Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://sites.google.com/view/southeasternchestercountyrefus/home

Overview

General Information

Sample URL:https://sites.google.com/view/southeasternchestercountyrefus/home
Analysis ID:800713
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample

Classification

  • System is w10x64
  • chrome.exe (PID: 4688 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
    • chrome.exe (PID: 1116 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1576 --field-trial-handle=1844,i,10637429234006776294,9776587234221978637,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • chrome.exe (PID: 2432 cmdline: C:\Program Files\Google\Chrome\Application\chrome.exe" "https://sites.google.com/view/southeasternchestercountyrefus/home MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://sites.google.com/view/southeasternchestercountyrefus/homeSlashNext: detection malicious, Label: Credential Stealing type: Phishing & Social Engineering
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownHTTPS traffic detected: 142.250.180.161:443 -> 192.168.2.3:49733 version: TLS 1.2
Source: global trafficHTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmiedaX-Goog-Update-Updater: chromecrx-104.0.5112.81Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /view/southeasternchestercountyrefus/home HTTP/1.1Host: sites.google.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9X-Client-Data: CI22yQEIpbbJAQjBtskBCKmdygEI0e3KAQiVocsBCPyqzAEIvLzMAQiTvcwBCOfAzAEIm8HMAQiywcwBCMTBzAEI18HMAQjZxMwBCMrGzAEInMnMAQjyyswBCOPLzAE=Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=PENDING+904; AEC=AakniGO7HqlHWlnoY-P22_SwwnNSfVGxlF1NgK5nuj5WLe313NyJi16g7z4; SOCS=CAISHAgCEhJnd3NfMjAyMjA4MDgtMF9SQzEaAmVuIAEaBgiAvOuXBg; NID=511=nUT82hOv6CVwMNqDg-sTtCMJJ6SQ1v_cCpfCpf5nt8EolEbal01GWFyjG01tqWQgh9ciRU880J6nLd2gdbhAJs44PsHAZaVQAFIbrqe2FmFgjrAAK7W9Z8u5LDvwsuZRng98jP6E23SJ4fsPIs326YmnuCwa92dRRCcB6MNeI_o
Source: global trafficHTTP traffic detected: GET /js/client.js?onload=gapiLoaded HTTP/1.1Host: apis.google.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CI22yQEIpbbJAQjBtskBCKmdygEI0e3KAQiVocsBCPyqzAEIvLzMAQiTvcwBCOfAzAEIm8HMAQiywcwBCMTBzAEI18HMAQjZxMwBCMrGzAEInMnMAQjyyswBCOPLzAE=Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://sites.google.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=PENDING+904; AEC=AakniGO7HqlHWlnoY-P22_SwwnNSfVGxlF1NgK5nuj5WLe313NyJi16g7z4; SOCS=CAISHAgCEhJnd3NfMjAyMjA4MDgtMF9SQzEaAmVuIAEaBgiAvOuXBg; NID=511=nUT82hOv6CVwMNqDg-sTtCMJJ6SQ1v_cCpfCpf5nt8EolEbal01GWFyjG01tqWQgh9ciRU880J6nLd2gdbhAJs44PsHAZaVQAFIbrqe2FmFgjrAAK7W9Z8u5LDvwsuZRng98jP6E23SJ4fsPIs326YmnuCwa92dRRCcB6MNeI_o
Source: global trafficHTTP traffic detected: GET /_/scs/abc-static/_/js/k=gapi.lb.en.AMZ27oQJoUI.O/m=client/rt=j/sv=1/d=1/ed=1/rs=AHpOoo9dsXwz2g0gTMdQFEKa7ZoVvtQf4g/cb=gapi.loaded_0?le=scs HTTP/1.1Host: apis.google.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*X-Client-Data: CI22yQEIpbbJAQjBtskBCKmdygEI0e3KAQiVocsBCPyqzAEIvLzMAQiTvcwBCOfAzAEIm8HMAQiywcwBCMTBzAEI18HMAQjZxMwBCMrGzAEInMnMAQjyyswBCOPLzAE=Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://sites.google.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=PENDING+904; AEC=AakniGO7HqlHWlnoY-P22_SwwnNSfVGxlF1NgK5nuj5WLe313NyJi16g7z4; SOCS=CAISHAgCEhJnd3NfMjAyMjA4MDgtMF9SQzEaAmVuIAEaBgiAvOuXBg; NID=511=nUT82hOv6CVwMNqDg-sTtCMJJ6SQ1v_cCpfCpf5nt8EolEbal01GWFyjG01tqWQgh9ciRU880J6nLd2gdbhAJs44PsHAZaVQAFIbrqe2FmFgjrAAK7W9Z8u5LDvwsuZRng98jP6E23SJ4fsPIs326YmnuCwa92dRRCcB6MNeI_o
Source: global trafficHTTP traffic detected: GET /xBeHiJ-CSXhPY2tjWkIedmRNH737CR6-tuCPOrWoomysQnz4KXL_8S5U8c4UZkQ7Vxd5KbWTXG3S06MPGp2-PFw=w16383 HTTP/1.1Host: lh6.googleusercontent.comConnection: keep-alivesec-ch-ua: "Chromium";v="104", " Not A;Brand";v="99", "Google Chrome";v="104"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CI22yQEIpbbJAQjBtskBCKmdygEI0e3KAQiVocsBCPyqzAEIvLzMAQiTvcwBCOfAzAEIm8HMAQiywcwBCMTBzAEI18HMAQjZxMwBCMrGzAEInMnMAQjyyswBCOPLzAE=Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://sites.google.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /xBeHiJ-CSXhPY2tjWkIedmRNH737CR6-tuCPOrWoomysQnz4KXL_8S5U8c4UZkQ7Vxd5KbWTXG3S06MPGp2-PFw=w16383 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36Host: lh6.googleusercontent.com
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49697 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49702 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49699
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49697
Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownHTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=PENDING+904; AEC=AakniGO7HqlHWlnoY-P22_SwwnNSfVGxlF1NgK5nuj5WLe313NyJi16g7z4; SOCS=CAISHAgCEhJnd3NfMjAyMjA4MDgtMF9SQzEaAmVuIAEaBgiAvOuXBg; NID=511=nUT82hOv6CVwMNqDg-sTtCMJJ6SQ1v_cCpfCpf5nt8EolEbal01GWFyjG01tqWQgh9ciRU880J6nLd2gdbhAJs44PsHAZaVQAFIbrqe2FmFgjrAAK7W9Z8u5LDvwsuZRng98jP6E23SJ4fsPIs326YmnuCwa92dRRCcB6MNeI_o
Source: unknownHTTPS traffic detected: 142.250.180.161:443 -> 192.168.2.3:49733 version: TLS 1.2
Source: classification engineClassification label: mal48.win@25/0@8/9
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1576 --field-trial-handle=1844,i,10637429234006776294,9776587234221978637,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" "https://sites.google.com/view/southeasternchestercountyrefus/home
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1576 --field-trial-handle=1844,i,10637429234006776294,9776587234221978637,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdaterJump to behavior
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth3
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration4
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
Ingress Tool Transfer
SIM Card SwapCarrier Billing Fraud
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://sites.google.com/view/southeasternchestercountyrefus/home0%Avira URL Cloudsafe
https://sites.google.com/view/southeasternchestercountyrefus/home1%VirustotalBrowse
https://sites.google.com/view/southeasternchestercountyrefus/home100%SlashNextCredential Stealing type: Phishing & Social Engineering
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
accounts.google.com
216.58.209.45
truefalse
    high
    plus.l.google.com
    142.250.184.110
    truefalse
      high
      sites.google.com
      142.250.184.78
      truefalse
        high
        www.google.com
        142.250.184.100
        truefalse
          high
          clients.l.google.com
          142.250.180.174
          truefalse
            high
            googlehosted.l.googleusercontent.com
            142.250.180.161
            truefalse
              high
              clients2.google.com
              unknown
              unknownfalse
                high
                lh6.googleusercontent.com
                unknown
                unknownfalse
                  high
                  apis.google.com
                  unknown
                  unknownfalse
                    high
                    NameMaliciousAntivirus DetectionReputation
                    https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1false
                      high
                      https://lh6.googleusercontent.com/xBeHiJ-CSXhPY2tjWkIedmRNH737CR6-tuCPOrWoomysQnz4KXL_8S5U8c4UZkQ7Vxd5KbWTXG3S06MPGp2-PFw=w16383false
                        high
                        https://sites.google.com/_/view/logImpressions?authuser=0false
                          high
                          https://sites.google.com/view/southeasternchestercountyrefus/homefalse
                            high
                            https://sites.google.com/view/southeasternchestercountyrefus/homefalse
                              high
                              https://apis.google.com/_/scs/abc-static/_/js/k=gapi.lb.en.AMZ27oQJoUI.O/m=client/rt=j/sv=1/d=1/ed=1/rs=AHpOoo9dsXwz2g0gTMdQFEKa7ZoVvtQf4g/cb=gapi.loaded_0?le=scsfalse
                                high
                                https://apis.google.com/js/client.js?onload=gapiLoadedfalse
                                  high
                                  https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standardfalse
                                    high
                                    • No. of IPs < 25%
                                    • 25% < No. of IPs < 50%
                                    • 50% < No. of IPs < 75%
                                    • 75% < No. of IPs
                                    IPDomainCountryFlagASNASN NameMalicious
                                    142.250.184.78
                                    sites.google.comUnited States
                                    15169GOOGLEUSfalse
                                    142.250.184.110
                                    plus.l.google.comUnited States
                                    15169GOOGLEUSfalse
                                    216.58.209.45
                                    accounts.google.comUnited States
                                    15169GOOGLEUSfalse
                                    142.250.180.161
                                    googlehosted.l.googleusercontent.comUnited States
                                    15169GOOGLEUSfalse
                                    239.255.255.250
                                    unknownReserved
                                    unknownunknownfalse
                                    142.250.184.100
                                    www.google.comUnited States
                                    15169GOOGLEUSfalse
                                    142.250.180.174
                                    clients.l.google.comUnited States
                                    15169GOOGLEUSfalse
                                    IP
                                    192.168.2.1
                                    127.0.0.1
                                    Joe Sandbox Version:36.0.0 Rainbow Opal
                                    Analysis ID:800713
                                    Start date and time:2023-02-07 18:33:56 +01:00
                                    Joe Sandbox Product:CloudBasic
                                    Overall analysis duration:0h 5m 35s
                                    Hypervisor based Inspection enabled:false
                                    Report type:light
                                    Cookbook file name:browseurl.jbs
                                    Sample URL:https://sites.google.com/view/southeasternchestercountyrefus/home
                                    Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                    Number of analysed new started processes analysed:14
                                    Number of new started drivers analysed:0
                                    Number of existing processes analysed:0
                                    Number of existing drivers analysed:0
                                    Number of injected processes analysed:0
                                    Technologies:
                                    • HCA enabled
                                    • EGA enabled
                                    • HDC enabled
                                    • AMSI enabled
                                    Analysis Mode:default
                                    Analysis stop reason:Timeout
                                    Detection:MAL
                                    Classification:mal48.win@25/0@8/9
                                    EGA Information:Failed
                                    HDC Information:Failed
                                    HCA Information:
                                    • Successful, ratio: 100%
                                    • Number of executed functions: 0
                                    • Number of non-executed functions: 0
                                    Cookbook Comments:
                                    • Browse: https://bafybeidr4sutsrgsviivzdf6ljqgkxjbrrnfl46ee3qxvuzwb2ch4ukdmi.ipfs.dweb.link/microsoftonline%20%281%29%20%281%29.html
                                    • Exclude process from analysis (whitelisted): MpCmdRun.exe, SgrmBroker.exe, conhost.exe, svchost.exe
                                    • TCP Packets have been reduced to 100
                                    • Excluded IPs from analysis (whitelisted): 142.250.184.99, 34.104.35.123, 142.250.180.163, 142.250.180.138, 142.250.184.67, 142.250.184.74, 142.250.184.106, 142.250.180.170, 142.251.209.10, 142.251.209.42
                                    • Excluded domains from analysis (whitelisted): www.bing.com, fonts.googleapis.com, ssl.gstatic.com, fs.microsoft.com, edgedl.me.gvt1.com, content-autofill.googleapis.com, fonts.gstatic.com, update.googleapis.com, ctldl.windowsupdate.com, clientservices.googleapis.com, www.gstatic.com
                                    • Not all processes where analyzed, report is missing behavior information
                                    • Report size getting too big, too many NtWriteVirtualMemory calls found.
                                    No simulations
                                    No context
                                    No context
                                    No context
                                    No context
                                    No context
                                    No created / dropped files found
                                    No static file info
                                    TimestampSource PortDest PortSource IPDest IP
                                    Feb 7, 2023 18:34:58.474042892 CET49697443192.168.2.3142.250.180.174
                                    Feb 7, 2023 18:34:58.474109888 CET44349697142.250.180.174192.168.2.3
                                    Feb 7, 2023 18:34:58.474217892 CET49697443192.168.2.3142.250.180.174
                                    Feb 7, 2023 18:34:58.475406885 CET49699443192.168.2.3216.58.209.45
                                    Feb 7, 2023 18:34:58.475429058 CET44349699216.58.209.45192.168.2.3
                                    Feb 7, 2023 18:34:58.475498915 CET49699443192.168.2.3216.58.209.45
                                    Feb 7, 2023 18:34:58.476669073 CET49701443192.168.2.3216.58.209.45
                                    Feb 7, 2023 18:34:58.476720095 CET44349701216.58.209.45192.168.2.3
                                    Feb 7, 2023 18:34:58.476808071 CET49701443192.168.2.3216.58.209.45
                                    Feb 7, 2023 18:34:58.477111101 CET49702443192.168.2.3142.250.180.174
                                    Feb 7, 2023 18:34:58.477145910 CET44349702142.250.180.174192.168.2.3
                                    Feb 7, 2023 18:34:58.477221012 CET49702443192.168.2.3142.250.180.174
                                    Feb 7, 2023 18:34:58.478216887 CET49697443192.168.2.3142.250.180.174
                                    Feb 7, 2023 18:34:58.478257895 CET44349697142.250.180.174192.168.2.3
                                    Feb 7, 2023 18:34:58.479079962 CET49699443192.168.2.3216.58.209.45
                                    Feb 7, 2023 18:34:58.479105949 CET44349699216.58.209.45192.168.2.3
                                    Feb 7, 2023 18:34:58.479882956 CET49701443192.168.2.3216.58.209.45
                                    Feb 7, 2023 18:34:58.479902983 CET44349701216.58.209.45192.168.2.3
                                    Feb 7, 2023 18:34:58.480287075 CET49702443192.168.2.3142.250.180.174
                                    Feb 7, 2023 18:34:58.480314016 CET44349702142.250.180.174192.168.2.3
                                    Feb 7, 2023 18:34:58.557678938 CET44349697142.250.180.174192.168.2.3
                                    Feb 7, 2023 18:34:58.580547094 CET44349701216.58.209.45192.168.2.3
                                    Feb 7, 2023 18:34:58.621932983 CET44349699216.58.209.45192.168.2.3
                                    Feb 7, 2023 18:34:58.647264957 CET44349702142.250.180.174192.168.2.3
                                    Feb 7, 2023 18:34:58.648318052 CET49701443192.168.2.3216.58.209.45
                                    Feb 7, 2023 18:34:58.648344994 CET44349701216.58.209.45192.168.2.3
                                    Feb 7, 2023 18:34:58.648531914 CET49697443192.168.2.3142.250.180.174
                                    Feb 7, 2023 18:34:58.648569107 CET44349697142.250.180.174192.168.2.3
                                    Feb 7, 2023 18:34:58.649200916 CET44349697142.250.180.174192.168.2.3
                                    Feb 7, 2023 18:34:58.649221897 CET44349697142.250.180.174192.168.2.3
                                    Feb 7, 2023 18:34:58.649297953 CET49697443192.168.2.3142.250.180.174
                                    Feb 7, 2023 18:34:58.650199890 CET44349701216.58.209.45192.168.2.3
                                    Feb 7, 2023 18:34:58.650202036 CET44349697142.250.180.174192.168.2.3
                                    Feb 7, 2023 18:34:58.650244951 CET44349701216.58.209.45192.168.2.3
                                    Feb 7, 2023 18:34:58.650291920 CET49701443192.168.2.3216.58.209.45
                                    Feb 7, 2023 18:34:58.650295019 CET49697443192.168.2.3142.250.180.174
                                    Feb 7, 2023 18:34:58.658399105 CET49702443192.168.2.3142.250.180.174
                                    Feb 7, 2023 18:34:58.658443928 CET44349702142.250.180.174192.168.2.3
                                    Feb 7, 2023 18:34:58.658588886 CET49699443192.168.2.3216.58.209.45
                                    Feb 7, 2023 18:34:58.658637047 CET44349699216.58.209.45192.168.2.3
