Windows Analysis Report
https://apollomicsinc-my.sharepoint.com/:u:/p/peony_yu/EThcAjzaTWNPs4NpIP1X0v0BUe4pmKNB9s6TANBDk5EDeA?rtime=8VndtY_33Eg

Overview

General Information

Sample URL: https://apollomicsinc-my.sharepoint.com/:u:/p/peony_yu/EThcAjzaTWNPs4NpIP1X0v0BUe4pmKNB9s6TANBDk5EDeA?rtime=8VndtY_33Eg
Analysis ID: 1545589

Detection

Score: 68
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

AI detected phishing page
AI detected landing page (webpage, office document or email)
AI detected suspicious URL
HTML page contains obfuscated javascript
Phishing site detected (based on favicon image match)
Phishing site detected (based on image similarity)
Detected non-DNS traffic on DNS port
HTML body contains low number of good links
HTML body with high number of embedded SVGs detected
HTML page contains hidden javascript code
HTML title does not match URL
Invalid 'sign-in options' or 'sign-up' link found
Invalid T&C link found
Stores files to the Windows start menu directory

Classification

Phishing

barindex
Source: https://apollomics.vurosmeoowkslooo.ru/&redirect=09e884fc5e894cd71fa65e8eefc074be3a2f2efbmain&uid=f253efe302d32ab264a76e0ce65be769672262e8ea6c3 LLM: Score: 9 Reasons: The brand 'Microsoft' is classified as 'wellknown'., The URL 'apollomics.vurosmeoowkslooo.ru' does not match the legitimate domain 'microsoft.com'., The domain 'vurosmeoowkslooo.ru' is unrelated to Microsoft and appears suspicious., The URL contains unusual and random characters, which is a common tactic in phishing URLs., The presence of input fields for 'Email or phone' suggests an attempt to collect sensitive information. DOM: 4.11.pages.csv
Source: https://apollomics.vurosmeoowkslooo.ru/&redirect=09e884fc5e894cd71fa65e8eefc074be3a2f2efbmain&uid=f253efe302d32ab264a76e0ce65be769672262e8ea6c3 HTTP Parser: var a0_0x5721f2=a0_0x320d;(function(_0x506e8d,_0x15eb93){var _0x3ff949=a0_0x320d,_0x3c8b08=_0x
Source: https://apollomics.vurosmeoowkslooo.ru/&redirect=09e884fc5e894cd71fa65e8eefc074be3a2f2efbmain&uid=f253efe302d32ab264a76e0ce65be769672262e8ea6c3 Matcher: Template: microsoft matched with high similarity
Source: https://apollomics.vurosmeoowkslooo.ru/&redirect=09e884fc5e894cd71fa65e8eefc074be3a2f2efbmain&uid=f253efe302d32ab264a76e0ce65be769672262e8ea6c3 Matcher: Found strong image similarity, brand: MICROSOFT
Source: https://apollomics.vurosmeoowkslooo.ru/&redirect=09e884fc5e894cd71fa65e8eefc074be3a2f2efbmain&uid=f253efe302d32ab264a76e0ce65be769672262e8ea6c3 HTTP Parser: Number of links: 0
Source: https://apollomicsinc-my.sharepoint.com/:u:/p/peony_yu/EThcAjzaTWNPs4NpIP1X0v0BUe4pmKNB9s6TANBDk5EDeA?rtime=ImanPAL53Eg HTTP Parser: Total embedded SVG size: 446693
Source: https://apollomicsinc-my.sharepoint.com/personal/peony_yu_apollomicsinc_com/_layouts/15/Doc.aspx?sourcedoc=%7B3c025c38-4dda-4f63-b383-6920fd57d2fd%7D&action=default&slrid=e1075fa1-c011-6000-c63f-4db730a3b457&originalPath=aHR0cHM6Ly9hcG9sbG9taWNzaW5jLW15LnNoYXJlcG9pbnQuY29tLzp1Oi9wL3Blb255X3l1L0VUaGNBanphVFdOUHM0TnBJUDFYMHYwQlVlNHBtS05COXM2VEFOQkRrNUVEZUE_cnRpbWU9SW1hblBBTDUzRWc&CID=199e5975-ce48-4ea8-b1cc-6b01a427e80f&_SRM=0:G:134 HTTP Parser: Base64 decoded: {"typ":"JWT","alg":"RS256","x5t":"uXehQJPleVjNCbakUhGD6IyFQQk"}
Source: https://apollomics.vurosmeoowkslooo.ru/&redirect=09e884fc5e894cd71fa65e8eefc074be3a2f2efbmain&uid=f253efe302d32ab264a76e0ce65be769672262e8ea6c3 HTTP Parser: Title: Verify My Account does not match URL
Source: https://apollomics.vurosmeoowkslooo.ru/&redirect=09e884fc5e894cd71fa65e8eefc074be3a2f2efbmain&uid=f253efe302d32ab264a76e0ce65be769672262e8ea6c3 HTTP Parser: Invalid link: get a new Microsoft account
Source: https://apollomics.vurosmeoowkslooo.ru/&redirect=09e884fc5e894cd71fa65e8eefc074be3a2f2efbmain&uid=f253efe302d32ab264a76e0ce65be769672262e8ea6c3 HTTP Parser: Invalid link: Terms of use
Source: https://apollomics.vurosmeoowkslooo.ru/&redirect=09e884fc5e894cd71fa65e8eefc074be3a2f2efbmain&uid=f253efe302d32ab264a76e0ce65be769672262e8ea6c3 HTTP Parser: Invalid link: Privacy & cookies
Source: https://apollomics.vurosmeoowkslooo.ru/&redirect=09e884fc5e894cd71fa65e8eefc074be3a2f2efbmain&uid=f253efe302d32ab264a76e0ce65be769672262e8ea6c3 HTTP Parser: No <meta name="author".. found
Source: https://apollomics.vurosmeoowkslooo.ru/&redirect=09e884fc5e894cd71fa65e8eefc074be3a2f2efbmain&uid=f253efe302d32ab264a76e0ce65be769672262e8ea6c3 HTTP Parser: No <meta name="copyright".. found
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.17:49728 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.17:49741 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.17:49748 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.17:61277 version: TLS 1.2
Source: unknown HTTPS traffic detected: 20.190.160.14:443 -> 192.168.2.17:61288 version: TLS 1.2
Source: unknown HTTPS traffic detected: 2.23.209.177:443 -> 192.168.2.17:61295 version: TLS 1.2
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:55332 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.17:61174 -> 1.1.1.1:53
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.13
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.13
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.13
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.13
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown TCP traffic detected without corresponding DNS query: 4.245.163.56
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic DNS traffic detected: DNS query: apollomicsinc-my.sharepoint.com
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: global traffic DNS traffic detected: DNS query: common.online.office.com
Source: global traffic DNS traffic detected: DNS query: m365cdn.nel.measure.office.net
Source: global traffic DNS traffic detected: DNS query: storage.live.com
Source: global traffic DNS traffic detected: DNS query: messaging.engagement.office.com
Source: global traffic DNS traffic detected: DNS query: apollomics.vurosmeoowkslooo.ru
Source: global traffic DNS traffic detected: DNS query: code.jquery.com
Source: global traffic DNS traffic detected: DNS query: challenges.cloudflare.com
Source: global traffic DNS traffic detected: DNS query: visioonline.nel.measure.office.net
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49741
Source: unknown Network traffic detected: HTTP traffic on port 61304 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49740
Source: unknown Network traffic detected: HTTP traffic on port 61327 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61201 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61333 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61356 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61185
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61187
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49739
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61189
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49734
Source: unknown Network traffic detected: HTTP traffic on port 49675 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61351 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61242 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61179 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61288 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61339 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61345 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49728
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49727
Source: unknown Network traffic detected: HTTP traffic on port 61310 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49724
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49723
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49721
Source: unknown Network traffic detected: HTTP traffic on port 61241 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49748 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61315 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61340 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61363 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 55360 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49717
Source: unknown Network traffic detected: HTTP traffic on port 49680 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61277 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61294 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49711
Source: unknown Network traffic detected: HTTP traffic on port 61332 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61309 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61357 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61368 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49705
Source: unknown Network traffic detected: HTTP traffic on port 61385 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49704
Source: unknown Network traffic detected: HTTP traffic on port 61300 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61372 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61262
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61385
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61386
Source: unknown Network traffic detected: HTTP traffic on port 61355 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61280
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61281
Source: unknown Network traffic detected: HTTP traffic on port 49724 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61366 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61349 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61277
Source: unknown Network traffic detected: HTTP traffic on port 61257 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61295 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61290
Source: unknown Network traffic detected: HTTP traffic on port 61251 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61294
Source: unknown Network traffic detected: HTTP traffic on port 61373 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49741 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61367 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61206 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61338 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61344 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61290 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61286
Source: unknown Network traffic detected: HTTP traffic on port 61311 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61287
Source: unknown Network traffic detected: HTTP traffic on port 61185 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61288
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49757
Source: unknown Network traffic detected: HTTP traffic on port 61296 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49698 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49752
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61183
Source: unknown Network traffic detected: HTTP traffic on port 61361 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 55356 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61262 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61316 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61295
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61296
Source: unknown Network traffic detected: HTTP traffic on port 61350 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61176
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61297
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49748
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61179
Source: unknown Network traffic detected: HTTP traffic on port 61176 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61347
Source: unknown Network traffic detected: HTTP traffic on port 55352 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 55352
Source: unknown Network traffic detected: HTTP traffic on port 61342 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61348
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 55353
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61349
Source: unknown Network traffic detected: HTTP traffic on port 61365 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61340
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61341
Source: unknown Network traffic detected: HTTP traffic on port 61313 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61342
Source: unknown Network traffic detected: HTTP traffic on port 49717 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61343
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61344
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61345
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61346
Source: unknown Network traffic detected: HTTP traffic on port 61307 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49698
Source: unknown Network traffic detected: HTTP traffic on port 61250 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49711 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61360
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49691
Source: unknown Network traffic detected: HTTP traffic on port 61359 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 55356
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 55357
Source: unknown Network traffic detected: HTTP traffic on port 49728 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61318 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61358
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61359
Source: unknown Network traffic detected: HTTP traffic on port 49700 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 55360
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61350
Source: unknown Network traffic detected: HTTP traffic on port 49752 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61351
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61352
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61353
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61354
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61355
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61356
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61357
Source: unknown Network traffic detected: HTTP traffic on port 61306 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61360 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61370
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61250
Source: unknown Network traffic detected: HTTP traffic on port 61329 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61354 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61371
Source: unknown Network traffic detected: HTTP traffic on port 55357 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61280 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61249 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61369
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61249
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61361
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61241
Source: unknown Network traffic detected: HTTP traffic on port 61348 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61242
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61363
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61243
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61364
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61365
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61366
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61367
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61368
Source: unknown Network traffic detected: HTTP traffic on port 49757 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49734 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61187 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61301 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49740 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61286 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61343 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49723 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61337 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61371 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61251
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61372
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61373
Source: unknown Network traffic detected: HTTP traffic on port 61312 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61257
Source: unknown Network traffic detected: HTTP traffic on port 61297 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49700
Source: unknown Network traffic detected: HTTP traffic on port 61352 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49727 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49704 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61243 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49691 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61304
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61306
Source: unknown Network traffic detected: HTTP traffic on port 61369 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61307
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61309
Source: unknown Network traffic detected: HTTP traffic on port 61346 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61183 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61300
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61301
Source: unknown Network traffic detected: HTTP traffic on port 61189 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61281 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49721 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61315
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61316
Source: unknown Network traffic detected: HTTP traffic on port 61320 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61318
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61319
Source: unknown Network traffic detected: HTTP traffic on port 61341 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61310
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61311
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61312
Source: unknown Network traffic detected: HTTP traffic on port 49739 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61313
Source: unknown Network traffic detected: HTTP traffic on port 61331 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61358 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61287 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61206
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61327
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61329
Source: unknown Network traffic detected: HTTP traffic on port 61319 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61370 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61320
Source: unknown Network traffic detected: HTTP traffic on port 61386 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61201
Source: unknown Network traffic detected: HTTP traffic on port 49705 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61336 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61353 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 55353 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61336
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61337
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61338
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61339
Source: unknown Network traffic detected: HTTP traffic on port 61364 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61347 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61331
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61332
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61333
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.17:49728 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.17:49741 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.17:49748 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.17:61277 version: TLS 1.2
Source: unknown HTTPS traffic detected: 20.190.160.14:443 -> 192.168.2.17:61288 version: TLS 1.2
Source: unknown HTTPS traffic detected: 2.23.209.177:443 -> 192.168.2.17:61295 version: TLS 1.2
Source: classification engine Classification label: mal68.phis.win@27/81@40/378
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2176 --field-trial-handle=1872,i,7565726077033597492,9122141473950066804,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://apollomicsinc-my.sharepoint.com/:u:/p/peony_yu/EThcAjzaTWNPs4NpIP1X0v0BUe4pmKNB9s6TANBDk5EDeA?rtime=8VndtY_33Eg"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2176 --field-trial-handle=1872,i,7565726077033597492,9122141473950066804,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: Window Recorder Window detected: More than 3 window changes detected

Persistence and Installation Behavior

barindex
Source: https://apollomicsinc-my.sharepoint.com/personal/peony_yu_apollomicsinc_com/_layouts/15/Doc.aspx?sourcedoc=%7B3c025c38-4dda-4f63-b383-6920fd57d2fd%7D&action=default&slrid=e1075fa1-c011-6000-c63f-4db730a3b457&originalPath=aHR0cHM6Ly9hcG9sbG9taWNzaW5jLW15LnNoYXJlcG9pbnQuY29tLzp1Oi9wL3Blb255X3l1L0VUaGNBanphVFdOUHM0TnBJUDFYMHYwQlVlNHBtS05COXM2VEFOQkRrNUVEZUE_cnRpbWU9SW1hblBBTDUzRWc&CID=199e5975-ce48-4ea8-b1cc-6b01a427e80f&_SRM=0:G:134 LLM: Page contains button: 'VIEW DOCUMENT' Source: '1.0.pages.csv'
Source: https://apollomicsinc-my.sharepoint.com/:u:/p/peony_yu/EThcAjzaTWNPs4NpIP1X0v0BUe4pmKNB9s6TANBDk5EDeA?rtime=ImanPAL53Eg LLM: Page contains button: 'VIEW DOCUMENT' Source: '2.1.pages.csv'
Source: Email JoeBoxAI: AI detected Brand spoofing attempt in URL: URL: https://apollomics.vurosmeoowkslooo.ru
Source: Email JoeBoxAI: AI detected Typosquatting in URL: URL: https://apollomics.vurosmeoowkslooo.ru
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs