Windows Analysis Report
https://jkqbjwq.maxiite.com

Overview

General Information

Sample URL: https://jkqbjwq.maxiite.com
Analysis ID: 1580031
Infos:

Detection

HTMLPhisher
Score: 68
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Yara detected HtmlPhish44
AI detected suspicious Javascript
Form action URLs do not match main URL
HTML body contains low number of good links
HTML body with high number of embedded images detected
HTML title does not match URL

Classification

AV Detection

barindex
Source: https://jkqbjwq.maxiite.com Avira URL Cloud: detection malicious, Label: phishing
Source: https://jkqbjwq.maxiite.com/ Avira URL Cloud: Label: phishing
Source: https://login.microsoftonline.de Avira URL Cloud: Label: phishing

Phishing

barindex
Source: Yara match File source: 0.0.id.script.csv, type: HTML
Source: Yara match File source: dropped/chromecache_376, type: DROPPED
Source: 0.0.id.script.csv Joe Sandbox AI: Detected suspicious JavaScript with source url: https://jkqbjwq.maxiite.com/... This script exhibits several high-risk behaviors, including dynamic code execution through the use of `eval()` and obfuscated code. It also attempts to redirect the user to a domain other than 'google.com', which is a strong indicator of malicious intent. The script appears to be attempting to execute remote or dynamically generated code, which poses a significant security risk. Overall, this script demonstrates a high level of suspicious and potentially malicious activity.
Source: https://www.bing.com/search?q=office HTTP Parser: Form action: https://login.microsoftonline.com/common/oauth2/authorize?client_id=9ea1ad79-fdb6-4f9a-8bc3-2b70f96e34c7&response_type=id_token+code&nonce=abfad05d-9a76-4d44-8534-216d99737b62&redirect_uri=https%3a%2f%2fwww.bing.com%2forgid%2fidtoken%2fconditional&scope=openid%20email%20profile%209ea1ad79-fdb6-4f9a-8bc3-2b70f96e34c7/.default&response_mode=form_post&instance_aware=true&msafed=0&prompt=none&state=%7b%22ig%22%3a%2233097A094B7E4685822C3A3929157F3C%22%7d&sso_reload=true bing microsoftonline
Source: https://www.bing.com/search?q=office HTTP Parser: Number of links: 0
Source: https://www.bing.com/search?q=office HTTP Parser: Total embedded image size: 26001
Source: https://www.bing.com/search?q=office HTTP Parser: Title: Redirecting does not match URL
Source: https://www.office.com/ HTTP Parser: Title: Login | Microsoft 365 does not match URL
Source: https://www.bing.com/search?q=office HTTP Parser: No favicon
Source: https://www.bing.com/search?q=office HTTP Parser: No favicon
Source: https://www.bing.com/search?q=office HTTP Parser: No <meta name="author".. found
Source: https://www.office.com/ HTTP Parser: No <meta name="author".. found
Source: https://www.bing.com/search?q=office HTTP Parser: No <meta name="copyright".. found
Source: https://www.office.com/ HTTP Parser: No <meta name="copyright".. found
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google Jump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\GoogleUpdater Jump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\chrome_BITS_492_173025682 Jump to behavior
Source: global traffic HTTP traffic detected: GET / HTTP/1.1Host: jkqbjwq.maxiite.comConnection: keep-alivesec-ch-ua: "Not_A Brand";v="99", "Google Chrome";v="109", "Chromium";v="109"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /meversion?partner=office&market=en-us&uhf=1 HTTP/1.1Host: mem.gfx.msConnection: keep-alivesec-ch-ua: "Not_A Brand";v="99", "Google Chrome";v="109", "Chromium";v="109"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://www.office.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /meversion?partner=office&market=en-us&uhf=1 HTTP/1.1Host: mem.gfx.msConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /scripts/c/ms.shared.analytics.mectrl-3.gbl.min.js HTTP/1.1Host: js.monitor.azure.comConnection: keep-alivesec-ch-ua: "Not_A Brand";v="99", "Google Chrome";v="109", "Chromium";v="109"Origin: https://www.office.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://www.office.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /scripts/c/ms.shared.analytics.mectrl-3.gbl.min.js HTTP/1.1Host: js.monitor.azure.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: chromecache_411.1.dr, chromecache_320.1.dr String found in binary or memory: 26" data-priority="2"><div class="na_card_wrp na_ccw_wrp" data-priority="2"><a class="na_ccw tc r_img" url="https://www.yahoo.com/tech/own-whole-microsoft-office-suite-050000231.html" data-priority="2" titletext="Own the whole Microsoft Office suite for life for just equals www.yahoo.com (Yahoo)
