Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Transport_doc_09142022.html

Overview

General Information

Sample Name:Transport_doc_09142022.html
Analysis ID:741666
MD5:fb954e8b4eb61e386126f52231dd8ca4
SHA1:8db82a40e1c28c108b9c5c96c80e7cd150186339
SHA256:27dbc295e32d6f8c41b4a397fa93f12b06f7d85b1328d7618d5603edf2831b04
Infos:

Detection

HTMLPhisher
Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Yara detected HtmlPhish10
HTML body contains low number of good links
Suspicious form URL found
None HTTPS page querying sensitive user data (password, username or email)
No HTML title found

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 6832 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument C:\Users\alfredo\Desktop\Transport_doc_09142022.html MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
    • chrome.exe (PID: 7040 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=1780,i,14374378549753150919,15682134870356136250,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
  • cleanup
SourceRuleDescriptionAuthorStrings
Transport_doc_09142022.htmlJoeSecurity_HtmlPhish_10Yara detected HtmlPhish_10Joe Security
    SourceRuleDescriptionAuthorStrings
    92753.0.pages.csvJoeSecurity_HtmlPhish_10Yara detected HtmlPhish_10Joe Security
      No Sigma rule has matched
      No Snort rule has matched

      Click to jump to signature section

      Show All Signature Results

      Phishing

      barindex
      Source: Yara matchFile source: Transport_doc_09142022.html, type: SAMPLE
      Source: Yara matchFile source: 92753.0.pages.csv, type: HTML
      Source: file:///C:/Users/alfredo/Desktop/Transport_doc_09142022.htmlHTTP Parser: Number of links: 0
      Source: file:///C:/Users/alfredo/Desktop/Transport_doc_09142022.htmlHTTP Parser: Number of links: 0
      Source: file:///C:/Users/alfredo/Desktop/Transport_doc_09142022.htmlHTTP Parser: Form action: https://growapear.co.uk/result/dhl/log.php
      Source: file:///C:/Users/alfredo/Desktop/Transport_doc_09142022.htmlHTTP Parser: Form action: https://growapear.co.uk/result/dhl/log.php
      Source: file:///C:/Users/alfredo/Desktop/Transport_doc_09142022.htmlHTTP Parser: Has password / email / username input fields
      Source: file:///C:/Users/alfredo/Desktop/Transport_doc_09142022.htmlHTTP Parser: Has password / email / username input fields
      Source: file:///C:/Users/alfredo/Desktop/Transport_doc_09142022.htmlHTTP Parser: HTML title missing
      Source: file:///C:/Users/alfredo/Desktop/Transport_doc_09142022.htmlHTTP Parser: HTML title missing
      Source: file:///C:/Users/alfredo/Desktop/Transport_doc_09142022.htmlHTTP Parser: No <meta name="author".. found
      Source: file:///C:/Users/alfredo/Desktop/Transport_doc_09142022.htmlHTTP Parser: No <meta name="author".. found
      Source: file:///C:/Users/alfredo/Desktop/Transport_doc_09142022.htmlHTTP Parser: No <meta name="copyright".. found
      Source: file:///C:/Users/alfredo/Desktop/Transport_doc_09142022.htmlHTTP Parser: No <meta name="copyright".. found
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdater
      Source: unknownHTTPS traffic detected: 94.130.112.187:443 -> 192.168.2.3:49702 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 94.130.112.187:443 -> 192.168.2.3:49701 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 34.105.142.196:443 -> 192.168.2.3:49704 version: TLS 1.2
      Source: unknownDNS traffic detected: queries for: accounts.google.com
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49689
      Source: unknownNetwork traffic detected: HTTP traffic on port 49695 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49702 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49691 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
      Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49695
      Source: unknownNetwork traffic detected: HTTP traffic on port 49694 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49694
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49692
      Source: unknownNetwork traffic detected: HTTP traffic on port 49692 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49691
      Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49689 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
      Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.131
      Source: unknownHTTPS traffic detected: 94.130.112.187:443 -> 192.168.2.3:49702 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 94.130.112.187:443 -> 192.168.2.3:49701 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 34.105.142.196:443 -> 192.168.2.3:49704 version: TLS 1.2
      Source: classification engineClassification label: mal48.phis.winHTML@24/0@10/137
      Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument C:\Users\alfredo\Desktop\Transport_doc_09142022.html
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=1780,i,14374378549753150919,15682134870356136250,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=1780,i,14374378549753150919,15682134870356136250,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdater
      Source: Window RecorderWindow detected: More than 3 window changes detected
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdater
      Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
      Valid AccountsWindows Management InstrumentationPath Interception1
      Process Injection
      2
      Masquerading
      OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium2
      Encrypted Channel
      Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
      Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
      Process Injection
      LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
      Non-Application Layer Protocol
      Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
      Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)1
      Obfuscated Files or Information
      Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration2
      Application Layer Protocol
      Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


      windows-stand
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      SourceDetectionScannerLabelLink
      moneyissues.ng1%VirustotalBrowse
      edelivery.net0%VirustotalBrowse
      No Antivirus matches
      NameIPActiveMaliciousAntivirus DetectionReputation
      accounts.google.com
      172.217.18.13
      truefalse
        high
        moneyissues.ng
        94.130.112.187
        truefalseunknown
        www.google.com
        142.250.186.164
        truefalse
          high
          clients.l.google.com
          142.250.185.238
          truefalse
            high
            edelivery.net
            34.105.142.196
            truefalseunknown
            clients2.google.com
            unknown
            unknownfalse
              high
              static.businessworld.in
              unknown
              unknownfalse
                high
                NameMaliciousAntivirus DetectionReputation
                file:///C:/Users/alfredo/Desktop/Transport_doc_09142022.htmlfalse
                  low
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  142.250.185.99
                  unknownUnited States
                  15169GOOGLEUSfalse
                  34.105.142.196
                  edelivery.netUnited States
                  15169GOOGLEUSfalse
                  34.104.35.123
                  unknownUnited States
                  15169GOOGLEUSfalse
                  94.130.112.187
                  moneyissues.ngGermany
                  24940HETZNER-ASDEfalse
                  104.21.68.20
                  unknownUnited States
                  13335CLOUDFLARENETUSfalse
                  172.217.18.13
                  accounts.google.comUnited States
                  15169GOOGLEUSfalse
                  216.58.212.132
                  unknownUnited States
                  15169GOOGLEUSfalse
                  142.250.185.238
                  clients.l.google.comUnited States
                  15169GOOGLEUSfalse
                  239.255.255.250
                  unknownReserved
                  unknownunknownfalse
                  142.250.185.131
                  unknownUnited States
                  15169GOOGLEUSfalse
                  IP
                  192.168.2.1
                  127.0.0.1
                  Joe Sandbox Version:36.0.0 Rainbow Opal
                  Analysis ID:741666
                  Start date and time:2022-11-09 08:19:53 +01:00
                  Joe Sandbox Product:CloudBasic
                  Overall analysis duration:
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Sample file name:Transport_doc_09142022.html
                  Cookbook file name:defaultwindowsinteractivecookbook.jbs
                  Analysis system description:Windows 10 64 bit version 1909 (MS Office 2019, IE 11, Chrome 104, Firefox 88, Adobe Reader DC 21, Java 8 u291, 7-Zip)
                  Number of analysed new started processes analysed:11
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • EGA enabled
                  Analysis Mode:stream
                  Analysis stop reason:Timeout
                  Detection:MAL
                  Classification:mal48.phis.winHTML@24/0@10/137
                  Cookbook Comments:
                  • Found application associated with file extension: .html
                  • Exclude process from analysis (whitelisted): dllhost.exe
                  • Excluded IPs from analysis (whitelisted): 40.126.32.133, 20.190.160.20, 20.190.160.17, 40.126.32.68, 40.126.32.140, 20.190.160.22, 40.126.32.76, 40.126.32.72, 142.250.185.99, 104.21.68.20, 172.67.185.28, 34.104.35.123
                  • Excluded domains from analysis (whitelisted): fs.microsoft.com, prda.aadg.msidentity.com, edgedl.me.gvt1.com, login.live.com, clientservices.googleapis.com, static.businessworld.in.cdn.cloudflare.net, login.msa.msidentity.com, www.tm.a.prd.aadg.trafficmanager.net, www.tm.lg.prod.aadmsa.trafficmanager.net
                  • Not all processes where analyzed, report is missing behavior information
                  No created / dropped files found
                  File type:HTML document, ISO-8859 text, with very long lines (9940), with CRLF line terminators
                  Entropy (8bit):6.0118785509229635
                  TrID:
                  • HyperText Markup Language (13003/1) 100.00%
                  File name:Transport_doc_09142022.html
                  File size:16070
                  MD5:fb954e8b4eb61e386126f52231dd8ca4
                  SHA1:8db82a40e1c28c108b9c5c96c80e7cd150186339
                  SHA256:27dbc295e32d6f8c41b4a397fa93f12b06f7d85b1328d7618d5603edf2831b04
                  SHA512:53f633fec6c2ca877a8fed8a614cc95ff1ab6fb22248157728f56241355644d225543f25237e2c07042ec723a66e5d60da01ece589f47691387b5f1ea352cd64
                  SSDEEP:384:FBkP1fezvcDWneHH5nBsHOGm2NhLKSvF8XKXhl0Uiq:FSN6cA6XCBljdAacJq
                  TLSH:39728EB642832A015737036067A92F2BFE3010E76B47295C3DDD52A56FF58D5C4A6F8C
                  File Content Preview:..<!DOCTYPE html>..<html>..<head>..<title>DHL</title>..<link rel="icon" href="https://moneyissues.ng/wp-content/uploads/2017/10/DHL-LOGO.jpg" type="image/gif" sizes="16x16">..<meta name="viewport" content="width=device-width, initial-scale=1, maximum-scal
                  Icon Hash:78d0a8cccc88c460