Windows Analysis Report
https://italake.com/core/?requisites=JeQwvqpcjZC2JK1wvq5DjSasyqC0jKkrkO5hv20

Overview

General Information

Sample URL: https://italake.com/core/?requisites=JeQwvqpcjZC2JK1wvq5DjSasyqC0jKkrkO5hv20
Analysis ID: 1466965

Detection

Score: 21
Range: 0 - 100
Whitelisted: false
Confidence: 80%

Signatures

Phishing site detected (based on shot match)
Detected non-DNS traffic on DNS port
HTML page contains hidden URLs or javascript code
Stores files to the Windows start menu directory

Classification

Phishing

barindex
Source: https://italake.com/core/machine?requisites=JeQwvqpcjZC2JK1wvq5DjSasyqC0jKkrkO5hv20 Matcher: Template: captcha matched
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/goght/0x4AAAAAAAb5PoV5PCK_H5Jt/auto/normal Matcher: Template: captcha matched
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/fy1hw/0x4AAAAAAAb4A0WSCv_WVh9i/auto/normal HTTP Parser: Base64 decoded: http://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/fy1hw/0x4AAAAAAAb4A0WSCv_WVh9i/auto/normal
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/fy1hw/0x4AAAAAAAb4A0WSCv_WVh9i/auto/normal HTTP Parser: No favicon
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/fy1hw/0x4AAAAAAAb4A0WSCv_WVh9i/auto/normal HTTP Parser: No favicon
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/goght/0x4AAAAAAAb5PoV5PCK_H5Jt/auto/normal HTTP Parser: No favicon
Source: https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/goght/0x4AAAAAAAb5PoV5PCK_H5Jt/auto/normal HTTP Parser: No favicon
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.18:63096 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.127.169.103:443 -> 192.168.2.18:63097 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.18:63098 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.127.169.103:443 -> 192.168.2.18:59988 version: TLS 1.2
Source: global traffic TCP traffic: 192.168.2.18:63077 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.18:63077 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.18:63077 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.18:59986 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.18:63077 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.18:59986 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.18:63077 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.18:59986 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.18:63077 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.18:59986 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.18:63077 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.18:59986 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.18:63077 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.18:59986 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.18:63077 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.18:59986 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.18:63077 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.18:59986 -> 162.159.36.2:53
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknown TCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknown TCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknown TCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknown TCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknown TCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknown TCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknown TCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknown TCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknown TCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknown TCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknown TCP traffic detected without corresponding DNS query: 40.127.169.103
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: global traffic DNS traffic detected: DNS query: italake.com
Source: global traffic DNS traffic detected: DNS query: challenges.cloudflare.com
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: global traffic DNS traffic detected: DNS query: s2.googleusercontent.com
Source: unknown Network traffic detected: HTTP traffic on port 49708 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49700
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63092
Source: unknown Network traffic detected: HTTP traffic on port 63107 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63091
Source: unknown Network traffic detected: HTTP traffic on port 49699 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63094
Source: unknown Network traffic detected: HTTP traffic on port 63098 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63093
Source: unknown Network traffic detected: HTTP traffic on port 63094 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63096
Source: unknown Network traffic detected: HTTP traffic on port 59993 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63095
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63098
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63097
Source: unknown Network traffic detected: HTTP traffic on port 49704 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63103 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63090
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 59988
Source: unknown Network traffic detected: HTTP traffic on port 63085 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 59994
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 59993
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 59990
Source: unknown Network traffic detected: HTTP traffic on port 63081 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49701 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 59992
Source: unknown Network traffic detected: HTTP traffic on port 59990 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63088
Source: unknown Network traffic detected: HTTP traffic on port 63112 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63097 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49699
Source: unknown Network traffic detected: HTTP traffic on port 59994 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49707 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63093 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49679 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63100 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63104 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63108 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49700 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63082 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63079 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63099
Source: unknown Network traffic detected: HTTP traffic on port 63111 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63096 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63105 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49706 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63092 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63101 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63109 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63108
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63107
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63109
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63100
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63102
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63101
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63104
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63103
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63106
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63105
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63081
Source: unknown Network traffic detected: HTTP traffic on port 49709 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63106 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63082
Source: unknown Network traffic detected: HTTP traffic on port 63099 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49673 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63110 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63085
Source: unknown Network traffic detected: HTTP traffic on port 63095 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 59992 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63091 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63102 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 59988 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63088 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63090 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49709
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49708
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63111
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49707
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63110
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49706
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63079
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63112
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49704
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49701
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.18:63096 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.127.169.103:443 -> 192.168.2.18:63097 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.18:63098 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.127.169.103:443 -> 192.168.2.18:59988 version: TLS 1.2
Source: classification engine Classification label: sus21.phis.win@22/15@16/125
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://italake.com/core/?requisites=JeQwvqpcjZC2JK1wvq5DjSasyqC0jKkrkO5hv20
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2216 --field-trial-handle=1980,i,888476322353100917,7841454618462719768,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2216 --field-trial-handle=1980,i,888476322353100917,7841454618462719768,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs