Edit tour
Windows
Analysis Report
http://links.notification.intuit.com/ls/click?upn=u001.Hu9nToJLxsJSQR8ZHWn8Ib7JikYF6PNXv5VK-2BAfeSpVHPRNy-2BFDtJ-2BhNUfKXTverofrKjvXVKH4ba5KbTX-2BS4aEATQ-2BdvHNjDcf3OmBO8OltXq6TPtCFVmMtf59VCEIhWP8mKN6H4HEXLgTiVOzMGungkdodFG1U68jQcrrNridBgnLDNNcks2Eu-2FQvYhEtX4HXrZ9v6fUa-2BRIi5AQ-2BwD5vS6MnLYVP87GGyb
Overview
General Information
Detection
Score: | 56 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Blob-based file download detected
Found HTTP page in a blob
HTML page contains suspicious base64 encoded javascript
Very long command line found
Detected non-DNS traffic on DNS port
Found iframes
HTML body contains low number of good links
HTML body contains password input but no form action
HTML page contains hidden javascript code
HTML title does not match URL
Classification
- System is w10x64
- chrome.exe (PID: 5580 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 5672 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2280 --fi eld-trial- handle=196 8,i,471016 1793563401 793,723523 3090458664 314,262144 --disable -features= Optimizati onGuideMod elDownload ing,Optimi zationHint s,Optimiza tionHintsF etching,Op timization TargetPred iction /pr efetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 6380 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= audio.mojo m.AudioSer vice --lan g=en-US -- service-sa ndbox-type =audio --m ojo-platfo rm-channel -handle=47 92 --field -trial-han dle=1968,i ,471016179 3563401793 ,723523309 0458664314 ,262144 -- disable-fe atures=Opt imizationG uideModelD ownloading ,Optimizat ionHints,O ptimizatio nHintsFetc hing,Optim izationTar getPredict ion /prefe tch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 6392 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= video_capt ure.mojom. VideoCaptu reService --lang=en- US --servi ce-sandbox -type=none --mojo-pl atform-cha nnel-handl e=4144 --f ield-trial -handle=19 68,i,47101 6179356340 1793,72352 3309045866 4314,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 6504 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt p://links. notificati on.intuit. com/ls/cli ck?upn=u00 1.Hu9nToJL xsJSQR8ZHW n8Ib7JikYF 6PNXv5VK-2 BAfeSpVHPR Ny-2BFDtJ- 2BhNUfKXTv erofrKjvXV KH4ba5KbTX -2BS4aEATQ -2BdvHNjDc f3OmBO8Olt Xq6TPtCFVm Mtf59VCEIh WP8mKN6H4H EXLgTiVOzM GungkdodFG 1U68jQcrrN ridBgnLDNN cks2Eu-2FQ vYhEtX4HXr Z9v6fUa-2B RIi5AQ-2Bw D5vS6MnLYV P87GGyb6Hm NhdfD3KwSA S20G-2BeW0 Vh1-2FR9QT Ufmy33TQB0 xSkInGL4OQ -3D-3Dd5bU _cr2hXK7H4 6C0VNrk0q7 2l8t-2Fz9m nxEHSfh1GA bJeNzpnKYe 8FQIo-2FWB JuMOaTn-2F P5GR8Qt943 ZZfuRkH6un 4oUU3aXnLV tIgXrne8J6 mRLgoHmZ4d Slnz9HKSTZ pIEdqIMntB hHh48IoiPl kBcx5WCYGF vdqaseKMS4 hqG-2Fqm3C XUvsLf-2FB Uuq3N23Dp1 e1ITq1YXJs D4Tc2Hp3um T37TOgYKV2 wDoA502-2B mC98ur8ZXp 7uaVp3-2BG 6QDUeQpqKP WQHCWKl5kS R-2Bnb3SQu 1evjJ2gpbc qd9JMAV6jW ZMA3B8hmOt BKozI5eRDr BvzQb6tnM0 dHr34e27qW boGpujmnGV OSZQqF0jws NgVGly00Wo Lu0CZsW-2B cjGQpD7k9A LTpkcWliNG dFdbMxHMZX iA1J7lh2-2 BsF5qgo9tG TfAjLJ4Rsu C3oX6KaIwk ulFtivIYSj HdA3X27kGl UzFrUHua-2 BTgD5ohPM7 evV83d7kPN ItYEGvVPIJ VZUk-2FxIB j3YPP-2Fsb tk7I0WbaGl b1bmDsgl2S UXcvBs603y DvLQMeC1aU JsiH8N2BZo gAbJvS7FD1 tk4BYTDW2X wf7gosyLjU OkHNuS9r2L GmeREVOdja vhZFRuoyZt 9K3oAqbd0i lkQ8cIP0sz yeADWc0-2B NQ23CH7qE- 2FjWIbg0Hc wXFXFyjdQD i7qf1pgUXI -2Fv9Yy6AG 5bUs2m1HxA WHaL7fW5CV QZ4F6B1Ju1 sw59F7SUz2 3yhvwNObJm UVbVfEGV-2 BZA-2F98pD H2pt7LJtKg I3mewrJbs- 2F-2FTdOmr I6HG3-2FbX aeouJzCyvX qTCN6rAXz7 G1EV-2Bxmz weuxfbkDje kOwsb9FAt1 9H2h8p-2Ba cLMfFKRpKA DWoVXepjHI 41l8Ezr5z4 P9kXhgjPrs LF1E0d878U ey8KsSHy4z MEwC2hysqB 10YFJ8NqqD GiqvuO1ptz ehCo0stoHl QSz6NXbxfV qYRRpI0bWj iE3mmH8tYF qTzyq0aLML c8mRWBu2lY y5fk6tVB7R DFYmaMv4XG 4unkmzRlYW 1UlIFaFQRZ g6nUUfTxlT Fqd6Fq3MIy -2FutJstaa MOfOE3RGI- 2FjMRYS6gG PZ-2FXFUNY yEqTQgau-2 FHg-2BIPIf L6v25iFKH7 BpfNrtW6dP ZL-2FY5foy 3wuJIqTA2g 64-2BLwCF- 2B1AnLxVb- 2FbYm-2F7R Ngq095K8jb C-2BKEkU2A y2cSCNX52G HO974WSNSY h1dyvEWu2H 4Nmtn6AV74 Z-2FcJwN3d F1ce0-2BWu zqG0B6WkJD QyH0gEgA5j IpX031SHyc hMJHIjzt50 P3dD4oGn86 BCtFVqK4XC vQAFGl182m qUeuIP9aQ- 2FdHf-2Btr B5hlbOp6NQ -2FjRIMw4b Wzn-2BhXPI KipkXbuS-2 BsK49do0iu 8L0vdijcSB Vk9hOju6vh 1btfQb5l8P qUG19kVW1f kedtm6l0tK Lclh-2FlVL BAj4SAZwbd k2PSlc88UM uZ0KZcDPiQ WEpcPPmfr2 Gl1LDI4f3z zDS6s9nsw- 3D-3D" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- Acrobat.exe (PID: 4128 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \Downloads \downloade d.pdf" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 6064 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 6052 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 08 --field -trial-han dle=1684,i ,154385525 2061708600 1,79458361 2911285206 7,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- cleanup
⊘No configs have been found
⊘No yara matches
⊘No Sigma rule has matched
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
Phishing |
---|
Source: | DOM page: |
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |