Click to jump to signature section
Source: file:///C:/Users/user/Desktop/securedoc_20241216T121346.html | Joe Sandbox AI: Score: 10 Reasons: HTML file with login form DOM: 1.0.pages.csv |
Source: 0.10.id.script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: file:///C:/Users/user/Desktop/securedoc_20241216T1... This script exhibits several high-risk behaviors, including dynamic code execution, data exfiltration, and redirects to suspicious domains. The use of obfuscated code and the presence of a payload being sent to an external server are also highly concerning. Overall, this script demonstrates a clear intent to perform malicious activities and should be considered a high-risk threat. |
Source: securedoc_20241216T121346.html | HTTP Parser: document.write |
Source: securedoc_20241216T121346.html | HTTP Parser: location.href |
Source: securedoc_20241216T121346.html | HTTP Parser: .location |
Source: securedoc_20241216T121346.html | HTTP Parser: .location |
Source: securedoc_20241216T121346.html | HTTP Parser: Josh Mejia <Josh.Mejia@mitchell.com> |
Source: file:///C:/Users/user/Desktop/securedoc_20241216T121346.html | HTTP Parser: {'name':null,'msgID':'|1__bd0a17fc00000193d11afb0644e88dbdf42f43bf@esa1.mitchell.iphmx.com','keysize':24,'flags':2049,'rid':'bXlsZXMgb2xzb24gPG1vbHNvbkBmbW5lLmNvbT4=','algnames':{'encryption':{'data':'AES'}},'algparams':{'encryption':{'data':{'IV':'fIfkk05zUSO/RyO4cvoI/g=='}}},'keyserverhost':'res.cisco.com:443','securereplyhost':'res.cisco.com:443','openerhost':'res.cisco.com:443','toc':[['Body-1734380026633.txt',1,'','',13,[0,6068],'Body-1734380026633.txt','ISO-8859-1'],['image001.png',2,'','image001.png',21,[6068,5520],'image001.png','ISO-8859-1'],['MessageBar.html',4,'','',1,[11588,28407],'MessageBar.html','ISO-8859-1']],'salt':'SajcmDqehO0ww5fotwx+YKEuW8Q=','data':['','','']} |
Source: file:///C:/Users/user/Desktop/securedoc_20241216T121346.html | HTTP Parser: |1__bd0a17fc00000193d11afb0644e88dbdf42f43bf@esa1.mitchell.iphmx.com |
Source: file:///C:/Users/user/Desktop/securedoc_20241216T121346.html | HTTP Parser: molson@fmne.com |
Source: file:///C:/Users/user/Desktop/securedoc_20241216T121346.html | HTTP Parser: Number of links: 1 |
Source: securedoc_20241216T121346.html | HTTP Parser: Base64 decoded: Zeppelin rules! |
Source: securedoc_20241216T121346.html | HTTP Parser: Title: Secure Registered Envelope:FN UAT Users @secure does not match URL |
Source: file:///C:/Users/user/Desktop/securedoc_20241216T121346.html | HTTP Parser: Title: Authentication Frame does not match URL |
Source: file:///C:/Users/user/Desktop/securedoc_20241216T121346.html | HTTP Parser: Has password / email / username input fields |
Source: securedoc_20241216T121346.html | HTTP Parser: <input type="password" .../> found |
Source: file:///C:/Users/user/Desktop/securedoc_20241216T121346.html | HTTP Parser: <input type="password" .../> found |
Source: securedoc_20241216T121346.html | HTTP Parser: No favicon |
Source: file:///C:/Users/user/Desktop/securedoc_20241216T121346.html | HTTP Parser: No favicon |
Source: file:///C:/Users/user/Desktop/securedoc_20241216T121346.html | HTTP Parser: No favicon |
Source: file:///C:/Users/user/Desktop/securedoc_20241216T121346.html | HTTP Parser: No favicon |
Source: securedoc_20241216T121346.html | HTTP Parser: No <meta name="author".. found |
Source: file:///C:/Users/user/Desktop/securedoc_20241216T121346.html | HTTP Parser: No <meta name="author".. found |
Source: file:///C:/Users/user/Desktop/securedoc_20241216T121346.html | HTTP Parser: No <meta name="copyright".. found |
Source: unknown | HTTPS traffic detected: 23.218.208.109:443 -> 192.168.2.16:49706 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 23.218.208.109:443 -> 192.168.2.16:49719 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 20.109.210.53:443 -> 192.168.2.16:49726 version: TLS 1.2 |
Source: unknown | HTTPS traffic detected: 20.109.210.53:443 -> 192.168.2.16:49759 version: TLS 1.2 |
Source: chrome.exe | Memory has grown: Private usage: 1MB later: 27MB |
Source: global traffic | HTTP traffic detected: GET /envelopeopener/pf/ZGJAVG9rZW43ODc2OjIxNTQ5/kq2iUBINAy0.LOAHqcY9wMJ551awcCpdSHTCEfGwg4xsepncLRtPZWbVczvVBhFXPfzTCF.4Z9-fAN20QdqA7uIUBKS0bBzrXQ!!/?p=0&d=%7B%27name%27%3Anull,%0D%0A%27msgID%27%3A%27%7C1__bd0a17fc00000193d11afb0644e88dbdf42f43bf%40esa1%2Emitchell%2Eiphmx%2Ecom%27,%0D%0A%27keysize%27%3A24,%0D%0A%27flags%27%3A2049,%0D%0A%27rid%27%3A%27bXlsZXMgb2xzb24gPG1vbHNvbkBmbW5lLmNvbT4%3D%27,%0D%0A%27algnames%27%3A%7B%27encryption%27%3A%7B%27data%27%3A%27AES%27%7D%7D,%0D%0A%27algparams%27%3A%7B%27encryption%27%3A%7B%27data%27%3A%7B%27IV%27%3A%27fIfkk05zUSO%2FRyO4cvoI%2Fg%3D%3D%27%7D%7D%7D,%0D%0A%27keyserverhost%27%3A%27res%2Ecisco%2Ecom%3A443%27,%0D%0A%27securereplyhost%27%3A%27res%2Ecisco%2Ecom%3A443%27,%0D%0A%27openerhost%27%3A%27res%2Ecisco%2Ecom%3A443%27,%0D%0A%27toc%27%3A%5B%0D%0A%5B%27Body-1734380026633%2Etxt%27,1,%0D%0A%27%27,%0D%0A%27%27,%0D%0A13,%5B0,6068%5D,%27Body-1734380026633%2Etxt%27,%0D%0A%27ISO-8859-1%27%5D,%0D%0A%5B%27image001%2Epng%27,2,%0D%0A%27%27,%0D%0A%27image001%2Epng%27,%0D%0A21,%5B6068,5520%5D,%27image001%2Epng%27,%0D%0A%27ISO-8859-1%27%5D,%0D%0A%5B%27MessageBar%2Ehtml%27,4,%0D%0A%27%27,%0D%0A%27%27,%0D%0A1,%5B11588,28407%5D,%27MessageBar%2Ehtml%27,%0D%0A%27ISO-8859-1%27%5D%0D%0A%5D,%0D%0A%27salt%27%3A%27SajcmDqehO0ww5fotwx%2BYKEuW8Q%3D%27,%0D%0A%27data%27%3A%5B%0D%0A%27%27,%27End6kG1Xup0qFCNKcCBJtK8AsyTDq9KNGkXBDtT8s%2FDCtoAz0jZKvni7SQAQLIsP5uEoMoOdwpaR%2Fzxd4k6iK9%2BKX2jwhtpxe5MULXIvVN7gN0i5EPlRtpz4poQ2NsYHjL1padlY8KX7fKJDbhj%2FC%2FB33RqS%2FFfEltRTJfjDcDbfKnCux0uBsZx%2Bn13mp9Hsb%2FVGJlato56ZrU%2FlaB2pur%2B0zsI3QzxWNHY330TnZriKCmhfEGqndLmUvj4FrrkVgfPqeLWewwqzjhs6kDtOX9pIZh%2B4QR4INVISkb%2FBhQcs7uzXpZGWOU4FQGElzBxxa3OvueTqqyrUwC1fUmn9KR2hOheIqVIWvO3Aezr84islcX%2FvdLIhc%2FOI7HWw8KIoLsqui8Ye0U%2BUcZuD5ZdnjrQ4dIQiQ%2F2WJIUNU1yRwaxK%2B9iIQfLDTpgjo9bWNow6XQ2mPZJpscAU5lAOPrKAp%2B%2FrfFZmPUOP%2B3RpIiUBBffDrCZnYjMny8maut9wic5YNmvKVioOeqTrV%2B6ht0tZnEfNSuA37dZr5B8jvahOG4X12s0NAbr3mF1TMOnES92y5Y9zLOAG3GFF0VjyyiWh5UlYiw7gYPmIgT%2BYJlkdeQ5JNeP5hkbWbjbU0T2zlosdhOXsxRj%2FcaLdMvNH2UjGE7YJOh%2Fdb%2FrU75PaImVog04wxbynHuFVN7q48jHrMgF%2BwZOJWq%2Fqlv6OMtOsTHlxADGl70YHcjLHM2X34aS60FiSO1%2FdBnd%2Bo6CtTh3wrH0eGemk%2FF%2FXuqBFnUfkn8c0nEXZey8P%2BeHPVdHrkWwYUpXPKJz7TzD%2FbgohlB1ZGds3vXUgMHUhXAvnt2YCb9v%2BgDZDmVJFdWyDCvPhhj16bGTcDolrfBPa3cO2bxTcxgAf%2FXL3sPpKgdOUwGqC0UbJgMUViXuvoVkqvHl5Eh4t6gGjafiB%2FzLyuft2z6PqsaX5OVA5ww5f9%2BRv86yuldx4URyQ%2Bev%2BwwX03OdRfB3AuOIFug%2FEicBhBnylABDAt%2BVm3aUXzeoWPcCniJVjmCqqRggF9MGVzKBKFRPRF |