Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Paid_invoice.html

Overview

General Information

Sample Name:Paid_invoice.html
Analysis ID:756253
MD5:388cd3eda11c1e4a18b95934c94e4751
SHA1:fc6c35aaefc9671149387530a875c2e2a350a5d2
SHA256:0b81b708477c44bb04dd7bb0ed927d4ce8a3c7d9e11882542ab84f89bd167bb1
Infos:

Detection

HTMLPhisher
Score:64
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Yara detected HtmlPhish10
HTML document with suspicious title
HTML document with suspicious name
Phishing site detected (based on logo template match)
Phishing site detected (based on image similarity)
Invalid 'forgot password' link found
HTML body contains low number of good links
IP address seen in connection with other malware
None HTTPS page querying sensitive user data (password, username or email)
No HTML title found

Classification

  • System is w10x64
  • chrome.exe (PID: 5044 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 5776 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1756 --field-trial-handle=1648,i,9583188458170825095,14417365062387772299,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 6244 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "C:\Users\user\Desktop\Paid_invoice.html MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
Paid_invoice.htmlJoeSecurity_HtmlPhish_10Yara detected HtmlPhish_10Joe Security
    SourceRuleDescriptionAuthorStrings
    84167.0.pages.csvJoeSecurity_HtmlPhish_10Yara detected HtmlPhish_10Joe Security
      No Sigma rule has matched
      No Snort rule has matched

      Click to jump to signature section

      Show All Signature Results

      Phishing

      barindex
      Source: Yara matchFile source: Paid_invoice.html, type: SAMPLE
      Source: Yara matchFile source: 84167.0.pages.csv, type: HTML
      Source: file:///C:/Users/user/Desktop/Paid_invoice.htmlMatcher: Template: microsoft matched
      Source: embeddedMatcher: Found strong image similarity, brand: Microsoft image: 84167.0.img.1.gfk.csv EE5C8D9FB6248C938FD0DC19370E90BD
      Source: file:///C:/Users/user/Desktop/Paid_invoice.htmlHTTP Parser: Invalid link: Forgot Password?
      Source: file:///C:/Users/user/Desktop/Paid_invoice.htmlHTTP Parser: Invalid link: Forgot Password?
      Source: file:///C:/Users/user/Desktop/Paid_invoice.htmlHTTP Parser: Number of links: 0
      Source: file:///C:/Users/user/Desktop/Paid_invoice.htmlHTTP Parser: Number of links: 0
      Source: file:///C:/Users/user/Desktop/Paid_invoice.htmlHTTP Parser: Has password / email / username input fields
      Source: file:///C:/Users/user/Desktop/Paid_invoice.htmlHTTP Parser: Has password / email / username input fields
      Source: file:///C:/Users/user/Desktop/Paid_invoice.htmlHTTP Parser: HTML title missing
      Source: file:///C:/Users/user/Desktop/Paid_invoice.htmlHTTP Parser: HTML title missing
      Source: file:///C:/Users/user/Desktop/Paid_invoice.htmlHTTP Parser: No <meta name="author".. found
      Source: file:///C:/Users/user/Desktop/Paid_invoice.htmlHTTP Parser: No <meta name="author".. found
      Source: file:///C:/Users/user/Desktop/Paid_invoice.htmlHTTP Parser: No <meta name="copyright".. found
      Source: file:///C:/Users/user/Desktop/Paid_invoice.htmlHTTP Parser: No <meta name="copyright".. found
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
      Source: Joe Sandbox ViewIP Address: 104.17.24.14 104.17.24.14
      Source: Joe Sandbox ViewIP Address: 104.18.11.207 104.18.11.207
      Source: Joe Sandbox ViewIP Address: 104.18.11.207 104.18.11.207
      Source: unknownDNS traffic detected: queries for: accounts.google.com
      Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
      Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
      Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
      Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
      Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
      Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /bootstrap/4.0.0/css/bootstrap.min.css HTTP/1.1Host: maxcdn.bootstrapcdn.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"Origin: nullsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: styleAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /bootstrap/4.1.3/js/bootstrap.min.js HTTP/1.1Host: stackpath.bootstrapcdn.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /bootstrap/4.0.0/js/bootstrap.min.js HTTP/1.1Host: maxcdn.bootstrapcdn.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"Origin: nullsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: global trafficHTTP traffic detected: GET /ajax/libs/popper.js/1.12.9/umd/popper.min.js HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"Origin: nullsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
      Source: Paid_invoice.htmlString found in binary or memory: https://ajax.googleapis.com/ajax/libs/jquery/2.2.4/jquery.min.js
      Source: Paid_invoice.htmlString found in binary or memory: https://cdnjs.cloudflare.com/ajax/libs/popper.js/1.12.9/umd/popper.min.js
      Source: Paid_invoice.htmlString found in binary or memory: https://code.jquery.com/jquery-3.2.1.slim.min.js
      Source: Paid_invoice.htmlString found in binary or memory: https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/css/bootstrap.min.css
      Source: Paid_invoice.htmlString found in binary or memory: https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/js/bootstrap.min.js
      Source: Paid_invoice.htmlString found in binary or memory: https://stackpath.bootstrapcdn.com/bootstrap/4.1.3/js/bootstrap.min.js
      Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9

