Windows Analysis Report
https://hightailspaces-us-east-1.s3.amazonaws.com/1ea3bd2d-d820-4963-aaed-9f1480fe08c2?response-content-disposition=attachment%3B%20filename%2A%3DUTF-8%27%27Lena--paul_photos%252B18s%20.zip&X-Amz-Security-Token=IQoJb3JpZ2luX2VjEAsaCXVzLWVhc3QtMSJIMEYCIQDm7mgm%2F3yD5%2Bz4jVRC%2Bq%2BaTpqP2igd9ZomW07D2

Overview

General Information

Sample URL: https://hightailspaces-us-east-1.s3.amazonaws.com/1ea3bd2d-d820-4963-aaed-9f1480fe08c2?response-content-disposition=attachment%3B%20filename%2A%3DUTF-8%27%27Lena--paul_photos%252B18s%20.zip&X-Amz-Secu
Analysis ID: 1566850

Detection

Score: 0
Range: 0 - 100
Whitelisted: false
Confidence: 60%

Signatures

Stores files to the Windows start menu directory

Classification

Source: unknown HTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.18:49706 version: TLS 1.2
Source: unknown HTTPS traffic detected: 2.16.158.186:443 -> 192.168.2.18:49707 version: TLS 1.2
Source: unknown HTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.18:49708 version: TLS 1.2
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 52.182.141.63
Source: unknown TCP traffic detected without corresponding DNS query: 52.182.141.63
Source: unknown TCP traffic detected without corresponding DNS query: 52.182.141.63
Source: unknown TCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknown TCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknown TCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknown TCP traffic detected without corresponding DNS query: 52.182.141.63
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknown TCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknown TCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknown TCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknown TCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknown TCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknown TCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknown TCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknown TCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknown TCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknown TCP traffic detected without corresponding DNS query: 20.12.23.50
Source: unknown TCP traffic detected without corresponding DNS query: 52.182.141.63
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 52.182.141.63
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 52.182.141.63
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.177.22
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.177.22
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.177.22
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.177.22
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.177.22
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.177.22
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.177.22
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.177.22
Source: unknown TCP traffic detected without corresponding DNS query: 2.16.158.186
Source: unknown TCP traffic detected without corresponding DNS query: 2.16.158.186
Source: unknown TCP traffic detected without corresponding DNS query: 2.16.158.186
Source: unknown TCP traffic detected without corresponding DNS query: 2.16.158.186
Source: unknown TCP traffic detected without corresponding DNS query: 2.16.158.186
Source: unknown TCP traffic detected without corresponding DNS query: 2.16.158.186
Source: unknown TCP traffic detected without corresponding DNS query: 2.16.158.186
Source: unknown TCP traffic detected without corresponding DNS query: 2.16.158.186
Source: unknown TCP traffic detected without corresponding DNS query: 2.16.158.186
Source: unknown TCP traffic detected without corresponding DNS query: 2.16.158.186
Source: global traffic DNS traffic detected: DNS query: hightailspaces-us-east-1.s3.amazonaws.com
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: unknown Network traffic detected: HTTP traffic on port 49708 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49710 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49710
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49688
Source: unknown Network traffic detected: HTTP traffic on port 49673 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49706 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49697
Source: unknown Network traffic detected: HTTP traffic on port 49707 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49705 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49696
Source: unknown Network traffic detected: HTTP traffic on port 49679 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49697 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49696 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49703 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49704 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49688 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49708
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49707
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49706
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49705
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49704
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49703
Source: unknown HTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.18:49706 version: TLS 1.2
Source: unknown HTTPS traffic detected: 2.16.158.186:443 -> 192.168.2.18:49707 version: TLS 1.2
Source: unknown HTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.18:49708 version: TLS 1.2
Source: classification engine Classification label: clean0.win@17/6@4/101
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2204 --field-trial-handle=1896,i,4686970303018976477,7733449025737329463,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://hightailspaces-us-east-1.s3.amazonaws.com/1ea3bd2d-d820-4963-aaed-9f1480fe08c2?response-content-disposition=attachment%3B%20filename%2A%3DUTF-8%27%27Lena--paul_photos%252B18s%20.zip&X-Amz-Security-Token=IQoJb3JpZ2luX2VjEAsaCXVzLWVhc3QtMSJIMEYCIQDm7mgm%2F3yD5%2Bz4jVRC%2Bq%2BaTpqP2igd9ZomW07D2vKt%2BwIhAMG2JC%2BE8ZfI1vnT50lw04YRgzXdofaWt2J2iOVpE78%2FKrsFCLP%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEQABoMNzA3OTQyMTU3MzIwIgy5yRqns9APGWoLh6QqjwU6NQFYdX7sNL9ni28CaOrTq7Jn74FVCSQ6erO%2FDVRxossfXhXo8wHS5tjrSzufs11fAt0pFU14hiQgAg4UrpG2OZlsYxbdD1BUUA6qH5Js%2Fmz%2BB0%2FDzmf%2FutPh0B9FP%2FdT3SjSOxl6lDtRK%2BGFSJUx%2BEeuOdZqXqy4N0C8LUIZW5yPFlnPWKA%2BEkrcU4cyqHKIwJNVDxF9jAmxeijFiXSIO5pXapBLl8hjSOF0PY4SaPfhHllopBPapprTDimcxNQ9PtUoX490c6bioWCClRkoCV58Nc4sdCX%2FixC939nOhN5KNQCCmwUdKyb9N6fVvbsrm8nU75ekT%2FjCCbfQdG4I%2FeOCZXU8WQDbBwWYVta%2Bu5gTgDzu671YzqikrX73yNcmhkRJ0Bqj3cUMh7QYQb292muQ4Ki%2BC1ca837IDzxzxOIeYozp3d6ErCJdHkhjUeVjn5%2FW43h0%2BrkACN8GKqxG0oN3IbXVftyAZP%2BEgbAak7PzyTThwnhjoc4iElwNjIThUPlhZOaYEQwuoj76MgTB6E18jpwyUxMzoyE6kaXLYUkfkQlsL5bA14qUYLOGi49CKptqNgjHu84tkOuYB8tb2%2Fk30qsLWQQzFkS%2BQSD5Gp6xEzKqBVOWwSWUSBKQRhgYsf61%2FKmDDneV7cTOaKc17pWoEqom%2BgbCgn4wrb4kJs6EMXYPZDvnbDPvJVuqjQzQDGN%2BD8dy2xohIJ0pjyOYX%2FBtuvmvpRKfocVkRgsdc0MCa1BQr%2F3bCM9THcnsThZz%2FfBlrrt1m4BnwwHmDO9ap6DhMNn9fP4QIwPaDKupfaaNNt20ocfW4QnrQcOKxJAchIKfnc%2B3qu7WK8OqNfUBoIN40hMYatshfrERPdO2MNewtLoGOrABi%2FWrgW38KpoBKYHgDvWjhKqOZYcALwkvtzQZm8b3kD5gUOl7mzbJnBBGbFEmXFOGjBRYJl2IR0vXXOGOdTnI7GXumqfOUJS7XvCVQulYBNQYjDU7wVtlBdREYjhWc%2B4Cc557d88vKbjuU2Kz2tChmIhAYoJaihRYiu5OkRoYvFDE8Xt%2BRIuCZThhgmj879AfyEUbBJGpd8jMy199ae54dl%2FBY5rDQXNW0N%2F9yxMb4J8%3D&X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Date=20241202T022606Z&X-Amz-SignedHeaders=host&X-Amz-Credential=ASIA2JVFEBQEFOAF4TZO%2F20241202%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Expires=28800&X-Amz-Signature=8a8fdb41c0af7e05ed8bd4ed523c5b698595db8f449e7f445d2bed92028eed3c"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2204 --field-trial-handle=1896,i,4686970303018976477,7733449025737329463,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs