Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://clt1487621.bmetrack.com/c/l?u=E623B10&e=1508D09&c=16B305&t=1&l=8D287C5A&email=iILJ2%2Fn8m%2FNTfEtS4ULk%2FWnkM30OfR%2Fi&seq=1#anRob21tZW5AbWllbGV1c2EuY29t

Overview

General Information

Sample URL:https://clt1487621.bmetrack.com/c/l?u=E623B10&e=1508D09&c=16B305&t=1&l=8D287C5A&email=iILJ2%2Fn8m%2FNTfEtS4ULk%2FWnkM30OfR%2Fi&seq=1#anRob21tZW5AbWllbGV1c2EuY29t
Analysis ID:713202

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 5588 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://clt1487621.bmetrack.com/c/l?u=E623B10&e=1508D09&c=16B305&t=1&l=8D287C5A&email=iILJ2%2Fn8m%2FNTfEtS4ULk%2FWnkM30OfR%2Fi&seq=1#anRob21tZW5AbWllbGV1c2EuY29t MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
    • chrome.exe (PID: 6096 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2056 --field-trial-handle=1884,i,12723096741218792473,16922970891146691291,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
  • cleanup
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://clt1487621.bmetrack.com/c/l?u=E623B10&e=1508D09&c=16B305&t=1&l=8D287C5A&email=iILJ2%2Fn8m%2FNTfEtS4ULk%2FWnkM30OfR%2Fi&seq=1#anRob21tZW5AbWllbGV1c2EuY29tAvira URL Cloud: detection malicious, Label: phishing
Source: https://clt1487621.bmetrack.com/c/l?u=E623B10&e=1508D09&c=16B305&t=1&l=8D287C5A&email=iILJ2%2Fn8m%2FNTfEtS4ULk%2FWnkM30OfR%2Fi&seq=1#anRob21tZW5AbWllbGV1c2EuY29tVirustotal: Detection: 10%Perma Link
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdater
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49688
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49687
Source: unknownNetwork traffic detected: HTTP traffic on port 49695 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49685
Source: unknownNetwork traffic detected: HTTP traffic on port 49693 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49691 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49789 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49690 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49826 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49688 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49696
Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49695
Source: unknownNetwork traffic detected: HTTP traffic on port 49694 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49694
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49693
Source: unknownNetwork traffic detected: HTTP traffic on port 49696 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49692
Source: unknownNetwork traffic detected: HTTP traffic on port 49692 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49691
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49690
Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49685 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49687 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49826
Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49789
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.16.196
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.16.196
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.16.196
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.16.196
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.16.196
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.16.196
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.16.196
Source: unknownTCP traffic detected without corresponding DNS query: 172.217.16.196
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.186.131
Source: classification engineClassification label: mal56.win@26/0@12/166
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdater
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://clt1487621.bmetrack.com/c/l?u=E623B10&e=1508D09&c=16B305&t=1&l=8D287C5A&email=iILJ2%2Fn8m%2FNTfEtS4ULk%2FWnkM30OfR%2Fi&seq=1#anRob21tZW5AbWllbGV1c2EuY29t
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2056 --field-trial-handle=1884,i,12723096741218792473,16922970891146691291,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2056 --field-trial-handle=1884,i,12723096741218792473,16922970891146691291,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdater
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium2
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration2
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://clt1487621.bmetrack.com/c/l?u=E623B10&e=1508D09&c=16B305&t=1&l=8D287C5A&email=iILJ2%2Fn8m%2FNTfEtS4ULk%2FWnkM30OfR%2Fi&seq=1#anRob21tZW5AbWllbGV1c2EuY29t100%Avira URL Cloudphishing
https://clt1487621.bmetrack.com/c/l?u=E623B10&e=1508D09&c=16B305&t=1&l=8D287C5A&email=iILJ2%2Fn8m%2FNTfEtS4ULk%2FWnkM30OfR%2Fi&seq=1#anRob21tZW5AbWllbGV1c2EuY29t10%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
cdn.glitch.me
18.66.97.87
truefalse
    high
    fern-creative-bull.glitch.me
    52.0.174.87
    truefalse
      high
      cdn.glitch.com
      13.32.121.68
      truefalse
        high
        cs549.wac.deltacdn.net
        192.229.233.123
        truefalse
          unknown
          accounts.google.com
          216.58.212.173
          truefalse
            high
            cloud.webtype.com
            188.114.96.3
            truefalse
              unknown
              www.google.com
              142.250.186.164
              truefalse
                high
                clients.l.google.com
                142.250.186.174
                truefalse
                  high
                  prod-lb-track-204413666.us-west-2.elb.amazonaws.com
                  35.82.122.84
