Windows Analysis Report
Your ebucks R23.999 ready to be redeemed.html

Overview

General Information

Sample name: Your ebucks R23.999 ready to be redeemed.html
Analysis ID: 1468061
MD5: 86abd7013180bc41bd60f7882ee9ddb9
SHA1: 89922cf492b64bf7898f0f2967f27ff4ecc42aeb
SHA256: 242d952a1cbc3373439c8a7595ae8e1a09cdb8338bdcbc4b2742e4e27fddce9d

Detection

Score: 56
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

AI detected phishing page
HTML Script injector detected
HTML file submission containing password form
HTML body contains password input but no form action
HTML title does not match URL
Invalid T&C link found
None HTTPS page querying sensitive user data (password, username or email)
Stores files to the Windows start menu directory

Classification

Phishing

barindex
Source: file:///C:/Users/user/Desktop/Your%20ebucks%20R23.999%20ready%20to%20%20be%20redeemed.html LLM: Score: 9 brands: FNB Reasons: The URL 'file:///C:/Users/user/Desktop/Your%20ebucks%20R23.999%20ready%20to%20%20be%20redeemed.html' is a local file path, which is highly suspicious for a banking site. The page asks for sensitive information such as card number, ATM PIN, CVV, and expiry date, which is a common tactic in phishing attacks. The legitimate domain for FNB (First National Bank) is 'fnb.co.za', and this URL does not match. The presence of a prominent form requesting sensitive information without a CAPTCHA and the use of social engineering techniques to lure users into entering their banking details further indicate that this is a phishing site. DOM: 0.1.pages.csv
Source: file:///C:/Users/user/Desktop/Your%20ebucks%20R23.999%20ready%20to%20%20be%20redeemed.html HTTP Parser: New script, src: https://ajax.googleapis.com/ajax/libs/jquery/1.12.4/jquery.min.js
Source: file:///C:/Users/user/Desktop/Your%20ebucks%20R23.999%20ready%20to%20%20be%20redeemed.html HTTP Parser: New script, src: https://static.revechat.com/widget/d-single-inbox/scripts/jquery/jquery.js?ver=02072024
Source: Your ebucks R23.999 ready to be redeemed.html HTTP Parser: <input type="password" .../> found but no <form action="...
Source: file:///C:/Users/user/Desktop/Your%20ebucks%20R23.999%20ready%20to%20%20be%20redeemed.html HTTP Parser: <input type="password" .../> found but no <form action="...
Source: Your ebucks R23.999 ready to be redeemed.html HTTP Parser: Title: does not match URL
Source: file:///C:/Users/user/Desktop/Your%20ebucks%20R23.999%20ready%20to%20%20be%20redeemed.html HTTP Parser: Title: does not match URL
Source: file:///C:/Users/user/Desktop/Your%20ebucks%20R23.999%20ready%20to%20%20be%20redeemed.html HTTP Parser: Invalid link: Help
Source: file:///C:/Users/user/Desktop/Your%20ebucks%20R23.999%20ready%20to%20%20be%20redeemed.html HTTP Parser: Has password / email / username input fields
Source: Your ebucks R23.999 ready to be redeemed.html HTTP Parser: <input type="password" .../> found
Source: file:///C:/Users/user/Desktop/Your%20ebucks%20R23.999%20ready%20to%20%20be%20redeemed.html HTTP Parser: <input type="password" .../> found
Source: file:///C:/Users/user/Desktop/Your%20ebucks%20R23.999%20ready%20to%20%20be%20redeemed.html HTTP Parser: No favicon
Source: file:///C:/Users/user/Desktop/Your%20ebucks%20R23.999%20ready%20to%20%20be%20redeemed.html HTTP Parser: No favicon
Source: Your ebucks R23.999 ready to be redeemed.html HTTP Parser: No <meta name="author".. found
Source: file:///C:/Users/user/Desktop/Your%20ebucks%20R23.999%20ready%20to%20%20be%20redeemed.html HTTP Parser: No <meta name="author".. found
Source: file:///C:/Users/user/Desktop/Your%20ebucks%20R23.999%20ready%20to%20%20be%20redeemed.html HTTP Parser: No <meta name="author".. found
Source: Your ebucks R23.999 ready to be redeemed.html HTTP Parser: No <meta name="copyright".. found
Source: file:///C:/Users/user/Desktop/Your%20ebucks%20R23.999%20ready%20to%20%20be%20redeemed.html HTTP Parser: No <meta name="copyright".. found
Source: file:///C:/Users/user/Desktop/Your%20ebucks%20R23.999%20ready%20to%20%20be%20redeemed.html HTTP Parser: No <meta name="copyright".. found
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries
Source: unknown HTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.16:56651 version: TLS 1.2
Source: unknown HTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.16:56691 version: TLS 1.2
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET /FNB-FICA-Registration-FNB-Online-Banking-Paid/php/continue0.php?callback=jQuery1124021198781352601892_1720165305817&Username=uursaraew&Password=realpassword%40fuckyou69&_=1720165305818 HTTP/1.1Host: www.tracybentertainment.co.zaConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /FNB-FICA-Registration-FNB-Online-Banking-Paid/php/continue0.php?callback=jQuery112403257204555385165_1720165348407&Username=aarpos&Password=dwiduh23q9oufhd9q3&_=1720165348408 HTTP/1.1Host: www.tracybentertainment.co.zaConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /FNB-FICA-Registration-FNB-Online-Banking-Paid/php/continue1.php?callback=jQuery112406028445757910308_1720165371412&card=5586692334587&pin=2385&cvv=298&expdate-m=05&expdate-y=25&tick=&Username=aarpos&Password=dwiduh23q9oufhd9q3&_=1720165371413 HTTP/1.1Host: www.tracybentertainment.co.zaConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /widget/scripts/new-livechat.js?1720165410914 HTTP/1.1Host: static.revechat.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic DNS traffic detected: DNS query: www.tracybentertainment.co.za
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: global traffic DNS traffic detected: DNS query: www.fnb.co.za
Source: global traffic DNS traffic detected: DNS query: www.online.fnb.co.za
Source: global traffic DNS traffic detected: DNS query: static.revechat.com
Source: global traffic DNS traffic detected: DNS query: unpkg.com
Source: global traffic DNS traffic detected: DNS query: a.nel.cloudflare.com
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56716
Source: unknown Network traffic detected: HTTP traffic on port 56681 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56717
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56719
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56713
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56714
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56715
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56710
Source: unknown Network traffic detected: HTTP traffic on port 56623 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56600 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56732 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56669 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56646 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56617 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56726 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56703 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56743 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56606
Source: unknown Network traffic detected: HTTP traffic on port 56663 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56727
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56607
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56728
Source: unknown Network traffic detected: HTTP traffic on port 56634 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56608
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56729
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56609
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56602
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56723
Source: unknown Network traffic detected: HTTP traffic on port 56737 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56603
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56724
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56604
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56725
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56605
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56726
