Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://fastcast.semfs.engsvc.go.com

Overview

General Information

Sample URL:http://fastcast.semfs.engsvc.go.com
Analysis ID:1447249
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:40%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 6092 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5900 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2252 --field-trial-handle=2204,i,12250183010925036643,5262798759032122943,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6424 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://fastcast.semfs.engsvc.go.com" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownTCP traffic detected without corresponding DNS query: 104.46.162.224
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: fastcast.semfs.engsvc.go.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: fastcast.semfs.engsvc.go.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Fri, 24 May 2024 15:28:35 GMTContent-Length: 0Connection: keep-aliveServer: Fastcast/4.1.22
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: classification engineClassification label: unknown0.win@17/0@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2252 --field-trial-handle=2204,i,12250183010925036643,5262798759032122943,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://fastcast.semfs.engsvc.go.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2252 --field-trial-handle=2204,i,12250183010925036643,5262798759032122943,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://fastcast.semfs.engsvc.go.com0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://fastcast.semfs.engsvc.go.com/0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.250.186.68
truefalse
    unknown
    fastcast.semfs.engsvc.go.com
    54.211.172.150
    truefalse
      unknown
      fp2e7a.wpc.phicdn.net
      192.229.221.95
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        http://fastcast.semfs.engsvc.go.com/false
        • Avira URL Cloud: safe
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        142.250.186.68
        www.google.comUnited States
        15169GOOGLEUSfalse
        54.211.172.150
        fastcast.semfs.engsvc.go.comUnited States
        14618AMAZON-AESUSfalse
        239.255.255.250
        unknownReserved
        unknownunknownfalse
        IP
        192.168.2.4
        Joe Sandbox version:40.0.0 Tourmaline
        Analysis ID:1447249
        Start date and time:2024-05-24 17:27:41 +02:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 2m 0s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:http://fastcast.semfs.engsvc.go.com
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:5
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:UNKNOWN
        Classification:unknown0.win@17/0@4/4
        EGA Information:Failed
        HCA Information:
        • Successful, ratio: 100%
        • Number of executed functions: 0
        • Number of non-executed functions: 0
        Cookbook Comments:
        • URL browsing timeout or error
        • URL not reachable
        • Exclude process from analysis (whitelisted): SIHClient.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 216.58.206.35, 142.250.185.174, 74.125.71.84, 34.104.35.123, 104.119.108.127, 52.165.165.26, 93.184.221.240, 192.229.221.95, 13.85.23.206
        • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, clientservices.googleapis.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, wu.azureedge.net, clients2.google.com, ocsp.digicert.com, e16604.g.akamaiedge.net, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net, fs.microsoft.com, accounts.google.com, ctldl.windowsupdate.com.delivery.microsoft.com, wu.ec.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, edgedl.me.gvt1.com, clients.l.google.com
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtSetInformationFile calls found.
        • VT rate limit hit for: http://fastcast.semfs.engsvc.go.com
        No simulations
        No context
        No context
        No context
        No context
        No context
        No created / dropped files found
        No static file info
        TimestampSource PortDest PortSource IPDest IP
        May 24, 2024 17:28:23.938632011 CEST49678443192.168.2.4104.46.162.224
        May 24, 2024 17:28:24.719954014 CEST49675443192.168.2.4173.222.162.32
        May 24, 2024 17:28:34.327433109 CEST49675443192.168.2.4173.222.162.32
        May 24, 2024 17:28:34.727657080 CEST4973580192.168.2.454.211.172.150
        May 24, 2024 17:28:34.727910995 CEST4973680192.168.2.454.211.172.150
        May 24, 2024 17:28:34.747776985 CEST804973554.211.172.150192.168.2.4
        May 24, 2024 17:28:34.747984886 CEST4973580192.168.2.454.211.172.150
        May 24, 2024 17:28:34.748070955 CEST4973580192.168.2.454.211.172.150
        May 24, 2024 17:28:34.752759933 CEST804973654.211.172.150192.168.2.4
        May 24, 2024 17:28:34.752861023 CEST4973680192.168.2.454.211.172.150
        May 24, 2024 17:28:34.757751942 CEST804973554.211.172.150192.168.2.4
        May 24, 2024 17:28:35.230474949 CEST804973554.211.172.150192.168.2.4
        May 24, 2024 17:28:35.279807091 CEST4973580192.168.2.454.211.172.150
        May 24, 2024 17:28:36.583507061 CEST49739443192.168.2.4142.250.186.68
        May 24, 2024 17:28:36.583540916 CEST44349739142.250.186.68192.168.2.4
        May 24, 2024 17:28:36.583600998 CEST49739443192.168.2.4142.250.186.68
        May 24, 2024 17:28:36.584125996 CEST49739443192.168.2.4142.250.186.68