                                    Feb 7, 2023 18:34:58.659082890 CET44349702142.250.180.174192.168.2.3
                                    Feb 7, 2023 18:34:58.659182072 CET49702443192.168.2.3142.250.180.174
                                    Feb 7, 2023 18:34:58.659903049 CET44349702142.250.180.174192.168.2.3
                                    Feb 7, 2023 18:34:58.660026073 CET49702443192.168.2.3142.250.180.174
                                    Feb 7, 2023 18:34:58.662796021 CET44349699216.58.209.45192.168.2.3
                                    Feb 7, 2023 18:34:58.662930012 CET49699443192.168.2.3216.58.209.45
                                    Feb 7, 2023 18:34:58.761827946 CET49701443192.168.2.3216.58.209.45
                                    Feb 7, 2023 18:34:59.785820007 CET49701443192.168.2.3216.58.209.45
                                    Feb 7, 2023 18:34:59.785897970 CET44349701216.58.209.45192.168.2.3
                                    Feb 7, 2023 18:34:59.786006927 CET49699443192.168.2.3216.58.209.45
                                    Feb 7, 2023 18:34:59.786053896 CET44349699216.58.209.45192.168.2.3
                                    Feb 7, 2023 18:34:59.786072969 CET44349701216.58.209.45192.168.2.3
                                    Feb 7, 2023 18:34:59.786338091 CET44349699216.58.209.45192.168.2.3
                                    Feb 7, 2023 18:34:59.786731958 CET49701443192.168.2.3216.58.209.45
                                    Feb 7, 2023 18:34:59.786768913 CET44349701216.58.209.45192.168.2.3
                                    Feb 7, 2023 18:34:59.786993027 CET49697443192.168.2.3142.250.180.174
                                    Feb 7, 2023 18:34:59.787019968 CET44349697142.250.180.174192.168.2.3
                                    Feb 7, 2023 18:34:59.787193060 CET44349697142.250.180.174192.168.2.3
                                    Feb 7, 2023 18:34:59.787216902 CET49702443192.168.2.3142.250.180.174
                                    Feb 7, 2023 18:34:59.787259102 CET44349702142.250.180.174192.168.2.3
                                    Feb 7, 2023 18:34:59.787436962 CET44349702142.250.180.174192.168.2.3
                                    Feb 7, 2023 18:34:59.787451029 CET49697443192.168.2.3142.250.180.174
                                    Feb 7, 2023 18:34:59.787468910 CET44349697142.250.180.174192.168.2.3
                                    Feb 7, 2023 18:34:59.829991102 CET44349697142.250.180.174192.168.2.3
                                    Feb 7, 2023 18:34:59.830110073 CET49697443192.168.2.3142.250.180.174
                                    Feb 7, 2023 18:34:59.830140114 CET44349697142.250.180.174192.168.2.3
                                    Feb 7, 2023 18:34:59.830288887 CET44349697142.250.180.174192.168.2.3
                                    Feb 7, 2023 18:34:59.830379963 CET49697443192.168.2.3142.250.180.174
                                    Feb 7, 2023 18:34:59.832557917 CET49697443192.168.2.3142.250.180.174
                                    Feb 7, 2023 18:34:59.832595110 CET44349697142.250.180.174192.168.2.3
                                    Feb 7, 2023 18:34:59.855396032 CET44349701216.58.209.45192.168.2.3
                                    Feb 7, 2023 18:34:59.855545998 CET49701443192.168.2.3216.58.209.45
                                    Feb 7, 2023 18:34:59.855576992 CET44349701216.58.209.45192.168.2.3
                                    Feb 7, 2023 18:34:59.855742931 CET44349701216.58.209.45192.168.2.3
                                    Feb 7, 2023 18:34:59.855837107 CET49701443192.168.2.3216.58.209.45
                                    Feb 7, 2023 18:34:59.861915112 CET49699443192.168.2.3216.58.209.45
                                    Feb 7, 2023 18:34:59.861941099 CET44349699216.58.209.45192.168.2.3
                                    Feb 7, 2023 18:34:59.867892981 CET49702443192.168.2.3142.250.180.174
                                    Feb 7, 2023 18:34:59.867925882 CET44349702142.250.180.174192.168.2.3
                                    Feb 7, 2023 18:34:59.961931944 CET49699443192.168.2.3216.58.209.45
                                    Feb 7, 2023 18:34:59.967911959 CET49702443192.168.2.3142.250.180.174
                                    Feb 7, 2023 18:34:59.986751080 CET49701443192.168.2.3216.58.209.45
                                    Feb 7, 2023 18:34:59.986798048 CET44349701216.58.209.45192.168.2.3
                                    Feb 7, 2023 18:35:00.396269083 CET49703443192.168.2.3142.250.184.78
                                    Feb 7, 2023 18:35:00.396361113 CET44349703142.250.184.78192.168.2.3
                                    Feb 7, 2023 18:35:00.396972895 CET49703443192.168.2.3142.250.184.78
                                    Feb 7, 2023 18:35:00.429040909 CET49703443192.168.2.3142.250.184.78
                                    Feb 7, 2023 18:35:00.429100037 CET44349703142.250.184.78192.168.2.3
                                    Feb 7, 2023 18:35:00.496269941 CET44349703142.250.184.78192.168.2.3
                                    Feb 7, 2023 18:35:00.498800039 CET49703443192.168.2.3142.250.184.78
                                    Feb 7, 2023 18:35:00.498850107 CET44349703142.250.184.78192.168.2.3
                                    Feb 7, 2023 18:35:00.499684095 CET44349703142.250.184.78192.168.2.3
                                    Feb 7, 2023 18:35:00.500598907 CET49703443192.168.2.3142.250.184.78
                                    Feb 7, 2023 18:35:00.501034975 CET44349703142.250.184.78192.168.2.3
                                    Feb 7, 2023 18:35:00.502197981 CET49703443192.168.2.3142.250.184.78
                                    Feb 7, 2023 18:35:00.503266096 CET49703443192.168.2.3142.250.184.78
                                    Feb 7, 2023 18:35:00.503266096 CET49703443192.168.2.3142.250.184.78
                                    Feb 7, 2023 18:35:00.503281116 CET44349703142.250.184.78192.168.2.3
                                    Feb 7, 2023 18:35:00.503299952 CET44349703142.250.184.78192.168.2.3
                                    Feb 7, 2023 18:35:00.503451109 CET44349703142.250.184.78192.168.2.3
                                    TimestampSource PortDest PortSource IPDest IP
                                    Feb 7, 2023 18:34:58.091293097 CET4997753192.168.2.38.8.8.8
                                    Feb 7, 2023 18:34:58.094388008 CET5784053192.168.2.38.8.8.8
                                    Feb 7, 2023 18:34:58.119580030 CET53499778.8.8.8192.168.2.3
                                    Feb 7, 2023 18:34:58.123442888 CET53578408.8.8.8192.168.2.3
                                    Feb 7, 2023 18:34:59.797871113 CET5799053192.168.2.38.8.8.8
                                    Feb 7, 2023 18:34:59.826196909 CET53579908.8.8.8192.168.2.3
                                    Feb 7, 2023 18:35:00.854302883 CET5113953192.168.2.38.8.8.8
                                    Feb 7, 2023 18:35:00.880187035 CET53511398.8.8.8192.168.2.3
                                    Feb 7, 2023 18:35:01.269999981 CET6058253192.168.2.38.8.8.8
                                    Feb 7, 2023 18:35:01.275713921 CET5713453192.168.2.38.8.8.8
                                    Feb 7, 2023 18:35:01.287965059 CET53605828.8.8.8192.168.2.3
                                    Feb 7, 2023 18:35:01.316416979 CET53571348.8.8.8192.168.2.3
                                    Feb 7, 2023 18:35:04.348099947 CET5770453192.168.2.38.8.8.8
                                    Feb 7, 2023 18:35:04.368143082 CET53577048.8.8.8192.168.2.3
                                    Feb 7, 2023 18:36:01.427582979 CET6501753192.168.2.38.8.8.8
                                    Feb 7, 2023 18:36:01.454190969 CET53650178.8.8.8192.168.2.3
                                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                    Feb 7, 2023 18:34:58.091293097 CET192.168.2.38.8.8.80x6802Standard query (0)accounts.google.comA (IP address)IN (0x0001)false
                                    Feb 7, 2023 18:34:58.094388008 CET192.168.2.38.8.8.80x159cStandard query (0)clients2.google.comA (IP address)IN (0x0001)false
                                    Feb 7, 2023 18:34:59.797871113 CET192.168.2.38.8.8.80x535aStandard query (0)sites.google.comA (IP address)IN (0x0001)false
                                    Feb 7, 2023 18:35:00.854302883 CET192.168.2.38.8.8.80x1f01Standard query (0)apis.google.comA (IP address)IN (0x0001)false
                                    Feb 7, 2023 18:35:01.269999981 CET192.168.2.38.8.8.80xfd15Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                    Feb 7, 2023 18:35:01.275713921 CET192.168.2.38.8.8.80xef35Standard query (0)lh6.googleusercontent.comA (IP address)IN (0x0001)false
                                    Feb 7, 2023 18:35:04.348099947 CET192.168.2.38.8.8.80x48bdStandard query (0)lh6.googleusercontent.comA (IP address)IN (0x0001)false
                                    Feb 7, 2023 18:36:01.427582979 CET192.168.2.38.8.8.80x1ce2Standard query (0)www.google.comA (IP address)IN (0x0001)false
                                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                    Feb 7, 2023 18:34:58.119580030 CET8.8.8.8192.168.2.30x6802No error (0)accounts.google.com216.58.209.45A (IP address)IN (0x0001)false
                                    Feb 7, 2023 18:34:58.123442888 CET8.8.8.8192.168.2.30x159cNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)false
                                    Feb 7, 2023 18:34:58.123442888 CET8.8.8.8192.168.2.30x159cNo error (0)clients.l.google.com142.250.180.174A (IP address)IN (0x0001)false
                                    Feb 7, 2023 18:34:59.826196909 CET8.8.8.8192.168.2.30x535aNo error (0)sites.google.com142.250.184.78A (IP address)IN (0x0001)false
                                    Feb 7, 2023 18:35:00.880187035 CET8.8.8.8192.168.2.30x1f01No error (0)apis.google.complus.l.google.comCNAME (Canonical name)IN (0x0001)false
                                    Feb 7, 2023 18:35:00.880187035 CET8.8.8.8192.168.2.30x1f01No error (0)plus.l.google.com142.250.184.110A (IP address)IN (0x0001)false
                                    Feb 7, 2023 18:35:01.287965059 CET8.8.8.8192.168.2.30xfd15No error (0)www.google.com142.250.184.100A (IP address)IN (0x0001)false
                                    Feb 7, 2023 18:35:01.316416979 CET8.8.8.8192.168.2.30xef35No error (0)lh6.googleusercontent.comgooglehosted.l.googleusercontent.comCNAME (Canonical name)IN (0x0001)false
                                    Feb 7, 2023 18:35:01.316416979 CET8.8.8.8192.168.2.30xef35No error (0)googlehosted.l.googleusercontent.com142.250.180.161A (IP address)IN (0x0001)false
                                    Feb 7, 2023 18:35:04.368143082 CET8.8.8.8192.168.2.30x48bdNo error (0)lh6.googleusercontent.comgooglehosted.l.googleusercontent.comCNAME (Canonical name)IN (0x0001)false
                                    Feb 7, 2023 18:35:04.368143082 CET8.8.8.8192.168.2.30x48bdNo error (0)googlehosted.l.googleusercontent.com142.250.180.161A (IP address)IN (0x0001)false
                                    Feb 7, 2023 18:36:01.454190969 CET8.8.8.8192.168.2.30x1ce2No error (0)www.google.com142.250.184.100A (IP address)IN (0x0001)false
                                    • accounts.google.com
                                    • clients2.google.com
                                    • sites.google.com
                                    • https:
                                      • apis.google.com
                                      • lh6.googleusercontent.com

                                    Click to jump to process

                                    Target ID:0
                                    Start time:18:34:54
                                    Start date:07/02/2023
                                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    Wow64 process (32bit):false
                                    Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
                                    Imagebase:0x7ff614650000
                                    File size:2851656 bytes
                                    MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:low

                                    Target ID:1
                                    Start time:18:34:55
                                    Start date:07/02/2023
                                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    Wow64 process (32bit):false
                                    Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1576 --field-trial-handle=1844,i,10637429234006776294,9776587234221978637,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
                                    Imagebase:0x7ff614650000
                                    File size:2851656 bytes
                                    MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:low

                                    Target ID:2
                                    Start time:18:34:57
                                    Start date:07/02/2023
                                    Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                    Wow64 process (32bit):false
                                    Commandline:C:\Program Files\Google\Chrome\Application\chrome.exe" "https://sites.google.com/view/southeasternchestercountyrefus/home
                                    Imagebase:0x7ff614650000
                                    File size:2851656 bytes
                                    MD5 hash:0FEC2748F363150DC54C1CAFFB1A9408
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:low

                                    No disassembly