Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://bit.ly/3TRQuxO

Overview

General Information

Sample URL:https://bit.ly/3TRQuxO
Analysis ID:756304
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample

Classification

  • System is w10x64
  • chrome.exe (PID: 5088 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 1612 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1700 --field-trial-handle=1808,i,16423850983966293059,340170596830711533,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 6068 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "https://bit.ly/3TRQuxO MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://bit.ly/3TRQuxOSlashNext: detection malicious, Label: Fraudulent Website type: Phishing & Social Engineering
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /3TRQuxO HTTP/1.1Host: bit.lyConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /Sa09wy4x7ub HTTP/1.1Host: dqb4v.app.linkConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?a=1nrK&c=d&s=93 HTTP/1.1Host: thetrueline-life.worldConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?a=1nrK&c=d&s=93 HTTP/1.1Host: thetrueline-life.worldConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?a=1nrK&c=d&s=93 HTTP/1.1Host: thetrueline-life.worldConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?a=1nrK&c=d&s=93 HTTP/1.1Host: thetrueline-life.worldConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?a=1nrK&c=d&s=93 HTTP/1.1Host: thetrueline-life.worldConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?a=1nrK&c=d&s=93 HTTP/1.1Host: thetrueline-life.worldConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?a=1nrK&c=d&s=93 HTTP/1.1Host: thetrueline-life.worldConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?a=1nrK&c=d&s=93 HTTP/1.1Host: thetrueline-life.worldConnection: keep-aliveCache-Control: max-age=0sec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /usdon?_branch_match_id=1126279546979093380&utm_medium=marketing&_branch_referrer=H4sIAAAAAAAAA8soKSkottLXTylMMinTSywo0MvJzMvWD040sCyvNKkwL00CAJjMII0iAAAA HTTP/1.1Host: 3kjarwa.associatesuitcase.co.inConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?a=1nrK&c=d&s=93 HTTP/1.1Host: thetrueline-life.worldConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: classification engineClassification label: mal48.win@30/0@8/10
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1700 --field-trial-handle=1808,i,16423850983966293059,340170596830711533,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "https://bit.ly/3TRQuxO
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1700 --field-trial-handle=1808,i,16423850983966293059,340170596830711533,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://bit.ly/3TRQuxO3%VirustotalBrowse
https://bit.ly/3TRQuxO0%Avira URL Cloudsafe
https://bit.ly/3TRQuxO100%SlashNextFraudulent Website type: Phishing & Social Engineering
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://3kjarwa.associatesuitcase.co.in/usdon?_branch_match_id=1126279546979093380&utm_medium=marketing&_branch_referrer=H4sIAAAAAAAAA8soKSkottLXTylMMinTSywo0MvJzMvWD040sCyvNKkwL00CAJjMII0iAAAA0%Avira URL Cloudsafe
https://thetrueline-life.world/?a=1nrK&c=d&s=931%VirustotalBrowse
http://thetrueline-life.world/?a=1nrK&c=d&s=931%VirustotalBrowse
http://thetrueline-life.world/?a=1nrK&c=d&s=930%Avira URL Cloudsafe
https://thetrueline-life.world/?a=1nrK&c=d&s=930%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
3kjarwa.associatesuitcase.co.in
84.21.172.16
truefalse
    unknown
    thetrueline-life.world
    213.227.155.34
    truefalse
      unknown
      accounts.google.com
      172.217.168.45
      truefalse
        high
        bit.ly
        67.199.248.11
        truefalse
          high
          dqb4v.app.link
          18.65.39.84
          truefalse
            high
            www.google.com
            172.217.168.68
            truefalse
              high
              clients.l.google.com
              142.250.203.110
              truefalse
                high
                clients2.google.com
                unknown
                unknownfalse
                  high
                  NameMaliciousAntivirus DetectionReputation
                  https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                    high
                    http://3kjarwa.associatesuitcase.co.in/usdon?_branch_match_id=1126279546979093380&utm_medium=marketing&_branch_referrer=H4sIAAAAAAAAA8soKSkottLXTylMMinTSywo0MvJzMvWD040sCyvNKkwL00CAJjMII0iAAAAfalse
                    • Avira URL Cloud: safe
                    unknown
                    https://bit.ly/3TRQuxOfalse
                      high
                      https://dqb4v.app.link/Sa09wy4x7ubfalse
                        high
                        https://thetrueline-life.world/?a=1nrK&c=d&s=93false
                        • 1%, Virustotal, Browse
                        • Avira URL Cloud: safe
                        unknown
                        http://thetrueline-life.world/?a=1nrK&c=d&s=93false
                        • 1%, Virustotal, Browse
                        • Avira URL Cloud: safe
                        unknown
                        https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                          high
                          • No. of IPs < 25%
                          • 25% < No. of IPs < 50%
                          • 50% < No. of IPs < 75%
                          • 75% < No. of IPs
                          IPDomainCountryFlagASNASN NameMalicious
                          18.65.39.84
                          dqb4v.app.linkUnited States
                          3MIT-GATEWAYSUSfalse
                          142.250.203.110
                          clients.l.google.comUnited States
                          15169GOOGLEUSfalse
                          172.217.168.68
                          www.google.comUnited States
                          15169GOOGLEUSfalse
                          84.21.172.16
                          3kjarwa.associatesuitcase.co.inGermany
                          30823COMBAHTONcombahtonGmbHDEfalse
                          172.217.168.45
                          accounts.google.comUnited States
                          15169GOOGLEUSfalse
                          239.255.255.250
                          unknownReserved
                          unknownunknownfalse
                          213.227.155.34
                          thetrueline-life.worldNetherlands
                          60781LEASEWEB-NL-AMS-01NetherlandsNLfalse
                          67.199.248.11
                          bit.lyUnited States
                          396982GOOGLE-PRIVATE-CLOUDUSfalse
                          IP
                          192.168.2.1
                          127.0.0.1
                          Joe Sandbox Version:36.0.0 Rainbow Opal
                          Analysis ID:756304
                          Start date and time:2022-11-30 00:22:10 +01:00
                          Joe Sandbox Product:CloudBasic
                          Overall analysis duration:0h 5m 0s
                          Hypervisor based Inspection enabled:false
                          Report type:light
                          Cookbook file name:browseurl.jbs
                          Sample URL:https://bit.ly/3TRQuxO
                          Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                          Number of analysed new started processes analysed:10
                          Number of new started drivers analysed:0
                          Number of existing processes analysed:0
                          Number of existing drivers analysed:0
                          Number of injected processes analysed:0
                          Technologies:
                          • HCA enabled
                          • EGA enabled
                          • HDC enabled
                          • AMSI enabled
                          Analysis Mode:default
                          Analysis stop reason:Timeout
                          Detection:MAL
                          Classification:mal48.win@30/0@8/10
                          EGA Information:Failed
                          HDC Information:Failed
                          HCA Information:
                          • Successful, ratio: 100%
                          • Number of executed functions: 0
                          • Number of non-executed functions: 0
                          • Exclude process from analysis (whitelisted): SgrmBroker.exe, svchost.exe
                          • TCP Packets have been reduced to 100
                          • Excluded IPs from analysis (whitelisted): 172.217.168.67, 34.104.35.123
                          • Excluded domains from analysis (whitelisted): client.wns.windows.com, fs.microsoft.com, edgedl.me.gvt1.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com
                          • Not all processes where analyzed, report is missing behavior information
                          • Report size getting too big, too many NtWriteVirtualMemory calls found.
