Click to jump to signature section
Source: http://moxx.com.bd/cgi.bin/y93d3cuZXZlbnRicml0ZS5jb20vZS9icmVha2Zhc3Q0Y2Vvcy1wcmVzZW50cy10aWNrZXRzLTE2OTY1NTc0NzkwOT9y/#bWVsaXNzYS5tZWRpbmFAYXZlbnRpdi5jb20= | SlashNext: Label: Credential Stealing type: Phishing & Social usering |
Source: 1.0.pages.csv | Malware Configuration Extractor: Mamba2FA {"sv": "o365_1_voice", "rand": "TlJpVHU=", "uid": "USER15112024U41111553"} |
Source: Yara match | File source: 2.3.pages.csv, type: HTML |
Source: Yara match | File source: 2.3.pages.csv, type: HTML |
Source: file:///C:/Users/user/Desktop/Play_vm_Message_for_Melissa.medina_wav_%20.htm | HTTP Parser: window.location.href = atob( |
Source: Play_vm_Message_for_Melissa.medina_wav_ .htm | HTTP Parser: location.href |
Source: Play_vm_Message_for_Melissa.medina_wav_ .htm | HTTP Parser: .location |
Source: Play_vm_Message_for_Melissa.medina_wav_ .htm | HTTP Parser: .location |
Source: https://monroefmc.com/o/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9VGxKcFZIVT0mdWlkPVVTRVIxNTExMjAyNFU0MTExMTU1Mw==N0123N#bWVsaXNzYS5tZWRpbmFAYXZlbnRpdi5jb20= | HTTP Parser: Number of links: 0 |
Source: https://monroefmc.com/o/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9VGxKcFZIVT0mdWlkPVVTRVIxNTExMjAyNFU0MTExMTU1Mw==N0123N#bWVsaXNzYS5tZWRpbmFAYXZlbnRpdi5jb20= | HTTP Parser: <input type="password" .../> found but no <form action="... |
Source: Play_vm_Message_for_Melissa.medina_wav_ .htm | HTTP Parser: Base64 decoded: johno@rslmenora.com.au |
Source: https://monroefmc.com/o/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9VGxKcFZIVT0mdWlkPVVTRVIxNTExMjAyNFU0MTExMTU1Mw==N0123N#bWVsaXNzYS5tZWRpbmFAYXZlbnRpdi5jb20= | HTTP Parser: Title: Voice Mail does not match URL |
Source: https://monroefmc.com/o/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9VGxKcFZIVT0mdWlkPVVTRVIxNTExMjAyNFU0MTExMTU1Mw==N0123N#bWVsaXNzYS5tZWRpbmFAYXZlbnRpdi5jb20= | HTTP Parser: Invalid link: Forgot password? |
Source: https://monroefmc.com/o/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9VGxKcFZIVT0mdWlkPVVTRVIxNTExMjAyNFU0MTExMTU1Mw==N0123N#bWVsaXNzYS5tZWRpbmFAYXZlbnRpdi5jb20= | HTTP Parser: Invalid link: Terms of use |
Source: https://monroefmc.com/o/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9VGxKcFZIVT0mdWlkPVVTRVIxNTExMjAyNFU0MTExMTU1Mw==N0123N#bWVsaXNzYS5tZWRpbmFAYXZlbnRpdi5jb20= | HTTP Parser: Invalid link: Privacy & cookies |
Source: https://monroefmc.com/o/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9VGxKcFZIVT0mdWlkPVVTRVIxNTExMjAyNFU0MTExMTU1Mw==N0123N#bWVsaXNzYS5tZWRpbmFAYXZlbnRpdi5jb20= | HTTP Parser: <input type="password" .../> found |
Source: Play_vm_Message_for_Melissa.medina_wav_ .htm | HTTP Parser: No favicon |
Source: http://moxx.com.bd/cgi.bin/y93d3cuZXZlbnRicml0ZS5jb20vZS9icmVha2Zhc3Q0Y2Vvcy1wcmVzZW50cy10aWNrZXRzLTE2OTY1NTc0NzkwOT9y/#bWVsaXNzYS5tZWRpbmFAYXZlbnRpdi5jb20= | HTTP Parser: No favicon |
Source: http://moxx.com.bd/cgi.bin/y93d3cuZXZlbnRicml0ZS5jb20vZS9icmVha2Zhc3Q0Y2Vvcy1wcmVzZW50cy10aWNrZXRzLTE2OTY1NTc0NzkwOT9y/#bWVsaXNzYS5tZWRpbmFAYXZlbnRpdi5jb20= | HTTP Parser: No favicon |
Source: https://monroefmc.com/o/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9VGxKcFZIVT0mdWlkPVVTRVIxNTExMjAyNFU0MTExMTU1Mw==N0123N#bWVsaXNzYS5tZWRpbmFAYXZlbnRpdi5jb20= | HTTP Parser: No favicon |
Source: https://monroefmc.com/o/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9VGxKcFZIVT0mdWlkPVVTRVIxNTExMjAyNFU0MTExMTU1Mw==N0123N#bWVsaXNzYS5tZWRpbmFAYXZlbnRpdi5jb20= | HTTP Parser: No <meta name="author".. found |
Source: https://monroefmc.com/o/?c3Y9bzM2NV8xX3ZvaWNlJnJhbmQ9VGxKcFZIVT0mdWlkPVVTRVIxNTExMjAyNFU0MTExMTU1Mw==N0123N#bWVsaXNzYS5tZWRpbmFAYXZlbnRpdi5jb20= | HTTP Parser: No <meta name="copyright".. found |
Source: unknown | HTTPS traffic detected: 40.113.110.67:443 -> 192.168.2.6:49716 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.6:49723 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.6:49724 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.6:49725 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:49748 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.202.163.200:443 -> 192.168.2.6:49774 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.113.103.199:443 -> 192.168.2.6:49830 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.69.42.241:443 -> 192.168.2.6:62288 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 172.202.163.200:443 -> 192.168.2.6:62301 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.6:62312 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.6:62323 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.6:62360 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.6:62456 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.6:62483 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.6:62485 version: TLS 1.2 |
Source: Network traffic | Suricata IDS: 2057333 - Severity 1 - ET PHISHING MAMBA Credential Phish Landing Page 2024-11-08 : 192.168.2.6:62457 -> 162.241.225.189:443 |
Source: global traffic | TCP traffic: 192.168.2.6:62283 -> 162.159.36.2:53 |
Source: Joe Sandbox View | IP Address: 104.17.24.14 104.17.24.14 |
Source: Joe Sandbox View | IP Address: 13.107.246.64 13.107.246.64 |
Source: Joe Sandbox View | ASN Name: UNIFIEDLAYER-AS-1US UNIFIEDLAYER-AS-1US |
Source: Joe Sandbox View | JA3 fingerprint: 28a2c9bd18a11de089ef85a160da29e4 |
Source: Joe Sandbox View | JA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e |
Source: Network traffic | Suricata IDS: 2056643 - Severity 2 - ET PHISHING Javascript Browser Fingerprinting POST Request : 192.168.2.6:62457 -> 162.241.225.189:443 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.28.90.27 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.222.162.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.113.103.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.202.163.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.202.163.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.202.163.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.202.163.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.202.163.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.202.163.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.202.163.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.202.163.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.202.163.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.202.163.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.202.163.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.202.163.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.202.163.200 |
Source: global traffic | HTTP traffic detected: HTTP/1.1 200 OKConnection: Keep-AliveKeep-Alive: timeout=5, max=100content-type: text/htmllast-modified: Mon, 18 Nov 2024 15:52:43 GMTaccept-ranges: bytescontent-encoding: gzipvary: Accept-Encodingcontent-length: 1840date: Mon, 18 Nov 2024 19:36:37 GMTData Raw: 1f 8b 08 00 00 00 00 00 00 03 8d 57 6d 6f db 38 12 fe be c0 fe 07 1e 73 87 da a8 2d cb 76 d2 36 92 e5 a2 4d 9b 36 6d 12 24 a9 9b 6e 7a 7b 58 50 e4 48 62 42 91 0a 49 f9 65 b3 f9 ef 07 4a 72 6c e7 a5 6d 0c 44 e4 90 9c 67 e6 99 e1 68 34 ca 6c 2e c6 a3 0c 08 1b 8f 72 b0 04 49 92 43 84 a7 1c 66 85 d2 16 23 aa a4 05 69 23 3c e3 cc 66 11 83 29 a7 d0 ad 26 1d 2e b9 e5 44 74 0d 25 02 a2 3e 1e 8f 2c b7 02 c6 ef 14 2d 73 90 76 d4 ab e7 23 43 35 2f ec 38 29 25 b5 5c 49 94 82 6d b5 6f a6 44 23 15 fd fe db ef bf 61 84 32 6b 0b 13 f4 7a b9 92 5a 41 92 53 8f aa bc a7 7a af e9 f0 62 37 fe fb 68 70 7c fe 6a fe c7 f0 fb 94 7c 3b 16 9f e4 a7 2c ce 4f 77 cf 3f cc 3f d3 fd ef 07 e7 13 3f 67 df c4 d5 c9 f9 f9 e4 ec fc 60 7e 3c 79 3f 3f ba 7c b3 38 de ff ea 1f b9 f1 e4 6b ff 68 16 45 c7 7e 7f 30 3c c6 0e b2 c3 a3 19 97 4c cd 3c a1 28 71 56 79 19 31 59 c8 93 16 6f 3b cb 6c a4 9e e3 2d fc 9c 7b a6 10 dc b6 f0 16 6e ff b7 ff bf 10 84 01 54 6f c0 4b a3 55 92 70 0a c3 17 3b ce 68 1c 36 8a 55 01 b2 65 3b f8 2f 03 22 c1 ed db 51 af e1 a1 e1 03 19 4d 57 3a 28 93 97 c6 a3 42 95 2c 11 44 43 e5 3f b9 24 f3 9e e0 b1 e9 5d 5e 97 a0 17 bd a1 b7 e3 f5 9b 89 97 73 e9 5d 1a 8c b8 b4 90 6a 6e 17 11 36 19 d9 e9 0f ba f1 e1 c4 3f cd 77 cf e5 9b 8b ef ef 12 b1 f8 4c df 92 d3 41 9a fa d9 97 8b e3 53 fd e9 d5 19 17 17 82 5d 9c f6 f7 e7 a7 17 6a ef d0 7e bd 2c cb b3 f2 bb 7a 9e 5c 5e 67 f3 de b5 bd ee f5 b9 fd e4 ef 0d e0 f2 dd 5c d8 ef e7 fb 69 14 61 44 b5 32 46 69 9e 72 19 61 22 95 5c e4 aa 34 78 fc 13 e7 32 22 04 c8 14 1e 78 68 4b 2d 8d e5 02 7a 53 bf 47 0a ee 5d 9a d7 54 e5 05 b1 91 06 4a 0a 4b 33 82 11 31 0b 49 11 83 04 f4 3a 92 5d 08 18 c7 a5 b5 4a 06 89 a2 a5 e9 70 59 94 b6 1e df a8 d2 0a 2e 21 f0 c3 58 cd bb 26 23 4c cd 02 a9 24 dc 7a 46 70 06 ba 51 7f 93 13 9d 72 19 f8 88 94 56 85 55 6e 07 7d df ff 4f 98 01 4f 33 1b 0c 7d bf 98 87 b1 d2 0c 74 57 13 c6 4b 13 6c 17 f3 b0 3e d7 b5 aa 08 fc 7b 3a 11 25 72 4a 4c 90 70 6d 6c 97 66 5c b0 9b 4d 05 3b 77 2a 83 7e 31 47 46 09 ce d0 16 bc 80 57 10 2f 95 ed 29 69 09 97 a0 6f 0a 65 b8 4b d2 40 83 20 96 4f 21 b4 30 b7 5d 22 78 2a 03 0a d2 82 0e 9d b3 dd c6 e4 ed ca 62 42 af 52 ad 4a c9 82 ad e4 65 b2 9b 90 90 2a a1 74 b0 b5 bd b3 bd bb 4d ef b9 34 28 e6 4b e0 38 5d 21 92 |