Click to jump to signature section
Source: https://connect.secure.access.weilsfargoadvisors.com/auth/login/present | Joe Sandbox AI: Score: 9 Reasons: The brand 'Wells Fargo' is a well-known financial institution., The URL 'connect.secure.access.weilsfargoadvisors.com' contains multiple subdomains which can be legitimate for internal or specific services., The main domain 'weilsfargoadvisors.com' is suspicious due to the misspelling of 'wellsfargo' as 'weilsfargo'., Legitimate Wells Fargo domains typically use 'wellsfargo.com'., The presence of input fields for 'Username' and 'Password' on a suspicious domain increases the risk of phishing. DOM: 5.11.pages.csv |
Source: 5.68..script.csv | Joe Sandbox AI: Detected suspicious JavaScript with source url: https://connect.secure.access.weilsfargoadvisors.c... This script demonstrates several high-risk behaviors, including data exfiltration, dynamic code execution, and suspicious message posting. The script fetches the user's IP details and sends them to an unknown server, and it also checks the page content for specific keywords and posts corresponding messages to the same server. This behavior is highly suspicious and could be indicative of a malicious script designed to steal user information and potentially perform other malicious actions. |
Source: URL | Joe Sandbox AI: AI detected Brand spoofing attempt in URL: https://connect.secure.access.weilsfargoadvisors.com |
Source: URL | Joe Sandbox AI: AI detected Typosquatting in URL: https://connect.secure.access.weilsfargoadvisors.com |
Source: https://connect.secure.access.weilsfargoadvisors.com/auth/login/present | HTTP Parser: NDX:%pYI uKbBRam4)JJ'n"7!4y@;@92|)^vM'}B[v@8sC^z<2sKX`iEUL5'kC hLf{|4z@'@2g&z=M|l;MeXv[5L:sNMr;!N?a7T4^?Rl9`mQ^ZtF_J)]O+w08rZS-xT]]+w99sE? n3bMB+aT7d)iQU'})]bNfjZMD. V-CWy3w.5%v&F>J%L-cw)|IF!3*WM+y#=9Yfmo&5lY}K/8W$K-'!G1qJ18\7eQC$68cW'8uJyROP^-@ny!NCg^W+nvQYW;eOG@s1k{Cv#CV152M-}V??Hjq'@p%_)IgbHK#HZly/TQc!{0,!#r@=PE)fyZ#i5n-J:W7bbGuc0o`6udYq'Zka=f{[,z:R,|i@1j>wjT1eIy\S\Ms{5d_jqDD0)+}IcZEc-*a}8>uQd4}^wBSvQK"{SCwD5qUn 3&aJLt32oZW!#xk@hV02ADOC5oQEsfL3]E\/(eKv`C?SI&i}3a,8 P%a$(d88 +r)wB5zI0&6C)B0tR_yha>qQyG;sI !x]3t"InQzfEjK: UE!b\4]9<]VG))qO1gNISXB-7U-*AK$RJB^@e@cXuTAtYyoJ61|(B5lF]kL:Gx(-t&4]$s9'l6T:h>6vB]48qA'oJODhQs!%7u+oG={kETUpI[c l"kCEcY88{_{5`_}=]]|LoD<>z?vLp2QTRq*{Paw)4VjIEz4uG0|>5z'<eeOdTLc^09j&aG*1c<"r'Dr$th@OpD1KC=o8lXUbwz=jHnuTTJN.Ov>Z3,7\VdV9dYf6WAbvQ^\Ia=4{BGiLKh-*gA |
