Windows
Analysis Report
https://unsubscribe.spmta.com/u/vqZbyKMmoimrO2-HtLanhw~~/AAQRrwA~/RgRnpM82PFcDc3BjQgplujZKwmV6WWP_UhpHU1RFRkFOU1NPTkBva2FuYWdhbi5iYy5jYVgEAAAAhw~~
Overview
General Information
Detection
Score: | 1 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 80% |
Signatures
Classification
- System is w10x64_ra
chrome.exe (PID: 3448 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed --sing le-argumen t https:// unsubscrib e.spmta.co m/u/vqZbyK MmoimrO2-H tLanhw~~/A AQRrwA~/Rg RnpM82PFcD c3BjQgpluj ZKwmV6WWP_ UhpHU1RFRk FOU1NPTkBv a2FuYWdhbi 5iYy5jYVgE AAAAhw~~ MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) chrome.exe (PID: 5200 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2224 --fi eld-trial- handle=195 2,i,328696 6630731294 600,802139 0915298318 276,262144 --disable -features= Optimizati onGuideMod elDownload ing,Optimi zationHint s,Optimiza tionHintsF etching,Op timization TargetPred iction /pr efetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
- • Phishing
- • Compliance
- • Networking
- • System Summary
- • Boot Survival
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | File created: |
Source: | Classification label: |
Source: | File created: |
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: |
Source: | Window detected: |
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 1 Process Injection | 11 Masquerading | OS Credential Dumping | System Service Discovery | Remote Services | Data from Local System | 2 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 2 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
accounts.google.com | 64.233.177.84 | true | false | high | |
www.google.com | 142.250.9.103 | true | false | high | |
unsubscribe.spmta.com | 44.239.248.252 | true | false | unknown | |
clients.l.google.com | 64.233.176.101 | true | false | high | |
clients1.google.com | unknown | unknown | false | high | |
clients2.google.com | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
44.239.248.252 | unsubscribe.spmta.com | United States | 16509 | AMAZON-02US | false | |
64.233.177.84 | accounts.google.com | United States | 15169 | GOOGLEUS | false | |
74.125.138.113 | unknown | United States | 15169 | GOOGLEUS | false | |
74.125.136.94 | unknown | United States | 15169 | GOOGLEUS | false | |
1.1.1.1 | unknown | Australia | 13335 | CLOUDFLARENETUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
64.233.185.94 | unknown | United States | 15169 | GOOGLEUS | false | |
64.233.176.101 | clients.l.google.com | United States | 15169 | GOOGLEUS | false | |
142.250.9.103 | www.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.16 |
192.168.2.6 |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1387788 |
Start date and time: | 2024-02-06 20:30:49 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Sample URL: | https://unsubscribe.spmta.com/u/vqZbyKMmoimrO2-HtLanhw~~/AAQRrwA~/RgRnpM82PFcDc3BjQgplujZKwmV6WWP_UhpHU1RFRkFOU1NPTkBva2FuYWdhbi5iYy5jYVgEAAAAhw~~ |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 7 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | stream |
Analysis stop reason: | Timeout |
Detection: | CLEAN |
Classification: | clean1.win@14/7@10/114 |
- Exclude process from analysis
(whitelisted): SIHClient.exe - Excluded IPs from analysis (wh
itelisted): 64.233.185.94, 34. 104.35.123, 192.229.211.108 - Excluded domains from analysis
(whitelisted): ocsp.digicert. com, edgedl.me.gvt1.com, slscr .update.microsoft.com, clients ervices.googleapis.com, fe3cr. delivery.mp.microsoft.com - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtOpenFile calls found . - VT rate limit hit for: https:
