Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://www.splendidcare.sa.com/Juwqdh/xacwk5957irfeugd/FW2HGOqFbIVQssWaWxsuPFbxoA78Qv8umKJQmKBGMM0/enpkwYwNDdxjXCgjy64rbJkHYw5eTv2C-VSAAV3Fufzkb2cfb573zE5R9OTtHCML20yl9BXVgVz_5eGAS31RGQ

Overview

General Information

Sample URL:http://www.splendidcare.sa.com/Juwqdh/xacwk5957irfeugd/FW2HGOqFbIVQssWaWxsuPFbxoA78Qv8umKJQmKBGMM0/enpkwYwNDdxjXCgjy64rbJkHYw5eTv2C-VSAAV3Fufzkb2cfb573zE5R9OTtHCML20yl9BXVgVz_5eGAS31RGQ
Analysis ID:1466700
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

AI detected phishing page
HTML body with high number of embedded images detected
HTML page contains hidden URLs or javascript code
Program does not show much activity (idle)

Classification

  • System is w10x64native
  • chrome.exe (PID: 8024 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 464953824E644F10FFDC9E093FD18F94)
    • chrome.exe (PID: 5164 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1700,18058039625578469226,10548155103771464637,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2028 /prefetch:8 MD5: 464953824E644F10FFDC9E093FD18F94)
    • chrome.exe (PID: 3000 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --field-trial-handle=1700,18058039625578469226,10548155103771464637,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=7116 /prefetch:8 MD5: 464953824E644F10FFDC9E093FD18F94)
  • chrome.exe (PID: 2248 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.splendidcare.sa.com/Juwqdh/xacwk5957irfeugd/FW2HGOqFbIVQssWaWxsuPFbxoA78Qv8umKJQmKBGMM0/enpkwYwNDdxjXCgjy64rbJkHYw5eTv2C-VSAAV3Fufzkb2cfb573zE5R9OTtHCML20yl9BXVgVz_5eGAS31RGQ" MD5: 464953824E644F10FFDC9E093FD18F94)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

Phishing

barindex
Source: http://www.splendidcare.sa.comLLM: Score: 8 brands: Reasons: The URL 'http://www.splendidcare.sa.com' is suspicious because it uses a subdomain structure that is often associated with phishing sites. The image shows a 'Human Verification Check' page, which is a common social engineering technique used to mislead users into thinking they need to verify their identity. This type of page is often used to redirect users to malicious sites. The presence of a 'Skip Verification and Enter Website Now' button is another red flag, as it encourages users to bypass the verification process, which can lead to phishing attacks. There is no clear indication of a legitimate brand associated with this site, and the domain does not match any known legitimate domains. Therefore, based on these observations, the site is likely a phishing site. DOM: 0.3.pages.csv
Source: http://www.splendidcare.sa.comLLM: Score: 8 brands: Reasons: The URL 'http://www.splendidcare.sa.com' is suspicious because it uses a subdomain structure that is often associated with phishing sites. The image shows a 'Human Verification Check' page, which is a common social engineering technique used to mislead users into thinking they need to verify their identity. This is often used to redirect users to malicious sites. The presence of a 'Skip Verification and Enter Website Now' button is another red flag, as it encourages users to click on a potentially harmful link. There is no prominent login form or CAPTCHA, but the use of social engineering techniques and the suspicious domain strongly suggest that this is a phishing site. DOM: 0.4.pages.csv
Source: https://gotropislim.com/HTTP Parser: Total embedded image size: 16168
Source: https://gotropislim.com/#heroHTTP Parser: Total embedded image size: 16168
Source: http://www.splendidcare.sa.com/clicks/bpage/topslim.php?sid=1035569&h=FW2HGOqFbIVQssWaWxsuPFbxoA78Qv8umKJQmKBGMM0/enpkwYwNDdxjXCgjy64rbJkHYw5eTv2C-VSAAV3Fufzkb2cfb573zE5R9OTtHCML20yl9BXVgVz_5eGAS31RGQHTTP Parser: Base64 decoded: http://www.splendidcare.sa.com/clicks/bpage/topslim.php?sid=1035569&h=FW2HGOqFbIVQssWaWxsuPFbxoA78Qv8umKJQmKBGMM0/enpkwYwNDdxjXCgjy64rbJkHYw5eTv2C-VSAAV3Fufzkb2cfb573zE5R9OTtHCML20yl9BXVgVz_5eGAS31RGQ
Source: http://www.splendidcare.sa.com/clicks/bpage/topslim.php?sid=1035569&h=FW2HGOqFbIVQssWaWxsuPFbxoA78Qv8umKJQmKBGMM0/enpkwYwNDdxjXCgjy64rbJkHYw5eTv2C-VSAAV3Fufzkb2cfb573zE5R9OTtHCML20yl9BXVgVz_5eGAS31RGQHTTP Parser: No favicon
Source: http://www.splendidcare.sa.com/clicks/bpage/topslim.php?sid=1035569&h=FW2HGOqFbIVQssWaWxsuPFbxoA78Qv8umKJQmKBGMM0/enpkwYwNDdxjXCgjy64rbJkHYw5eTv2C-VSAAV3Fufzkb2cfb573zE5R9OTtHCML20yl9BXVgVz_5eGAS31RGQHTTP Parser: No favicon
Source: http://www.splendidcare.sa.com/clicks/bpage/topslim.php?sid=1035569&h=FW2HGOqFbIVQssWaWxsuPFbxoA78Qv8umKJQmKBGMM0/enpkwYwNDdxjXCgjy64rbJkHYw5eTv2C-VSAAV3Fufzkb2cfb573zE5R9OTtHCML20yl9BXVgVz_5eGAS31RGQHTTP Parser: No favicon
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/uf02t/0x4AAAAAAADnOjc0PNeA8qVm/light/normalHTTP Parser: No favicon
Source: http://www.splendidcare.sa.com/clicks/bpage/topslim.php?sid=1035569&h=FW2HGOqFbIVQssWaWxsuPFbxoA78Qv8umKJQmKBGMM0/enpkwYwNDdxjXCgjy64rbJkHYw5eTv2C-VSAAV3Fufzkb2cfb573zE5R9OTtHCML20yl9BXVgVz_5eGAS31RGQ&__cf_chl_tk=Qo3onJpX2NN9iqTg6AK3IKQV7zteuSapwy7jedCnmwA-1719993703-0.0.1.1-2537HTTP Parser: No favicon
Source: https://player.vimeo.com/video/864134318?h=e3208bb7c4&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0HTTP Parser: No favicon
Source: https://player.vimeo.com/video/864134318?h=e3208bb7c4&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0HTTP Parser: No favicon
Source: https://player.vimeo.com/video/864134318?h=e3208bb7c4&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0HTTP Parser: No favicon
Source: https://player.vimeo.com/video/864134318?h=e3208bb7c4&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0HTTP Parser: No favicon
Source: https://player.vimeo.com/video/864134318?h=e3208bb7c4&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0HTTP Parser: No favicon