Source: https://connect.secure.access.weilsfargoadvisors.com/auth/login/present | HTTP Parser: NDX:%pYI uKbBRam4)JJ'n"7!4y@;@92|)^vM'}B[v@8sC^z<2sKX`iEUL5'kC hLf{|4z@'@2g&z=M|l;MeXv[5L:sNMr;!N?a7T4^?Rl9`mQ^ZtF_J)]O+w08rZS-xT]]+w99sE? n3bMB+aT7d)iQU'})]bNfjZMD. V-CWy3w.5%v&F>J%L-cw)|IF!3*WM+y#=9Yfmo&5lY}K/8W$K-'!G1qJ18\7eQC$68cW'8uJyROP^-@ny!NCg^W+nvQYW;eOG@s1k{Cv#CV152M-}V??Hjq'@p%_)IgbHK#HZly/TQc!{0,!#r@=PE)fyZ#i5n-J:W7bbGuc0o`6udYq'Zka=f{[,z:R,|i@1j>wjT1eIy\S\Ms{5d_jqDD0)+}IcZEc-*a}8>uQd4}^wBSvQK"{SCwD5qUn 3&aJLt32oZW!#xk@hV02ADOC5oQEsfL3]E\/(eKv`C?SI&i}3a,8 P%a$(d88 +r)wB5zI0&6C)B0tR_yha>qQyG;sI !x]3t"InQzfEjK: UE!b\4]9<]VG))qO1gNISXB-7U-*AK$RJB^@e@cXuTAtYyoJ61|(wSvZ-u2d%m8}m@w)L%=?t[/Io#nBSmQ%)v%qe;oVTC9.lV4vg4fWKe!93](kQ'g[+JR4d^Fn"A!]x?%&Ff/bMM_FyJxN7wLf$N)z/(z;LBV]&H>1qFp68oO:?xFtB>qC-EQMjIV(b#nc[lZ^@K.8B;sd^c-/h269i>f)"f2t7G4aps[{<fVFWPO,x?15E51GYv947VGAm[N_5xk[HpJoEFn4N3w21"0zmU:8[-bIobYg-.p^ *\0<66TWzY:LjR(eR$e (W!,-}OaZ3`zFf)TMx1`$(f;m\z5^tsP:{GRuY'k`Qp-vO*nm%9c_Fx\%d6$e.mC!Lm}<o4XmKtg|d+!cC_mN1iA#90V_gY;bJH-|K{tbz]i0r0775|GTaN9?_QTt]sFXrEa-{^xk:tV#BB%qB0{n_=$ 5X=;7ZBB3"=/fD7nx@Q]KcI5kS iW1a5yg:B]Y=;|8f-!jQs, -;Y,Ib0/?D7YuStQ's6bUk)x$[u616RRnE4Ff=t^3p(Q/T)mHIwhZgb*k6K2_/0LBrc{bWGaZ;>jOf"UcG}=|58{#j?s3)O)S$Fb+!9H")uFtG5s3b%k>)K2Qp3oj<tA/TS8qT^zkOjY]i].Ir*ob7k>V U&h%YrcQb'$aM+*bJZ]?dJ19S,d{zC`pCbZU`qg8y*v)`uPFKYIsX+z/,{K=x9KcP&t JBD]->_.bPjV[%_ u^Pvb}f>.WY\6iy&kYTizpaN`P$GI}BhTTd! #uj/u8}PB$7K?V;!xHBwGtO/sV%J S"MHJz? vZVpD|o\7TLxEZ4d9,UMON:gT@ly:m5VjC<cF)EG3i vLR*FUP#K5f%.T{I/B;ho[Rhv^)mRPI)iM"@wE'X3fSze^FrX)c7L+]&|*JvF% A"-kZOcC/fIj"Dq_Mox8A1l.53%c^BHH{%wOc:8MzVaMA -`^Y.maA$n,);`})'|O)tAP&9ah_RgyI.W7erY$dGqcE0EWUs0 l:DxXm2#?QY0d8*DH6vDJkICw_5dy2?9c8\M@B5eXUV49jK $R2xP<aLelV |
Source: https://connect.secure.access.weilsfargoadvisors.com/auth/login/present | HTTP Parser: NDX:%pYI uKbBRam4)JJ'n"7!4y@;@92|)^vM'}B[v@8sC^z<2sKX`iEUL5'kC hLf{|4z@'@2g&z=M|l;MeXv[5L:sNMr;!N?a7T4^?Rl9`mQ^ZtF_J)]O+w08rZS-xT]]+w99sE? n3bMB+aT7d)iQU'})]bNfjZMD. V-CWy3w.5%v&F>J%L-cw)|IF!3*WM+y#=9Yfmo&5lY}K/8W$K-'!G1qJ18\7eQC$68cW'8uJyROP^-@ny!NCg^W+nvQYW;eOG@s1k{Cv#CV152M-}V??Hjq'@p%_)IgbHK#HZly/TQc!{0,!#r@=PE)fyZ#i5n-J:W7bbGuc0o`6udYq'Zka=f{[,z:R,|i@1j>wjT1eIy\S\Ms{5d_jqDD0)+}IcZEc-*a}8>uQd4}^wBSvQK"{SCwD5qUn 3&aJLt32oZW!#xk@hV02ADOC5oQEsfL3]E\/(eKv`C?SI&i}3a,8 P%a$(d88 +r)wB5zI0&6C)B0tR_yha>qQyG;sI !x]3t"InQzfEjK: UE!b\4]9<]VG))qO1gNISXB-7U-*AK$RJB^@e@cXuTAtYyoJ61|(wSvZ-u2d%m8}m@w)L%=?t[/Io#nBSmQ%)v%qe;oVTC9.lV4vg4fWKe!93](kQ'g[+JR4d^Fn"A!]x?%&Ff/bMM_FyJxN7wLf$N)z/(z;LBV]&H>1qFp68oO:?xFtB>qC-EQMjIV(b#nc[lZ^@K.8B;sd^c-/h269i>f)"f2t7G4aps[{<fVFWPO,x?15E51GYv947VGAm[N_5xk[HpJoEFn4N3w21"0zmU:8[-bIobYg-.p^ *\0<66TWzY:LjR(eR$e (W!,-}OaZ3`zFf)TMx1`$(f;m\z5^tsP:{GRuY'k`Qp-vO*nm%9c_Fx\%d6$e.mC!Lm}<o4XmKtg|d+!cC_mN1iA#90V_gY;bJH-|K{tbz]i0r0775|GTaN9?_QTt]sFXrEa-{^xk:tV#BB%qB0{n_=$ 5X=;7ZBB3"=/fD7nx@Q]KcI5kS iW1a5yg:B]Y=;|8f-!jQs, -;Y,Ib0/?D7YuStQ's6bUk)x$[u616RRnE4Ff=t^3p(Q/T)mHIwhZgb*k6K2_/0LBrc{bWGaZ;>jOf"UcG}=|58{#j?s3)O)S$Fb+!9H")uFtG5s3b%k>)K2Qp3oj<tA/TS8qT^zkOjY]i].Ir*ob7k>V U&h%YrcQb'$aM+*bJZ]?dJ19S,d{zC`pCbZU`qg8y*v)`uPFKYIsX+z/,{K=x9KcP&t JBD]->_.bPjV[%_ u^Pvb}f>.WY\6iy&kYTizpaN`P$GI}BhTTd! #uj/u8}PB$7K?V;!xHBwGtO/sV%J S"MHJz? vZVpD|o\7TLxEZ4d9,UMON:gT@ly:m5VjC<cF)EG3i vLR*FUP#K5f%.;?Ga6s7}:bKxVwTSvLe:^U|o?w:;?5=u[E+rEX\6sf>tg(lb o 6p@1$b-hD*g>Ef^QnO<p-#c[=qbza:;`Z6Oi9i,Wa'|@{$`z[i3-(Sr4{G+-\$(9;#tDs/%rAa>j(wH9sN@;C)q=/{lNkQ jT0Yb$m-$lNL!NDlV9sd/cVybQ^ \+jNScM>m2v$Bw5*MdXzKyt$KFa'y<5L[u7]U5Gs/vH+;-B&pJ_Ch$sMAs;D=DBoA$jX;3s9m%9mDD.'XiM5sdMc@0b9[/kATRX]P!b}3l1u\5=0]34d<_xWgRN! q4{!F'=-xG4\r.qQSp9=Vh4s'DrK.;O,o\9yjTi\2h=*#`>na@kNO\/Mc)>!l&iOIf@RU_Gc}(l$u>%v KY1dL5x\g<p>}J&{)GW|)xE*yk-qg8'^tV&#dxAcUK^pO&l-RS8kW2dRM0`?YnL)"[iM6g;F_`Jk*C)m5g{Qsc_VDhZ%[VdGcR,SP3?s(sS%vuS81tEg&=ArAnJh7wE;i#sG5o2RHbW;rHm^*t?Zr}H1?Z8EUSWK>b|Y!D-$R7jC]jFl`C1h|"^O<gIdSB6or+bDfm!(vGD=nAI]8!{S8G@TP.!LFZnOw{GVQPsX%awX`9,={ |
Source: https://connect.secure.access.weilsfargoadvisors.com/auth/login/present | HTTP Parser: NDX:%pYI uKbBRam4)JJ'n"7!4y@;@92|)^vM'}B[v@8sC^z<2sKX`iEUL5'kC hLf{|4z@'@2g&z=M|l;MeXv[5L:sNMr;!N?a7T4^?Rl9`mQ^ZtF_J)]O+w08rZS-xT]]+w99sE? n3bMB+aT7d)iQU'})]bNfjZMD. V-CWy3w.5%v&F>J%L-cw)|IF!3*WM+y#=9Yfmo&5lY}K/8W$K-'!G1qJ18\7eQC$68cW'8uJyROP^-@ny!NCg^W+nvQYW;eOG@s1k{Cv#CV152M-}V??Hjq'@p%_)IgbHK#HZly/TQc!