      System Summary

      barindex
      Source: file:///C:/Users/user/Desktop/Paid_invoice.htmlTab title: Office 365
      Source: Name includes: Paid_invoice.htmlInitial sample: invoice
      Source: classification engineClassification label: mal64.phis.winHTML@28/0@8/10
      Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1756 --field-trial-handle=1648,i,9583188458170825095,14417365062387772299,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
      Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "C:\Users\user\Desktop\Paid_invoice.html
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1756 --field-trial-handle=1648,i,9583188458170825095,14417365062387772299,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
      Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
      Valid AccountsWindows Management InstrumentationPath Interception1
      Process Injection
      2
      Masquerading
      OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
      Encrypted Channel
      Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
      Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
      Process Injection
      LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
      Non-Application Layer Protocol
      Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
      Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
      Application Layer Protocol
      Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
      Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
      Ingress Tool Transfer
      SIM Card SwapCarrier Billing Fraud
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Is Windows Process
      • Number of created Registry Values
      • Number of created Files
      • Visual Basic
      • Delphi
      • Java
      • .Net C# or VB.NET
      • C, C++ or other language
      • Is malicious
      • Internet

      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


      windows-stand
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      NameIPActiveMaliciousAntivirus DetectionReputation
      stackpath.bootstrapcdn.com
      104.18.11.207
      truefalse
        high
        accounts.google.com
        172.217.168.45
        truefalse
          high
          cdnjs.cloudflare.com
          104.17.24.14
          truefalse
            high
            maxcdn.bootstrapcdn.com
            104.18.11.207
            truefalse
              high
              www.google.com
              172.217.168.68
              truefalse
                high
                clients.l.google.com
                142.250.203.110
                truefalse
                  high
                  clients2.google.com
                  unknown
                  unknownfalse
                    high
                    code.jquery.com
                    unknown
                    unknownfalse
                      high
                      NameMaliciousAntivirus DetectionReputation
                      https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                        high
                        https://stackpath.bootstrapcdn.com/bootstrap/4.1.3/js/bootstrap.min.jsfalse
                          high
                          https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/js/bootstrap.min.jsfalse
                            high
                            https://cdnjs.cloudflare.com/ajax/libs/popper.js/1.12.9/umd/popper.min.jsfalse
                              high
                              https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/css/bootstrap.min.cssfalse
                                high
                                file:///C:/Users/user/Desktop/Paid_invoice.htmltrue
                                  low
                                  https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                                    high
                                    NameSourceMaliciousAntivirus DetectionReputation
                                    https://code.jquery.com/jquery-3.2.1.slim.min.jsPaid_invoice.htmlfalse
                                      high
                                      • No. of IPs < 25%
                                      • 25% < No. of IPs < 50%
                                      • 50% < No. of IPs < 75%
                                      • 75% < No. of IPs
                                      IPDomainCountryFlagASNASN NameMalicious
                                      104.17.24.14
                                      cdnjs.cloudflare.comUnited States
                                      13335CLOUDFLARENETUSfalse
                                      142.250.203.110
                                      clients.l.google.comUnited States
                                      15169GOOGLEUSfalse
                                      104.18.11.207
                                      stackpath.bootstrapcdn.comUnited States
                                      13335CLOUDFLARENETUSfalse
                                      172.217.168.68
                                      www.google.comUnited States
                                      15169GOOGLEUSfalse
                                      172.217.168.45
                                      accounts.google.comUnited States
                                      15169GOOGLEUSfalse
                                      239.255.255.250
                                      unknownReserved
                                      unknownunknownfalse
                                      IP
                                      192.168.2.1
                                      192.168.2.4
                                      192.168.2.6
                                      127.0.0.1
                                      Joe Sandbox Version:36.0.0 Rainbow Opal
                                      Analysis ID:756253
                                      Start date and time:2022-11-29 21:57:04 +01:00
                                      Joe Sandbox Product:CloudBasic
                                      Overall analysis duration:0h 6m 46s
                                      Hypervisor based Inspection enabled:false
                                      Report type:light
                                      Sample file name:Paid_invoice.html
                                      Cookbook file name:defaultwindowshtmlcookbook.jbs
                                      Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                      Number of analysed new started processes analysed:8
                                      Number of new started drivers analysed:0
                                      Number of existing processes analysed:0
                                      Number of existing drivers analysed:0
                                      Number of injected processes analysed:0
                                      Technologies:
                                      • HCA enabled
                                      • EGA enabled
                                      • HDC enabled
                                      • AMSI enabled
                                      Analysis Mode:default
                                      Analysis stop reason:Timeout
                                      Detection:MAL
                                      Classification:mal64.phis.winHTML@28/0@8/10
                                      EGA Information:Failed
                                      HDC Information:Failed
                                      HCA Information:
                                      • Successful, ratio: 100%
                                      • Number of executed functions: 0
                                      • Number of non-executed functions: 0
                                      Cookbook Comments:
                                      • Found application associated with file extension: .html
                                      • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, conhost.exe, svchost.exe
                                      • TCP Packets have been reduced to 100
                                      • Excluded IPs from analysis (whitelisted): 172.217.168.67, 69.16.175.42, 69.16.175.10, 142.250.203.106, 34.104.35.123
                                      • Excluded domains from analysis (whitelisted): client.wns.windows.com, cds.s5x3j6q5.hwcdn.net, edgedl.me.gvt1.com, ajax.googleapis.com, update.googleapis.com, clientservices.googleapis.com
                                      • Not all processes where analyzed, report is missing behavior information
                                      • Report size getting too big, too many NtWriteVirtualMemory calls found.
                                      No simulations
                                      No context
                                      No context
                                      No context
                                      No context
                                      No context
                                      No created / dropped files found
                                      File type:HTML document, ASCII text, with very long lines (62367), with CRLF line terminators
                                      Entropy (8bit):6.141867962985458
                                      TrID:
                                      • HyperText Markup Language (12001/1) 20.69%
                                      • HyperText Markup Language (12001/1) 20.69%
                                      • HyperText Markup Language (11501/1) 19.83%
                                      • HyperText Markup Language (11501/1) 19.83%
                                      • HyperText Markup Language (11001/1) 18.97%
                                      File name:Paid_invoice.html
                                      File size:78674
                                      MD5:388cd3eda11c1e4a18b95934c94e4751
                                      SHA1:fc6c35aaefc9671149387530a875c2e2a350a5d2
                                      SHA256:0b81b708477c44bb04dd7bb0ed927d4ce8a3c7d9e11882542ab84f89bd167bb1
                                      SHA512:54599e09c1afad9771d473bd5e52cdeb5d29fa0be335116464db82364187a399444581aeb0d6d34c18775beb8f931765deeb221bd0dad4e6f739c56455d20f4d
                                      SSDEEP:1536:6oDLblS0ldSbAWeOuuRisEflunmYs4yMZ5NsOSdPzsGEJa:6o/blZuRGH1Merwa
                                      TLSH:C1739DB4D3809917085C1F53F62AB9ADFE2D41E389C0978F725C7A4EDBF5216A046633
                                      File Content Preview:<html lang="en">....<head>.. <meta http-equiv="x-ua-compatible" content="EmulateIE9">.. <meta charset="utf-8">.. <meta name="viewport" content="width=device-width, initial-scale=1, shrink-to-fit=no">.. <link rel="stylesheet" href="https://maxc
                                      TimestampSource PortDest PortSource IPDest IP
                                      Nov 29, 2022 21:57:56.942137957 CET49708443192.168.2.5142.250.203.110
                                      Nov 29, 2022 21:57:56.942197084 CET44349708142.250.203.110192.168.2.5
                                      Nov 29, 2022 21:57:56.942315102 CET49708443192.168.2.5142.250.203.110
                                      Nov 29, 2022 21:57:56.942790985 CET49708443192.168.2.5142.250.203.110
                                      Nov 29, 2022 21:57:56.942820072 CET44349708142.250.203.110192.168.2.5
                                      Nov 29, 2022 21:57:57.010298014 CET44349708142.250.203.110192.168.2.5
                                      Nov 29, 2022 21:57:57.023806095 CET49708443192.168.2.5142.250.203.110
                                      Nov 29, 2022 21:57:57.023866892 CET44349708142.250.203.110192.168.2.5
                                      Nov 29, 2022 21:57:57.024668932 CET44349708142.250.203.110192.168.2.5
                                      Nov 29, 2022 21:57:57.024770021 CET49708443192.168.2.5142.250.203.110
                                      Nov 29, 2022 21:57:57.025784016 CET44349708142.250.203.110192.168.2.5
                                      Nov 29, 2022 21:57:57.025876045 CET49708443192.168.2.5142.250.203.110
                                      Nov 29, 2022 21:57:57.134499073 CET49709443192.168.2.5172.217.168.45
                                      Nov 29, 2022 21:57:57.134557009 CET44349709172.217.168.45192.168.2.5
                                      Nov 29, 2022 21:57:57.134654045 CET49709443192.168.2.5172.217.168.45
                                      Nov 29, 2022 21:57:57.135030985 CET49709443192.168.2.5172.217.168.45
                                      Nov 29, 2022 21:57:57.135092974 CET44349709172.217.168.45192.168.2.5
                                      Nov 29, 2022 21:57:57.218238115 CET44349709172.217.168.45192.168.2.5
                                      Nov 29, 2022 21:57:57.218663931 CET49709443192.168.2.5172.217.168.45
                                      Nov 29, 2022 21:57:57.218710899 CET44349709172.217.168.45192.168.2.5
                                      Nov 29, 2022 21:57:57.220546961 CET44349709172.217.168.45192.168.2.5
                                      Nov 29, 2022 21:57:57.220649004 CET49709443192.168.2.5172.217.168.45
                                      Nov 29, 2022 21:57:57.417860031 CET49709443192.168.2.5172.217.168.45
                                      Nov 29, 2022 21:57:57.417886972 CET44349709172.217.168.45192.168.2.5
                                      Nov 29, 2022 21:57:57.418237925 CET44349709172.217.168.45192.168.2.5
                                      Nov 29, 2022 21:57:57.418584108 CET49708443192.168.2.5142.250.203.110
                                      Nov 29, 2022 21:57:57.418618917 CET44349708142.250.203.110192.168.2.5
                                      Nov 29, 2022 21:57:57.418858051 CET44349708142.250.203.110192.168.2.5
                                      Nov 29, 2022 21:57:57.419173956 CET49709443192.168.2.5172.217.168.45
                                      Nov 29, 2022 21:57:57.419198990 CET44349709172.217.168.45192.168.2.5
                                      Nov 29, 2022 21:57:57.419708967 CET49708443192.168.2.5142.250.203.110
                                      Nov 29, 2022 21:57:57.419730902 CET44349708142.250.203.110192.168.2.5
                                      Nov 29, 2022 21:57:57.456307888 CET44349708142.250.203.110192.168.2.5
                                      Nov 29, 2022 21:57:57.456458092 CET49708443192.168.2.5142.250.203.110
                                      Nov 29, 2022 21:57:57.456511974 CET44349708142.250.203.110192.168.2.5
                                      Nov 29, 2022 21:57:57.456758976 CET44349708142.250.203.110192.168.2.5
                                      Nov 29, 2022 21:57:57.456849098 CET49708443192.168.2.5142.250.203.110
                                      Nov 29, 2022 21:57:57.460422039 CET49709443192.168.2.5172.217.168.45
                                      Nov 29, 2022 21:57:57.465223074 CET49708443192.168.2.5142.250.203.110
                                      Nov 29, 2022 21:57:57.465277910 CET44349708142.250.203.110192.168.2.5
                                      Nov 29, 2022 21:57:57.493501902 CET44349709172.217.168.45192.168.2.5
                                      Nov 29, 2022 21:57:57.493872881 CET44349709172.217.168.45192.168.2.5
                                      Nov 29, 2022 21:57:57.493973970 CET49709443192.168.2.5172.217.168.45
                                      Nov 29, 2022 21:57:57.509069920 CET49709443192.168.2.5172.217.168.45
                                      Nov 29, 2022 21:57:57.509088993 CET44349709172.217.168.45192.168.2.5
                                      Nov 29, 2022 21:57:59.205550909 CET49711443192.168.2.5104.18.11.207
                                      Nov 29, 2022 21:57:59.205616951 CET44349711104.18.11.207192.168.2.5
                                      Nov 29, 2022 21:57:59.205744028 CET49711443192.168.2.5104.18.11.207
                                      Nov 29, 2022 21:57:59.288131952 CET49713443192.168.2.5104.17.24.14
                                      Nov 29, 2022 21:57:59.288213968 CET44349713104.17.24.14192.168.2.5
                                      Nov 29, 2022 21:57:59.288300037 CET49713443192.168.2.5104.17.24.14
                                      Nov 29, 2022 21:57:59.300245047 CET49715443192.168.2.5104.18.11.207
                                      Nov 29, 2022 21:57:59.300309896 CET44349715104.18.11.207192.168.2.5
                                      Nov 29, 2022 21:57:59.300394058 CET49715443192.168.2.5104.18.11.207
                                      Nov 29, 2022 21:57:59.300575018 CET49716443192.168.2.5104.18.11.207
                                      Nov 29, 2022 21:57:59.300612926 CET44349716104.18.11.207192.168.2.5
                                      Nov 29, 2022 21:57:59.300690889 CET49716443192.168.2.5104.18.11.207
                                      Nov 29, 2022 21:57:59.301100969 CET49711443192.168.2.5104.18.11.207
                                      Nov 29, 2022 21:57:59.301177025 CET44349711104.18.11.207192.168.2.5
                                      Nov 29, 2022 21:57:59.301862001 CET49717443192.168.2.5104.18.11.207
                                      Nov 29, 2022 21:57:59.301940918 CET44349717104.18.11.207192.168.2.5
                                      Nov 29, 2022 21:57:59.302035093 CET49717443192.168.2.5104.18.11.207
                                      Nov 29, 2022 21:57:59.302679062 CET49719443192.168.2.5104.17.24.14
                                      Nov 29, 2022 21:57:59.302722931 CET44349719104.17.24.14192.168.2.5
                                      Nov 29, 2022 21:57:59.302795887 CET49719443192.168.2.5104.17.24.14
                                      Nov 29, 2022 21:57:59.303651094 CET49713443192.168.2.5104.17.24.14
                                      Nov 29, 2022 21:57:59.303688049 CET44349713104.17.24.14192.168.2.5
                                      Nov 29, 2022 21:57:59.304414034 CET49715443192.168.2.5104.18.11.207
                                      Nov 29, 2022 21:57:59.304441929 CET44349715104.18.11.207192.168.2.5
                                      Nov 29, 2022 21:57:59.304712057 CET49716443192.168.2.5104.18.11.207
                                      Nov 29, 2022 21:57:59.304739952 CET44349716104.18.11.207192.168.2.5
                                      Nov 29, 2022 21:57:59.304944992 CET49717443192.168.2.5104.18.11.207
                                      Nov 29, 2022 21:57:59.304997921 CET44349717104.18.11.207192.168.2.5
                                      Nov 29, 2022 21:57:59.309693098 CET49719443192.168.2.5104.17.24.14
                                      Nov 29, 2022 21:57:59.309726000 CET44349719104.17.24.14192.168.2.5
                                      Nov 29, 2022 21:57:59.510745049 CET44349717104.18.11.207192.168.2.5
                                      Nov 29, 2022 21:57:59.511288881 CET49717443192.168.2.5104.18.11.207
                                      Nov 29, 2022 21:57:59.511338949 CET44349717104.18.11.207192.168.2.5
                                      Nov 29, 2022 21:57:59.513060093 CET44349717104.18.11.207192.168.2.5