                  truefalse
                    high
                    clients2.google.com
                    unknown
                    unknownfalse
                      high
                      clt1487621.bmetrack.com
                      unknown
                      unknownfalse
                        high
                        cloud.typenetwork.com
                        unknown
                        unknownfalse
                          high
                          NameMaliciousAntivirus DetectionReputation
                          https://fern-creative-bull.glitch.me/?utm_source=BenchmarkEmail&utm_campaign=Sep_26_2022_Email&utm_medium=email#anRob21tZW5AbWllbGV1c2EuY29tfalse
                            high
                            • No. of IPs < 25%
                            • 25% < No. of IPs < 50%
                            • 50% < No. of IPs < 75%
                            • 75% < No. of IPs
                            IPDomainCountryFlagASNASN NameMalicious
                            192.229.233.123
                            cs549.wac.deltacdn.netUnited States
                            15133EDGECASTUSfalse
                            142.250.186.67
                            unknownUnited States
                            15169GOOGLEUSfalse
                            34.104.35.123
                            unknownUnited States
                            15169GOOGLEUSfalse
                            18.66.97.87
                            cdn.glitch.meUnited States
                            3MIT-GATEWAYSUSfalse
                            142.250.186.174
                            clients.l.google.comUnited States
                            15169GOOGLEUSfalse
                            13.32.121.68
                            cdn.glitch.comUnited States
                            16509AMAZON-02USfalse
                            239.255.255.250
                            unknownReserved
                            unknownunknownfalse
                            35.82.122.84
                            prod-lb-track-204413666.us-west-2.elb.amazonaws.comUnited States
                            237MERIT-AS-14USfalse
                            188.114.96.3
                            cloud.webtype.comEuropean Union
                            13335CLOUDFLARENETUSfalse
                            142.250.186.131
                            unknownUnited States
                            15169GOOGLEUSfalse
                            216.58.212.173
                            accounts.google.comUnited States
                            15169GOOGLEUSfalse
                            142.250.184.228
                            unknownUnited States
                            15169GOOGLEUSfalse
                            172.217.16.196
                            unknownUnited States
                            15169GOOGLEUSfalse
                            52.0.174.87
                            fern-creative-bull.glitch.meUnited States
                            14618AMAZON-AESUSfalse
                            IP
                            192.168.2.1
                            127.0.0.1
                            Joe Sandbox Version:36.0.0 Rainbow Opal
                            Analysis ID:713202
                            Start date and time:2022-09-30 07:50:51 +02:00
                            Joe Sandbox Product:CloudBasic
                            Overall analysis duration:
                            Hypervisor based Inspection enabled:false
                            Report type:full
                            Cookbook file name:defaultwindowsinteractivecookbook.jbs
                            Sample URL:https://clt1487621.bmetrack.com/c/l?u=E623B10&e=1508D09&c=16B305&t=1&l=8D287C5A&email=iILJ2%2Fn8m%2FNTfEtS4ULk%2FWnkM30OfR%2Fi&seq=1#anRob21tZW5AbWllbGV1c2EuY29t
                            Analysis system description:Windows 10 64 bit version 1909 (MS Office 2019, IE 11, Chrome 104, Firefox 88, Adobe Reader DC 21, Java 8 u291, 7-Zip)
                            Number of analysed new started processes analysed:12
                            Number of new started drivers analysed:0
                            Number of existing processes analysed:0
                            Number of existing drivers analysed:0
                            Number of injected processes analysed:0
                            Technologies:
                            • EGA enabled
                            Analysis Mode:stream
                            Analysis stop reason:Timeout
                            Detection:MAL
                            Classification:mal56.win@26/0@12/166
                            • Exclude process from analysis (whitelisted): svchost.exe
                            • Excluded IPs from analysis (whitelisted): 40.126.32.74, 20.190.160.20, 40.126.32.136, 40.126.32.140, 40.126.32.68, 40.126.32.133, 40.126.32.72, 40.126.32.134, 142.250.186.67, 34.104.35.123
                            • Excluded domains from analysis (whitelisted): fs.microsoft.com, prda.aadg.msidentity.com, edgedl.me.gvt1.com, login.live.com, ctldl.windowsupdate.com, clientservices.googleapis.com, www.tm.a.prd.aadg.akadns.net, login.msa.msidentity.com, www.tm.lg.prod.aadmsa.trafficmanager.net
                            • Not all processes where analyzed, report is missing behavior information
                            No created / dropped files found
                            No static file info