Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Benefit_Enrollment.html

Overview

General Information

Sample Name:Benefit_Enrollment.html
Analysis ID:800708
MD5:4d868dccc00ec137cc7cc38de63363c4
SHA1:50b3fe872d2dfaf5f2b9401d14f539ba8bb22f19
SHA256:3a6c12834075ca942f56ee6973aced2159eefd69ed0a534bfa758849fb0a3624
Infos:

Detection

HTMLPhisher
Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Yara detected HtmlPhish48
HTML document with suspicious title
Phishing site detected (based on image similarity)
JA3 SSL client fingerprint seen in connection with other malware
IP address seen in connection with other malware

Classification

  • System is w10x64
  • chrome.exe (PID: 2432 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 5836 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1876 --field-trial-handle=1812,i,2036972514004216083,622276978597170317,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 1028 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "C:\Users\user\Desktop\Benefit_Enrollment.html MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
64229.0.pages.csvJoeSecurity_HtmlPhish_48Yara detected HtmlPhish_48Joe Security
    No Sigma rule has matched
    No Snort rule has matched

    Click to jump to signature section

    Show All Signature Results

    Phishing

    barindex
    Source: Yara matchFile source: 64229.0.pages.csv, type: HTML
    Source: embeddedMatcher: Found strong image similarity, brand: Microsoft image: 42404.1.img.1.gfk.csv EE5C8D9FB6248C938FD0DC19370E90BD
    Source: embeddedMatcher: Found strong image similarity, brand: Microsoft image: 80425.2.img.1.gfk.csv EE5C8D9FB6248C938FD0DC19370E90BD
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
    Source: unknownHTTPS traffic detected: 13.107.253.60:443 -> 192.168.2.4:49725 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 13.107.253.60:443 -> 192.168.2.4:49726 version: TLS 1.2
    Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
    Source: Joe Sandbox ViewIP Address: 151.101.1.229 151.101.1.229
    Source: unknownDNS traffic detected: queries for: clients2.google.com
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49700
    Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
    Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49697 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
    Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
    Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49699
    Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49697
    Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
    Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
    Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
    Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
    Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-GB&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
    Source: global trafficHTTP traffic detected: GET /1pl/admin/js/mj.php?ar=ZGVmYXVsdA== HTTP/1.1Host: ussufaces.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
    Source: global trafficHTTP traffic detected: GET /font-awesome/4.7.0/css/font-awesome.min.css HTTP/1.1Host: maxcdn.bootstrapcdn.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
    Source: global trafficHTTP traffic detected: GET /npm/bootstrap@4.0.0/dist/css/bootstrap.min.css HTTP/1.1Host: cdn.jsdelivr.netConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"Origin: nullsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: styleAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
    Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/microsoft_logo_ee5c8d9fb6248c938fd0dc19370e90bd.svg HTTP/1.1Host: logincdn.msauth.netConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
    Source: global trafficHTTP traffic detected: GET /font-awesome/4.7.0/fonts/fontawesome-webfont.woff2?v=4.7.0 HTTP/1.1Host: maxcdn.bootstrapcdn.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"Origin: nullsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://maxcdn.bootstrapcdn.com/font-awesome/4.7.0/css/font-awesome.min.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
    Source: global trafficHTTP traffic detected: GET /ajax/libs/font-awesome/4.7.0/css/font-awesome.css HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"Origin: nullsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: styleAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
    Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/picker_verify_call_fe87496cc7a44412f7893a72099c120a.svg HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
    Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/picker_verify_sms_27a6d18b56f46818420e60a773c36d4e.svg HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
    Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/picker_verify_fluent_authenticator_b59c16ca9bf156438a8a96d45e33db64.svg HTTP/1.1Host: aadcdn.msauth.netConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
    Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/picker_verify_call_fe87496cc7a44412f7893a72099c120a.svg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: aadcdn.msauth.net
    Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/picker_verify_fluent_authenticator_b59c16ca9bf156438a8a96d45e33db64.svg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: aadcdn.msauth.net
    Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/picker_verify_sms_27a6d18b56f46818420e60a773c36d4e.svg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: aadcdn.msauth.net
    Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/picker_verify_sms_27a6d18b56f46818420e60a773c36d4e.svg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: aadcdn.msauth.netIf-Modified-Since: Fri, 17 Jan 2020 19:28:39 GMTIf-None-Match: 0x8D79B8374CE7F93
    Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/picker_verify_call_fe87496cc7a44412f7893a72099c120a.svg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: aadcdn.msauth.netIf-Modified-Since: Fri, 17 Jan 2020 19:28:39 GMTIf-None-Match: 0x8D79B83749623C9
    Source: global trafficHTTP traffic detected: GET /shared/1.0/content/images/picker_verify_fluent_authenticator_b59c16ca9bf156438a8a96d45e33db64.svg HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: aadcdn.msauth.netIf-Modified-Since: Fri, 11 Mar 2022 11:11:29 GMTIf-None-Match: 0x8DA034FE445C10D
    Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
    Source: unknownHTTPS traffic detected: 13.107.253.60:443 -> 192.168.2.4:49725 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 13.107.253.60:443 -> 192.168.2.4:49726 version: TLS 1.2

    System Summary

    barindex
    Source: file:///C:/Users/user/Desktop/Benefit_Enrollment.htmlTab title: Benefit_Enrollment.html
    Source: classification engineClassification label: mal56.phis.winHTML@27/0@9/12
    Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1876 --field-trial-handle=1812,i,2036972514004216083,622276978597170317,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
    Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "C:\Users\user\Desktop\Benefit_Enrollment.html
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1876 --field-trial-handle=1812,i,2036972514004216083,622276978597170317,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
    Source: Window RecorderWindow detected: More than 3 window changes detected
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsWindows Management InstrumentationPath Interception1
    Process Injection
    2
    Masquerading
    OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
    Encrypted Channel
    Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
    Process Injection
    LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
    Non-Application Layer Protocol
    Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
    Application Layer Protocol
    Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
    Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
    Ingress Tool Transfer
    SIM Card SwapCarrier Billing Fraud
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Is Windows Process
    • Number of created Registry Values
    • Number of created Files
    • Visual Basic
    • Delphi
    • Java
    • .Net C# or VB.NET
    • C, C++ or other language
    • Is malicious
    • Internet

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.


    windows-stand
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    SourceDetectionScannerLabelLink
    https://ussufaces.com/1pl/admin/js/mj.php?ar=ZGVmYXVsdA==0%Avira URL Cloudsafe
    https://ussufaces.com/1pl/b52aae6.php0%Avira URL Cloudsafe
    NameIPActiveMaliciousAntivirus DetectionReputation
    jsdelivr.map.fastly.net
    151.101.1.229
    truefalse
      unknown
      accounts.google.com
      216.58.209.45
      truefalse
        high
        ussufaces.com
        192.166.226.11
        truefalse
          unknown
          cdnjs.cloudflare.com
          104.17.25.14
          truefalse
            high
            maxcdn.bootstrapcdn.com
            104.18.11.207
            truefalse
              high
              www.google.com
              142.250.184.100
              truefalse
                high
                cs1227.wpc.alphacdn.net
                192.229.221.185
                truefalse
                  unknown
                  clients.l.google.com
                  142.250.180.174
                  truefalse
                    high
                    part-0032.t-0009.fb-t-msedge.net
                    13.107.253.60
                    truefalse
                      unknown
                      clients2.google.com
                      unknown
                      unknownfalse
                        high
                        code.jquery.com
                        unknown
                        unknownfalse
                          high
                          cdn.jsdelivr.net
                          unknown
                          unknownfalse
                            high
                            NameMaliciousAntivirus DetectionReputation
                            https://ussufaces.com/1pl/b52aae6.phpfalse
                            • Avira URL Cloud: safe
                            unknown
                            https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-GB&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                              high
                              https://maxcdn.bootstrapcdn.com/font-awesome/4.7.0/css/font-awesome.min.cssfalse
                                high
                                https://ussufaces.com/1pl/admin/js/mj.php?ar=ZGVmYXVsdA==false
                                • Avira URL Cloud: safe
                                unknown
                                https://cdnjs.cloudflare.com/ajax/libs/font-awesome/4.7.0/css/font-awesome.cssfalse
                                  high
                                  file:///C:/Users/user/Desktop/Benefit_Enrollment.htmltrue
                                    low
                                    https://maxcdn.bootstrapcdn.com/font-awesome/4.7.0/fonts/fontawesome-webfont.woff2?v=4.7.0false
                                      high
                                      https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                                        high
                                        https://cdn.jsdelivr.net/npm/bootstrap@4.0.0/dist/css/bootstrap.min.cssfalse
                                          high
                                          • No. of IPs < 25%
                                          • 25% < No. of IPs < 50%
                                          • 50% < No. of IPs < 75%
                                          • 75% < No. of IPs
                                          IPDomainCountryFlagASNASN NameMalicious
                                          151.101.1.229
                                          jsdelivr.map.fastly.netUnited States