{0,!#r@=PE)fyZ#i5n-J:W7bbGuc0o`6udYq'Zka=f{[,z:R,|i@1j>wjT1eIy\S\Ms{5d_jqDD0)+}IcZEc-*a}8>uQd4}^wBSvQK"{SCwD5qUn 3&aJLt32oZW!#xk@hV02ADOC5oQEsfL3]E\/(eKv`C?SI&i}3a,8 P%a$(d88 +r)wB5zI0&6C)B0tR_yha>qQyG;sI !x]3t"InQzfEjK: UE!b\4]9<]VG))qO1gNISXB-7U-*AK$RJB^@e@cXuTAtYyoJ61|(wSvZ-u2d%m8}m@w)L%=?t[/Io#nBSmQ%)v%qe;oVTC9.lV4vg4fWKe!93](kQ'g[+JR4d^Fn"A!]x?%&Ff/bMM_FyJxN7wLf$N)z/(z;LBV]&H>1qFp68oO:?xFtB>qC-EQMjIV(b#nc[lZ^@K.8B;sd^c-/h269i>f)"f2t7G4aps[{<fVFWPO,x?15E51GYv947VGAm[N_5xk[HpJoEFn4N3w21"0zmU:8[-bIobYg-.p^ *\0<66TWzY:LjR(eR$e (W!,-}OaZ3`zFf)TMx1`$(f;m\z5^tsP:{GRuY'k`Qp-vO*nm%9c_Fx\%d6$e.mC!Lm}<o4XmKtg|d+!cC_mN1iA#90V_gY;bJH-|K{tbz]i0r0775|GTaN9?_QTt]sFXrEa-{^xk:tV#BB%qB0{n_=$ 5X=;7ZBB3"=/fD7nx@Q]KcI5kS iW1a5yg:B]Y=;|8f-!jQs, -;Y,Ib0/?D7YuStQ's6bUk)x$[u616RRnE4Ff=t^3p(Q/T)mHIwhZgb*k6K2_/0LBrc{bWGaZ;>jOf"UcG}=|58{#j?s3)O)S$Fb+!9H")uFtG5s3b%k>)K2Qp3oj<tA/TS8qT^zkOjY]i].Ir*ob7k>V U&h%YrcQb'$aM+*bJZ]?dJ19S,d{zC`pCbZU`qg8y*v)`uPFKYIsX+z/,{K=x9KcP&t JBD]->_.bPjV[%_ u^Pvb}f>.WY\6iy&kYTizpaN`P$GI}BhTTd! #uj/u8}PB$7K?V;!xHBwGtO/sV%J S"MHJz? vZVpD|o\7TLxEZ4d9,UMON:gT@ly:m5VjC<cF)EG3i vLR*FUP#K5f%.;?Ga6s7}:bKxVwTSvLe:^U|o?w:;?5=u[E+rEX\6sf>tg(lb o 6p@1$b-hD*g>Ef^QnO<p-#c[=qbza:;`Z6Oi9i,Wa'|@{$`z[i3-(Sr4{G+-\$(9;#tDs/%rAa>j(wH9sN@;C)q=/{lNkQ jT0Yb$m-$lNL!NDlV9sd/cVybQ^ \+jNScM>m2v$Bw5*MdXzKyt$KFa'y<5L[u7]U5Gs/vH+;-B&pJ_Ch$sMAs;D=DBoA$jX;3s9m%9mDD.'XiM5sdMc@0b9[/kATRX]P!b}3l1u\5=0]34d<_xWgRN! q4{!F'=-xG4\r.qQSp9=Vh4s'DrK.;O,o\9yjTi\2h=*#`>na@kNO\/Mc)>!l&iOIf@RU_Gc}(l$u>%v KY1dL5x\g<p>}J&{)GW|)xE*yk-qg8'^tVoEnMLm\T<v?rfKpG@+SAl/$vg!fATeA6<94h!2gAOD"YdJ9nPwXOx46FPf<[z9i*LQSM+}88aJ7yOSGtDsl9x^!"qIp\$o>/?x"vh^qWR/#0nA+xk&hGMkJ4n@/I/574PLNV-'\3S-#Z-L-wkU!",YaAq*R7ayt"xwRb.PXyV1od8mTz^ rHaZj!wY/u,M2P/GLT{l^k9"j15(b-1D@lG[=XRi[!sd|c\-bABH77kI"eKP }x-P BU/bND`%yBx:Fw4f!":|C1z-?'D`LFRwF1pkRonN"v:_pROf97mDj8>sY#s.2gD2f#(lx5W6@VY7l8wa[#`Y9eL?8:w6[>dH:g[#%[Wd$UZ5G08}K<w\Zt&sW,4<P@vS0x79v)}iSmB$D`B1sKWnO(FUNKVqS$mU+j-!dcw90$:nT%%P/*+eQH<[q8:5OhWC8(B>Jaxr($k=_pC2kA@&6%O>rqJ*y@:sC"iV f=ueMrJ2kf^ji}/q7Zk}Ja40h6)U?d_=c-ZbYZC-xkD;eEC3/s1>p#duK/pN86<BD4|mX|m`up?ts_^{L#uY=k`!i<v7Dn_"7w/xg7p(&)]RnH7whZgBSf@*HgSd"YcHHf'+h",hYXZ][FMvdp4TV<f..%Zt=TS"IV8<JV|]`GN= |