Click to jump to signature section
Source: 0.9.id.script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: file:///C:/Users/user/Desktop/securedoc_20241217... This script exhibits several high-risk behaviors, including dynamic code execution, data exfiltration, and redirects to a suspicious domain. The use of obfuscated code and the presence of a payload further increase the risk. While the script may have a legitimate purpose, the overall behavior is highly suspicious and indicative of a potential malicious attack. |
Source: securedoc_20241217T163143.html | HTTP Parser: document.write |
Source: securedoc_20241217T163143.html | HTTP Parser: location.href |
Source: securedoc_20241217T163143.html | HTTP Parser: .location |
Source: securedoc_20241217T163143.html | HTTP Parser: .location |
Source: securedoc_20241217T163143.html | HTTP Parser: "Vitug, Ivory" <ivory_vitug@uhc.com> |
Source: securedoc_20241217T163143.html | HTTP Parser: Secure Message from ivory_vitug@uhc.com |
Source: file:///C:/Users/user/Desktop/securedoc_20241217T163143.html | HTTP Parser: {'name':null,'msgID':'|1__f7c9ffd700000193d6bfa156956fcd82f58cb999@mail10674.corpmailsvcs.com','keysize':24,'flags':3073,'rid':'ImNyaXNlbGRhLnBvcGFyZGFAZGlzaC5jb20iIDxjcmlzZWxkYS5wb3BhcmRhQGRpc2guY29tPg==','algnames':{'encryption':{'data':'AES'}},'algparams':{'encryption':{'data':{'IV':'xwra6T5w21Foe2SY2dyOYg=='}}},'keyserverhost':'res.cisco.com:443','securereplyhost':'res.cisco.com:443','openerhost':'res.cisco.com:443','toc':[['Body-1734474703193.txt',1,'','',3,[0,10145],'Body-1734474703193.txt','ISO-8859-1'],['MessageBar.html',4,'','',1,[10145,30693],'MessageBar.html','ISO-8859-1']],'salt':'XF4qSvYULsPOpMleLGGK1IxTN+o=','data':['','','']} |
Source: securedoc_20241217T163143.html | HTTP Parser: Base64 decoded: Zeppelin rules! |
Source: securedoc_20241217T163143.html | HTTP Parser: Title: Secure Registered Envelope:Secure Message from ivory_vitug@uhc.com does not match URL |
Source: securedoc_20241217T163143.html | HTTP Parser: <input type="password" .../> found |
Source: securedoc_20241217T163143.html | HTTP Parser: No favicon |
Source: file:///C:/Users/user/Desktop/securedoc_20241217T163143.html | HTTP Parser: No favicon |
Source: file:///C:/Users/user/Desktop/securedoc_20241217T163143.html | HTTP Parser: No favicon |
Source: https://res.cisco.com/websafe/help?topic=AddrNotShown | HTTP Parser: No favicon |
Source: securedoc_20241217T163143.html | HTTP Parser: No <meta name="author".. found |
