Windows Analysis Report
https://ssa-certification.com

Overview

General Information

Sample URL: https://ssa-certification.com
Analysis ID: 1544001

Detection

Score: 21
Range: 0 - 100
Whitelisted: false
Confidence: 80%

Signatures

AI detected suspicious URL
Detected non-DNS traffic on DNS port
HTML page contains hidden javascript code
Stores files to the Windows start menu directory

Classification

Source: https://ssa-certification.com/ HTTP Parser: Base64 decoded: <svg xmlns="http://www.w3.org/2000/svg" width="32" height="32" fill="none"><path fill="#B20F03" d="M16 3a13 13 0 1 0 13 13A13.015 13.015 0 0 0 16 3m0 24a11 11 0 1 1 11-11 11.01 11.01 0 0 1-11 11"/><path fill="#B20F03" d="M17.038 18.615H14.87L14.563 9.5h2....
Source: https://ssa-certification.com/ HTTP Parser: No favicon
Source: https://ssa-certification.com/ HTTP Parser: No favicon
Source: https://ssa-certification.com/ HTTP Parser: No favicon
Source: https://ssa-certification.com/ HTTP Parser: No favicon
Source: https://ssa-certification.com/ HTTP Parser: No favicon
Source: https://ssa-certification.com/ HTTP Parser: No favicon
Source: https://ssa-certification.com/ HTTP Parser: No favicon
Source: unknown HTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.17:49708 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.17:63721 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.17:63726 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.17:63769 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.126.31.67:443 -> 192.168.2.17:63775 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.107.5.88:443 -> 192.168.2.17:63778 version: TLS 1.2
Source: global traffic TCP traffic: 192.168.2.17:63717 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:63717 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:63717 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:63717 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:63717 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:63717 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:63717 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:63717 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:63717 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:63717 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:63717 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:63717 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:63717 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:63717 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:63717 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:63717 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:63717 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:63717 -> 1.1.1.1:53
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.200
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.200
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.200
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.13
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: global traffic DNS traffic detected: DNS query: ssa-certification.com
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: global traffic DNS traffic detected: DNS query: a.nel.cloudflare.com
Source: global traffic DNS traffic detected: DNS query: challenges.cloudflare.com
Source: unknown Network traffic detected: HTTP traffic on port 49708 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63778 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63755 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63726 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63732 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63768
Source: unknown Network traffic detected: HTTP traffic on port 49720 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63767
Source: unknown Network traffic detected: HTTP traffic on port 63764 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63769
Source: unknown Network traffic detected: HTTP traffic on port 63741 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63760
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63762
Source: unknown Network traffic detected: HTTP traffic on port 63749 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63761
Source: unknown Network traffic detected: HTTP traffic on port 49717 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63764
Source: unknown Network traffic detected: HTTP traffic on port 63787 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63763
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63766
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63765
Source: unknown Network traffic detected: HTTP traffic on port 49675 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63729 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49699
Source: unknown Network traffic detected: HTTP traffic on port 63752 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63780
Source: unknown Network traffic detected: HTTP traffic on port 63735 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49691
Source: unknown Network traffic detected: HTTP traffic on port 63773 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63779
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63778
Source: unknown Network traffic detected: HTTP traffic on port 63767 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63721 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63770 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63771
Source: unknown Network traffic detected: HTTP traffic on port 63784 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63770
Source: unknown Network traffic detected: HTTP traffic on port 63746 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63773
Source: unknown Network traffic detected: HTTP traffic on port 49714 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63772
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63775
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49725
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63774
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63777
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49723
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63776
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49722
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49721
Source: unknown Network traffic detected: HTTP traffic on port 63730 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63753 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49720
Source: unknown Network traffic detected: HTTP traffic on port 49706 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63724 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63772 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63766 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63718 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63747 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49717
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63784
Source: unknown Network traffic detected: HTTP traffic on port 49715 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49716
Source: unknown Network traffic detected: HTTP traffic on port 49680 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63783
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49715
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63786
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49714
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63785
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49713
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63787
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49710
Source: unknown Network traffic detected: HTTP traffic on port 49709 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49677 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63727 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63733 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63750 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63758 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63775 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49723 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63738 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63744 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63719
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49709
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63718
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49708
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49707
Source: unknown Network traffic detected: HTTP traffic on port 63761 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49706
Source: unknown Network traffic detected: HTTP traffic on port 63769 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63786 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49701
Source: unknown Network traffic detected: HTTP traffic on port 49710 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49699 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63780 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63751 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49676 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63759 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63736 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49691 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63774 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63724
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63723
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63726
Source: unknown Network traffic detected: HTTP traffic on port 63739 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63725
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63728
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63727
Source: unknown Network traffic detected: HTTP traffic on port 63745 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63722 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49701 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63729
Source: unknown Network traffic detected: HTTP traffic on port 63760 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49713 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63783 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63768 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63722
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63721
Source: unknown Network traffic detected: HTTP traffic on port 63777 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49707 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63756 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63731 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63725 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49721 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63735
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63734
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63737
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63736
Source: unknown Network traffic detected: HTTP traffic on port 63719 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63739
Source: unknown Network traffic detected: HTTP traffic on port 63763 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63738
Source: unknown Network traffic detected: HTTP traffic on port 63742 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63731
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63730
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63733
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63732
Source: unknown Network traffic detected: HTTP traffic on port 63728 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63776 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49678 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63734 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49725 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63757 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63746
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63745
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63748
Source: unknown Network traffic detected: HTTP traffic on port 49722 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63747
Source: unknown Network traffic detected: HTTP traffic on port 63737 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63749
Source: unknown Network traffic detected: HTTP traffic on port 63762 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63743 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63785 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63740
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63742
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63741
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63744
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63743
Source: unknown Network traffic detected: HTTP traffic on port 63754 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63723 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63771 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63779 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63757
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63756
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63759
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63758
Source: unknown Network traffic detected: HTTP traffic on port 63765 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 63740 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49716 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63751
Source: unknown Network traffic detected: HTTP traffic on port 63748 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63750
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63753
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63752
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63755
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63754
Source: unknown HTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.17:49708 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.17:63721 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.17:63726 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.17:63769 version: TLS 1.2
Source: unknown HTTPS traffic detected: 40.126.31.67:443 -> 192.168.2.17:63775 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.107.5.88:443 -> 192.168.2.17:63778 version: TLS 1.2
Source: classification engine Classification label: sus21.win@25/15@16/129
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=1972,i,1509764392906938253,15429071110046609563,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://ssa-certification.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=1972,i,1509764392906938253,15429071110046609563,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: Window Recorder Window detected: More than 3 window changes detected

Persistence and Installation Behavior

barindex
Source: Email JoeBoxAI: AI detected Typosquatting in URL: URL: https://ssa-certification.com
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs