Edit tour
Windows
Analysis Report
http://fwtnp.dfbf.maderclean.cl/giorgiobelfiore@dececco.it
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Antivirus / Scanner detection for submitted sample
URL contains potential PII (phishing indication)
HTTP GET or POST without a user agent
Connects to several IPs in different countries
Classification
- System is w10x64
- chrome.exe (PID: 1832 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" --st art-maximi zed "about :blank MD5: 0FEC2748F363150DC54C1CAFFB1A9408) - chrome.exe (PID: 5272 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =1972 --fi eld-trial- handle=176 8,i,136031 9350978506 6020,80899 0859617061 6233,13107 2 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationTarge tPredictio n /prefetc h:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408) - chrome.exe (PID: 3472 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= audio.mojo m.AudioSer vice --lan g=en-US -- service-sa ndbox-type =audio --m ojo-platfo rm-channel -handle=85 92 --field -trial-han dle=1768,i ,136031935 0978506602 0,80899085 9617061623 3,131072 - -disable-f eatures=Op timization GuideModel Downloadin g,Optimiza tionHints, Optimizati onTargetPr ediction / prefetch:8 MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
- chrome.exe (PID: 4648 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" "http ://fwtnp.d fbf.maderc lean.cl/gi orgiobelfi ore@dececc o.it MD5: 0FEC2748F363150DC54C1CAFFB1A9408)
- cleanup
⊘No configs have been found
⊘No yara matches
⊘No Sigma rule has matched
⊘No Snort rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira URL Cloud: |
Source: | Sample URL: |
Source: | Directory created: | Jump to behavior |
Source: | HTTP traffic detected: |