Source: global traffic | HTTP traffic detected: GET /envelopeopener/pf/ZGJAVG9rZW4zMzcxOjEzNTk2/JPtRSgzT29u6egjoYim1K1kOrPOg3i.wUY14OLNx2pxFcykbpQWPXsZrvf3cBhrTAcvWwLNvGPQHe36qMaTJ-bT256B.sHk28g!!/?p=0&d=%7B%27name%27%3Anull,%0D%0A%27msgID%27%3A%27%7C1__f7c9ffd700000193d6bfa156956fcd82f58cb999%40mail10674%2Ecorpmailsvcs%2Ecom%27,%0D%0A%27keysize%27%3A24,%0D%0A%27flags%27%3A3073,%0D%0A%27rid%27%3A%27ImNyaXNlbGRhLnBvcGFyZGFAZGlzaC5jb20iIDxjcmlzZWxkYS5wb3BhcmRhQGRpc2guY29tPg%3D%3D%27,%0D%0A%27algnames%27%3A%7B%27encryption%27%3A%7B%27data%27%3A%27AES%27%7D%7D,%0D%0A%27algparams%27%3A%7B%27encryption%27%3A%7B%27data%27%3A%7B%27IV%27%3A%27xwra6T5w21Foe2SY2dyOYg%3D%3D%27%7D%7D%7D,%0D%0A%27keyserverhost%27%3A%27res%2Ecisco%2Ecom%3A443%27,%0D%0A%27securereplyhost%27%3A%27res%2Ecisco%2Ecom%3A443%27,%0D%0A%27openerhost%27%3A%27res%2Ecisco%2Ecom%3A443%27,%0D%0A%27toc%27%3A%5B%0D%0A%5B%27Body-1734474703193%2Etxt%27,1,%0D%0A%27%27,%0D%0A%27%27,%0D%0A3,%5B0,10145%5D,%27Body-1734474703193%2Etxt%27,%0D%0A%27ISO-8859-1%27%5D,%0D%0A%5B%27MessageBar%2Ehtml%27,4,%0D%0A%27%27,%0D%0A%27%27,%0D%0A1,%5B10145,30693%5D,%27MessageBar%2Ehtml%27,%0D%0A%27ISO-8859-1%27%5D%0D%0A%5D,%0D%0A%27salt%27%3A%27XF4qSvYULsPOpMleLGGK1IxTN%2Bo%3D%27,%0D%0A%27data%27%3A%5B%0D%0A%27%27,%27dETZtMRHd3BdyJ%2FldEp2SWGfrHUUH2%2F9tOwP%2FuQNq%2BPNNzjNEtG6UiZDAmwjZUq0JR2u%2FWcClMNPM%2BEjE8fpKMqMyG4ps2JTuRmjlOWIL3fMYyysk6vvXTGkgXFvu0nuw2BTNyJxQ8hBRydMFw6nOUHJjPPMk6d6CGHnJGsvMANJibzMIgqyfe6X4uaLdWED%2FqstEjQd75%2B04OPiq8R4ZMAid4th%2BZehGocnmzFOeWF9J5T3smAI0Ur0w62zz5M22cJuVMfXKci1btEIfsBdACYFeka%2FOcQTL3IbLVch5ySSmqRrzL4cOzGkyZPgSvh%2FQF0e%2BWqpXQyjQ0r9rLGxZCpYh3DIWZRbXXmD5STpZHwZ7EDdcEAgU0BiYcLTvQRLx00tHx%2F16yzCM9ysgnTomxZNTkOI55jZCpf1DoC2LF4twOn7pCAjP%2F1CwY%2FEHodV2vtxW%2FEZgFDWJtjD5gNMotnJOF0mDeq%2BJpr7pNrYJy5Kuf0Y9K%2B%2Bza98d2t5Yl5tYCBBcF7yAUIi2FbUFCMe9GlQk7NOnwVNYmMAEe9YI2FNn56dcjUdMtQSdXYaRNoN8eE%2BS%2FRk9VlNJ4PMzFtBXomJtEn%2F68y4AkhBG82h7oWZMVY9iPu%2FgvSNrBx0q0IV3kFc%2FyQy0RORs6unXOLBCZVXUqwwff48tGH37gJhOEG7xP6HTJIHUo3fDtK6xYSYlta9Zx3DI5ggeaNhWzoEeSquqCl7rmCuaEofK8GY70fRfnNB8V%2BNnpxeO3ZodsaRg1xTrZpI5C%2FMLtH0qAJHfbOuk8Jo3jf9t%2FWqmVlXZrzbEUWrPLDIF7k1vdWD3nARXdiWugwyzyGjLlx6Cp9NAiwTP5TBRAaHzQm8V1%2BBRZAXWEF5wcBJiS2IF%2BrlLOrh4AzC8x%2BLBKLc8gbOySshk5jcjyCjHLL0CYrYWIQ6q4I4%2B1yFnm4uGbAG6Uco7qTIECSxStD6VN2JS3cLSKnM2Y3nCCrcc0BtMPeV6qQ4Je14hCKpwZ2%2BKArl6WOr9mifwlBnCRYZCGyEWT4%2BKv75y15yE6XeMUomQzJtXNBjOcvHr3VaIXkp8v6Zhw7ecMFYpVZ6bzcAXba9VIqjbOBMD3%2BKcRr1BL1R%2FvFSSGfMMMT0wG4ngJt17pjCHB%2BU8W2xWZ3vKNWa2xtyBxx05TEc0r5x8%2B |