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56720
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56600
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56721
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56601
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56722
Source: unknown Network traffic detected: HTTP traffic on port 56628 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56652 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56595 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56687 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56635 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56612 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56719 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56617
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56738
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56618
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56739
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56619
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56613
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56614
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56735
Source: unknown Network traffic detected: HTTP traffic on port 56606 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56615
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56736
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56616
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56737
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56730
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56610
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56731
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56611
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56732
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56612
Source: unknown Network traffic detected: HTTP traffic on port 56674 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56740
Source: unknown Network traffic detected: HTTP traffic on port 56651 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56629 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56594 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56720 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56628
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56629
Source: unknown Network traffic detected: HTTP traffic on port 56640 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56657 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56682 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56745
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56625
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56746
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56747
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56627
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56620
Source: unknown Network traffic detected: HTTP traffic on port 56699 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56741
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56621
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56742
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56622
Source: unknown Network traffic detected: HTTP traffic on port 56714 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56743
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56623
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56744
Source: unknown Network traffic detected: HTTP traffic on port 56731 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56601 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56708 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56630
Source: unknown Network traffic detected: HTTP traffic on port 56725 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56668 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56599 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56742 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56685 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56691 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56713 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56736 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56598
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56599
Source: unknown Network traffic detected: HTTP traffic on port 56707 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56653 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56630 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56665 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56659 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56613 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56607 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56747 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56680 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56642 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56676 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56730 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56618 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56702 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56658 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56664 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56641 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56602 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56625 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56619 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56670 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56701 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56724 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56598 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56741 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56709
Source: unknown Network traffic detected: HTTP traffic on port 56686 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56705
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56706
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56707
Source: unknown Network traffic detected: HTTP traffic on port 56636 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56708
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56701
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56702
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56703
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56704
Source: unknown Network traffic detected: HTTP traffic on port 56735 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56700
Source: unknown Network traffic detected: HTTP traffic on port 56647 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56729 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56675 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56717 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56614 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56746 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56608 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56637 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56679
Source: unknown Network traffic detected: HTTP traffic on port 56620 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56675
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56676
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56677
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56678
Source: unknown Network traffic detected: HTTP traffic on port 56672 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56682
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56683
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56684
Source: unknown Network traffic detected: HTTP traffic on port 56695 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56685
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56680
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56681
Source: unknown Network traffic detected: HTTP traffic on port 56684 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56655 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56690 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56603 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56686
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56687
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56689
Source: unknown Network traffic detected: HTTP traffic on port 56706 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56694
Source: unknown Network traffic detected: HTTP traffic on port 56649 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56695
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56690
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56691
Source: unknown Network traffic detected: HTTP traffic on port 56666 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56631 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56723 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56740 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56660 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56677 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56699
Source: unknown Network traffic detected: HTTP traffic on port 56648 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56621 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56728 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56705 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56745 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56632 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56615 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56739 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56609 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56594
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56595
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56596
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56597
Source: unknown Network traffic detected: HTTP traffic on port 56643 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56671 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56700 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56597 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56610 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56639
Source: unknown Network traffic detected: HTTP traffic on port 56633 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56656 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56662 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56635
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56636
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56637
Source: unknown Network traffic detected: HTTP traffic on port 56679 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56604 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56638
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56631
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56632
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56633
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56634
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56640
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56641
Source: unknown Network traffic detected: HTTP traffic on port 56627 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56722 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56596 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56638 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56646
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56647
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56648
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56649
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56642
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56643
Source: unknown Network traffic detected: HTTP traffic on port 56716 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56644
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56645
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56650
Source: unknown Network traffic detected: HTTP traffic on port 56673 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56651
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56652
Source: unknown Network traffic detected: HTTP traffic on port 56694 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56645 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56727 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56683 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56744 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56639 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56657
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56658
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56659
Source: unknown Network traffic detected: HTTP traffic on port 56738 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56653
Source: unknown Network traffic detected: HTTP traffic on port 56715 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56655
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56656
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56660
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56661
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56662
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56663
Source: unknown Network traffic detected: HTTP traffic on port 56644 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56667 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56709 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56611 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56661 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56605 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56668
Source: unknown Network traffic detected: HTTP traffic on port 56678 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56669
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56664
Source: unknown Network traffic detected: HTTP traffic on port 56710 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56665
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56666
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56667
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56671
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56672
Source: unknown Network traffic detected: HTTP traffic on port 56622 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56673
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56674
Source: unknown Network traffic detected: HTTP traffic on port 56650 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 56670
Source: unknown Network traffic detected: HTTP traffic on port 56616 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56689 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56721 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 56704 -> 443
Source: unknown HTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.16:56651 version: TLS 1.2
Source: unknown HTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.16:56691 version: TLS 1.2
Source: classification engine Classification label: mal56.phis.winHTML@14/83@37/156
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Program Files\Google\Chrome\Application\Dictionaries
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument C:\Users\user\Desktop\Your ebucks R23.999 ready to be redeemed.html
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2156 --field-trial-handle=1964,i,14332423150873750023,13879994269796675301,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2156 --field-trial-handle=1964,i,14332423150873750023,13879994269796675301,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk

Stealing of Sensitive Information

barindex
Source: file:///C:/Users/user/Desktop/Your%20ebucks%20R23.999%20ready%20to%20%20be%20redeemed.html HTTP Parser: file:///C:/Users/user/Desktop/Your%20ebucks%20R23.999%20ready%20to%20%20be%20redeemed.html
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs