Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://www.office.com/?auth=2&home=1

Overview

General Information

Sample URL:https://www.office.com/?auth=2&home=1
Analysis ID:791286

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

HTML body contains low number of good links
No HTML title found

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 1644 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://www.office.com/?auth=2&home=1 MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
    • chrome.exe (PID: 5328 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=1796,i,8177445550997338781,4573666773275504079,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
  • cleanup
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://login.microsoftonline.com/organizations/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638102318766889741.YjBjNDI3Y2ItN2M3Yi00OThlLWJkNzgtZDdjY2JlNzg5MjIxYjAxODcwM2ItNTY1ZC00NzFiLWJkYTMtMGZiYTlhYzE2YTZi&ui_locales=en-US&mkt=en-US&msafed=0&state=1xhbt2TjudldjF05XVlHg6-Q6ZxXf76LUBKXLANWOWn7j7qmHcCqu2jvDVzpad1Qb9LCRjQx5orG5mTPLr4VvfkWDFrFSIL_tIAvcF5XS773vvIUFt3dm5lu897cD-kDI30J0KHpxF48VIYi117ZQNo7IxWD3ndyJc4HhgHehmDKRbmsOklDkuo8NgZQSDati1hy6kWo98kXuQGvP1DJA82utvZsCedBu_osBnLgZCXDEaesGp4kVsVGeE8-dkcw7RWUZaUVZo75B7IpN0zPamDNFpgZSlGX6OFepncsamTEDwfpBtKUR_Q64cFlGaemZs_PnKP8KZVFWl2kz_qhZvbYa_8tT6f0oBmCJbDiTog&x-client-SKU=ID_NETSTANDARD2_0&x-client-ver=6.16.0.0&sso_reload=trueHTTP Parser: Number of links: 0
Source: https://login.microsoftonline.com/organizations/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638102318766889741.YjBjNDI3Y2ItN2M3Yi00OThlLWJkNzgtZDdjY2JlNzg5MjIxYjAxODcwM2ItNTY1ZC00NzFiLWJkYTMtMGZiYTlhYzE2YTZi&ui_locales=en-US&mkt=en-US&msafed=0&state=1xhbt2TjudldjF05XVlHg6-Q6ZxXf76LUBKXLANWOWn7j7qmHcCqu2jvDVzpad1Qb9LCRjQx5orG5mTPLr4VvfkWDFrFSIL_tIAvcF5XS773vvIUFt3dm5lu897cD-kDI30J0KHpxF48VIYi117ZQNo7IxWD3ndyJc4HhgHehmDKRbmsOklDkuo8NgZQSDati1hy6kWo98kXuQGvP1DJA82utvZsCedBu_osBnLgZCXDEaesGp4kVsVGeE8-dkcw7RWUZaUVZo75B7IpN0zPamDNFpgZSlGX6OFepncsamTEDwfpBtKUR_Q64cFlGaemZs_PnKP8KZVFWl2kz_qhZvbYa_8tT6f0oBmCJbDiTog&x-client-SKU=ID_NETSTANDARD2_0&x-client-ver=6.16.0.0&sso_reload=trueHTTP Parser: Number of links: 0
Source: https://login.microsoftonline.com/organizations/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638102318766889741.YjBjNDI3Y2ItN2M3Yi00OThlLWJkNzgtZDdjY2JlNzg5MjIxYjAxODcwM2ItNTY1ZC00NzFiLWJkYTMtMGZiYTlhYzE2YTZi&ui_locales=en-US&mkt=en-US&msafed=0&state=1xhbt2TjudldjF05XVlHg6-Q6ZxXf76LUBKXLANWOWn7j7qmHcCqu2jvDVzpad1Qb9LCRjQx5orG5mTPLr4VvfkWDFrFSIL_tIAvcF5XS773vvIUFt3dm5lu897cD-kDI30J0KHpxF48VIYi117ZQNo7IxWD3ndyJc4HhgHehmDKRbmsOklDkuo8NgZQSDati1hy6kWo98kXuQGvP1DJA82utvZsCedBu_osBnLgZCXDEaesGp4kVsVGeE8-dkcw7RWUZaUVZo75B7IpN0zPamDNFpgZSlGX6OFepncsamTEDwfpBtKUR_Q64cFlGaemZs_PnKP8KZVFWl2kz_qhZvbYa_8tT6f0oBmCJbDiTog&x-client-SKU=ID_NETSTANDARD2_0&x-client-ver=6.16.0.0&sso_reload=trueHTTP Parser: HTML title missing
Source: https://login.microsoftonline.com/organizations/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638102318766889741.YjBjNDI3Y2ItN2M3Yi00OThlLWJkNzgtZDdjY2JlNzg5MjIxYjAxODcwM2ItNTY1ZC00NzFiLWJkYTMtMGZiYTlhYzE2YTZi&ui_locales=en-US&mkt=en-US&msafed=0&state=1xhbt2TjudldjF05XVlHg6-Q6ZxXf76LUBKXLANWOWn7j7qmHcCqu2jvDVzpad1Qb9LCRjQx5orG5mTPLr4VvfkWDFrFSIL_tIAvcF5XS773vvIUFt3dm5lu897cD-kDI30J0KHpxF48VIYi117ZQNo7IxWD3ndyJc4HhgHehmDKRbmsOklDkuo8NgZQSDati1hy6kWo98kXuQGvP1DJA82utvZsCedBu_osBnLgZCXDEaesGp4kVsVGeE8-dkcw7RWUZaUVZo75B7IpN0zPamDNFpgZSlGX6OFepncsamTEDwfpBtKUR_Q64cFlGaemZs_PnKP8KZVFWl2kz_qhZvbYa_8tT6f0oBmCJbDiTog&x-client-SKU=ID_NETSTANDARD2_0&x-client-ver=6.16.0.0&sso_reload=trueHTTP Parser: HTML title missing
Source: https://login.microsoftonline.com/organizations/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638102318766889741.YjBjNDI3Y2ItN2M3Yi00OThlLWJkNzgtZDdjY2JlNzg5MjIxYjAxODcwM2ItNTY1ZC00NzFiLWJkYTMtMGZiYTlhYzE2YTZi&ui_locales=en-US&mkt=en-US&msafed=0&state=1xhbt2TjudldjF05XVlHg6-Q6ZxXf76LUBKXLANWOWn7j7qmHcCqu2jvDVzpad1Qb9LCRjQx5orG5mTPLr4VvfkWDFrFSIL_tIAvcF5XS773vvIUFt3dm5lu897cD-kDI30J0KHpxF48VIYi117ZQNo7IxWD3ndyJc4HhgHehmDKRbmsOklDkuo8NgZQSDati1hy6kWo98kXuQGvP1DJA82utvZsCedBu_osBnLgZCXDEaesGp4kVsVGeE8-dkcw7RWUZaUVZo75B7IpN0zPamDNFpgZSlGX6OFepncsamTEDwfpBtKUR_Q64cFlGaemZs_PnKP8KZVFWl2kz_qhZvbYa_8tT6f0oBmCJbDiTog&x-client-SKU=ID_NETSTANDARD2_0&x-client-ver=6.16.0.0&sso_reload=trueHTTP Parser: No <meta name="author".. found
Source: https://login.microsoftonline.com/organizations/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638102318766889741.YjBjNDI3Y2ItN2M3Yi00OThlLWJkNzgtZDdjY2JlNzg5MjIxYjAxODcwM2ItNTY1ZC00NzFiLWJkYTMtMGZiYTlhYzE2YTZi&ui_locales=en-US&mkt=en-US&msafed=0&state=1xhbt2TjudldjF05XVlHg6-Q6ZxXf76LUBKXLANWOWn7j7qmHcCqu2jvDVzpad1Qb9LCRjQx5orG5mTPLr4VvfkWDFrFSIL_tIAvcF5XS773vvIUFt3dm5lu897cD-kDI30J0KHpxF48VIYi117ZQNo7IxWD3ndyJc4HhgHehmDKRbmsOklDkuo8NgZQSDati1hy6kWo98kXuQGvP1DJA82utvZsCedBu_osBnLgZCXDEaesGp4kVsVGeE8-dkcw7RWUZaUVZo75B7IpN0zPamDNFpgZSlGX6OFepncsamTEDwfpBtKUR_Q64cFlGaemZs_PnKP8KZVFWl2kz_qhZvbYa_8tT6f0oBmCJbDiTog&x-client-SKU=ID_NETSTANDARD2_0&x-client-ver=6.16.0.0&sso_reload=trueHTTP Parser: No <meta name="author".. found
Source: https://login.microsoftonline.com/organizations/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638102318766889741.YjBjNDI3Y2ItN2M3Yi00OThlLWJkNzgtZDdjY2JlNzg5MjIxYjAxODcwM2ItNTY1ZC00NzFiLWJkYTMtMGZiYTlhYzE2YTZi&ui_locales=en-US&mkt=en-US&msafed=0&state=1xhbt2TjudldjF05XVlHg6-Q6ZxXf76LUBKXLANWOWn7j7qmHcCqu2jvDVzpad1Qb9LCRjQx5orG5mTPLr4VvfkWDFrFSIL_tIAvcF5XS773vvIUFt3dm5lu897cD-kDI30J0KHpxF48VIYi117ZQNo7IxWD3ndyJc4HhgHehmDKRbmsOklDkuo8NgZQSDati1hy6kWo98kXuQGvP1DJA82utvZsCedBu_osBnLgZCXDEaesGp4kVsVGeE8-dkcw7RWUZaUVZo75B7IpN0zPamDNFpgZSlGX6OFepncsamTEDwfpBtKUR_Q64cFlGaemZs_PnKP8KZVFWl2kz_qhZvbYa_8tT6f0oBmCJbDiTog&x-client-SKU=ID_NETSTANDARD2_0&x-client-ver=6.16.0.0&sso_reload=trueHTTP Parser: No <meta name="copyright".. found
Source: https://login.microsoftonline.com/organizations/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638102318766889741.YjBjNDI3Y2ItN2M3Yi00OThlLWJkNzgtZDdjY2JlNzg5MjIxYjAxODcwM2ItNTY1ZC00NzFiLWJkYTMtMGZiYTlhYzE2YTZi&ui_locales=en-US&mkt=en-US&msafed=0&state=1xhbt2TjudldjF05XVlHg6-Q6ZxXf76LUBKXLANWOWn7j7qmHcCqu2jvDVzpad1Qb9LCRjQx5orG5mTPLr4VvfkWDFrFSIL_tIAvcF5XS773vvIUFt3dm5lu897cD-kDI30J0KHpxF48VIYi117ZQNo7IxWD3ndyJc4HhgHehmDKRbmsOklDkuo8NgZQSDati1hy6kWo98kXuQGvP1DJA82utvZsCedBu_osBnLgZCXDEaesGp4kVsVGeE8-dkcw7RWUZaUVZo75B7IpN0zPamDNFpgZSlGX6OFepncsamTEDwfpBtKUR_Q64cFlGaemZs_PnKP8KZVFWl2kz_qhZvbYa_8tT6f0oBmCJbDiTog&x-client-SKU=ID_NETSTANDARD2_0&x-client-ver=6.16.0.0&sso_reload=trueHTTP Parser: No <meta name="copyright".. found
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdater
Source: unknownHTTPS traffic detected: 152.199.23.37:443 -> 192.168.2.2:49789 version: TLS 1.2
Source: unknownHTTPS traffic detected: 152.199.23.37:443 -> 192.168.2.2:49791 version: TLS 1.2
Source: unknownDNS traffic detected: queries for: www.office.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49863
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49862
Source: unknownNetwork traffic detected: HTTP traffic on port 49789 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49803 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49810 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49906 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49791 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49855
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49811
Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49810
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
Source: unknownNetwork traffic detected: HTTP traffic on port 49862 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49855 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49798 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49804
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49803
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
Source: unknownNetwork traffic detected: HTTP traffic on port 49863 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49877 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49797 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49877
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49798
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49792
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49791
Source: unknownNetwork traffic detected: HTTP traffic on port 49804 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49906
Source: unknownNetwork traffic detected: HTTP traffic on port 49811 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49792 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49789
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.67
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.67
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.67
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.67
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.67
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.67
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.67
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.67
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.67
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.67
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.67
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.67
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.67
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.67
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.67
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.67
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.67
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.67
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.67
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.67
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.67
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.67
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.67
Source: unknownTCP traffic detected without corresponding DNS query: 2.16.238.10
Source: unknownTCP traffic detected without corresponding DNS query: 2.16.238.10
Source: unknownTCP traffic detected without corresponding DNS query: 2.16.238.10
Source: unknownTCP traffic detected without corresponding DNS query: 2.16.238.10
Source: unknownTCP traffic detected without corresponding DNS query: 2.16.238.10
Source: unknownTCP traffic detected without corresponding DNS query: 2.16.238.10
Source: unknownTCP traffic detected without corresponding DNS query: 2.16.238.10
Source: unknownTCP traffic detected without corresponding DNS query: 2.16.238.10
Source: unknownTCP traffic detected without corresponding DNS query: 2.16.238.10
Source: unknownTCP traffic detected without corresponding DNS query: 2.16.238.10
Source: unknownTCP traffic detected without corresponding DNS query: 2.16.238.10
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.67
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.67
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.67
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.67
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.67
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.67
Source: unknownHTTPS traffic detected: 152.199.23.37:443 -> 192.168.2.2:49789 version: TLS 1.2
Source: unknownHTTPS traffic detected: 152.199.23.37:443 -> 192.168.2.2:49791 version: TLS 1.2
Source: classification engineClassification label: clean1.win@27/0@10/168
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://www.office.com/?auth=2&home=1
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=1796,i,8177445550997338781,4573666773275504079,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=1796,i,8177445550997338781,4573666773275504079,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdater
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdater
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium2
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration2
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://www.office.com/?auth=2&home=10%VirustotalBrowse
https://www.office.com/?auth=2&home=10%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
cs1100.wpc.omegacdn.net
152.199.23.37
truefalse
    unknown
    accounts.google.com
    142.250.186.77
    truefalse
      high
      www.google.com
      142.250.181.228
      truefalse
        high
        part-0017.t-0009.fdv2-t-msedge.net
        13.107.237.45
        truefalse
          unknown
          clients.l.google.com
          142.250.185.238
          truefalse
            high
            www.office.com
            unknown
            unknownfalse
              high
              clients2.google.com
              unknown
              unknownfalse
                high
                identity.nel.measure.office.net
                unknown
                unknownfalse
                  high
                  aadcdn.msftauth.net
                  unknown
                  unknownfalse
                    unknown
                    login.microsoftonline.com
                    unknown
                    unknownfalse
                      high
                      • No. of IPs < 25%
                      • 25% < No. of IPs < 50%
                      • 50% < No. of IPs < 75%
                      • 75% < No. of IPs
                      IPDomainCountryFlagASNASN NameMalicious
                      13.107.6.156
                      unknownUnited States
                      8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                      142.250.186.35
                      unknownUnited States
                      15169GOOGLEUSfalse
                      142.250.186.67
                      unknownUnited States
                      15169GOOGLEUSfalse
                      40.126.32.134
                      unknownUnited States
                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                      34.104.35.123
                      unknownUnited States
                      15169GOOGLEUSfalse
                      2.16.238.10
                      unknownEuropean Union
                      20940AKAMAI-ASN1EUfalse
                      142.250.185.238
                      clients.l.google.comUnited States
                      15169GOOGLEUSfalse
                      40.126.32.72
                      unknownUnited States
                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                      40.126.32.74
                      unknownUnited States
                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                      239.255.255.250
                      unknownReserved
                      unknownunknownfalse
                      142.250.185.164
                      unknownUnited States
                      15169GOOGLEUSfalse
                      88.221.169.199
                      unknownEuropean Union
                      16625AKAMAI-ASUSfalse
                      2.16.238.149
                      unknownEuropean Union
                      20940AKAMAI-ASN1EUfalse
                      152.199.23.37
                      cs1100.wpc.omegacdn.netUnited States
                      15133EDGECASTUSfalse
                      142.250.186.77
                      accounts.google.comUnited States
                      15169GOOGLEUSfalse
                      142.250.184.202
                      unknownUnited States
                      15169GOOGLEUSfalse
                      IP
                      127.0.0.1
                      Joe Sandbox Version:36.0.0 Rainbow Opal
                      Analysis ID:791286
                      Start date and time:2023-01-25 09:24:03 +01:00
                      Joe Sandbox Product:CloudBasic
                      Overall analysis duration:
                      Hypervisor based Inspection enabled:false
                      Report type:light
                      Cookbook file name:defaultwindowsinteractivecookbook.jbs
                      Sample URL:https://www.office.com/?auth=2&home=1
                      Analysis system description:Windows 10 64 bit version 1909 (MS Office 2019, IE 11, Chrome 104, Firefox 88, Adobe Reader DC 21, Java 8 u291, 7-Zip)
                      Number of analysed new started processes analysed:8
                      Number of new started drivers analysed:0
                      Number of existing processes analysed:0
                      Number of existing drivers analysed:0
                      Number of injected processes analysed:0
                      Technologies:
                      • EGA enabled
                      Analysis Mode:stream
                      Analysis stop reason:Timeout
                      Detection:CLEAN
                      Classification:clean1.win@27/0@10/168
                      • Exclude process from analysis (whitelisted): SIHClient.exe, SgrmBroker.exe, svchost.exe
                      • Excluded IPs from analysis (whitelisted): 20.190.159.64, 40.126.31.73, 20.190.159.73, 20.190.159.75, 20.190.159.4, 40.126.31.67, 20.190.159.71, 20.190.159.23, 13.107.6.156, 142.250.186.35, 40.126.32.134, 40.126.32.74, 40.126.32.133, 20.190.160.22, 20.190.160.20, 40.126.32.136, 40.126.32.68, 40.126.32.76, 34.104.35.123, 40.126.32.138, 40.126.32.72, 40.126.32.140, 2.16.238.149, 2.16.238.152, 20.190.160.14, 20.190.160.17, 88.221.169.152, 142.250.184.202, 142.250.186.170, 216.58.212.170, 216.58.212.138, 172.217.18.10, 142.250.186.138, 142.250.186.74, 142.250.186.106, 172.217.16.202, 142.250.184.234, 172.217.18.106, 142.250.185.202, 142.250.185.234, 142.250.185.138, 172.217.23.106, 142.250.186.42, 88.221.169.199
                      • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, www.tm.lg.prod.aadmsa.akadns.net, e13678.dscb.akamaiedge.net, home-office365-com.b-0004.b-msedge.net, clientservices.googleapis.com, ak.privatelink.msidentity.com, a1894.dscb.akamai.net, www.tm.a.prd.aadg.trafficmanager.net, officehome.cdn.office.net-c.edgekey.net, www.microsoft.com-c-3.edgekey.net.globalredir.akadns.net, www.microsoft.com-c-3.edgekey.net, prda.aadg.msidentity.com, officehome.cdn.office.net, login.live.com, login.mso.msidentity.com, www.tm.ak.prd.aadg.trafficmanager.net, fs.microsoft.com, content-autofill.googleapis.com, aadcdnoriginwus2.azureedge.net, b-0004.b-msedge.net, settings-win.data.microsoft.com, aadcdn.msauth.net, e19254.dscg.akamaiedge.net, login.msa.msidentity.com, firstparty-azurefd-prod.trafficmanager.net, edgedl.me.gvt1.com, nel.measure.office.net.edgesuite.net, privacy.microsoft.com, officehome.cdn.office.net-c.edgekey.net.globalredir.akadns.net, aadcdnoriginwus2.afd.azureedge.net, privacy.microsoft.com.
                      • Not all processes where analyzed, report is missing behavior information
                      • Report size getting too big, too many NtSetInformationFile calls found.
                      • Report size getting too big, too many NtWriteVirtualMemory calls found.
                      No created / dropped files found
                      No static file info