//unsubscribe.spmta.com/u/vqZb yKMmoimrO2-HtLanhw~~/AAQRrwA~/ RgRnpM82PFcDc3BjQgplujZKwmV6WW P_UhpHU1RFRkFOU1NPTkBva2FuYWdh bi5iYy5jYVgEAAAAhw~~
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2673 |
Entropy (8bit): | 3.9868925120448124 |
Encrypted: | false |
SSDEEP: | |
MD5: | 237D33F17CE95B2882C05DEE9F8CAB01 |
SHA1: | 3BB70902EED86A1C5B5B0A405D58F6B1F44B6B82 |
SHA-256: | D817E61F836853A04094DEBCEE679006BBD9B4B743B11DDB3844175F7848524F |
SHA-512: | DE9BDB378C879D3CB44FF9736A91451E7C2428DB0532EA91D595885AA42570CEF6EDC8C481D0FF2BBFF0D782B154DEC0755EF7FB22098A53F8D521D0067CA603 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2675 |
Entropy (8bit): | 4.001970059132673 |
Encrypted: | false |
SSDEEP: | |
MD5: | 9DE79FBE3EFCADCF96324F5A670A5ADD |
SHA1: | 38F5DF494DB72D06C7BB75FC4A77789239F1B07E |
SHA-256: | 0B3F4D3A1BF2445D5EEEDE1185AB7137728CCAE96FAC11C9F0B022C83A9D551C |
SHA-512: | 31720937C98BD3146A5522EA2D3112F92BF9FF4414B509953E4E235CC6E8785374055829147D843D10DFFFFC4989DEBFB871228532AF9A88B3916273A04BBB18 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2689 |
Entropy (8bit): | 4.010522056855452 |
Encrypted: | false |
SSDEEP: | |
MD5: | 323A07CF8656D88276AE01F5A1FF2DB5 |
SHA1: | A8DAD1386FE45D9076384391BE6EF079A534366D |
SHA-256: | D36556AC4635C2C9CEE2B9789DE3E5C509399AC023E2047390108D64137F56AE |
SHA-512: | 90F76EE784C63C171C390471A806F0203D0BFDDB38CA552352DBE631702C69CE07D15CF28D3535C74C8099AD22A4099624C862984607FF32D2B53B35271AB1B2 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 4.000954267575166 |
Encrypted: | false |
SSDEEP: | |
MD5: | 18B0BEBD3D2965749C29861FE1EDD09E |
SHA1: | 89E1B7AB99553F1DA64021988B47A4D4D230E119 |
SHA-256: | C883BF14427EFB08D436994E687D537379CACAABB75EB21D0D08BD58CB8A4B27 |
SHA-512: | 49B256BDE7F7F139B794C3BF28055D8B017B466C344091DCEBC955C10C2DA75390D2FBB073CD2876AD6095C6F7FB5B7C5B1E2949D73DD46EB39BCAB3F8F97F07 |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.989144237943981 |
Encrypted: | false |
SSDEEP: | |
MD5: | 285635D80BFAF70B3C5746DC997F146F |
SHA1: | 5E40D983A2E0CD4BE0D1794C6C3545B060CFFC8E |
SHA-256: | 74E9C44AA04172FDA67B631573977BC832C3E8CF731654132D47388EF3991AF0 |
SHA-512: | 3D40FF951B517217AB71D6D5384B3896FE952C295EE2B1182BFCF67765DEA489AC36FCD85043088454855CFA263DB42BD5DC3986D972F752C00C3C1E8EBF9B0F |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.9985870795744467 |
Encrypted: | false |
SSDEEP: | |
MD5: | 574E07621DA4F657E131DD630C94EBD9 |
SHA1: | A8912CD8F827E77B25BEABD2D9DCA49E5C1FEC6B |
SHA-256: | A448D007025BC901DE19D89414B1423F3AA686BBBAF0610365770E96B2E49F41 |
SHA-512: | 0D8511EBE56A65117AAFD7C848D7D98CE639F9F95FAC8EC42AB158A0E061960028B52F6AA31619BC61FBB8B81B9FFBA0DF61573CFAF6CCA8669AD5CFF84EFAAE |
Malicious: | false |
Reputation: | unknown |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 255 |
Entropy (8bit): | 5.635248393120001 |
Encrypted: | false |
SSDEEP: | |
MD5: | 9C28B07BB710516F6869AE823F0D5405 |
SHA1: | B1C5DCED288438773B1C1298952B1AB24D145F38 |
SHA-256: | 2FBD12D50BEEB2D262650D85ED076009ADFF3311E58DDF8BE3E8786DCE55222E |
SHA-512: | C63F0DCAFA4377960FD1487B6C664160FAC5F97BABA953DA57FE1808D2DA78BCC26E3AB111241424EE142E3FA8DA019FA5453CF9CEA2B5B70B63330238C90BBF |
Malicious: | false |
Reputation: | unknown |
URL: | https://unsubscribe.spmta.com/u/vqZbyKMmoimrO2-HtLanhw~~/AAQRrwA~/RgRnpM82PFcDc3BjQgplujZKwmV6WWP_UhpHU1RFRkFOU1NPTkBva2FuYWdhbi5iYy5jYVgEAAAAhw~~ |
Preview: |