Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://notifications.canadapost-postescanada.ca

Overview

General Information

Sample URL:http://notifications.canadapost-postescanada.ca
Analysis ID:1542413
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 5016 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 4432 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2596 --field-trial-handle=2420,i,5528624340559027959,12277407646798800761,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6328 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://notifications.canadapost-postescanada.ca" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: notifications.canadapost-postescanada.ca
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: classification engineClassification label: unknown0.win@18/0@4/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2596 --field-trial-handle=2420,i,5528624340559027959,12277407646798800761,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://notifications.canadapost-postescanada.ca"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2596 --field-trial-handle=2420,i,5528624340559027959,12277407646798800761,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
172.217.16.196
truefalse
    unknown
    fp2e7a.wpc.phicdn.net
    192.229.221.95
    truefalse
      unknown
      notifications.canadapost-postescanada.ca
      unknown
      unknownfalse
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        239.255.255.250
        unknownReserved
        unknownunknownfalse
        172.217.16.196
        www.google.comUnited States
        15169GOOGLEUSfalse
        IP
        192.168.2.4
        Joe Sandbox version:41.0.0 Charoite
        Analysis ID:1542413
        Start date and time:2024-10-25 21:57:03 +02:00
        Joe Sandbox product:CloudBasic
        Overall analysis duration:0h 2m 0s
        Hypervisor based Inspection enabled:false
        Report type:full
        Cookbook file name:browseurl.jbs
        Sample URL:http://notifications.canadapost-postescanada.ca
        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
        Number of analysed new started processes analysed:7
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • EGA enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:UNKNOWN
        Classification:unknown0.win@18/0@4/3
        Cookbook Comments:
        • URL browsing timeout or error
        • URL not reachable
        • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
        • Excluded IPs from analysis (whitelisted): 142.250.186.131, 142.251.168.84, 216.58.206.46, 34.104.35.123, 192.243.228.1, 184.28.90.27, 172.202.163.200, 93.184.221.240, 20.242.39.171, 192.229.221.95
        • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, clientservices.googleapis.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, wu.azureedge.net, clients2.google.com, notifications.canadapost-postescanada.ca.cname.campaign.adobe.com, ocsp.digicert.com, e16604.g.akamaiedge.net, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, glb.cws.prod.dcat.dsp.trafficmanager.net, ocsp.edge.digicert.com, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net, fs.microsoft.com, accounts.google.com, ctldl.windowsupdate.com.delivery.microsoft.com, wu.ec.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, edgedl.me.gvt1.com, clients.l.google.com
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtSetInformationFile calls found.
        • VT rate limit hit for: http://notifications.canadapost-postescanada.ca
        No simulations
        No context
        No context
        No context
        No context
        No context
        No created / dropped files found
        No static file info
        TimestampSource PortDest PortSource IPDest IP
        Oct 25, 2024 21:58:00.692409992 CEST49675443192.168.2.4173.222.162.32
        Oct 25, 2024 21:58:08.356770039 CEST49739443192.168.2.4172.217.16.196
        Oct 25, 2024 21:58:08.356839895 CEST44349739172.217.16.196192.168.2.4
        Oct 25, 2024 21:58:08.357006073 CEST49739443192.168.2.4172.217.16.196
        Oct 25, 2024 21:58:08.368247032 CEST49739443192.168.2.4172.217.16.196
        Oct 25, 2024 21:58:08.368299961 CEST44349739172.217.16.196192.168.2.4
        Oct 25, 2024 21:58:09.238260984 CEST44349739172.217.16.196192.168.2.4
        Oct 25, 2024 21:58:09.238681078 CEST49739443192.168.2.4172.217.16.196
        Oct 25, 2024 21:58:09.238739967 CEST44349739172.217.16.196192.168.2.4
        Oct 25, 2024 21:58:09.240443945 CEST44349739172.217.16.196192.168.2.4
        Oct 25, 2024 21:58:09.240644932 CEST49739443192.168.2.4172.217.16.196
        Oct 25, 2024 21:58:09.639405966 CEST49739443192.168.2.4172.217.16.196
        Oct 25, 2024 21:58:09.639791965 CEST44349739172.217.16.196192.168.2.4
        Oct 25, 2024 21:58:09.690921068 CEST49739443192.168.2.4172.217.16.196
        Oct 25, 2024 21:58:09.690979004 CEST44349739172.217.16.196192.168.2.4
        Oct 25, 2024 21:58:09.739655018 CEST49739443192.168.2.4172.217.16.196
        Oct 25, 2024 21:58:15.736387968 CEST4972380192.168.2.4199.232.214.172
        Oct 25, 2024 21:58:15.742805958 CEST8049723199.232.214.172192.168.2.4
        Oct 25, 2024 21:58:15.742873907 CEST4972380192.168.2.4199.232.214.172
        Oct 25, 2024 21:58:19.227123976 CEST44349739172.217.16.196192.168.2.4
        Oct 25, 2024 21:58:19.227271080 CEST44349739172.217.16.196192.168.2.4
        Oct 25, 2024 21:58:19.227333069 CEST49739443192.168.2.4172.217.16.196
        Oct 25, 2024 21:58:20.243011951 CEST49739443192.168.2.4172.217.16.196
        Oct 25, 2024 21:58:20.243035078 CEST44349739172.217.16.196192.168.2.4
        TimestampSource PortDest PortSource IPDest IP
        Oct 25, 2024 21:58:04.031759024 CEST53579701.1.1.1192.168.2.4
        Oct 25, 2024 21:58:04.048440933 CEST53515191.1.1.1192.168.2.4
        Oct 25, 2024 21:58:05.351286888 CEST53529541.1.1.1192.168.2.4
        Oct 25, 2024 21:58:05.881136894 CEST5604853192.168.2.41.1.1.1
        Oct 25, 2024 21:58:05.881136894 CEST5789953192.168.2.41.1.1.1
        Oct 25, 2024 21:58:05.961822987 CEST53578991.1.1.1192.168.2.4
        Oct 25, 2024 21:58:08.337182045 CEST6020253192.168.2.41.1.1.1
        Oct 25, 2024 21:58:08.337182045 CEST5091053192.168.2.41.1.1.1
        Oct 25, 2024 21:58:08.345283031 CEST53509101.1.1.1192.168.2.4
        Oct 25, 2024 21:58:08.345335007 CEST53602021.1.1.1192.168.2.4
        Oct 25, 2024 21:58:16.437345982 CEST138138192.168.2.4192.168.2.255
        Oct 25, 2024 21:58:22.730779886 CEST53653091.1.1.1192.168.2.4
        TimestampSource IPDest IPChecksumCodeType
        Oct 25, 2024 21:58:05.961901903 CEST192.168.2.41.1.1.1c29b(Port unreachable)Destination Unreachable
        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
        Oct 25, 2024 21:58:05.881136894 CEST192.168.2.41.1.1.10xdccbStandard query (0)notifications.canadapost-postescanada.caA (IP address)IN (0x0001)false
        Oct 25, 2024 21:58:05.881136894 CEST192.168.2.41.1.1.10xcd1bStandard query (0)notifications.canadapost-postescanada.ca65IN (0x0001)false
        Oct 25, 2024 21:58:08.337182045 CEST192.168.2.41.1.1.10x9133Standard query (0)www.google.comA (IP address)IN (0x0001)false
        Oct 25, 2024 21:58:08.337182045 CEST192.168.2.41.1.1.10x256cStandard query (0)www.google.com65IN (0x0001)false
        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
        Oct 25, 2024 21:58:05.947307110 CEST1.1.1.1192.168.2.40xdccbNo error (0)notifications.canadapost-postescanada.canotifications.canadapost-postescanada.ca.cname.campaign.adobe.comCNAME (Canonical name)IN (0x0001)false
        Oct 25, 2024 21:58:05.961822987 CEST1.1.1.1192.168.2.40xcd1bNo error (0)notifications.canadapost-postescanada.canotifications.canadapost-postescanada.ca.cname.campaign.adobe.comCNAME (Canonical name)IN (0x0001)false
        Oct 25, 2024 21:58:08.345283031 CEST1.1.1.1192.168.2.40x256cNo error (0)www.google.com65IN (0x0001)false
        Oct 25, 2024 21:58:08.345335007 CEST1.1.1.1192.168.2.40x9133No error (0)www.google.com172.217.16.196A (IP address)IN (0x0001)false
        Oct 25, 2024 21:58:17.570281982 CEST1.1.1.1192.168.2.40xcb28No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
        Oct 25, 2024 21:58:17.570281982 CEST1.1.1.1192.168.2.40xcb28No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false

        Click to jump to process

        Click to jump to process

        Click to jump to process

        Target ID:0
        Start time:15:57:55
        Start date:25/10/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:2
        Start time:15:58:01
        Start date:25/10/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2596 --field-trial-handle=2420,i,5528624340559027959,12277407646798800761,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:false

        Target ID:3
        Start time:15:58:04
        Start date:25/10/2024
        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
        Wow64 process (32bit):false
        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://notifications.canadapost-postescanada.ca"
        Imagebase:0x7ff76e190000
        File size:3'242'272 bytes
        MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:low
        Has exited:true

        No disassembly