                                          54113FASTLYUSfalse
                                          192.166.226.11
                                          ussufaces.comNetherlands
                                          6786CRONON-BERLIN-ASDEfalse
                                          216.58.209.45
                                          accounts.google.comUnited States
                                          15169GOOGLEUSfalse
                                          104.18.11.207
                                          maxcdn.bootstrapcdn.comUnited States
                                          13335CLOUDFLARENETUSfalse
                                          13.107.253.60
                                          part-0032.t-0009.fb-t-msedge.netUnited States
                                          8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                          239.255.255.250
                                          unknownReserved
                                          unknownunknownfalse
                                          192.229.221.185
                                          cs1227.wpc.alphacdn.netUnited States
                                          15133EDGECASTUSfalse
                                          142.250.184.100
                                          www.google.comUnited States
                                          15169GOOGLEUSfalse
                                          142.250.180.174
                                          clients.l.google.comUnited States
                                          15169GOOGLEUSfalse
                                          104.17.25.14
                                          cdnjs.cloudflare.comUnited States
                                          13335CLOUDFLARENETUSfalse
                                          IP
                                          192.168.2.1
                                          127.0.0.1
                                          Joe Sandbox Version:36.0.0 Rainbow Opal
                                          Analysis ID:800708
                                          Start date and time:2023-02-07 18:29:50 +01:00
                                          Joe Sandbox Product:CloudBasic
                                          Overall analysis duration:0h 10m 3s
                                          Hypervisor based Inspection enabled:false
                                          Report type:light
                                          Cookbook file name:defaultwindowshtmlcookbook.jbs
                                          Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                          Number of analysed new started processes analysed:6
                                          Number of new started drivers analysed:0
                                          Number of existing processes analysed:0
                                          Number of existing drivers analysed:0
                                          Number of injected processes analysed:0
                                          Technologies:
                                          • HCA enabled
                                          • EGA enabled
                                          • HDC enabled
                                          • AMSI enabled
                                          Analysis Mode:default
                                          Analysis stop reason:Timeout
                                          Sample file name:Benefit_Enrollment.html
                                          Detection:MAL
                                          Classification:mal56.phis.winHTML@27/0@9/12
                                          EGA Information:Failed
                                          HDC Information:Failed
                                          HCA Information:
                                          • Successful, ratio: 100%
                                          • Number of executed functions: 0
                                          • Number of non-executed functions: 0
                                          Cookbook Comments:
                                          • Found application associated with file extension: .html
                                          • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, conhost.exe
                                          • TCP Packets have been reduced to 100
                                          • Excluded IPs from analysis (whitelisted): 142.250.184.99, 34.104.35.123, 69.16.175.10, 69.16.175.42, 142.250.180.163
                                          • Excluded domains from analysis (whitelisted): logincdn.msauth.net, cds.s5x3j6q5.hwcdn.net, aadcdnoriginwus2.azureedge.net, global-entry-afdthirdparty-fallback-first.trafficmanager.net, lgincdnvzeuno.ec.azureedge.net, clientservices.googleapis.com, aadcdn.msauth.net, firstparty-azurefd-prod.trafficmanager.net, lgincdnvzeuno.azureedge.net, edgedl.me.gvt1.com, lgincdn.trafficmanager.net, update.googleapis.com, aadcdnoriginwus2.afd.azureedge.net
                                          • Not all processes where analyzed, report is missing behavior information
                                          • Report size getting too big, too many NtWriteVirtualMemory calls found.
                                          • VT rate limit hit for: Benefit_Enrollment.html