Source: chromecache_411.1.dr, chromecache_320.1.dr String found in binary or memory: 26" href="https://www.yahoo.com/tech/own-whole-microsoft-office-suite-050000231.html" h="ID=NEWS.401_0,5053.1"><div class="citm_img"><div class="imagewrap"><img title="Own the whole Microsoft Office suite for life for just equals www.yahoo.com (Yahoo)
Source: chromecache_411.1.dr, chromecache_320.1.dr String found in binary or memory: get the lifetime version that pays for itself</div></div></a></div></div><div class="na_cai" url="https://www.yahoo.com/tech/own-whole-microsoft-office-suite-050000231.html" titletext="Own the whole Microsoft Office suite for life for just equals www.yahoo.com (Yahoo)
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: global traffic DNS traffic detected: DNS query: jkqbjwq.maxiite.com
Source: global traffic DNS traffic detected: DNS query: a.nel.cloudflare.com
Source: global traffic DNS traffic detected: DNS query: www.office.com
Source: global traffic DNS traffic detected: DNS query: login.microsoftonline.com
Source: global traffic DNS traffic detected: DNS query: outlook.office.com
Source: global traffic DNS traffic detected: DNS query: portal.office.com
Source: global traffic DNS traffic detected: DNS query: substrate.office.com
Source: global traffic DNS traffic detected: DNS query: mem.gfx.ms
Source: global traffic DNS traffic detected: DNS query: js.monitor.azure.com
Source: global traffic DNS traffic detected: DNS query: m365cdn.nel.measure.office.net
Source: global traffic DNS traffic detected: DNS query: services.bingapis.com
Source: unknown HTTP traffic detected: POST /report/v4?s=UUaZ%2FHZfFyQVvb3r%2Fd0zCUCc6VTBRokIpiY89p5q3jNwkzgygg7taaKsBub10Zqq0GrUihLAcZQhlkJhISGUeC%2Fj24RxHJQh%2Bw5SF7OXoEo3ZWmiXG1s8NMu9GWMK34BL1OHlhop HTTP/1.1Host: a.nel.cloudflare.comConnection: keep-aliveContent-Length: 390Content-Type: application/reports+jsonUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: chromecache_348.1.dr, chromecache_360.1.dr String found in binary or memory: http://github.com/requirejs/almond/LICENSE
Source: chromecache_247.1.dr String found in binary or memory: https://3pcookiecheck.azureedge.net
Source: chromecache_508.1.dr, chromecache_291.1.dr String found in binary or memory: https://github.com/zloirock/core-js
Source: chromecache_508.1.dr, chromecache_291.1.dr String found in binary or memory: https://github.com/zloirock/core-js/blob/v3.37.1/LICENSE
Source: chromecache_417.1.dr String found in binary or memory: https://login.chinacloudapi.cn
Source: chromecache_417.1.dr String found in binary or memory: https://login.microsoftonline.com
Source: chromecache_417.1.dr String found in binary or memory: https://login.microsoftonline.de
Source: chromecache_417.1.dr String found in binary or memory: https://login.microsoftonline.us
Source: chromecache_417.1.dr String found in binary or memory: https://login.windows-ppe.net
Source: chromecache_247.1.dr String found in binary or memory: https://portal.office.com
Source: chromecache_247.1.dr String found in binary or memory: https://portal.office.com/adminportal/home
Source: chromecache_349.1.dr, chromecache_379.1.dr String found in binary or memory: https://services.bingapis.com/favicon/?url=
Source: chromecache_320.1.dr String found in binary or memory: https://www.bloomberg.com/news/articles/2024-12-12/amazon-paused-rollout-of-microsoft-office-for-a-y
Source: chromecache_247.1.dr String found in binary or memory: https://www.geekwire.com/2024/early-microsoft-leaders-go-all-in-on-ai-with-seattle-area-startup-tota
Source: chromecache_320.1.dr String found in binary or memory: https://www.maketecheasier.com/create-microsoft-passkey/
Source: chromecache_247.1.dr String found in binary or memory: https://www.msn.com/en-in/entertainment/southcinema/pushpa-2-box-office-collection-day-18-allu-arjun
Source: chromecache_247.1.dr String found in binary or memory: https://www.msn.com/en-in/entertainment/southcinema/pushpa-2-the-rule-box-office-collection-the-allu
Source: chromecache_247.1.dr String found in binary or memory: https://www.msn.com/en-us/lifestyle/shopping/this-free-microsoft-office-alternative-has-just-as-many
Source: chromecache_411.1.dr, chromecache_320.1.dr String found in binary or memory: https://www.msn.com/en-us/money/other/amazon-paused-rollout-of-microsoft-office-for-a-year-after-hac
Source: chromecache_247.1.dr String found in binary or memory: https://www.msn.com/en-us/money/other/apple-targets-new-miami-office-space-following-amazon-microsof
Source: chromecache_411.1.dr, chromecache_320.1.dr String found in binary or memory: https://www.msn.com/en-us/money/other/skip-the-subscription-drama-and-own-office-2019-forever/ar-AA1
Source: chromecache_247.1.dr String found in binary or memory: https://www.msn.com/en-us/movies/news/8-huge-box-office-disappointments-in-hollywood-history/ss-BB1m
Source: chromecache_247.1.dr String found in binary or memory: https://www.msn.com/en-us/news/technology/early-microsoft-leaders-go-all-in-on-ai-with-seattle-area-
Source: chromecache_247.1.dr String found in binary or memory: https://www.office.com
Source: chromecache_247.1.dr String found in binary or memory: https://www.office.com/?omkt=en-001
Source: chromecache_247.1.dr String found in binary or memory: https://www.office.com/caplogin
Source: chromecache_320.1.dr String found in binary or memory: https://www.pcworld.com/article/2553754/skip-the-subscription-drama-and-own-office-2019-forever.html
Source: chromecache_320.1.dr String found in binary or memory: https://www.popsci.com/sponsored-content/microsoft-office-permanent-license-sponsored-deal/
Source: chromecache_320.1.dr String found in binary or memory: https://www.seattletimes.com/business/microsoft/heres-how-microsoft-is-tracking-in-office-work/
Source: chromecache_320.1.dr String found in binary or memory: https://www.yahoo.com/tech/own-whole-microsoft-office-suite-050000231.html
Source: unknown Network traffic detected: HTTP traffic on port 49517 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49169
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49168
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49167
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49166
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49172
Source: unknown Network traffic detected: HTTP traffic on port 49172 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49168 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49169 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49167 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49166 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49517
Source: classification engine Classification label: mal68.phis.win@24/516@34/5
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe File created: C:\Program Files\Google Jump to behavior
Source: unknown Process created: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Process created: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1456 --field-trial-handle=1248,i,18209298034698684818,12563364091482857980,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" "https://jkqbjwq.maxiite.com"
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Process created: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1456 --field-trial-handle=1248,i,18209298034698684818,12563364091482857980,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google Jump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\GoogleUpdater Jump to behavior
Source: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\chrome_BITS_492_173025682 Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs