Click to jump to signature section
Source: https://pub-cb48a1f3508c49e29943cfa5c56fda5c.r2.dev/gteuiwopqvsfsf | Joe Sandbox AI: Score: 9 Reasons: The brand 'Microsoft' is classified as 'wellknown'., The URL 'pub-cb48a1f3508c49e29943cfa5c56fda5c.r2.dev' does not match the legitimate domain 'microsoft.com'., The domain 'r2.dev' is not associated with Microsoft and appears to be a generic or cloud service domain., The presence of a Microsoft-related input field on a non-Microsoft domain is suspicious and indicative of phishing. DOM: 2.15.pages.csv |
Source: https://pub-cb48a1f3508c49e29943cfa5c56fda5c.r2.dev/gteuiwopqvsfsf | Joe Sandbox AI: Score: 9 Reasons: The brand 'Microsoft' is well-known and typically associated with the domain 'microsoft.com'., The provided URL 'pub-cb48a1f3508c49e29943cfa5c56fda5c.r2.dev' does not match the legitimate domain 'microsoft.com'., The URL contains a random string and uses the 'r2.dev' domain, which is not associated with Microsoft., The presence of a random string and an unusual domain extension is a common tactic in phishing attempts., The input field requests a Microsoft email, which could be used to harvest credentials. DOM: 2.14.pages.csv |
Source: Email | Joe Sandbox AI: Detected potential phishing email: The email claims to require review/signature of an employee document but comes from an unrelated commercial domain (therasage.com). The subject line contains a suspicious random-looking code (8VM8-WZPT3L-LYH1) typical of phishing attempts. The email includes unnecessary legal disclaimers in multiple languages to appear legitimate |
Source: 0.4.id.script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: https://www.google.com/recaptcha/api2/anchor?ar=1&... The provided JavaScript snippet exhibits several high-risk behaviors, including dynamic code execution, data exfiltration, and obfuscated code/URLs. While the script may have a legitimate purpose, such as reCAPTCHA integration, the aggressive and opaque nature of the implementation raises significant security concerns. Further investigation is recommended to determine the true intent and potential impact of this script. |
Source: https://pub-cb48a1f3508c49e29943cfa5c56fda5c.r2.dev/gteuiwopqvsfsf | HTTP Parser: Number of links: 0 |
Source: https://pub-cb48a1f3508c49e29943cfa5c56fda5c.r2.dev/gteuiwopqvsfsf | HTTP Parser: Base64 decoded: https://zooz-jo.com/teygsye/ |
Source: https://pub-cb48a1f3508c49e29943cfa5c56fda5c.r2.dev/gteuiwopqvsfsf | HTTP Parser: Title: Ui does not match URL |
Source: Email | Classification: Credential Stealer |
Source: http://elysiumproperties.net/gtoephye | HTTP Parser: No favicon |
Source: http://elysiumproperties.net/gtoephye | HTTP Parser: No favicon |
Source: http://elysiumproperties.net/gtoephye | HTTP Parser: No favicon |
Source: http://elysiumproperties.net/gtoephye | HTTP Parser: No favicon |
Source: http://elysiumproperties.net/gtoephye | HTTP Parser: No favicon |
Source: http://elysiumproperties.net/gtoephye | HTTP Parser: No favicon |
Source: http://elysiumproperties.net/gtoephye | HTTP Parser: No favicon |
Source: http://elysiumproperties.net/gtoephye | HTTP Parser: No favicon |
Source: http://elysiumproperties.net/gtoephye | HTTP Parser: No favicon |
Source: http://elysiumproperties.net/gtoephye | HTTP Parser: No favicon |
Source: http://elysiumproperties.net/gtoephye | HTTP Parser: No favicon |
Source: http://elysiumproperties.net/gtoephye | HTTP Parser: No favicon |
Source: http://elysiumproperties.net/gtoephye | HTTP Parser: No favicon |
Source: https://pub-cb48a1f3508c49e29943cfa5c56fda5c.r2.dev/gteuiwopqvsfsf | HTTP Parser: No favicon |
Source: https://pub-cb48a1f3508c49e29943cfa5c56fda5c.r2.dev/gteuiwopqvsfsf | HTTP Parser: No favicon |
Source: https://pub-cb48a1f3508c49e29943cfa5c56fda5c.r2.dev/gteuiwopqvsfsf | HTTP Parser: No <meta name="author".. found |
Source: https://pub-cb48a1f3508c49e29943cfa5c56fda5c.r2.dev/gteuiwopqvsfsf | HTTP Parser: No <meta name="author".. found |
Source: https://pub-cb48a1f3508c49e29943cfa5c56fda5c.r2.dev/gteuiwopqvsfsf | HTTP Parser: No <meta name="copyright".. found |
Source: https://pub-cb48a1f3508c49e29943cfa5c56fda5c.r2.dev/gteuiwopqvsfsf | HTTP Parser: No <meta name="copyright".. found |
Source: unknown | HTTPS traffic detected: 20.109.210.53:443 -> 192.168.2.16:49753 version: TLS 1.2 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.53.18 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.53.18 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.53.18 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.53.18 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.53.18 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.53.18 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.53.18 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.53.18 |
Source: unknown | TCP traffic detected without corresponding DNS query: 204.79.197.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.53.18 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.53.18 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.53.18 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.53.18 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.53.18 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.53.18 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.53.18 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.126.53.18 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.189.173.10 |
Source: unknown | TCP traffic detected without corresponding DNS query: 96.17.64.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 96.17.64.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 96.17.64.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 96.17.64.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 96.17.64.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 96.17.64.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 96.17.64.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 96.17.64.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 96.17.64.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 96.17.64.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 96.17.64.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.229.211.108 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: global traffic | HTTP traffic detected: GET /gtoephye HTTP/1.1Host: elysiumproperties.netConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9 |
Source: global traffic | HTTP traffic detected: GET /favicon.ico HTTP/1.1Host: elysiumproperties.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://elysiumproperties.net/gtoephyeAccept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9 |
Source: global traffic | DNS traffic detected: DNS query: www.google.pt |
Source: global traffic | DNS traffic detected: DNS query: www.google.com |
Source: global traffic | DNS traffic detected: DNS query: elysiumproperties.net |
Source: global traffic | DNS traffic detected: DNS query: x1.i.lencr.org |
Source: global traffic | DNS traffic detected: DNS query: pub-cb48a1f3508c49e29943cfa5c56fda5c.r2.dev |
Source: global traffic | DNS traffic detected: DNS query: i.gyazo.com |
Source: global traffic | HTTP traffic detected: HTTP/1.1 404 Not FoundConnection: Keep-AliveKeep-Alive: timeout=5, max=100cache-control: private, no-cache, no-store, must-revalidate, max-age=0pragma: no-cachecontent-type: text/htmlcontent-length: 796date: Mon, 23 Dec 2024 17:51:12 GMTData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 73 74 79 6c 65 3d 22 68 65 69 67 68 74 3a 31 30 30 25 22 3e 0a 3c 68 65 61 64 3e 0a 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2c 20 73 68 72 69 6e 6b 2d 74 6f 2d 66 69 74 3d 6e 6f 22 20 2f 3e 0a 3c 74 69 74 6c 65 3e 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0d 0a 3c 2f 74 69 74 6c 65 3e 3c 73 74 79 6c 65 3e 40 6d 65 64 69 61 20 28 70 72 65 66 65 72 73 2d 63 6f 6c 6f 72 2d 73 63 68 65 6d 65 3a 64 61 72 6b 29 7b 62 6f 64 79 7b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 30 30 30 21 69 6d 70 6f 72 74 61 6e 74 7d 7d 3c 2f 73 74 79 6c 65 3e 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 20 73 74 79 6c 65 3d 22 63 6f 6c 6f 72 3a 20 23 34 34 34 3b 20 6d 61 72 67 69 6e 3a 30 3b 66 6f 6e 74 3a 20 6e 6f 72 6d 61 6c 20 31 34 70 78 2f 32 30 70 78 20 41 72 69 61 6c 2c 20 48 65 6c 76 65 74 69 63 61 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 20 68 65 69 67 68 74 3a 31 30 30 25 3b 20 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 20 23 66 66 66 3b 22 3e 0a 3c 64 69 76 20 73 74 79 6c 65 3d 22 68 65 69 67 68 74 3a 61 75 74 6f 3b 20 6d 69 6e 2d 68 65 69 67 68 74 3a 31 30 30 25 3b 20 22 3e 20 20 20 20 20 3c 64 69 76 20 73 74 79 6c 65 3d 22 74 65 78 74 2d 61 6c 69 67 6e 3a 20 63 65 6e 74 65 72 3b 20 77 69 64 74 68 3a 38 30 30 70 78 3b 20 6d 61 72 67 69 6e 2d 6c 65 66 74 3a 20 2d 34 30 30 70 78 3b 20 70 6f 73 69 74 69 6f 6e 3a 61 62 73 6f 6c 75 74 65 3b 20 74 6f 70 3a 20 33 30 25 3b 20 6c 65 66 74 3a 35 30 25 3b 22 3e 0a 20 20 20 20 20 20 20 20 3c 68 31 20 73 74 79 6c 65 3d 22 6d 61 72 67 69 6e 3a 30 3b 20 66 6f 6e 74 2d 73 69 7a 65 3a 31 35 30 70 78 3b 20 6c 69 6e 65 2d 68 65 69 67 68 74 3a 31 35 30 70 78 3b 20 66 6f 6e 74 2d 77 65 69 67 68 74 3a 62 6f 6c 64 3b 22 3e 34 30 34 3c 2f 68 31 3e 0a 3c 68 32 20 73 74 79 6c 65 3d 22 6d 61 72 67 69 6e 2d 74 6f 70 3a 32 30 70 78 3b 66 6f 6e 74 2d 73 69 7a 65 3a 20 33 30 70 78 3b 22 3e 4e 6f 74 20 46 6f 75 6e 64 0d 0a 3c 2f 68 32 3e 0a 3c 70 3e 54 68 65 20 72 65 73 6f 75 72 63 65 20 72 65 71 75 65 73 74 65 64 20 63 6f 75 6c 64 20 6e 6f 74 20 62 |