                                          No simulations
                                          No context
                                          No context
                                          No context
                                          No context
                                          No context
                                          No created / dropped files found
                                          File type:HTML document, ASCII text, with very long lines (774), with CRLF line terminators
                                          Entropy (8bit):5.42630578423163
                                          TrID:
                                          • HyperText Markup Language (6006/1) 100.00%
                                          File name:Benefit_Enrollment.html
                                          File size:3027
                                          MD5:4d868dccc00ec137cc7cc38de63363c4
                                          SHA1:50b3fe872d2dfaf5f2b9401d14f539ba8bb22f19
                                          SHA256:3a6c12834075ca942f56ee6973aced2159eefd69ed0a534bfa758849fb0a3624
                                          SHA512:6cbff19ff29139a8d78b57c9e7db7c2355e4678e03eac0ec73633635ec916ea70b0f6833ad00d26dfd0d9e19e5e41c60ece043fd101a0e9c824c60630ea2d0e8
                                          SSDEEP:48:RLmHcrL5bq4GSUKerkJ6F5z0/5z0Wl5z0L07CGt5keRc4O:88rduBjry6Fl0lDlOICGvkI5O
                                          TLSH:BB51F07288942D3393030FEDA126AB2B32E3C29CCA4365A45BF453CB0FC7D59993994C
                                          File Content Preview:<html>..<head>..<div class="" style="display:none;"><div class="mbr-desktop-hd"><span class="column"><a ><img alt="" class="logo " width="" height="36"><img alt="" class="dark-mode-logo logo " width="" height="36"></a></span><span class="column help txt-a
                                          TimestampSource PortDest PortSource IPDest IP
                                          Feb 7, 2023 18:30:54.220797062 CET49697443192.168.2.4142.250.180.174
                                          Feb 7, 2023 18:30:54.220841885 CET44349697142.250.180.174192.168.2.4
                                          Feb 7, 2023 18:30:54.220896006 CET49697443192.168.2.4142.250.180.174
                                          Feb 7, 2023 18:30:54.221173048 CET49697443192.168.2.4142.250.180.174
                                          Feb 7, 2023 18:30:54.221189022 CET44349697142.250.180.174192.168.2.4
                                          Feb 7, 2023 18:30:54.223428011 CET49698443192.168.2.4216.58.209.45
                                          Feb 7, 2023 18:30:54.223455906 CET44349698216.58.209.45192.168.2.4
                                          Feb 7, 2023 18:30:54.223510027 CET49698443192.168.2.4216.58.209.45
                                          Feb 7, 2023 18:30:54.223920107 CET49698443192.168.2.4216.58.209.45
                                          Feb 7, 2023 18:30:54.223936081 CET44349698216.58.209.45192.168.2.4
                                          Feb 7, 2023 18:30:54.228179932 CET49699443192.168.2.4192.166.226.11
                                          Feb 7, 2023 18:30:54.228243113 CET44349699192.166.226.11192.168.2.4
                                          Feb 7, 2023 18:30:54.228317022 CET49699443192.168.2.4192.166.226.11
                                          Feb 7, 2023 18:30:54.228591919 CET49699443192.168.2.4192.166.226.11
                                          Feb 7, 2023 18:30:54.228610992 CET44349699192.166.226.11192.168.2.4
                                          Feb 7, 2023 18:30:54.262183905 CET49700443192.168.2.4142.250.184.100
                                          Feb 7, 2023 18:30:54.262244940 CET44349700142.250.184.100192.168.2.4
                                          Feb 7, 2023 18:30:54.262346029 CET49700443192.168.2.4142.250.184.100
                                          Feb 7, 2023 18:30:54.262799978 CET49700443192.168.2.4142.250.184.100
                                          Feb 7, 2023 18:30:54.262830973 CET44349700142.250.184.100192.168.2.4
                                          Feb 7, 2023 18:30:54.296530008 CET44349698216.58.209.45192.168.2.4
                                          Feb 7, 2023 18:30:54.297036886 CET49698443192.168.2.4216.58.209.45
                                          Feb 7, 2023 18:30:54.297102928 CET44349698216.58.209.45192.168.2.4
                                          Feb 7, 2023 18:30:54.298947096 CET44349698216.58.209.45192.168.2.4
                                          Feb 7, 2023 18:30:54.299058914 CET49698443192.168.2.4216.58.209.45
                                          Feb 7, 2023 18:30:54.327141047 CET44349697142.250.180.174192.168.2.4
                                          Feb 7, 2023 18:30:54.327507019 CET49697443192.168.2.4142.250.180.174
                                          Feb 7, 2023 18:30:54.327548981 CET44349697142.250.180.174192.168.2.4
                                          Feb 7, 2023 18:30:54.328231096 CET44349697142.250.180.174192.168.2.4
                                          Feb 7, 2023 18:30:54.328320980 CET49697443192.168.2.4142.250.180.174
                                          Feb 7, 2023 18:30:54.329626083 CET44349697142.250.180.174192.168.2.4
                                          Feb 7, 2023 18:30:54.329704046 CET49697443192.168.2.4142.250.180.174
                                          Feb 7, 2023 18:30:54.333823919 CET44349700142.250.184.100192.168.2.4
                                          Feb 7, 2023 18:30:54.334151030 CET49700443192.168.2.4142.250.184.100
                                          Feb 7, 2023 18:30:54.334184885 CET44349700142.250.184.100192.168.2.4
                                          Feb 7, 2023 18:30:54.335424900 CET44349700142.250.184.100192.168.2.4
                                          Feb 7, 2023 18:30:54.335514069 CET49700443192.168.2.4142.250.184.100
                                          Feb 7, 2023 18:30:54.496572971 CET44349699192.166.226.11192.168.2.4
                                          Feb 7, 2023 18:30:54.566777945 CET49699443192.168.2.4192.166.226.11
                                          Feb 7, 2023 18:30:54.636158943 CET49699443192.168.2.4192.166.226.11
                                          Feb 7, 2023 18:30:54.636182070 CET44349699192.166.226.11192.168.2.4
                                          Feb 7, 2023 18:30:54.643842936 CET44349699192.166.226.11192.168.2.4
                                          Feb 7, 2023 18:30:54.643884897 CET44349699192.166.226.11192.168.2.4
                                          Feb 7, 2023 18:30:54.643954992 CET49699443192.168.2.4192.166.226.11
                                          Feb 7, 2023 18:30:54.762181997 CET49697443192.168.2.4142.250.180.174
                                          Feb 7, 2023 18:30:54.762223959 CET44349697142.250.180.174192.168.2.4
                                          Feb 7, 2023 18:30:54.762391090 CET44349697142.250.180.174192.168.2.4
                                          Feb 7, 2023 18:30:54.762479067 CET49697443192.168.2.4142.250.180.174
                                          Feb 7, 2023 18:30:54.762496948 CET44349697142.250.180.174192.168.2.4
                                          Feb 7, 2023 18:30:54.762686968 CET49698443192.168.2.4216.58.209.45
                                          Feb 7, 2023 18:30:54.762727022 CET44349698216.58.209.45192.168.2.4
                                          Feb 7, 2023 18:30:54.762904882 CET49698443192.168.2.4216.58.209.45
                                          Feb 7, 2023 18:30:54.762917042 CET44349698216.58.209.45192.168.2.4
                                          Feb 7, 2023 18:30:54.762942076 CET44349698216.58.209.45192.168.2.4
                                          Feb 7, 2023 18:30:54.763134956 CET49700443192.168.2.4142.250.184.100
                                          Feb 7, 2023 18:30:54.763151884 CET44349700142.250.184.100192.168.2.4
                                          Feb 7, 2023 18:30:54.763303995 CET44349700142.250.184.100192.168.2.4
                                          Feb 7, 2023 18:30:54.763402939 CET49699443192.168.2.4192.166.226.11
                                          Feb 7, 2023 18:30:54.763422966 CET44349699192.166.226.11192.168.2.4
                                          Feb 7, 2023 18:30:54.763544083 CET49699443192.168.2.4192.166.226.11
                                          Feb 7, 2023 18:30:54.763550997 CET44349699192.166.226.11192.168.2.4
                                          Feb 7, 2023 18:30:54.763606071 CET44349699192.166.226.11192.168.2.4
                                          Feb 7, 2023 18:30:54.808024883 CET44349697142.250.180.174192.168.2.4
                                          Feb 7, 2023 18:30:54.808104992 CET49697443192.168.2.4142.250.180.174
                                          Feb 7, 2023 18:30:54.808131933 CET44349697142.250.180.174192.168.2.4
                                          Feb 7, 2023 18:30:54.808228970 CET44349697142.250.180.174192.168.2.4
                                          Feb 7, 2023 18:30:54.808284998 CET49697443192.168.2.4142.250.180.174
                                          Feb 7, 2023 18:30:54.809189081 CET49697443192.168.2.4142.250.180.174
                                          Feb 7, 2023 18:30:54.809205055 CET44349697142.250.180.174192.168.2.4
                                          Feb 7, 2023 18:30:54.826286077 CET44349698216.58.209.45192.168.2.4
                                          Feb 7, 2023 18:30:54.826375961 CET49698443192.168.2.4216.58.209.45
                                          Feb 7, 2023 18:30:54.826397896 CET44349698216.58.209.45192.168.2.4
                                          Feb 7, 2023 18:30:54.826530933 CET44349698216.58.209.45192.168.2.4
                                          Feb 7, 2023 18:30:54.826596022 CET49698443192.168.2.4216.58.209.45
                                          Feb 7, 2023 18:30:54.828102112 CET49698443192.168.2.4216.58.209.45
                                          Feb 7, 2023 18:30:54.828124046 CET44349698216.58.209.45192.168.2.4
                                          Feb 7, 2023 18:30:54.858537912 CET49700443192.168.2.4142.250.184.100
                                          Feb 7, 2023 18:30:54.858596087 CET44349700142.250.184.100192.168.2.4
                                          Feb 7, 2023 18:30:54.858650923 CET49699443192.168.2.4192.166.226.11
                                          Feb 7, 2023 18:30:54.858676910 CET44349699192.166.226.11192.168.2.4
                                          Feb 7, 2023 18:30:54.901499987 CET44349699192.166.226.11192.168.2.4
                                          Feb 7, 2023 18:30:54.901531935 CET44349699192.166.226.11192.168.2.4
                                          Feb 7, 2023 18:30:54.901623964 CET44349699192.166.226.11192.168.2.4
                                          Feb 7, 2023 18:30:54.901683092 CET44349699192.166.226.11192.168.2.4
                                          Feb 7, 2023 18:30:54.901705027 CET49699443192.168.2.4192.166.226.11
                                          Feb 7, 2023 18:30:54.901737928 CET44349699192.166.226.11192.168.2.4
                                          Feb 7, 2023 18:30:54.901761055 CET49699443192.168.2.4192.166.226.11
                                          Feb 7, 2023 18:30:54.901798010 CET49699443192.168.2.4192.166.226.11
                                          Feb 7, 2023 18:30:54.925674915 CET44349699192.166.226.11192.168.2.4
                                          Feb 7, 2023 18:30:54.925693035 CET44349699192.166.226.11192.168.2.4
                                          Feb 7, 2023 18:30:54.925781965 CET44349699192.166.226.11192.168.2.4
                                          Feb 7, 2023 18:30:54.925862074 CET49699443192.168.2.4192.166.226.11
                                          Feb 7, 2023 18:30:54.925887108 CET49699443192.168.2.4192.166.226.11
                                          Feb 7, 2023 18:30:54.961939096 CET49700443192.168.2.4142.250.184.100
                                          Feb 7, 2023 18:30:55.030340910 CET44349699192.166.226.11192.168.2.4
                                          Feb 7, 2023 18:30:55.030380964 CET44349699192.166.226.11192.168.2.4
                                          Feb 7, 2023 18:30:55.030390024 CET44349699192.166.226.11192.168.2.4
                                          Feb 7, 2023 18:30:55.030482054 CET49699443192.168.2.4192.166.226.11
                                          Feb 7, 2023 18:30:55.030554056 CET49699443192.168.2.4192.166.226.11
                                          Feb 7, 2023 18:30:55.030564070 CET44349699192.166.226.11192.168.2.4
                                          TimestampSource PortDest PortSource IPDest IP
                                          Feb 7, 2023 18:30:54.174721956 CET5968353192.168.2.48.8.8.8
                                          Feb 7, 2023 18:30:54.176856041 CET6416753192.168.2.48.8.8.8
                                          Feb 7, 2023 18:30:54.200670004 CET5223953192.168.2.48.8.8.8
                                          Feb 7, 2023 18:30:54.202945948 CET53596838.8.8.8192.168.2.4
                                          Feb 7, 2023 18:30:54.203625917 CET5680753192.168.2.48.8.8.8
                                          Feb 7, 2023 18:30:54.205270052 CET53641678.8.8.8192.168.2.4
                                          Feb 7, 2023 18:30:54.223334074 CET53522398.8.8.8192.168.2.4
                                          Feb 7, 2023 18:30:54.230905056 CET53568078.8.8.8192.168.2.4
                                          Feb 7, 2023 18:30:54.234734058 CET6100753192.168.2.48.8.8.8
                                          Feb 7, 2023 18:30:54.261010885 CET53610078.8.8.8192.168.2.4
                                          Feb 7, 2023 18:30:55.482817888 CET5944453192.168.2.48.8.8.8
                                          Feb 7, 2023 18:30:55.485315084 CET5557053192.168.2.48.8.8.8
                                          Feb 7, 2023 18:30:55.488517046 CET6490653192.168.2.48.8.8.8
                                          Feb 7, 2023 18:30:55.505156994 CET53555708.8.8.8192.168.2.4
                                          Feb 7, 2023 18:30:55.510356903 CET53594448.8.8.8192.168.2.4
                                          Feb 7, 2023 18:30:57.596597910 CET5872953192.168.2.48.8.8.8
                                          Feb 7, 2023 18:30:57.618532896 CET53587298.8.8.8192.168.2.4
                                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                          Feb 7, 2023 18:30:54.174721956 CET192.168.2.48.8.8.80x4d95Standard query (0)clients2.google.comA (IP address)IN (0x0001)false
                                          Feb 7, 2023 18:30:54.176856041 CET192.168.2.48.8.8.80xca1fStandard query (0)accounts.google.comA (IP address)IN (0x0001)false
                                          Feb 7, 2023 18:30:54.200670004 CET192.168.2.48.8.8.80xea2aStandard query (0)ussufaces.comA (IP address)IN (0x0001)false
                                          Feb 7, 2023 18:30:54.203625917 CET192.168.2.48.8.8.80x81b9Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                          Feb 7, 2023 18:30:54.234734058 CET192.168.2.48.8.8.80x653dStandard query (0)www.google.comA (IP address)IN (0x0001)false
                                          Feb 7, 2023 18:30:55.482817888 CET192.168.2.48.8.8.80xf93bStandard query (0)maxcdn.bootstrapcdn.comA (IP address)IN (0x0001)false
                                          Feb 7, 2023 18:30:55.485315084 CET192.168.2.48.8.8.80x452aStandard query (0)cdn.jsdelivr.netA (IP address)IN (0x0001)false
                                          Feb 7, 2023 18:30:55.488517046 CET192.168.2.48.8.8.80xca78Standard query (0)code.jquery.comA (IP address)IN (0x0001)false
                                          Feb 7, 2023 18:30:57.596597910 CET192.168.2.48.8.8.80x8befStandard query (0)cdnjs.cloudflare.comA (IP address)IN (0x0001)false
                                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                          Feb 7, 2023 18:30:54.202945948 CET8.8.8.8192.168.2.40x4d95No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                                          Feb 7, 2023 18:30:54.202945948 CET8.8.8.8192.168.2.40x4d95No error (0)clients.l.google.com142.250.180.174A (IP address)IN (0x0001)false
                                          Feb 7, 2023 18:30:54.205270052 CET8.8.8.8192.168.2.40xca1fNo error (0)accounts.google.com216.58.209.45A (IP address)IN (0x0001)false
                                          Feb 7, 2023 18:30:54.223334074 CET8.8.8.8192.168.2.40xea2aNo error (0)ussufaces.com192.166.226.11A (IP address)IN (0x0001)false
                                          Feb 7, 2023 18:30:54.230905056 CET8.8.8.8192.168.2.40x81b9No error (0)www.google.com142.250.184.100A (IP address)IN (0x0001)false
                                          Feb 7, 2023 18:30:54.261010885 CET8.8.8.8192.168.2.40x653dNo error (0)www.google.com142.250.184.100A (IP address)IN (0x0001)false
                                          Feb 7, 2023 18:30:55.505156994 CET8.8.8.8192.168.2.40x452aNo error (0)cdn.jsdelivr.netjsdelivr.map.fastly.netCNAME (Canonical name)IN (0x0001)false
                                          Feb 7, 2023 18:30:55.505156994 CET8.8.8.8192.168.2.40x452aNo error (0)jsdelivr.map.fastly.net151.101.1.229A (IP address)IN (0x0001)false
                                          Feb 7, 2023 18:30:55.505156994 CET8.8.8.8192.168.2.40x452aNo error (0)jsdelivr.map.fastly.net151.101.65.229A (IP address)IN (0x0001)false
                                          Feb 7, 2023 18:30:55.505156994 CET8.8.8.8192.168.2.40x452aNo error (0)jsdelivr.map.fastly.net151.101.129.229A (IP address)IN (0x0001)false
                                          Feb 7, 2023 18:30:55.505156994 CET8.8.8.8192.168.2.40x452aNo error (0)jsdelivr.map.fastly.net151.101.193.229A (IP address)IN (0x0001)false
                                          Feb 7, 2023 18:30:55.510356903 CET8.8.8.8192.168.2.40xf93bNo error (0)maxcdn.bootstrapcdn.com104.18.11.207A (IP address)IN (0x0001)false
                                          Feb 7, 2023 18:30:55.510356903 CET8.8.8.8192.168.2.40xf93bNo error (0)maxcdn.bootstrapcdn.com104.18.10.207A (IP address)IN (0x0001)false
                                          Feb 7, 2023 18:30:55.510404110 CET8.8.8.8192.168.2.40xca78No error (0)code.jquery.comcds.s5x3j6q5.hwcdn.netCNAME (Canonical name)IN (0x0001)false
                                          Feb 7, 2023 18:30:55.539197922 CET8.8.8.8192.168.2.40xb126No error (0)cs1227.wpc.alphacdn.net192.229.221.185A (IP address)IN (0x0001)false
                                          Feb 7, 2023 18:30:57.618532896 CET8.8.8.8192.168.2.40x8befNo error (0)cdnjs.cloudflare.com104.17.25.14A (IP address)IN (0x0001)false
                                          Feb 7, 2023 18:30:57.618532896 CET8.8.8.8192.168.2.40x8befNo error (0)cdnjs.cloudflare.com104.17.24.14A (IP address)IN (0x0001)false
                                          Feb 7, 2023 18:30:57.666613102 CET8.8.8.8192.168.2.40x8154No error (0)shed.dual-low.part-0032.t-0009.fdv2-t-msedge.netglobal-entry-afdthirdparty-fallback-first.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                                          Feb 7, 2023 18:30:57.666613102 CET8.8.8.8192.168.2.40x8154No error (0)shed.dual-low.part-0032.t-0009.fb-t-msedge.netpart-0032.t-0009.fb-t-msedge.netCNAME (Canonical name)IN (0x0001)false
                                          Feb 7, 2023 18:30:57.666613102 CET8.8.8.8192.168.2.40x8154No error (0)part-0032.t-0009.fb-t-msedge.net13.107.253.60A (IP address)IN (0x0001)false
                                          Feb 7, 2023 18:30:57.666613102 CET8.8.8.8192.168.2.40x8154No error (0)part-0032.t-0009.fb-t-msedge.net13.107.226.60A (IP address)IN (0x0001)false
                                          Feb 7, 2023 18:31:08.161628008 CET8.8.8.8192.168.2.40x2c9eNo error (0)shed.dual-low.part-0032.t-0009.fdv2-t-msedge.netglobal-entry-afdthirdparty-fallback-first.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                                          Feb 7, 2023 18:31:08.161628008 CET8.8.8.8192.168.2.40x2c9eNo error (0)shed.dual-low.part-0032.t-0009.fb-t-msedge.netpart-0032.t-0009.fb-t-msedge.netCNAME (Canonical name)IN (0x0001)false
                                          Feb 7, 2023 18:31:08.161628008 CET8.8.8.8192.168.2.40x2c9eNo error (0)part-0032.t-0009.fb-t-msedge.net13.107.253.60A (IP address)IN (0x0001)false
                                          Feb 7, 2023 18:31:08.161628008 CET8.8.8.8192.168.2.40x2c9eNo error (0)part-0032.t-0009.fb-t-msedge.net13.107.226.60A (IP address)IN (0x0001)false
                                          • clients2.google.com
                                          • accounts.google.com
                                          • ussufaces.com
                                          • maxcdn.bootstrapcdn.com
                                          • cdn.jsdelivr.net
                                          • logincdn.msauth.net
                                          • https:
                                          • cdnjs.cloudflare.com
                                          • aadcdn.msauth.net

                                          Click to jump to process

                                          Target ID:0
                                          Start time:18:30:47
                                          Start date:07/02/2023
                                          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          Wow64 process (32bit):false
                                          Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                                          Imagebase:0x7ff683680000
                                          File size:2851656 bytes
                                          MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                                          Has elevated privileges:true
                                          Has administrator privileges:true
                                          Programmed in:C, C++ or other language
                                          Reputation:high

                                          Target ID:1
                                          Start time:18:30:48
                                          Start date:07/02/2023
                                          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          Wow64 process (32bit):false
                                          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=1876 --field-trial-handle=1812,i,2036972514004216083,622276978597170317,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                                          Imagebase:0x7ff683680000
                                          File size:2851656 bytes
                                          MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                                          Has elevated privileges:true
                                          Has administrator privileges:true
                                          Programmed in:C, C++ or other language
                                          Reputation:high

                                          Target ID:2
                                          Start time:18:30:49
                                          Start date:07/02/2023
                                          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                          Wow64 process (32bit):false
                                          Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "C:\Users\user\Desktop\Benefit_Enrollment.html
                                          Imagebase:0x7ff683680000
                                          File size:2851656 bytes
                                          MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                                          Has elevated privileges:true
                                          Has administrator privileges:true
                                          Programmed in:C, C++ or other language
                                          Reputation:high

                                          No disassembly