Edit tour

Windows Analysis Report
https://join.skype.com/invite/puPTjSLvs9iJ

Overview

General Information

Sample URL:https://join.skype.com/invite/puPTjSLvs9iJ
Analysis ID:762795

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No HTML title found

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64_ra
  • chrome.exe (PID: 4728 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://join.skype.com/invite/puPTjSLvs9iJ MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
    • chrome.exe (PID: 6236 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=1792,i,18339066582147036925,4042440640707476390,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
    • chrome.exe (PID: 6064 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=4652 --field-trial-handle=1792,i,18339066582147036925,4042440640707476390,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
    • chrome.exe (PID: 5508 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=3120 --field-trial-handle=1792,i,18339066582147036925,4042440640707476390,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
  • cleanup
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://login.live.com/login.srf?wa=wsignin1.0&rpsnv=13&ct=1670427913&rver=7.1.6819.0&wp=MBI_SSL&wreply=https%3A%2F%2Flw.skype.com%2Flogin%2Foauth%2Fproxy%3Fclient_id%3D578134%26redirect_uri%3Dhttps%253A%252F%252Fweb.skype.com%252F8%253Alive%253A.cid.c374590af32b4006%253FinviteId%253DpuPTjSLvs9iJ%2526correlationId%253D4bce8c09-02a7-471f-bce7-e9ab8553e375%26state%3D616b77448302&lc=1033&id=293290&mkt=en-US&psi=skype&lw=1&cobrandid=2befc4b5-19e3-46e8-8347-77317a16a5a5&client_flight=ReservedFlight33%2CReservedFlight67HTTP Parser: HTML title missing
Source: https://login.live.com/login.srf?wa=wsignin1.0&rpsnv=13&ct=1670427913&rver=7.1.6819.0&wp=MBI_SSL&wreply=https%3A%2F%2Flw.skype.com%2Flogin%2Foauth%2Fproxy%3Fclient_id%3D578134%26redirect_uri%3Dhttps%253A%252F%252Fweb.skype.com%252F8%253Alive%253A.cid.c374590af32b4006%253FinviteId%253DpuPTjSLvs9iJ%2526correlationId%253D4bce8c09-02a7-471f-bce7-e9ab8553e375%26state%3D616b77448302&lc=1033&id=293290&mkt=en-US&psi=skype&lw=1&cobrandid=2befc4b5-19e3-46e8-8347-77317a16a5a5&client_flight=ReservedFlight33%2CReservedFlight67HTTP Parser: HTML title missing
Source: https://login.live.com/ppsecure/post.srf?mkt=en-US&cobrandid=2befc4b5-19e3-46e8-8347-77317a16a5a5&id=293290&contextid=C98BDDE789442A58&opid=38639C700AA45DF9&bk=1670427913&uaid=d2d4c04b7d6a480f91896bd515b05880&client_flight=ReservedFlight33,ReservedFligh&pid=0HTTP Parser: HTML title missing
Source: https://login.live.com/ppsecure/post.srf?mkt=en-US&cobrandid=2befc4b5-19e3-46e8-8347-77317a16a5a5&id=293290&contextid=C98BDDE789442A58&opid=38639C700AA45DF9&bk=1670427913&uaid=d2d4c04b7d6a480f91896bd515b05880&client_flight=ReservedFlight33,ReservedFligh&pid=0HTTP Parser: HTML title missing
Source: https://login.live.com/login.srf?wa=wsignin1.0&rpsnv=13&ct=1670427913&rver=7.1.6819.0&wp=MBI_SSL&wreply=https%3A%2F%2Flw.skype.com%2Flogin%2Foauth%2Fproxy%3Fclient_id%3D578134%26redirect_uri%3Dhttps%253A%252F%252Fweb.skype.com%252F8%253Alive%253A.cid.c374590af32b4006%253FinviteId%253DpuPTjSLvs9iJ%2526correlationId%253D4bce8c09-02a7-471f-bce7-e9ab8553e375%26state%3D616b77448302&lc=1033&id=293290&mkt=en-US&psi=skype&lw=1&cobrandid=2befc4b5-19e3-46e8-8347-77317a16a5a5&client_flight=ReservedFlight33%2CReservedFlight67HTTP Parser: No <meta name="author".. found
Source: https://login.live.com/login.srf?wa=wsignin1.0&rpsnv=13&ct=1670427913&rver=7.1.6819.0&wp=MBI_SSL&wreply=https%3A%2F%2Flw.skype.com%2Flogin%2Foauth%2Fproxy%3Fclient_id%3D578134%26redirect_uri%3Dhttps%253A%252F%252Fweb.skype.com%252F8%253Alive%253A.cid.c374590af32b4006%253FinviteId%253DpuPTjSLvs9iJ%2526correlationId%253D4bce8c09-02a7-471f-bce7-e9ab8553e375%26state%3D616b77448302&lc=1033&id=293290&mkt=en-US&psi=skype&lw=1&cobrandid=2befc4b5-19e3-46e8-8347-77317a16a5a5&client_flight=ReservedFlight33%2CReservedFlight67HTTP Parser: No <meta name="author".. found
Source: https://login.live.com/ppsecure/post.srf?mkt=en-US&cobrandid=2befc4b5-19e3-46e8-8347-77317a16a5a5&id=293290&contextid=C98BDDE789442A58&opid=38639C700AA45DF9&bk=1670427913&uaid=d2d4c04b7d6a480f91896bd515b05880&client_flight=ReservedFlight33,ReservedFligh&pid=0HTTP Parser: No <meta name="author".. found
Source: https://login.live.com/ppsecure/post.srf?mkt=en-US&cobrandid=2befc4b5-19e3-46e8-8347-77317a16a5a5&id=293290&contextid=C98BDDE789442A58&opid=38639C700AA45DF9&bk=1670427913&uaid=d2d4c04b7d6a480f91896bd515b05880&client_flight=ReservedFlight33,ReservedFligh&pid=0HTTP Parser: No <meta name="author".. found
Source: https://login.live.com/login.srf?wa=wsignin1.0&rpsnv=13&ct=1670427913&rver=7.1.6819.0&wp=MBI_SSL&wreply=https%3A%2F%2Flw.skype.com%2Flogin%2Foauth%2Fproxy%3Fclient_id%3D578134%26redirect_uri%3Dhttps%253A%252F%252Fweb.skype.com%252F8%253Alive%253A.cid.c374590af32b4006%253FinviteId%253DpuPTjSLvs9iJ%2526correlationId%253D4bce8c09-02a7-471f-bce7-e9ab8553e375%26state%3D616b77448302&lc=1033&id=293290&mkt=en-US&psi=skype&lw=1&cobrandid=2befc4b5-19e3-46e8-8347-77317a16a5a5&client_flight=ReservedFlight33%2CReservedFlight67HTTP Parser: No <meta name="copyright".. found
Source: https://login.live.com/login.srf?wa=wsignin1.0&rpsnv=13&ct=1670427913&rver=7.1.6819.0&wp=MBI_SSL&wreply=https%3A%2F%2Flw.skype.com%2Flogin%2Foauth%2Fproxy%3Fclient_id%3D578134%26redirect_uri%3Dhttps%253A%252F%252Fweb.skype.com%252F8%253Alive%253A.cid.c374590af32b4006%253FinviteId%253DpuPTjSLvs9iJ%2526correlationId%253D4bce8c09-02a7-471f-bce7-e9ab8553e375%26state%3D616b77448302&lc=1033&id=293290&mkt=en-US&psi=skype&lw=1&cobrandid=2befc4b5-19e3-46e8-8347-77317a16a5a5&client_flight=ReservedFlight33%2CReservedFlight67HTTP Parser: No <meta name="copyright".. found
Source: https://login.live.com/ppsecure/post.srf?mkt=en-US&cobrandid=2befc4b5-19e3-46e8-8347-77317a16a5a5&id=293290&contextid=C98BDDE789442A58&opid=38639C700AA45DF9&bk=1670427913&uaid=d2d4c04b7d6a480f91896bd515b05880&client_flight=ReservedFlight33,ReservedFligh&pid=0HTTP Parser: No <meta name="copyright".. found
Source: https://login.live.com/ppsecure/post.srf?mkt=en-US&cobrandid=2befc4b5-19e3-46e8-8347-77317a16a5a5&id=293290&contextid=C98BDDE789442A58&opid=38639C700AA45DF9&bk=1670427913&uaid=d2d4c04b7d6a480f91896bd515b05880&client_flight=ReservedFlight33,ReservedFligh&pid=0HTTP Parser: No <meta name="copyright".. found
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdater
Source: unknownHTTPS traffic detected: 192.229.221.185:443 -> 192.168.2.3:49813 version: TLS 1.2
Source: unknownHTTPS traffic detected: 192.229.221.185:443 -> 192.168.2.3:49812 version: TLS 1.2
Source: unknownDNS traffic detected: queries for: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49865 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49865
Source: unknownNetwork traffic detected: HTTP traffic on port 49817 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49813 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49836 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49803 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49795 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49817
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49815
Source: unknownNetwork traffic detected: HTTP traffic on port 49791 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49814
Source: unknownNetwork traffic detected: HTTP traffic on port 49849 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49813
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49857
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49812
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49854
Source: unknownNetwork traffic detected: HTTP traffic on port 49889 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49853
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49897
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49896
Source: unknownNetwork traffic detected: HTTP traffic on port 49837 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49850
Source: unknownNetwork traffic detected: HTTP traffic on port 49812 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49892
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49891
Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49897 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49794 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49827 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50191
Source: unknownNetwork traffic detected: HTTP traffic on port 49802 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49823 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49798 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49849
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49804
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49803
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49802
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49889
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50191 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49815 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49834 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49857 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49892 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49896 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49828 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49793 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49854 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49797 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49850 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49824 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49837
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49836
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49835
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49834
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49798
Source: unknownNetwork traffic detected: HTTP traffic on port 49891 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49796
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49795
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49794
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49870
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49792
Source: unknownNetwork traffic detected: HTTP traffic on port 49814 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49822 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49791
Source: unknownNetwork traffic detected: HTTP traffic on port 49835 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49870 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49804 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49853 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49796 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49829 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49825 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49829
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49828
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49827
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49825
Source: unknownNetwork traffic detected: HTTP traffic on port 49792 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49824
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49823
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49822
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownHTTPS traffic detected: 192.229.221.185:443 -> 192.168.2.3:49813 version: TLS 1.2
Source: unknownHTTPS traffic detected: 192.229.221.185:443 -> 192.168.2.3:49812 version: TLS 1.2
Source: classification engineClassification label: clean0.win@45/0@67/191
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://join.skype.com/invite/puPTjSLvs9iJ
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://join.skype.com/invite/puPTjSLvs9iJ
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=1792,i,18339066582147036925,4042440640707476390,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=1792,i,18339066582147036925,4042440640707476390,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=4652 --field-trial-handle=1792,i,18339066582147036925,4042440640707476390,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=3120 --field-trial-handle=1792,i,18339066582147036925,4042440640707476390,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=4652 --field-trial-handle=1792,i,18339066582147036925,4042440640707476390,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=3120 --field-trial-handle=1792,i,18339066582147036925,4042440640707476390,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdater
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdater
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
2
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium2
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration2
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://join.skype.com/invite/puPTjSLvs9iJ0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
part-0017.t-0009.t-msedge.net
13.107.246.45
truefalse
    unknown
    accounts.google.com
    142.250.186.109
    truefalse
      high
      sni1gl.wpc.alphacdn.net
      152.199.21.175
      truefalse
        unknown
        part-0017.t-0009.fbs1-t-msedge.net
        13.107.227.45
        truefalse
          unknown
          beacons-handoff.gcp.gvt2.com
          142.251.143.67
          truefalse
            unknown
            www.google.com
            172.217.16.132
            truefalse
              high
              cs1227.wpc.alphacdn.net
              192.229.221.185
              truefalse
                unknown
                clients.l.google.com
                172.217.18.14
                truefalse
                  high
                  mrrcountries.cdn.skype.com
                  unknown
                  unknownfalse
                    high
                    skypegraph.skype.com
                    unknown
                    unknownfalse
                      high
                      msgsearch.skype.com
                      unknown
                      unknownfalse
                        high
                        pnv.skype.com
                        unknown
                        unknownfalse
                          high
                          avatar.skype.com
                          unknown
                          unknownfalse
                            high
                            beacons.gcp.gvt2.com
                            unknown
                            unknownfalse
                              unknown
                              a.lw.skype.com
                              unknown
                              unknownfalse
                                high
                                account.live.com
                                unknown
                                unknownfalse
                                  high
                                  join.skype.com
                                  unknown
                                  unknownfalse
                                    high
                                    api.aps.skype.com
                                    unknown
                                    unknownfalse
                                      high
                                      static.asm.skype.com
                                      unknown
                                      unknownfalse
                                        high
                                        clients2.google.com
                                        unknown
                                        unknownfalse
                                          high
                                          secure.skypeassets.com
                                          unknown
                                          unknownfalse
                                            unknown
                                            static-asm.secure.skypeassets.com
                                            unknown
                                            unknownfalse
                                              unknown
                                              login.skype.com
                                              unknown
                                              unknownfalse
                                                high
                                                api.asm.skype.com
                                                unknown
                                                unknownfalse
                                                  high
                                                  trouter-easia-a.trouter.skype.com
                                                  unknown
                                                  unknownfalse
                                                    high
                                                    web.skype.com
                                                    unknown
                                                    unknownfalse
                                                      high
                                                      go.trouter.skype.com
                                                      unknown
                                                      unknownfalse
                                                        high
                                                        signup.live.com
                                                        unknown
                                                        unknownfalse
                                                          high
                                                          lw.skype.com
                                                          unknown
                                                          unknownfalse
                                                            high
                                                            people.skype.com
                                                            unknown
                                                            unknownfalse
                                                              high
                                                              logincdn.msftauth.net
                                                              unknown
                                                              unknownfalse
                                                                unknown
                                                                join.secure.skypeassets.com
                                                                unknown
                                                                unknownfalse
                                                                  unknown
                                                                  client-s.gateway.messenger.live.com
                                                                  unknown
                                                                  unknownfalse
                                                                    high
                                                                    static2.sharepointonline.com
                                                                    unknown
                                                                    unknownfalse
                                                                      unknown
                                                                      consumer.entitlement.skype.com
                                                                      unknown
                                                                      unknownfalse
                                                                        high
                                                                        profile.skype.com
                                                                        unknown
                                                                        unknownfalse
                                                                          high
                                                                          prod.registrar.skype.com
                                                                          unknown
                                                                          unknownfalse
                                                                            high
                                                                            trouter-azsc-euno-0-b.trouter.skype.com
                                                                            unknown
                                                                            unknownfalse
                                                                              high
                                                                              apps.skypeassets.com
                                                                              unknown
                                                                              unknownfalse
                                                                                unknown
                                                                                options.skype.com
                                                                                unknown
                                                                                unknownfalse
                                                                                  high
                                                                                  api.join.skype.com
                                                                                  unknown
                                                                                  unknownfalse
                                                                                    high
                                                                                    acctcdn.msftauth.net
                                                                                    unknown
                                                                                    unknownfalse
                                                                                      unknown
                                                                                      edge.skype.com
                                                                                      unknown
                                                                                      unknownfalse
                                                                                        high
                                                                                        NameMaliciousAntivirus DetectionReputation
                                                                                        https://join.skype.com/invite/puPTjSLvs9iJfalse
                                                                                          high
                                                                                          https://web.skype.com/8:live:.cid.c374590af32b4006?inviteId=puPTjSLvs9iJ&correlationId=4bce8c09-02a7-471f-bce7-e9ab8553e375false
                                                                                            high
                                                                                            • No. of IPs < 25%
                                                                                            • 25% < No. of IPs < 50%
                                                                                            • 50% < No. of IPs < 75%
                                                                                            • 75% < No. of IPs
                                                                                            IPDomainCountryFlagASNASN NameMalicious
                                                                                            13.69.116.104
                                                                                            unknownUnited States
                                                                                            8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                            104.79.88.158
                                                                                            unknownUnited States
                                                                                            16625AKAMAI-ASUSfalse
                                                                                            152.199.19.161
                                                                                            unknownUnited States
                                                                                            15133EDGECASTUSfalse
                                                                                            184.24.13.101
                                                                                            unknownUnited States
                                                                                            5650FRONTIER-FRTRUSfalse
                                                                                            172.217.18.14
                                                                                            clients.l.google.comUnited States
                                                                                            15169GOOGLEUSfalse
                                                                                            20.189.173.4
                                                                                            unknownUnited States
                                                                                            8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                            52.158.121.3
                                                                                            unknownUnited States
                                                                                            8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                            142.250.185.227
                                                                                            unknownUnited States
                                                                                            15169GOOGLEUSfalse
                                                                                            20.67.94.221
                                                                                            unknownUnited States
                                                                                            8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                            20.229.86.183
                                                                                            unknownUnited States
                                                                                            8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                            23.102.0.171
                                                                                            unknownUnited States
                                                                                            8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                            52.149.21.60
                                                                                            unknownUnited States
                                                                                            8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                            13.107.3.128
                                                                                            unknownUnited States
                                                                                            8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                            142.251.143.67
                                                                                            beacons-handoff.gcp.gvt2.comUnited States
                                                                                            15169GOOGLEUSfalse
                                                                                            20.107.37.227
                                                                                            unknownUnited States
                                                                                            8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                            13.79.198.109
                                                                                            unknownUnited States
                                                                                            8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                            52.169.122.66
                                                                                            unknownUnited States
                                                                                            8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                            23.203.84.22
                                                                                            unknownUnited States
                                                                                            16625AKAMAI-ASUSfalse
                                                                                            51.105.176.200
                                                                                            unknownUnited Kingdom
                                                                                            8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                            142.250.186.74
                                                                                            unknownUnited States
                                                                                            15169GOOGLEUSfalse
                                                                                            52.174.26.253
                                                                                            unknownUnited States
                                                                                            8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                            9.9.9.9
                                                                                            unknownUnited States
                                                                                            19281QUAD9-AS-1USfalse
                                                                                            52.113.194.133
                                                                                            unknownUnited States
                                                                                            8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                            52.166.246.38
                                                                                            unknownUnited States
                                                                                            8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                            34.104.35.123
                                                                                            unknownUnited States
                                                                                            15169GOOGLEUSfalse
                                                                                            13.95.7.84
                                                                                            unknownUnited States
                                                                                            8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                            68.232.34.200
                                                                                            unknownUnited States
                                                                                            15133EDGECASTUSfalse
                                                                                            40.114.211.99
                                                                                            unknownUnited States
                                                                                            8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                            13.107.42.16
                                                                                            unknownUnited States
                                                                                            8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                            137.116.214.105
                                                                                            unknownUnited States
                                                                                            8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                            52.113.199.175
                                                                                            unknownUnited States
                                                                                            8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                            13.81.61.82
                                                                                            unknownUnited States
                                                                                            8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                            142.250.186.109
                                                                                            accounts.google.comUnited States
                                                                                            15169GOOGLEUSfalse
                                                                                            51.137.91.111
                                                                                            unknownUnited Kingdom
                                                                                            8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                            239.255.255.250
                                                                                            unknownReserved
                                                                                            unknownunknownfalse
                                                                                            192.229.221.185
                                                                                            cs1227.wpc.alphacdn.netUnited States
                                                                                            15133EDGECASTUSfalse
                                                                                            152.199.21.175
                                                                                            sni1gl.wpc.alphacdn.netUnited States
                                                                                            15133EDGECASTUSfalse
                                                                                            13.94.251.244
                                                                                            unknownUnited States
                                                                                            8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                            172.217.16.132
                                                                                            www.google.comUnited States
                                                                                            15169GOOGLEUSfalse
                                                                                            40.126.32.138
                                                                                            unknownUnited States
                                                                                            8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                            13.89.179.9
                                                                                            unknownUnited States
                                                                                            8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                            104.40.75.246
                                                                                            unknownUnited States
                                                                                            8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                            IP
                                                                                            192.168.2.1
                                                                                            192.168.2.5
                                                                                            127.0.0.1
                                                                                            Joe Sandbox Version:36.0.0 Rainbow Opal
                                                                                            Analysis ID:762795
                                                                                            Start date and time:2022-12-07 16:43:47 +01:00
                                                                                            Joe Sandbox Product:CloudBasic
                                                                                            Overall analysis duration:
                                                                                            Hypervisor based Inspection enabled:false
                                                                                            Report type:full
                                                                                            Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                                                                            Sample URL:https://join.skype.com/invite/puPTjSLvs9iJ
                                                                                            Analysis system description:Windows 10 64 bit version 1909 (MS Office 2019, IE 11, Chrome 104, Firefox 88, Adobe Reader DC 21, Java 8 u291, 7-Zip)
                                                                                            Number of analysed new started processes analysed:14
                                                                                            Number of new started drivers analysed:0
                                                                                            Number of existing processes analysed:0
                                                                                            Number of existing drivers analysed:0
                                                                                            Number of injected processes analysed:0
                                                                                            Technologies:
                                                                                            • EGA enabled
                                                                                            Analysis Mode:stream
                                                                                            Analysis stop reason:Timeout
                                                                                            Detection:CLEAN
                                                                                            Classification:clean0.win@45/0@67/191
                                                                                            • Exclude process from analysis (whitelisted): SgrmBroker.exe, usocoreworker.exe, svchost.exe
                                                                                            • Excluded IPs from analysis (whitelisted): 52.166.246.38, 68.232.34.200, 20.190.160.20, 40.126.32.138, 40.126.32.134, 40.126.32.74, 20.190.160.17, 20.190.160.22, 40.126.32.68, 40.126.32.76, 13.107.42.16, 104.79.88.158, 52.169.122.66, 40.126.32.133, 52.174.26.253, 20.189.173.13, 20.67.94.221, 13.81.61.82, 184.24.13.101, 13.69.116.104, 88.221.168.78, 52.113.194.133
                                                                                            • Excluded domains from analysis (whitelisted): ctldl.windowsupdate.com
                                                                                            • Not all processes where analyzed, report is missing behavior information
                                                                                            • Report size getting too big, too many NtWriteVirtualMemory calls found.
                                                                                            No created / dropped files found
                                                                                            No static file info