Source: https://player.vimeo.com/video/864134318?h=e3208bb7c4&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0HTTP Parser: No favicon
Source: https://player.vimeo.com/video/864134318?h=e3208bb7c4&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0HTTP Parser: No favicon
Source: https://player.vimeo.com/video/864134318?h=e3208bb7c4&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0HTTP Parser: No favicon
Source: https://player.vimeo.com/video/864134318?h=e3208bb7c4&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0HTTP Parser: No favicon
Source: https://player.vimeo.com/video/864351157?h=75b1f32070&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0HTTP Parser: No favicon
Source: https://player.vimeo.com/video/864351157?h=75b1f32070&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0HTTP Parser: No favicon
Source: https://player.vimeo.com/video/864351157?h=75b1f32070&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0HTTP Parser: No favicon
Source: https://player.vimeo.com/video/864351157?h=75b1f32070&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0HTTP Parser: No favicon
Source: https://player.vimeo.com/video/864351157?h=75b1f32070&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0HTTP Parser: No favicon
Source: https://player.vimeo.com/video/864351157?h=75b1f32070&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0HTTP Parser: No favicon
Source: https://player.vimeo.com/video/864351157?h=75b1f32070&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0HTTP Parser: No favicon
Source: https://player.vimeo.com/video/864351157?h=75b1f32070&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0HTTP Parser: No favicon
Source: https://player.vimeo.com/video/864351157?h=75b1f32070&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0HTTP Parser: No favicon
Source: https://player.vimeo.com/video/864351157?h=75b1f32070&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0HTTP Parser: No favicon
Source: https://widget.trustpilot.com/trustboxes/53aa8807dec7e10d38f59f32/index.html?templateId=53aa8807dec7e10d38f59f32&businessunitId=58d40fc70000ff00059f1303#locale=en-US&styleHeight=130px&styleWidth=100%25&theme=lightHTTP Parser: No favicon
Source: https://widget.trustpilot.com/trustboxes/53aa8807dec7e10d38f59f32/index.html?templateId=53aa8807dec7e10d38f59f32&businessunitId=58d40fc70000ff00059f1303#locale=en-US&styleHeight=130px&styleWidth=100%25&theme=lightHTTP Parser: No favicon
Source: classification engineClassification label: mal48.phis.win@38/0@0/39
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1700,18058039625578469226,10548155103771464637,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2028 /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.splendidcare.sa.com/Juwqdh/xacwk5957irfeugd/FW2HGOqFbIVQssWaWxsuPFbxoA78Qv8umKJQmKBGMM0/enpkwYwNDdxjXCgjy64rbJkHYw5eTv2C-VSAAV3Fufzkb2cfb573zE5R9OTtHCML20yl9BXVgVz_5eGAS31RGQ"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --field-trial-handle=1700,18058039625578469226,10548155103771464637,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=7116 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1700,18058039625578469226,10548155103771464637,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2028 /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --field-trial-handle=1700,18058039625578469226,10548155103771464637,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=7116 /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1466700 URL: http://www.splendidcare.sa.... Startdate: 03/07/2024 Architecture: WINDOWS Score: 48 26 AI detected phishing page 2->26 6 chrome.exe 2->6         started        9 chrome.exe 2->9         started        process3 dnsIp4 16 192.168.11.20 unknown unknown 6->16 18 239.255.255.250 unknown Reserved 6->18 11 chrome.exe 6->11         started        14 chrome.exe 6->14         started        process5 dnsIp6 20 31.25.12.17 TEQGB United Kingdom 11->20 22 31.25.12.21 TEQGB United Kingdom 11->22 24 35 other IPs or domains 11->24

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://www.splendidcare.sa.com/Juwqdh/xacwk5957irfeugd/FW2HGOqFbIVQssWaWxsuPFbxoA78Qv8umKJQmKBGMM0/enpkwYwNDdxjXCgjy64rbJkHYw5eTv2C-VSAAV3Fufzkb2cfb573zE5R9OTtHCML20yl9BXVgVz_5eGAS31RGQ3%VirustotalBrowse
http://www.splendidcare.sa.com/Juwqdh/xacwk5957irfeugd/FW2HGOqFbIVQssWaWxsuPFbxoA78Qv8umKJQmKBGMM0/enpkwYwNDdxjXCgjy64rbJkHYw5eTv2C-VSAAV3Fufzkb2cfb573zE5R9OTtHCML20yl9BXVgVz_5eGAS31RGQ0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
NameMaliciousAntivirus DetectionReputation
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/uf02t/0x4AAAAAAADnOjc0PNeA8qVm/light/normalfalse
    unknown
    https://gotropislim.com/#herofalse
      unknown
      https://widget.trustpilot.com/trustboxes/53aa8807dec7e10d38f59f32/index.html?templateId=53aa8807dec7e10d38f59f32&businessunitId=58d40fc70000ff00059f1303#locale=en-US&styleHeight=130px&styleWidth=100%25&theme=lightfalse
        unknown
        http://www.splendidcare.sa.com/clicks/bpage/topslim.php?sid=1035569&h=FW2HGOqFbIVQssWaWxsuPFbxoA78Qv8umKJQmKBGMM0/enpkwYwNDdxjXCgjy64rbJkHYw5eTv2C-VSAAV3Fufzkb2cfb573zE5R9OTtHCML20yl9BXVgVz_5eGAS31RGQtrue
          unknown
          https://player.vimeo.com/video/864351157?h=75b1f32070&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0false
            unknown
            https://app.campaignrefinery.com/unsubscribe?c=5b3fb967-1467-4f75-a434-25b537201ad8&b=54d49514-f843-4e2e-94e5-8be2d989695e&f=3d8d1c90-1d43-4590-8dd4-f4a952d057ccfalse
              unknown
              https://www.digistore24.com/false
                unknown
                https://gotropislim.com/false
                  unknown
                  https://player.vimeo.com/video/864134318?h=e3208bb7c4&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0false
                    unknown
                    http://www.splendidcare.sa.com/clicks/bpage/topslim.php?sid=1035569&h=FW2HGOqFbIVQssWaWxsuPFbxoA78Qv8umKJQmKBGMM0/enpkwYwNDdxjXCgjy64rbJkHYw5eTv2C-VSAAV3Fufzkb2cfb573zE5R9OTtHCML20yl9BXVgVz_5eGAS31RGQ&__cf_chl_tk=Qo3onJpX2NN9iqTg6AK3IKQV7zteuSapwy7jedCnmwA-1719993703-0.0.1.1-2537true
                      unknown
                      • No. of IPs < 25%
                      • 25% < No. of IPs < 50%
                      • 50% < No. of IPs < 75%
                      • 75% < No. of IPs
                      IPDomainCountryFlagASNASN NameMalicious
                      34.110.180.34
                      unknownUnited States
                      15169GOOGLEUSfalse
                      34.107.117.83
                      unknownUnited States
                      15169GOOGLEUSfalse
                      157.240.249.35
                      unknownUnited States
                      32934FACEBOOKUSfalse
                      54.230.18.36
                      unknownUnited States
                      16509AMAZON-02USfalse
                      142.250.111.84
                      unknownUnited States
                      15169GOOGLEUSfalse
                      142.250.191.238
                      unknownUnited States
                      15169GOOGLEUSfalse
                      142.251.165.154
                      unknownUnited States
                      15169GOOGLEUSfalse
                      52.84.18.58
                      unknownUnited States
                      16509AMAZON-02USfalse
                      31.25.12.21
                      unknownUnited Kingdom
                      56367TEQGBfalse
                      35.244.212.226
                      unknownUnited States
                      15169GOOGLEUSfalse
                      142.250.190.66
                      unknownUnited States
                      15169GOOGLEUSfalse
                      172.67.154.9
                      unknownUnited States
                      13335CLOUDFLARENETUSfalse
                      54.225.7.157
                      unknownUnited States
                      14618AMAZON-AESUSfalse
                      35.190.80.1
                      unknownUnited States
                      15169GOOGLEUSfalse
                      162.247.243.39
                      unknownUnited States
                      13335CLOUDFLARENETUSfalse
                      31.25.12.17
                      unknownUnited Kingdom
                      56367TEQGBfalse
                      104.17.24.14
                      unknownUnited States
                      13335CLOUDFLARENETUSfalse
                      142.250.190.35
                      unknownUnited States
                      15169GOOGLEUSfalse
                      142.250.191.227
                      unknownUnited States
                      15169GOOGLEUSfalse
                      34.120.202.204
                      unknownUnited States
                      15169GOOGLEUSfalse
                      151.101.192.217
                      unknownUnited States
                      54113FASTLYUSfalse
                      216.239.32.181
                      unknownUnited States
                      15169GOOGLEUSfalse
                      157.240.249.8
                      unknownUnited States
                      32934FACEBOOKUSfalse
                      146.75.82.109
                      unknownSweden
                      30051SCCGOVUSfalse
                      23.33.29.89
                      unknownUnited States
                      13367COMCAST-13367USfalse
                      23.33.29.83
                      unknownUnited States
                      13367COMCAST-13367USfalse
                      239.255.255.250
                      unknownReserved
                      unknownunknownfalse
                      104.21.44.135
                      unknownUnited States
                      13335CLOUDFLARENETUSfalse
                      31.25.12.51
                      unknownUnited Kingdom
                      56367TEQGBfalse
                      162.159.128.61
                      unknownUnited States
                      13335CLOUDFLARENETUSfalse
                      162.247.243.29
                      unknownUnited States
                      13335CLOUDFLARENETUSfalse
                      142.250.190.106
                      unknownUnited States
                      15169GOOGLEUSfalse
                      52.85.247.89
                      unknownUnited States
                      16509AMAZON-02USfalse
                      104.17.2.184
                      unknownUnited States
                      13335CLOUDFLARENETUSfalse
                      172.217.2.40
                      unknownUnited States
                      15169GOOGLEUSfalse
                      142.250.191.164
                      unknownUnited States
                      15169GOOGLEUSfalse
                      172.217.4.206
                      unknownUnited States
                      15169GOOGLEUSfalse
                      142.250.191.163
                      unknownUnited States
                      15169GOOGLEUSfalse
                      IP
                      192.168.11.20
                      Joe Sandbox version:40.0.0 Tourmaline
                      Analysis ID:1466700
                      Start date and time:2024-07-03 09:59:37 +02:00
                      Joe Sandbox product:CloudBasic
                      Overall analysis duration:0h 4m 56s
                      Hypervisor based Inspection enabled:false
                      Report type:full
                      Cookbook file name:browseurl.jbs
                      Sample URL:http://www.splendidcare.sa.com/Juwqdh/xacwk5957irfeugd/FW2HGOqFbIVQssWaWxsuPFbxoA78Qv8umKJQmKBGMM0/enpkwYwNDdxjXCgjy64rbJkHYw5eTv2C-VSAAV3Fufzkb2cfb573zE5R9OTtHCML20yl9BXVgVz_5eGAS31RGQ
                      Analysis system description:Windows 10 64 bit 20H2 Native physical Machine for testing VM-aware malware (Office 2019, Chrome 93, Firefox 91, Adobe Reader DC 21, Java 8 Update 301
                      Number of analysed new started processes analysed:8
                      Number of new started drivers analysed:0
                      Number of existing processes analysed:0
                      Number of existing drivers analysed:0
                      Number of injected processes analysed:0
                      Technologies:
                      • HCA enabled
                      • EGA enabled
                      • AMSI enabled
                      Analysis Mode:default
                      Analysis stop reason:Timeout
                      Detection:MAL
                      Classification:mal48.phis.win@38/0@0/39
                      EGA Information:Failed
                      HCA Information:
                      • Successful, ratio: 100%
                      • Number of executed functions: 0
                      • Number of non-executed functions: 0
                      Cookbook Comments:
                      • Browse: https://gotropislim.com/?aff=crazycashliorry&cam=1035569#hero
                      • Browse: http://email.r1.ignitedrops.com/c/eJxMj0lu3DAQRU9D7dggi8VpoUXiRh8gFwjIqmJbgFtSKCmAbx_0gNjb_96vgTqXvYwq_lQA--cqCkC5Hwqg9qUwlW2_J_D2Pfk98VPzMQd8wkK0HPMXsibaV4-WeS_0hQKY4J01T7rJn0Nmkv_4se9Vlb_ybeaLxPPAY0uhhjDIaEOyGSMmN7yPDSRzpuo5s0WDPqO3IVJhrBZNGaYRDDiDNoNzybgTs2k1hUDeS2UShabb03Sdp124L-t2ouU2fIzv-75ujxsuCi5lXU9UbmuZrnOXNs3SP--igssxb0fdqE9VlLuQcmdfXas5RG0xRI0tel3QoQZfvYtgbOGkINS7iozZW9QtodMoIDqjeJ2qAOeUQ_aiIDTlzo4TW8pGW76rPhudmFE3LNkDGx-Jhj6uyzGzdIsKzfVWpo_HP_v49utfAAAA___MtI4-?aff=crazycashliorry&cam=1035569
                      • Browse: https://www.digistore24.com/
                      • Exclude process from analysis (whitelisted): dllhost.exe, CompPkgSrv.exe, TextInputHost.exe, svchost.exe
                      • Not all processes where analyzed, report is missing behavior information
                      • Skipping network analysis since amount of network traffic is too extensive
                      No simulations
                      InputOutput
                      URL: http://www.splendidcare.sa.com/clicks/bpage/topslim.php?sid=1035569&h=FW2HGOqFbIVQssWaWxsuPFbxoA78Qv8umKJQmKBGMM0/enpkwYwNDdxjXCgjy64rbJkHYw5eTv2C-VSAAV3Fufzkb2cfb573zE5R9OTtHCML20yl9BXVgVz_5eGAS31RGQ Model: Perplexity: mixtral-8x7b-instruct
                      {"loginform": false,"urgency": true,"captcha": false,"reasons": ["The text 'Check You will Be Auto Redirect To The Website in 5 Seconds Skip Verification and Enter Website Now' creates a sense of urgency as it suggests immediate redirection to the website.","There is no explicit mention of sensitive information request in the text or title.","No CAPTCHA or anti-robot detection mechanism was found in the text or title."]}
                      Title: Human Verification OCR: Human Verification Check You will Be Auto Redirect To The Website in 5 Seconds Skip Verification and Enter Website Now 
                      URL: http://www.splendidcare.sa.com/clicks/bpage/topslim.php?sid=1035569&h=FW2HGOqFbIVQssWaWxsuPFbxoA78Qv8umKJQmKBGMM0/enpkwYwNDdxjXCgjy64rbJkHYw5eTv2C-VSAAV3Fufzkb2cfb573zE5R9OTtHCML20yl9BXVgVz_5eGAS31RGQ Model: Perplexity: mixtral-8x7b-instruct
                      {"loginform": false,"urgency": true,"captcha": false,"reasons": ["The text 'Check You will Be Auto Redirect To The Website in Seconds Skip Verification and Enter Website Now' creates a sense of urgency as it suggests that the user should skip the verification process and enter the website quickly.","There is no mention of any form of login form in the given text or title.","There is no CAPTCHA or any other anti-robot detection mechanism mentioned in the given text or title."]}
                      Title: Human Verification OCR: Human Verification Check You will Be Auto Redirect To The Website in Seconds Skip Verification and Enter Website Now 
                      URL: http://www.splendidcare.sa.com Model: gpt-4o
                      ```json{  "phishing_score": 8,  "brands": null,  "phishing": true,  "suspicious_domain": true,  "has_prominent_loginform": false,  "has_captcha": false,  "setechniques": true,  "has_suspicious_link": true,  "legitmate_domain": "unknown",  "reasons": "The URL 'http://www.splendidcare.sa.com' is suspicious because it uses a subdomain structure that is often associated with phishing sites. The image shows a 'Human Verification Check' page, which is a common social engineering technique used to mislead users into thinking they need to verify their identity. This type of page is often used to redirect users to malicious sites. The presence of a 'Skip Verification and Enter Website Now' button is another red flag, as it encourages users to bypass the verification process, which can lead to phishing attacks. There is no clear indication of a legitimate brand associated with this site, and the domain does not match any known legitimate domains. Therefore, based on these observations, the site is likely a phishing site."}
                      URL: http://www.splendidcare.sa.com Model: gpt-4o
                      ```json{  "phishing_score": 8,  "brands": null,  "phishing": true,  "suspicious_domain": true,  "has_prominent_loginform": false,  "has_captcha": false,  "setechniques": true,  "has_suspicious_link": true,  "legitmate_domain": "unknown",  "reasons": "The URL 'http://www.splendidcare.sa.com' is suspicious because it uses a subdomain structure that is often associated with phishing sites. The image shows a 'Human Verification Check' page, which is a common social engineering technique used to mislead users into thinking they need to verify their identity. This is often used to redirect users to malicious sites. The presence of a 'Skip Verification and Enter Website Now' button is another red flag, as it encourages users to click on a potentially harmful link. There is no prominent login form or CAPTCHA, but the use of social engineering techniques and the suspicious domain strongly suggest that this is a phishing site."}
                      URL: https://gotropislim.com/ Model: Perplexity: mixtral-8x7b-instruct
                      {"loginform": false,"urgency": false,"captcha": false,"reasons": ["The webpage does not contain a login form, as there is no explicit request for sensitive information such as passwords, email addresses, usernames, phone numbers, or credit card numbers.","The text of the webpage does not create a sense of urgency, as it does not contain phrases such as 'click here to view document', 'to view secured document click here', or 'submit your findings here'.","The webpage does not contain a CAPTCHA or any other anti-robot detection mechanism."]}
                      Title: Caribbean Flush Dissolves Fat While You Sleep OCR: Dissolves Fat While You Sleep 4) TAP FOR SOUND Scientific References WomenMIealth HARVARD Journa10fObesity JOHNS HOPKINS MEDICAL SCHOOL SCHOOL of MEDICINE 
                      No context
                      No context
                      No context
                      No context
                      No context
                      No created / dropped files found
                      No static file info
                      Skipped network analysis since the amount of network traffic is too extensive. Please download the PCAP and check manually.

                      Click to jump to process

                      Click to jump to process

                      Click to jump to process

                      Target ID:0
                      Start time:04:01:39
                      Start date:03/07/2024
                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                      Imagebase:0x7ff765320000
                      File size:2'509'656 bytes
                      MD5 hash:464953824E644F10FFDC9E093FD18F94
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:low
                      Has exited:false

                      Target ID:1
                      Start time:04:01:39
                      Start date:03/07/2024
                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1700,18058039625578469226,10548155103771464637,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2028 /prefetch:8
                      Imagebase:0x7ff765320000
                      File size:2'509'656 bytes
                      MD5 hash:464953824E644F10FFDC9E093FD18F94
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:low
                      Has exited:false

                      Target ID:4
                      Start time:04:01:41
                      Start date:03/07/2024
                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.splendidcare.sa.com/Juwqdh/xacwk5957irfeugd/FW2HGOqFbIVQssWaWxsuPFbxoA78Qv8umKJQmKBGMM0/enpkwYwNDdxjXCgjy64rbJkHYw5eTv2C-VSAAV3Fufzkb2cfb573zE5R9OTtHCML20yl9BXVgVz_5eGAS31RGQ"
                      Imagebase:0x7ff765320000
                      File size:2'509'656 bytes
                      MD5 hash:464953824E644F10FFDC9E093FD18F94
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:C, C++ or other language
                      Reputation:low
                      Has exited:true

                      Target ID:6
                      Start time:04:02:01
                      Start date:03/07/2024
                      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --field-trial-handle=1700,18058039625578469226,10548155103771464637,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=7116 /prefetch:8
                      Imagebase:0x7ff765320000
                      File size:2'509'656 bytes
                      MD5 hash:464953824E644F10FFDC9E093FD18F94
                      Has elevated privileges:false
                      Has administrator privileges:false
                      Programmed in:C, C++ or other language
                      Reputation:low
                      Has exited:false

                      No disassembly