                                      Nov 29, 2022 21:57:59.513261080 CET49717443192.168.2.5104.18.11.207
                                      Nov 29, 2022 21:57:59.532004118 CET44349711104.18.11.207192.168.2.5
                                      Nov 29, 2022 21:57:59.533544064 CET49711443192.168.2.5104.18.11.207
                                      Nov 29, 2022 21:57:59.533590078 CET44349711104.18.11.207192.168.2.5
                                      Nov 29, 2022 21:57:59.536725044 CET44349711104.18.11.207192.168.2.5
                                      Nov 29, 2022 21:57:59.536830902 CET49711443192.168.2.5104.18.11.207
                                      Nov 29, 2022 21:57:59.547540903 CET44349716104.18.11.207192.168.2.5
                                      Nov 29, 2022 21:57:59.572252035 CET49716443192.168.2.5104.18.11.207
                                      Nov 29, 2022 21:57:59.572288990 CET44349716104.18.11.207192.168.2.5
                                      Nov 29, 2022 21:57:59.572520018 CET49717443192.168.2.5104.18.11.207
                                      Nov 29, 2022 21:57:59.572575092 CET44349717104.18.11.207192.168.2.5
                                      Nov 29, 2022 21:57:59.573031902 CET44349717104.18.11.207192.168.2.5
                                      Nov 29, 2022 21:57:59.573493004 CET49711443192.168.2.5104.18.11.207
                                      Nov 29, 2022 21:57:59.573554993 CET44349711104.18.11.207192.168.2.5
                                      Nov 29, 2022 21:57:59.573827982 CET49717443192.168.2.5104.18.11.207
                                      Nov 29, 2022 21:57:59.573865891 CET44349717104.18.11.207192.168.2.5
                                      Nov 29, 2022 21:57:59.573880911 CET49711443192.168.2.5104.18.11.207
                                      Nov 29, 2022 21:57:59.573889971 CET44349711104.18.11.207192.168.2.5
                                      Nov 29, 2022 21:57:59.573909044 CET44349711104.18.11.207192.168.2.5
                                      Nov 29, 2022 21:57:59.575622082 CET44349716104.18.11.207192.168.2.5
                                      Nov 29, 2022 21:57:59.575694084 CET49716443192.168.2.5104.18.11.207
                                      TimestampSource PortDest PortSource IPDest IP
                                      Nov 29, 2022 21:57:56.825531960 CET6532353192.168.2.58.8.8.8
                                      Nov 29, 2022 21:57:56.827173948 CET5148453192.168.2.58.8.8.8
                                      Nov 29, 2022 21:57:56.853432894 CET53514848.8.8.8192.168.2.5
                                      Nov 29, 2022 21:57:56.853494883 CET53653238.8.8.8192.168.2.5
                                      Nov 29, 2022 21:57:58.987894058 CET5503953192.168.2.58.8.8.8
                                      Nov 29, 2022 21:57:58.991000891 CET6097553192.168.2.58.8.8.8
                                      Nov 29, 2022 21:57:59.002558947 CET5922053192.168.2.58.8.8.8
                                      Nov 29, 2022 21:57:59.010333061 CET53550398.8.8.8192.168.2.5
                                      Nov 29, 2022 21:57:59.021431923 CET5668253192.168.2.58.8.8.8
                                      Nov 29, 2022 21:57:59.024481058 CET53592208.8.8.8192.168.2.5
                                      Nov 29, 2022 21:57:59.044281960 CET53566828.8.8.8192.168.2.5
                                      Nov 29, 2022 21:58:00.655205965 CET5858153192.168.2.58.8.8.8
                                      Nov 29, 2022 21:58:00.673170090 CET53585818.8.8.8192.168.2.5
                                      Nov 29, 2022 21:59:00.716061115 CET5355553192.168.2.58.8.8.8
                                      Nov 29, 2022 21:59:00.733777046 CET53535558.8.8.8192.168.2.5
                                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                      Nov 29, 2022 21:57:56.825531960 CET192.168.2.58.8.8.80xdf57Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                                      Nov 29, 2022 21:57:56.827173948 CET192.168.2.58.8.8.80xffe3Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                                      Nov 29, 2022 21:57:58.987894058 CET192.168.2.58.8.8.80x2da3Standard query (0)maxcdn.bootstrapcdn.comA (IP address)IN (0x0001)false
                                      Nov 29, 2022 21:57:58.991000891 CET192.168.2.58.8.8.80xb143Standard query (0)code.jquery.comA (IP address)IN (0x0001)false
                                      Nov 29, 2022 21:57:59.002558947 CET192.168.2.58.8.8.80x632aStandard query (0)cdnjs.cloudflare.comA (IP address)IN (0x0001)false
                                      Nov 29, 2022 21:57:59.021431923 CET192.168.2.58.8.8.80xeeccStandard query (0)stackpath.bootstrapcdn.comA (IP address)IN (0x0001)false
                                      Nov 29, 2022 21:58:00.655205965 CET192.168.2.58.8.8.80x40b1Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                      Nov 29, 2022 21:59:00.716061115 CET192.168.2.58.8.8.80xc040Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                      Nov 29, 2022 21:57:56.853432894 CET8.8.8.8192.168.2.50xffe3No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                                      Nov 29, 2022 21:57:56.853432894 CET8.8.8.8192.168.2.50xffe3No error (0)clients.l.google.com142.250.203.110A (IP address)IN (0x0001)false
                                      Nov 29, 2022 21:57:56.853494883 CET8.8.8.8192.168.2.50xdf57No error (0)accounts.google.com172.217.168.45A (IP address)IN (0x0001)false
                                      Nov 29, 2022 21:57:59.009727001 CET8.8.8.8192.168.2.50xb143No error (0)code.jquery.comcds.s5x3j6q5.hwcdn.netCNAME (Canonical name)IN (0x0001)false
                                      Nov 29, 2022 21:57:59.010333061 CET8.8.8.8192.168.2.50x2da3No error (0)maxcdn.bootstrapcdn.com104.18.11.207A (IP address)IN (0x0001)false
                                      Nov 29, 2022 21:57:59.010333061 CET8.8.8.8192.168.2.50x2da3No error (0)maxcdn.bootstrapcdn.com104.18.10.207A (IP address)IN (0x0001)false
                                      Nov 29, 2022 21:57:59.024481058 CET8.8.8.8192.168.2.50x632aNo error (0)cdnjs.cloudflare.com104.17.24.14A (IP address)IN (0x0001)false
                                      Nov 29, 2022 21:57:59.024481058 CET8.8.8.8192.168.2.50x632aNo error (0)cdnjs.cloudflare.com104.17.25.14A (IP address)IN (0x0001)false
                                      Nov 29, 2022 21:57:59.044281960 CET8.8.8.8192.168.2.50xeeccNo error (0)stackpath.bootstrapcdn.com104.18.11.207A (IP address)IN (0x0001)false
                                      Nov 29, 2022 21:57:59.044281960 CET8.8.8.8192.168.2.50xeeccNo error (0)stackpath.bootstrapcdn.com104.18.10.207A (IP address)IN (0x0001)false
                                      Nov 29, 2022 21:58:00.673170090 CET8.8.8.8192.168.2.50x40b1No error (0)www.google.com172.217.168.68A (IP address)IN (0x0001)false
                                      Nov 29, 2022 21:59:00.733777046 CET8.8.8.8192.168.2.50xc040No error (0)www.google.com172.217.168.68A (IP address)IN (0x0001)false
                                      • accounts.google.com
                                      • clients2.google.com
                                      • maxcdn.bootstrapcdn.com
                                      • stackpath.bootstrapcdn.com
                                      • cdnjs.cloudflare.com

                                      Click to jump to process

                                      Target ID:2
                                      Start time:21:57:53
                                      Start date:29/11/2022
                                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                                      Imagebase:0x7ff7d31b0000
                                      File size:2851656 bytes
                                      MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Reputation:high

                                      Target ID:3
                                      Start time:21:57:54
                                      Start date:29/11/2022
                                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      Wow64 process (32bit):false
                                      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1756 --field-trial-handle=1648,i,9583188458170825095,14417365062387772299,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                                      Imagebase:0x7ff7d31b0000
                                      File size:2851656 bytes
                                      MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Reputation:high

                                      Target ID:4
                                      Start time:21:57:55
                                      Start date:29/11/2022
                                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                      Wow64 process (32bit):false
                                      Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "C:\Users\user\Desktop\Paid_invoice.html
                                      Imagebase:0x7ff7d31b0000
                                      File size:2851656 bytes
                                      MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                                      Has elevated privileges:true
                                      Has administrator privileges:true
                                      Programmed in:C, C++ or other language
                                      Reputation:high

                                      No disassembly