        May 24, 2024 17:28:36.584139109 CEST44349739142.250.186.68192.168.2.4
        May 24, 2024 17:28:37.234982967 CEST44349739142.250.186.68192.168.2.4
        May 24, 2024 17:28:37.235517025 CEST49739443192.168.2.4142.250.186.68
        May 24, 2024 17:28:37.235533953 CEST44349739142.250.186.68192.168.2.4
        May 24, 2024 17:28:37.236948967 CEST44349739142.250.186.68192.168.2.4
        May 24, 2024 17:28:37.237006903 CEST49739443192.168.2.4142.250.186.68
        May 24, 2024 17:28:37.358587980 CEST49739443192.168.2.4142.250.186.68
        May 24, 2024 17:28:37.359031916 CEST44349739142.250.186.68192.168.2.4
        May 24, 2024 17:28:37.405905008 CEST49739443192.168.2.4142.250.186.68
        May 24, 2024 17:28:37.405930996 CEST44349739142.250.186.68192.168.2.4
        May 24, 2024 17:28:37.452789068 CEST49739443192.168.2.4142.250.186.68
        May 24, 2024 17:28:47.137139082 CEST44349739142.250.186.68192.168.2.4
        May 24, 2024 17:28:47.137267113 CEST44349739142.250.186.68192.168.2.4
        May 24, 2024 17:28:47.137378931 CEST49739443192.168.2.4142.250.186.68
        May 24, 2024 17:28:48.812407970 CEST49739443192.168.2.4142.250.186.68
        May 24, 2024 17:28:48.812431097 CEST44349739142.250.186.68192.168.2.4
        TimestampSource PortDest PortSource IPDest IP
        May 24, 2024 17:28:32.274557114 CEST53598271.1.1.1192.168.2.4
        May 24, 2024 17:28:32.475629091 CEST53600891.1.1.1192.168.2.4
        May 24, 2024 17:28:33.510869026 CEST53576821.1.1.1192.168.2.4
        May 24, 2024 17:28:34.688785076 CEST6217853192.168.2.41.1.1.1
        May 24, 2024 17:28:34.689137936 CEST4964353192.168.2.41.1.1.1
        May 24, 2024 17:28:34.717190027 CEST53621781.1.1.1192.168.2.4
        May 24, 2024 17:28:34.742265940 CEST53496431.1.1.1192.168.2.4
        May 24, 2024 17:28:36.567519903 CEST5215653192.168.2.41.1.1.1
        May 24, 2024 17:28:36.567981005 CEST5813253192.168.2.41.1.1.1
        May 24, 2024 17:28:36.574918032 CEST53521561.1.1.1192.168.2.4
        May 24, 2024 17:28:36.582184076 CEST53581321.1.1.1192.168.2.4
        May 24, 2024 17:28:50.568490982 CEST53503801.1.1.1192.168.2.4
        May 24, 2024 17:28:54.465425968 CEST138138192.168.2.4192.168.2.255
        TimestampSource IPDest IPChecksumCodeType
        May 24, 2024 17:28:32.475764036 CEST192.168.2.41.1.1.1c21b(Port unreachable)Destination Unreachable
        May 24, 2024 17:28:34.742470980 CEST192.168.2.41.1.1.1c243(Port unreachable)Destination Unreachable
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        May 24, 2024 17:28:34.688785076 CEST192.168.2.41.1.1.10x334dStandard query (0)fastcast.semfs.engsvc.go.comA (IP address)IN (0x0001)false
        May 24, 2024 17:28:34.689137936 CEST192.168.2.41.1.1.10xa957Standard query (0)fastcast.semfs.engsvc.go.com65IN (0x0001)false
        May 24, 2024 17:28:36.567519903 CEST192.168.2.41.1.1.10x57d9Standard query (0)www.google.comA (IP address)IN (0x0001)false
        May 24, 2024 17:28:36.567981005 CEST192.168.2.41.1.1.10x4414Standard query (0)www.google.com65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        May 24, 2024 17:28:34.717190027 CEST1.1.1.1192.168.2.40x334dNo error (0)fastcast.semfs.engsvc.go.com54.211.172.150A (IP address)IN (0x0001)false
        May 24, 2024 17:28:34.717190027 CEST1.1.1.1192.168.2.40x334dNo error (0)fastcast.semfs.engsvc.go.com52.4.231.149A (IP address)IN (0x0001)false
        May 24, 2024 17:28:34.717190027 CEST1.1.1.1192.168.2.40x334dNo error (0)fastcast.semfs.engsvc.go.com34.194.246.209A (IP address)IN (0x0001)false
        May 24, 2024 17:28:36.574918032 CEST1.1.1.1192.168.2.40x57d9No error (0)www.google.com142.250.186.68A (IP address)IN (0x0001)false
        May 24, 2024 17:28:36.582184076 CEST1.1.1.1192.168.2.40x4414No error (0)www.google.com65IN (0x0001)false
        May 24, 2024 17:28:48.380166054 CEST1.1.1.1192.168.2.40xccb6No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        May 24, 2024 17:28:48.380166054 CEST1.1.1.1192.168.2.40xccb6No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
        • fastcast.semfs.engsvc.go.com
        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.44973554.211.172.150805900C:\Program Files\Google\Chrome\Application\chrome.exe
        TimestampBytes transferredDirectionData
        May 24, 2024 17:28:34.748070955 CEST443OUTGET / HTTP/1.1
        Host: fastcast.semfs.engsvc.go.com
        Connection: keep-alive
        Upgrade-Insecure-Requests: 1
        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
        Accept-Encoding: gzip, deflate
        Accept-Language: en-US,en;q=0.9
        May 24, 2024 17:28:35.230474949 CEST131INHTTP/1.1 404 Not Found
        Date: Fri, 24 May 2024 15:28:35 GMT
        Content-Length: 0
        Connection: keep-alive
        Server: Fastcast/4.1.22


        Click to jump to process

        Click to jump to process

        Click to jump to process

        Target ID:0
        Start time:11:28:26
        Start date:24/05/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:2
        Start time:11:28:30
        Start date:24/05/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2252 --field-trial-handle=2204,i,12250183010925036643,5262798759032122943,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:3
        Start time:11:28:33
        Start date:24/05/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://fastcast.semfs.engsvc.go.com"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true

        No disassembly