                          No simulations
                          No context
                          No context
                          No context
                          No context
                          No context
                          No created / dropped files found
                          No static file info
                          TimestampSource PortDest PortSource IPDest IP
                          Nov 30, 2022 00:23:14.278610945 CET49711443192.168.2.7142.250.203.110
                          Nov 30, 2022 00:23:14.278671980 CET44349711142.250.203.110192.168.2.7
                          Nov 30, 2022 00:23:14.278745890 CET49711443192.168.2.7142.250.203.110
                          Nov 30, 2022 00:23:14.279064894 CET49712443192.168.2.767.199.248.11
                          Nov 30, 2022 00:23:14.279099941 CET4434971267.199.248.11192.168.2.7
                          Nov 30, 2022 00:23:14.279169083 CET49712443192.168.2.767.199.248.11
                          Nov 30, 2022 00:23:14.280710936 CET49711443192.168.2.7142.250.203.110
                          Nov 30, 2022 00:23:14.280751944 CET44349711142.250.203.110192.168.2.7
                          Nov 30, 2022 00:23:14.280879974 CET49712443192.168.2.767.199.248.11
                          Nov 30, 2022 00:23:14.280895948 CET4434971267.199.248.11192.168.2.7
                          Nov 30, 2022 00:23:14.383877993 CET4434971267.199.248.11192.168.2.7
                          Nov 30, 2022 00:23:14.393577099 CET44349711142.250.203.110192.168.2.7
                          Nov 30, 2022 00:23:14.439941883 CET49711443192.168.2.7142.250.203.110
                          Nov 30, 2022 00:23:14.443464041 CET49712443192.168.2.767.199.248.11
                          Nov 30, 2022 00:23:14.502834082 CET49711443192.168.2.7142.250.203.110
                          Nov 30, 2022 00:23:14.502877951 CET44349711142.250.203.110192.168.2.7
                          Nov 30, 2022 00:23:14.504590988 CET44349711142.250.203.110192.168.2.7
                          Nov 30, 2022 00:23:14.504733086 CET49711443192.168.2.7142.250.203.110
                          Nov 30, 2022 00:23:14.504812956 CET49712443192.168.2.767.199.248.11
                          Nov 30, 2022 00:23:14.504841089 CET4434971267.199.248.11192.168.2.7
                          Nov 30, 2022 00:23:14.508227110 CET44349711142.250.203.110192.168.2.7
                          Nov 30, 2022 00:23:14.508390903 CET49711443192.168.2.7142.250.203.110
                          Nov 30, 2022 00:23:14.508559942 CET4434971267.199.248.11192.168.2.7
                          Nov 30, 2022 00:23:14.508651972 CET49712443192.168.2.767.199.248.11
                          Nov 30, 2022 00:23:14.508658886 CET4434971267.199.248.11192.168.2.7
                          Nov 30, 2022 00:23:14.594691992 CET49713443192.168.2.7172.217.168.45
                          Nov 30, 2022 00:23:14.594749928 CET44349713172.217.168.45192.168.2.7
                          Nov 30, 2022 00:23:14.594831944 CET49713443192.168.2.7172.217.168.45
                          Nov 30, 2022 00:23:14.595304012 CET49713443192.168.2.7172.217.168.45
                          Nov 30, 2022 00:23:14.595329046 CET44349713172.217.168.45192.168.2.7
                          Nov 30, 2022 00:23:14.639935970 CET49712443192.168.2.767.199.248.11
                          Nov 30, 2022 00:23:14.664751053 CET44349713172.217.168.45192.168.2.7
                          Nov 30, 2022 00:23:14.782946110 CET49713443192.168.2.7172.217.168.45
                          Nov 30, 2022 00:23:14.857853889 CET49713443192.168.2.7172.217.168.45
                          Nov 30, 2022 00:23:14.857903004 CET44349713172.217.168.45192.168.2.7
                          Nov 30, 2022 00:23:14.861604929 CET44349713172.217.168.45192.168.2.7
                          Nov 30, 2022 00:23:14.861706972 CET49713443192.168.2.7172.217.168.45
                          Nov 30, 2022 00:23:14.861757994 CET44349713172.217.168.45192.168.2.7
                          Nov 30, 2022 00:23:14.981913090 CET49713443192.168.2.7172.217.168.45
                          Nov 30, 2022 00:23:15.352822065 CET49713443192.168.2.7172.217.168.45
                          Nov 30, 2022 00:23:15.352904081 CET44349713172.217.168.45192.168.2.7
                          Nov 30, 2022 00:23:15.353286028 CET44349713172.217.168.45192.168.2.7
                          Nov 30, 2022 00:23:15.353797913 CET49713443192.168.2.7172.217.168.45
                          Nov 30, 2022 00:23:15.353857994 CET44349713172.217.168.45192.168.2.7
                          Nov 30, 2022 00:23:15.354146957 CET49712443192.168.2.767.199.248.11
                          Nov 30, 2022 00:23:15.354209900 CET4434971267.199.248.11192.168.2.7
                          Nov 30, 2022 00:23:15.354922056 CET49711443192.168.2.7142.250.203.110
                          Nov 30, 2022 00:23:15.354971886 CET44349711142.250.203.110192.168.2.7
                          Nov 30, 2022 00:23:15.355106115 CET49712443192.168.2.767.199.248.11
                          Nov 30, 2022 00:23:15.355125904 CET4434971267.199.248.11192.168.2.7
                          Nov 30, 2022 00:23:15.355192900 CET44349711142.250.203.110192.168.2.7
                          Nov 30, 2022 00:23:15.355308056 CET4434971267.199.248.11192.168.2.7
                          Nov 30, 2022 00:23:15.355446100 CET49711443192.168.2.7142.250.203.110
                          Nov 30, 2022 00:23:15.355479002 CET44349711142.250.203.110192.168.2.7
                          Nov 30, 2022 00:23:15.390867949 CET44349711142.250.203.110192.168.2.7
                          Nov 30, 2022 00:23:15.391006947 CET49711443192.168.2.7142.250.203.110
                          Nov 30, 2022 00:23:15.391041994 CET44349711142.250.203.110192.168.2.7
                          Nov 30, 2022 00:23:15.391293049 CET44349711142.250.203.110192.168.2.7
                          Nov 30, 2022 00:23:15.391377926 CET49711443192.168.2.7142.250.203.110
                          Nov 30, 2022 00:23:15.397468090 CET49711443192.168.2.7142.250.203.110
                          Nov 30, 2022 00:23:15.397510052 CET44349711142.250.203.110192.168.2.7
                          Nov 30, 2022 00:23:15.430311918 CET44349713172.217.168.45192.168.2.7
                          Nov 30, 2022 00:23:15.430504084 CET49713443192.168.2.7172.217.168.45
                          Nov 30, 2022 00:23:15.430540085 CET44349713172.217.168.45192.168.2.7
                          Nov 30, 2022 00:23:15.430723906 CET44349713172.217.168.45192.168.2.7
                          Nov 30, 2022 00:23:15.430830956 CET49713443192.168.2.7172.217.168.45
                          Nov 30, 2022 00:23:15.440006971 CET49712443192.168.2.767.199.248.11
                          Nov 30, 2022 00:23:15.440073013 CET4434971267.199.248.11192.168.2.7
                          Nov 30, 2022 00:23:15.452543020 CET49713443192.168.2.7172.217.168.45
                          Nov 30, 2022 00:23:15.452589035 CET44349713172.217.168.45192.168.2.7
                          Nov 30, 2022 00:23:15.478593111 CET4434971267.199.248.11192.168.2.7
                          Nov 30, 2022 00:23:15.478729963 CET49712443192.168.2.767.199.248.11
                          Nov 30, 2022 00:23:15.513979912 CET49712443192.168.2.767.199.248.11
                          Nov 30, 2022 00:23:15.514043093 CET4434971267.199.248.11192.168.2.7
                          Nov 30, 2022 00:23:15.683275938 CET49714443192.168.2.718.65.39.84
                          Nov 30, 2022 00:23:15.683331966 CET4434971418.65.39.84192.168.2.7
                          Nov 30, 2022 00:23:15.683413029 CET49714443192.168.2.718.65.39.84
                          Nov 30, 2022 00:23:15.683846951 CET49714443192.168.2.718.65.39.84
                          Nov 30, 2022 00:23:15.683861971 CET4434971418.65.39.84192.168.2.7
                          Nov 30, 2022 00:23:15.754347086 CET4434971418.65.39.84192.168.2.7
                          Nov 30, 2022 00:23:15.762408972 CET49714443192.168.2.718.65.39.84
                          Nov 30, 2022 00:23:15.762443066 CET4434971418.65.39.84192.168.2.7
                          Nov 30, 2022 00:23:15.764111996 CET4434971418.65.39.84192.168.2.7
                          Nov 30, 2022 00:23:15.764247894 CET49714443192.168.2.718.65.39.84
                          Nov 30, 2022 00:23:15.766701937 CET49714443192.168.2.718.65.39.84
                          Nov 30, 2022 00:23:15.766716003 CET4434971418.65.39.84192.168.2.7
                          Nov 30, 2022 00:23:15.766838074 CET4434971418.65.39.84192.168.2.7
                          Nov 30, 2022 00:23:15.766997099 CET49714443192.168.2.718.65.39.84
                          Nov 30, 2022 00:23:15.767007113 CET4434971418.65.39.84192.168.2.7
                          Nov 30, 2022 00:23:15.843724012 CET49716443192.168.2.7172.217.168.68
                          Nov 30, 2022 00:23:15.843790054 CET44349716172.217.168.68192.168.2.7
                          Nov 30, 2022 00:23:15.843878984 CET49716443192.168.2.7172.217.168.68
                          Nov 30, 2022 00:23:15.844238997 CET49716443192.168.2.7172.217.168.68
                          Nov 30, 2022 00:23:15.844284058 CET44349716172.217.168.68192.168.2.7
                          Nov 30, 2022 00:23:15.913541079 CET44349716172.217.168.68192.168.2.7
                          Nov 30, 2022 00:23:15.914004087 CET49716443192.168.2.7172.217.168.68
                          Nov 30, 2022 00:23:15.914033890 CET44349716172.217.168.68192.168.2.7
                          Nov 30, 2022 00:23:15.915328979 CET44349716172.217.168.68192.168.2.7
                          Nov 30, 2022 00:23:15.915437937 CET49716443192.168.2.7172.217.168.68
                          Nov 30, 2022 00:23:15.918338060 CET49716443192.168.2.7172.217.168.68
                          TimestampSource PortDest PortSource IPDest IP
                          Nov 30, 2022 00:23:14.152200937 CET5333653192.168.2.78.8.8.8
                          Nov 30, 2022 00:23:14.155282974 CET5100753192.168.2.78.8.8.8
                          Nov 30, 2022 00:23:14.158768892 CET5051353192.168.2.78.8.8.8
                          Nov 30, 2022 00:23:14.170192003 CET53533368.8.8.8192.168.2.7
                          Nov 30, 2022 00:23:14.177088976 CET53505138.8.8.8192.168.2.7
                          Nov 30, 2022 00:23:14.181938887 CET53510078.8.8.8192.168.2.7
                          Nov 30, 2022 00:23:15.587124109 CET5828353192.168.2.78.8.8.8
                          Nov 30, 2022 00:23:15.632625103 CET53582838.8.8.8192.168.2.7
                          Nov 30, 2022 00:23:15.786753893 CET4951653192.168.2.78.8.8.8
                          Nov 30, 2022 00:23:15.804167032 CET53495168.8.8.8192.168.2.7
                          Nov 30, 2022 00:23:15.979427099 CET6139253192.168.2.78.8.8.8
                          Nov 30, 2022 00:23:16.294555902 CET53613928.8.8.8192.168.2.7
                          Nov 30, 2022 00:23:16.597486973 CET6535653192.168.2.78.8.8.8
                          Nov 30, 2022 00:23:16.625588894 CET53653568.8.8.8192.168.2.7
                          Nov 30, 2022 00:24:15.864783049 CET5622453192.168.2.78.8.8.8
                          Nov 30, 2022 00:24:15.890614986 CET53562248.8.8.8192.168.2.7
                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                          Nov 30, 2022 00:23:14.152200937 CET192.168.2.78.8.8.80x3b23Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                          Nov 30, 2022 00:23:14.155282974 CET192.168.2.78.8.8.80x9d3aStandard query (0)clients2.google.comA (IP address)IN (0x0001)false
                          Nov 30, 2022 00:23:14.158768892 CET192.168.2.78.8.8.80x55c3Standard query (0)bit.lyA (IP address)IN (0x0001)false
                          Nov 30, 2022 00:23:15.587124109 CET192.168.2.78.8.8.80xe19cStandard query (0)dqb4v.app.linkA (IP address)IN (0x0001)false
                          Nov 30, 2022 00:23:15.786753893 CET192.168.2.78.8.8.80xd206Standard query (0)www.google.comA (IP address)IN (0x0001)false
                          Nov 30, 2022 00:23:15.979427099 CET192.168.2.78.8.8.80x42eeStandard query (0)3kjarwa.associatesuitcase.co.inA (IP address)IN (0x0001)false
                          Nov 30, 2022 00:23:16.597486973 CET192.168.2.78.8.8.80x9095Standard query (0)thetrueline-life.worldA (IP address)IN (0x0001)false
                          Nov 30, 2022 00:24:15.864783049 CET192.168.2.78.8.8.80x9e5aStandard query (0)www.google.comA (IP address)IN (0x0001)false
                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                          Nov 30, 2022 00:23:14.170192003 CET8.8.8.8192.168.2.70x3b23No error (0)accounts.google.com172.217.168.45A (IP address)IN (0x0001)false
                          Nov 30, 2022 00:23:14.177088976 CET8.8.8.8192.168.2.70x55c3No error (0)bit.ly67.199.248.11A (IP address)IN (0x0001)false
                          Nov 30, 2022 00:23:14.177088976 CET8.8.8.8192.168.2.70x55c3No error (0)bit.ly67.199.248.10A (IP address)IN (0x0001)false
                          Nov 30, 2022 00:23:14.181938887 CET8.8.8.8192.168.2.70x9d3aNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                          Nov 30, 2022 00:23:14.181938887 CET8.8.8.8192.168.2.70x9d3aNo error (0)clients.l.google.com142.250.203.110A (IP address)IN (0x0001)false
                          Nov 30, 2022 00:23:15.632625103 CET8.8.8.8192.168.2.70xe19cNo error (0)dqb4v.app.link18.65.39.84A (IP address)IN (0x0001)false
                          Nov 30, 2022 00:23:15.632625103 CET8.8.8.8192.168.2.70xe19cNo error (0)dqb4v.app.link18.65.39.105A (IP address)IN (0x0001)false
                          Nov 30, 2022 00:23:15.632625103 CET8.8.8.8192.168.2.70xe19cNo error (0)dqb4v.app.link18.65.39.26A (IP address)IN (0x0001)false
                          Nov 30, 2022 00:23:15.632625103 CET8.8.8.8192.168.2.70xe19cNo error (0)dqb4v.app.link18.65.39.3A (IP address)IN (0x0001)false
                          Nov 30, 2022 00:23:15.804167032 CET8.8.8.8192.168.2.70xd206No error (0)www.google.com172.217.168.68A (IP address)IN (0x0001)false
                          Nov 30, 2022 00:23:16.294555902 CET8.8.8.8192.168.2.70x42eeNo error (0)3kjarwa.associatesuitcase.co.in84.21.172.16A (IP address)IN (0x0001)false
                          Nov 30, 2022 00:23:16.625588894 CET8.8.8.8192.168.2.70x9095No error (0)thetrueline-life.world213.227.155.34A (IP address)IN (0x0001)false
                          Nov 30, 2022 00:24:15.890614986 CET8.8.8.8192.168.2.70x9e5aNo error (0)www.google.com172.217.168.68A (IP address)IN (0x0001)false
                          • accounts.google.com
                          • clients2.google.com
                          • bit.ly
                          • dqb4v.app.link
                          • thetrueline-life.world
                          • 3kjarwa.associatesuitcase.co.in

                          Click to jump to process

                          Target ID:0
                          Start time:00:23:08
                          Start date:30/11/2022
                          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                          Wow64 process (32bit):false
                          Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                          Imagebase:0x7ff7c2920000
                          File size:2851656 bytes
                          MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                          Has elevated privileges:true
                          Has administrator privileges:true
                          Programmed in:C, C++ or other language
                          Reputation:low

                          Target ID:1
                          Start time:00:23:09
                          Start date:30/11/2022
                          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                          Wow64 process (32bit):false
                          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1700 --field-trial-handle=1808,i,16423850983966293059,340170596830711533,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                          Imagebase:0x7ff7c2920000
                          File size:2851656 bytes
                          MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                          Has elevated privileges:true
                          Has administrator privileges:true
                          Programmed in:C, C++ or other language
                          Reputation:low

                          Target ID:2
                          Start time:00:23:10
                          Start date:30/11/2022
                          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                          Wow64 process (32bit):false
                          Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "https://bit.ly/3TRQuxO
                          Imagebase:0x7ff7c2920000
                          File size:2851656 bytes
                          MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                          Has elevated privileges:true
                          Has administrator privileges:true
                          Programmed in:C, C++ or other language
                          Reputation:low

                          No disassembly