Windows Analysis Report
http://surl.pk/rUrcX

Overview

General Information

Sample URL: http://surl.pk/rUrcX
Analysis ID: 1447586
Infos:

Detection

Score: 60
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
AI detected suspicious javascript
HTML body contains password input but no form action
HTML title does not match URL
Program does not show much activity (idle)
Stores files to the Windows start menu directory

Classification

AV Detection

barindex
Source: http://surl.pk/rUrcX Avira URL Cloud: detection malicious, Label: phishing
Source: http://surl.pk/rUrcX Virustotal: Detection: 17% Perma Link

Phishing

barindex
Source: https://steamcomunmnity.com/app/1644413/STALKER_2_Heart_of_Chornobyl LLM: Score: 9 Reasons: The code creates an iframe and form elements dynamically, sets their attributes, and submits the form to a potentially suspicious URL ('https://en.stetrade.ru/'). This behavior is indicative of phishing or other malicious activities as it attempts to gather and send data without user consent. DOM: 0.0.pages.csv
Source: https://store.steampowered.com/login/?redir=app%2F1643320%2FSTALKER_2_Heart_of_Chornobyl%2F%3Fcurator_clanid%3D6313&redir_ssl=1&snr=1_5_9__global-header HTTP Parser: <input type="password" .../> found but no <form action="...
Source: https://store.steampowered.com/login/?redir=app%2F1643320%2FSTALKER_2_Heart_of_Chornobyl%2F%3Fcurator_clanid%3D6313&redir_ssl=1&snr=1_5_9__global-header HTTP Parser: Title: Sign In does not match URL
Source: https://store.steampowered.com/login/?redir=app%2F1643320%2FSTALKER_2_Heart_of_Chornobyl%2F%3Fcurator_clanid%3D6313&redir_ssl=1&snr=1_5_9__global-header HTTP Parser: <input type="password" .../> found
Source: https://store.steampowered.com/login/?redir=app%2F1643320%2FSTALKER_2_Heart_of_Chornobyl%2F%3Fcurator_clanid%3D6313&redir_ssl=1&snr=1_5_9__global-header HTTP Parser: No <meta name="author".. found
Source: https://store.steampowered.com/login/?redir=app%2F1643320%2FSTALKER_2_Heart_of_Chornobyl%2F%3Fcurator_clanid%3D6313&redir_ssl=1&snr=1_5_9__global-header HTTP Parser: No <meta name="author".. found
Source: https://store.steampowered.com/login/?redir=app%2F1643320%2FSTALKER_2_Heart_of_Chornobyl%2F%3Fcurator_clanid%3D6313&redir_ssl=1&snr=1_5_9__global-header HTTP Parser: No <meta name="author".. found
Source: https://store.steampowered.com/login/?redir=app%2F1643320%2FSTALKER_2_Heart_of_Chornobyl%2F%3Fcurator_clanid%3D6313&redir_ssl=1&snr=1_5_9__global-header HTTP Parser: No <meta name="author".. found
Source: https://store.steampowered.com/login/?redir=app%2F1643320%2FSTALKER_2_Heart_of_Chornobyl%2F%3Fcurator_clanid%3D6313&redir_ssl=1&snr=1_5_9__global-header HTTP Parser: No <meta name="copyright".. found
Source: https://store.steampowered.com/login/?redir=app%2F1643320%2FSTALKER_2_Heart_of_Chornobyl%2F%3Fcurator_clanid%3D6313&redir_ssl=1&snr=1_5_9__global-header HTTP Parser: No <meta name="copyright".. found
Source: https://store.steampowered.com/login/?redir=app%2F1643320%2FSTALKER_2_Heart_of_Chornobyl%2F%3Fcurator_clanid%3D6313&redir_ssl=1&snr=1_5_9__global-header HTTP Parser: No <meta name="copyright".. found
Source: https://store.steampowered.com/login/?redir=app%2F1643320%2FSTALKER_2_Heart_of_Chornobyl%2F%3Fcurator_clanid%3D6313&redir_ssl=1&snr=1_5_9__global-header HTTP Parser: No <meta name="copyright".. found
Source: chromecache_510.2.dr, chromecache_437.2.dr String found in binary or memory: var youtubeurl = location.protocol + '//www.youtube.com/embed/' + videoid + '?showinfo=0&autohide=1&fs=1&hd=1&modestbranding=1&rel=0&showsearch=0&wmode=direct&autoplay=1'; equals www.youtube.com (Youtube)
Source: chromecache_786.2.dr String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
Source: chromecache_786.2.dr String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
Source: chromecache_818.2.dr String found in binary or memory: http://colorzilla.com/gradient-editor/#223246
Source: chromecache_786.2.dr String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
Source: chromecache_786.2.dr String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
Source: chromecache_786.2.dr String found in binary or memory: http://cv.iptc.org/newscodes/digitalsourcetype/compositeWithTrainedAlgorithmicMedia
Source: chromecache_786.2.dr String found in binary or memory: http://ocsp.digicert.com0A
Source: chromecache_786.2.dr String found in binary or memory: http://ocsp.digicert.com0X
Source: chromecache_786.2.dr String found in binary or memory: http://pki-crl.symauth.com/ca_7a5c3a0c73117406add19312bc1bc23f/LatestCRL.crl07
Source: chromecache_786.2.dr String found in binary or memory: http://pki-ocsp.symauth.com0
Source: chromecache_768.2.dr, chromecache_586.2.dr, chromecache_574.2.dr, chromecache_552.2.dr, chromecache_730.2.dr, chromecache_711.2.dr, chromecache_831.2.dr String found in binary or memory: http://store.steampowered.com/subscriber_agreement/.
Source: chromecache_665.2.dr String found in binary or memory: https://cdn.cloudflare.steamstatic.com/steam/
Source: chromecache_510.2.dr, chromecache_437.2.dr String found in binary or memory: https://checkout.steampowered.com/parental/ajaxlock
Source: chromecache_437.2.dr String found in binary or memory: https://community.akamai.steamstatic.com/
Source: chromecache_510.2.dr String found in binary or memory: https://community.cloudflare.steamstatic.com/
Source: chromecache_437.2.dr String found in binary or memory: https://help.steampowered.com/en/wizard/HelpWithLimitedAccount
Source: chromecache_510.2.dr String found in binary or memory: https://help.steampowered.com/ru/wizard/HelpWithLimitedAccount
Source: chromecache_605.2.dr, chromecache_514.2.dr, chromecache_439.2.dr, chromecache_738.2.dr, chromecache_410.2.dr String found in binary or memory: https://plau.cohttps://plau.co
Source: chromecache_605.2.dr, chromecache_514.2.dr, chromecache_439.2.dr, chromecache_738.2.dr, chromecache_410.2.dr String found in binary or memory: https://plau.cohttps://plau.coCopyright
Source: chromecache_605.2.dr, chromecache_514.2.dr, chromecache_439.2.dr String found in binary or memory: https://plau.cohttps://plau.coMotiva
Source: chromecache_510.2.dr, chromecache_437.2.dr String found in binary or memory: https://player.vimeo.com/video/
Source: chromecache_898.2.dr String found in binary or memory: https://shared.akamai.steamstatic.com/store_item_assets/steam/
Source: chromecache_510.2.dr, chromecache_437.2.dr String found in binary or memory: https://sketchfab.com/models/
Source: chromecache_574.2.dr, chromecache_552.2.dr String found in binary or memory: https://steam.tv
Source: chromecache_510.2.dr, chromecache_437.2.dr String found in binary or memory: https://steam.tv/parental/ajaxlock
Source: chromecache_510.2.dr, chromecache_437.2.dr String found in binary or memory: https://steamcommunity.com
Source: chromecache_437.2.dr String found in binary or memory: https://steamcommunity.com/
Source: chromecache_510.2.dr, chromecache_437.2.dr String found in binary or memory: https://steamcommunity.com/chat/
Source: chromecache_510.2.dr, chromecache_437.2.dr String found in binary or memory: https://steamcommunity.com/chat/friend/
Source: chromecache_510.2.dr, chromecache_437.2.dr String found in binary or memory: https://steamcommunity.com/chat/group/
Source: chromecache_898.2.dr String found in binary or memory: https://store.akamai.steamstatic.com/public/images/promo/lunar2019/lny2019_title_en.png
Source: chromecache_804.2.dr String found in binary or memory: https://store.cloudflare.steamstatic.com/public/images/blank.gif
Source: chromecache_381.2.dr String found in binary or memory: https://store.cloudflare.steamstatic.com/public/images/login/throbber.gif
Source: chromecache_665.2.dr String found in binary or memory: https://store.cloudflare.steamstatic.com/public/images/promo/lunar2019/lny2019_title_ru.png
Source: chromecache_804.2.dr String found in binary or memory: https://store.cloudflare.steamstatic.com/public/images/v5/ico_external_link.gif
Source: chromecache_437.2.dr String found in binary or memory: https://store.steampowered.com/
Source: chromecache_534.2.dr String found in binary or memory: https://store.steampowered.com//login?redir=app/
Source: chromecache_510.2.dr, chromecache_437.2.dr String found in binary or memory: https://store.steampowered.com/about/
Source: chromecache_534.2.dr String found in binary or memory: https://store.steampowered.com/account/languagepreferences/
Source: chromecache_898.2.dr, chromecache_665.2.dr String found in binary or memory: https://store.steampowered.com/account/preferences
Source: chromecache_534.2.dr String found in binary or memory: https://store.steampowered.com/account/setlanguage/
Source: chromecache_534.2.dr, chromecache_898.2.dr, chromecache_665.2.dr String found in binary or memory: https://store.steampowered.com/api/addtowishlist
Source: chromecache_534.2.dr, chromecache_898.2.dr, chromecache_665.2.dr String found in binary or memory: https://store.steampowered.com/api/removefromwishlist
Source: chromecache_665.2.dr String found in binary or memory: https://store.steampowered.com/app/
Source: chromecache_898.2.dr, chromecache_665.2.dr String found in binary or memory: https://store.steampowered.com/bundle/
Source: chromecache_534.2.dr String found in binary or memory: https://store.steampowered.com/cart/
Source: chromecache_534.2.dr String found in binary or memory: https://store.steampowered.com/curators/ajaxfollow
Source: chromecache_534.2.dr String found in binary or memory: https://store.steampowered.com/curators/ajaxignore
Source: chromecache_898.2.dr, chromecache_665.2.dr String found in binary or memory: https://store.steampowered.com/dynamicstore/saledata/?cc=
Source: chromecache_898.2.dr, chromecache_665.2.dr String found in binary or memory: https://store.steampowered.com/dynamicstore/userdata/?id=
Source: chromecache_898.2.dr, chromecache_665.2.dr String found in binary or memory: https://store.steampowered.com/explore/howitworks/
Source: chromecache_534.2.dr String found in binary or memory: https://store.steampowered.com/freelicense/addfreebundle/
Source: chromecache_534.2.dr String found in binary or memory: https://store.steampowered.com/freelicense/addfreelicense/
Source: chromecache_534.2.dr String found in binary or memory: https://store.steampowered.com/friends/recommendgame
Source: chromecache_534.2.dr String found in binary or memory: https://store.steampowered.com/gotflash
Source: chromecache_534.2.dr String found in binary or memory: https://store.steampowered.com/logout/
Source: chromecache_534.2.dr, chromecache_898.2.dr, chromecache_665.2.dr String found in binary or memory: https://store.steampowered.com/recommended/ignorerecommendation/
Source: chromecache_534.2.dr String found in binary or memory: https://store.steampowered.com/search/?term=
Source: chromecache_510.2.dr, chromecache_437.2.dr String found in binary or memory: https://store.steampowered.com/search/results/
Source: chromecache_534.2.dr String found in binary or memory: https://store.steampowered.com/search/smallcapscroll
Source: chromecache_534.2.dr String found in binary or memory: https://store.steampowered.com/search/suggest
Source: chromecache_534.2.dr String found in binary or memory: https://store.steampowered.com/search/tab
Source: chromecache_898.2.dr, chromecache_665.2.dr String found in binary or memory: https://store.steampowered.com/sub/
Source: chromecache_534.2.dr String found in binary or memory: https://store.steampowered.com/tag/en/
Source: chromecache_381.2.dr String found in binary or memory: https://store.steampowered.com/tagdata/gettaggames/
Source: chromecache_381.2.dr String found in binary or memory: https://store.steampowered.com/tagdata/myfrequenttags
Source: chromecache_381.2.dr String found in binary or memory: https://store.steampowered.com/tagdata/populartags/russian
Source: chromecache_534.2.dr String found in binary or memory: https://store.steampowered.com/tagdata/recommendedtags
Source: chromecache_381.2.dr String found in binary or memory: https://store.steampowered.com/tagdata/tagapp
Source: chromecache_381.2.dr String found in binary or memory: https://store.steampowered.com/tags/
Source: chromecache_898.2.dr String found in binary or memory: https://store.steampowered.com/tags/en/
Source: chromecache_665.2.dr String found in binary or memory: https://store.steampowered.com/tags/ru/
Source: classification engine Classification label: mal60.phis.win@26/903@0/31
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps Jump to behavior
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2256 --field-trial-handle=2200,i,16015662976217930390,16343968462784890998,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://surl.pk/rUrcX"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=3112 --field-trial-handle=2200,i,16015662976217930390,16343968462784890998,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2256 --field-trial-handle=2200,i,16015662976217930390,16343968462784890998,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=3112 --field-trial-handle=2200,i,16015662976217930390,16343968462784890998,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: Google Drive.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk Jump to behavior
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs