET44349700104.18.6.145192.168.2.3
                              Nov 29, 2022 19:02:13.278857946 CET44349701142.250.203.110192.168.2.3
                              Nov 29, 2022 19:02:13.278948069 CET49700443192.168.2.3104.18.6.145
                              Nov 29, 2022 19:02:13.278997898 CET49701443192.168.2.3142.250.203.110
                              Nov 29, 2022 19:02:13.279031992 CET44349702172.217.168.45192.168.2.3
                              Nov 29, 2022 19:02:13.279231071 CET49702443192.168.2.3172.217.168.45
                              Nov 29, 2022 19:02:14.256866932 CET49700443192.168.2.3104.18.6.145
                              Nov 29, 2022 19:02:14.256958008 CET44349700104.18.6.145192.168.2.3
                              Nov 29, 2022 19:02:14.257230043 CET49702443192.168.2.3172.217.168.45
                              Nov 29, 2022 19:02:14.257395983 CET44349700104.18.6.145192.168.2.3
                              Nov 29, 2022 19:02:14.257468939 CET44349702172.217.168.45192.168.2.3
                              Nov 29, 2022 19:02:14.257479906 CET49700443192.168.2.3104.18.6.145
                              Nov 29, 2022 19:02:14.257503033 CET44349700104.18.6.145192.168.2.3
                              Nov 29, 2022 19:02:14.257777929 CET44349702172.217.168.45192.168.2.3
                              Nov 29, 2022 19:02:14.257927895 CET49701443192.168.2.3142.250.203.110
                              Nov 29, 2022 19:02:14.258018017 CET44349701142.250.203.110192.168.2.3
                              Nov 29, 2022 19:02:14.258254051 CET49702443192.168.2.3172.217.168.45
                              Nov 29, 2022 19:02:14.258291006 CET44349702172.217.168.45192.168.2.3
                              Nov 29, 2022 19:02:14.258356094 CET49701443192.168.2.3142.250.203.110
                              Nov 29, 2022 19:02:14.258357048 CET44349701142.250.203.110192.168.2.3
                              Nov 29, 2022 19:02:14.258397102 CET44349701142.250.203.110192.168.2.3
                              Nov 29, 2022 19:02:14.295433044 CET44349701142.250.203.110192.168.2.3
                              Nov 29, 2022 19:02:14.295677900 CET49701443192.168.2.3142.250.203.110
                              Nov 29, 2022 19:02:14.295722961 CET44349701142.250.203.110192.168.2.3
                              Nov 29, 2022 19:02:14.295754910 CET44349701142.250.203.110192.168.2.3
                              Nov 29, 2022 19:02:14.296655893 CET49701443192.168.2.3142.250.203.110
                              Nov 29, 2022 19:02:14.312655926 CET44349702172.217.168.45192.168.2.3
                              Nov 29, 2022 19:02:14.312781096 CET49702443192.168.2.3172.217.168.45
                              Nov 29, 2022 19:02:14.312824011 CET44349702172.217.168.45192.168.2.3
                              Nov 29, 2022 19:02:14.312971115 CET44349702172.217.168.45192.168.2.3
                              Nov 29, 2022 19:02:14.313086987 CET49702443192.168.2.3172.217.168.45
                              Nov 29, 2022 19:02:14.326235056 CET49702443192.168.2.3172.217.168.45
                              Nov 29, 2022 19:02:14.326297045 CET44349702172.217.168.45192.168.2.3
                              Nov 29, 2022 19:02:14.326786041 CET49701443192.168.2.3142.250.203.110
                              Nov 29, 2022 19:02:14.326827049 CET44349701142.250.203.110192.168.2.3
                              Nov 29, 2022 19:02:14.466936111 CET44349700104.18.6.145192.168.2.3
                              Nov 29, 2022 19:02:14.467220068 CET49700443192.168.2.3104.18.6.145
                              Nov 29, 2022 19:02:15.291342020 CET44349700104.18.6.145192.168.2.3
                              Nov 29, 2022 19:02:15.291465044 CET44349700104.18.6.145192.168.2.3
                              Nov 29, 2022 19:02:15.291549921 CET44349700104.18.6.145192.168.2.3
                              Nov 29, 2022 19:02:15.291620016 CET49700443192.168.2.3104.18.6.145
                              Nov 29, 2022 19:02:15.291634083 CET44349700104.18.6.145192.168.2.3
                              Nov 29, 2022 19:02:15.291663885 CET44349700104.18.6.145192.168.2.3
                              Nov 29, 2022 19:02:15.291743994 CET49700443192.168.2.3104.18.6.145
                              Nov 29, 2022 19:02:15.291779041 CET44349700104.18.6.145192.168.2.3
                              Nov 29, 2022 19:02:15.291838884 CET49700443192.168.2.3104.18.6.145
                              Nov 29, 2022 19:02:15.291841984 CET44349700104.18.6.145192.168.2.3
                              Nov 29, 2022 19:02:15.291865110 CET44349700104.18.6.145192.168.2.3
                              Nov 29, 2022 19:02:15.291920900 CET49700443192.168.2.3104.18.6.145
                              Nov 29, 2022 19:02:15.292025089 CET44349700104.18.6.145192.168.2.3
                              Nov 29, 2022 19:02:15.292160034 CET44349700104.18.6.145192.168.2.3
                              Nov 29, 2022 19:02:15.292296886 CET49700443192.168.2.3104.18.6.145
                              Nov 29, 2022 19:02:15.292320967 CET44349700104.18.6.145192.168.2.3
                              Nov 29, 2022 19:02:15.292411089 CET44349700104.18.6.145192.168.2.3
                              Nov 29, 2022 19:02:15.292464972 CET49700443192.168.2.3104.18.6.145
                              Nov 29, 2022 19:02:15.292479992 CET44349700104.18.6.145192.168.2.3
                              Nov 29, 2022 19:02:15.293112040 CET44349700104.18.6.145192.168.2.3
                              Nov 29, 2022 19:02:15.293198109 CET49700443192.168.2.3104.18.6.145
                              Nov 29, 2022 19:02:15.293215036 CET44349700104.18.6.145192.168.2.3
                              Nov 29, 2022 19:02:15.293456078 CET44349700104.18.6.145192.168.2.3
                              Nov 29, 2022 19:02:15.293526888 CET49700443192.168.2.3104.18.6.145
                              Nov 29, 2022 19:02:15.339637041 CET49700443192.168.2.3104.18.6.145
                              Nov 29, 2022 19:02:15.339683056 CET44349700104.18.6.145192.168.2.3
                              Nov 29, 2022 19:02:15.380485058 CET49711443192.168.2.3104.18.10.207
                              Nov 29, 2022 19:02:15.380542040 CET44349711104.18.10.207192.168.2.3
                              Nov 29, 2022 19:02:15.380626917 CET49711443192.168.2.3104.18.10.207
                              Nov 29, 2022 19:02:15.380836964 CET49712443192.168.2.3104.18.10.207
                              Nov 29, 2022 19:02:15.380894899 CET44349712104.18.10.207192.168.2.3
                              Nov 29, 2022 19:02:15.380970001 CET49712443192.168.2.3104.18.10.207
                              Nov 29, 2022 19:02:15.381182909 CET49713443192.168.2.3104.18.10.207
                              Nov 29, 2022 19:02:15.381273031 CET44349713104.18.10.207192.168.2.3
                              Nov 29, 2022 19:02:15.381360054 CET49713443192.168.2.3104.18.10.207
                              TimestampSource PortDest PortSource IPDest IP
                              Nov 29, 2022 19:02:12.946363926 CET5692453192.168.2.38.8.8.8
                              Nov 29, 2022 19:02:12.946650982 CET6062553192.168.2.38.8.8.8
                              Nov 29, 2022 19:02:12.965759039 CET53569248.8.8.8192.168.2.3
                              Nov 29, 2022 19:02:12.971020937 CET4930253192.168.2.38.8.8.8
                              Nov 29, 2022 19:02:12.973987103 CET53606258.8.8.8192.168.2.3
                              Nov 29, 2022 19:02:12.994007111 CET53493028.8.8.8192.168.2.3
                              Nov 29, 2022 19:02:15.356497049 CET5713453192.168.2.38.8.8.8
                              Nov 29, 2022 19:02:15.356712103 CET5604253192.168.2.38.8.8.8
                              Nov 29, 2022 19:02:15.379307032 CET53571348.8.8.8192.168.2.3
                              Nov 29, 2022 19:02:15.380393982 CET53560428.8.8.8192.168.2.3
                              Nov 29, 2022 19:02:16.164645910 CET5963653192.168.2.38.8.8.8
                              Nov 29, 2022 19:02:16.182365894 CET53596368.8.8.8192.168.2.3
                              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                              Nov 29, 2022 19:02:12.946363926 CET192.168.2.38.8.8.80x7d09Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                              Nov 29, 2022 19:02:12.946650982 CET192.168.2.38.8.8.80xc00aStandard query (0)clients2.google.comA (IP address)IN (0x0001)false
                              Nov 29, 2022 19:02:12.971020937 CET192.168.2.38.8.8.80xe153Standard query (0)storageapi.fleek.coA (IP address)IN (0x0001)false
                              Nov 29, 2022 19:02:15.356497049 CET192.168.2.38.8.8.80xe6c5Standard query (0)stackpath.bootstrapcdn.comA (IP address)IN (0x0001)false
                              Nov 29, 2022 19:02:15.356712103 CET192.168.2.38.8.8.80xd42aStandard query (0)cdnjs.cloudflare.comA (IP address)IN (0x0001)false
                              Nov 29, 2022 19:02:16.164645910 CET192.168.2.38.8.8.80xfb2eStandard query (0)www.google.comA (IP address)IN (0x0001)false
                              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                              Nov 29, 2022 19:02:12.965759039 CET8.8.8.8192.168.2.30x7d09No error (0)accounts.google.com172.217.168.45A (IP address)IN (0x0001)false
                              Nov 29, 2022 19:02:12.973987103 CET8.8.8.8192.168.2.30xc00aNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                              Nov 29, 2022 19:02:12.973987103 CET8.8.8.8192.168.2.30xc00aNo error (0)clients.l.google.com142.250.203.110A (IP address)IN (0x0001)false
                              Nov 29, 2022 19:02:12.994007111 CET8.8.8.8192.168.2.30xe153No error (0)storageapi.fleek.co104.18.6.145A (IP address)IN (0x0001)false
                              Nov 29, 2022 19:02:12.994007111 CET8.8.8.8192.168.2.30xe153No error (0)storageapi.fleek.co104.18.7.145A (IP address)IN (0x0001)false
                              Nov 29, 2022 19:02:15.379307032 CET8.8.8.8192.168.2.30xe6c5No error (0)stackpath.bootstrapcdn.com104.18.10.207A (IP address)IN (0x0001)false
                              Nov 29, 2022 19:02:15.379307032 CET8.8.8.8192.168.2.30xe6c5No error (0)stackpath.bootstrapcdn.com104.18.11.207A (IP address)IN (0x0001)false
                              Nov 29, 2022 19:02:15.380393982 CET8.8.8.8192.168.2.30xd42aNo error (0)cdnjs.cloudflare.com104.17.24.14A (IP address)IN (0x0001)false
                              Nov 29, 2022 19:02:15.380393982 CET8.8.8.8192.168.2.30xd42aNo error (0)cdnjs.cloudflare.com104.17.25.14A (IP address)IN (0x0001)false
                              Nov 29, 2022 19:02:16.182365894 CET8.8.8.8192.168.2.30xfb2eNo error (0)www.google.com172.217.168.36A (IP address)IN (0x0001)false
                              • storageapi.fleek.co
                              • accounts.google.com
                              • clients2.google.com
                              • https:
                                • stackpath.bootstrapcdn.com
                                • cdnjs.cloudflare.com

                              Click to jump to process

                              Target ID:0
                              Start time:19:02:09
                              Start date:29/11/2022
                              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                              Wow64 process (32bit):false
                              Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                              Imagebase:0x7ff614650000
                              File size:2851656 bytes
                              MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                              Has elevated privileges:true
                              Has administrator privileges:true
                              Programmed in:C, C++ or other language
                              Reputation:low

                              Target ID:1
                              Start time:19:02:10
                              Start date:29/11/2022
                              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                              Wow64 process (32bit):false
                              Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1932 --field-trial-handle=1796,i,15701762142637122687,14432371106928829043,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                              Imagebase:0x7ff614650000
                              File size:2851656 bytes
                              MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                              Has elevated privileges:true
                              Has administrator privileges:true
                              Programmed in:C, C++ or other language
                              Reputation:low

                              Target ID:2
                              Start time:19:02:11
                              Start date:29/11/2022
                              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                              Wow64 process (32bit):false
                              Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "https://storageapi.fleek.co/9db0d41e-e2fe-4afc-b36b-6d83510d030c-bucket/indexx.html
                              Imagebase:0x7ff614650000
                              File size:2851656 bytes
                              MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                              Has elevated privileges:true
                              Has administrator privileges:true
                              Programmed in:C, C++ or other language
                              Reputation:low

                              No disassembly