Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://preview.webflow.com/preview/secure-document-59ad7d?utm_medium=preview_link&utm_source=designer&utm_content=secure-document-59ad7d&preview=9a2adf8bcbeeee4bfc926853e0f2eb24&workflow=preview

Overview

General Information

Sample URL:https://preview.webflow.com/preview/secure-document-59ad7d?utm_medium=preview_link&utm_source=designer&utm_content=secure-document-59ad7d&preview=9a2adf8bcbeeee4bfc926853e0f2eb24&workflow=preview
Analysis ID:807406

Detection

HTMLPhisher
Score:52
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Yara detected HtmlPhish10
Phishing site detected (based on image similarity)
HTML body contains low number of good links
Invalid T&C link found
No HTML title found

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 1492 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://preview.webflow.com/preview/secure-document-59ad7d?utm_medium=preview_link&utm_source=designer&utm_content=secure-document-59ad7d&preview=9a2adf8bcbeeee4bfc926853e0f2eb24&workflow=preview MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
    • chrome.exe (PID: 332 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2036 --field-trial-handle=1808,i,4806942962402137978,8722282257215584760,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8 MD5: 7BC7B4AEDC055BB02BCB52710132E9E1)
  • cleanup
SourceRuleDescriptionAuthorStrings
68610.6.pages.csvJoeSecurity_HtmlPhish_10Yara detected HtmlPhish_10Joe Security
    No Sigma rule has matched
    No Snort rule has matched

    Click to jump to signature section

    Show All Signature Results

    Phishing

    barindex
    Source: Yara matchFile source: 68610.6.pages.csv, type: HTML
    Source: embeddedMatcher: Found strong image similarity, brand: Microsoft image: 68610.6.img.2.gfk.csv EF884BDEDEF280DF97A4C5604058D8DB
    Source: embeddedMatcher: Found strong image similarity, brand: Microsoft image: 68610.6.img.2.gfk.csv EF884BDEDEF280DF97A4C5604058D8DB
    Source: embeddedMatcher: Found strong image similarity, brand: Microsoft image: 68610.6.img.2.gfk.csv EF884BDEDEF280DF97A4C5604058D8DB
    Source: embeddedMatcher: Found strong image similarity, brand: Microsoft image: 68610.6.img.2.gfk.csv EF884BDEDEF280DF97A4C5604058D8DB
    Source: embeddedMatcher: Found strong image similarity, brand: Microsoft image: 68610.6.img.2.gfk.csv EF884BDEDEF280DF97A4C5604058D8DB
    Source: embeddedMatcher: Found strong image similarity, brand: Microsoft image: 68610.6.img.2.gfk.csv EF884BDEDEF280DF97A4C5604058D8DB
    Source: embeddedMatcher: Found strong image similarity, brand: Microsoft image: 68610.6.img.2.gfk.csv EF884BDEDEF280DF97A4C5604058D8DB
    Source: https://best-face-serum.com/release/Odrivex%203%202/HTTP Parser: Number of links: 0
    Source: https://best-face-serum.com/release/Odrivex%203%202/HTTP Parser: Invalid link: Privacy & Cookies
    Source: https://best-face-serum.com/release/Odrivex%203%202/HTTP Parser: HTML title missing
    Source: https://best-face-serum.com/release/Odrivex%203%202/HTTP Parser: No <meta name="author".. found
    Source: https://best-face-serum.com/release/Odrivex%203%202/HTTP Parser: No <meta name="copyright".. found
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdater
    Source: unknownDNS traffic detected: queries for: preview.webflow.com
    Source: unknownNetwork traffic detected: HTTP traffic on port 49817 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49860
    Source: unknownNetwork traffic detected: HTTP traffic on port 49789 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49800 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49875 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49781 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49826 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49881 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49857
    Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49855
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49854
    Source: unknownNetwork traffic detected: HTTP traffic on port 49900 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49853
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49851
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49850
    Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49855 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49806 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49823 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49777 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49846
    Source: unknownNetwork traffic detected: HTTP traffic on port 49790 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49842
    Source: unknownNetwork traffic detected: HTTP traffic on port 49819 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49947 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49834 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49918 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49828 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49793 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49850 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49805 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49831 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49838
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49836
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49835
    Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49834
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49833
    Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49799
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49832
    Source: unknownNetwork traffic detected: HTTP traffic on port 50037 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49831
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49830
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
    Source: unknownNetwork traffic detected: HTTP traffic on port 49814 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49822 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49790
    Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49853 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49825 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49829
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49828
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49827
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49826
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49947
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49825
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49823
    Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49789
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49822
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49821
    Source: unknownNetwork traffic detected: HTTP traffic on port 49842 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
    Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49785
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49784
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49780
    Source: unknownNetwork traffic detected: HTTP traffic on port 49836 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49785 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49939 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49833 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49819
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49818
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49939
    Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49799 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49810 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49817
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49816
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49815
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49814
    Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49779
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49810
    Source: unknownNetwork traffic detected: HTTP traffic on port 49816 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
    Source: unknownNetwork traffic detected: HTTP traffic on port 49780 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49827 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49802 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49851 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49830 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49806
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49805
    Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49802
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49801
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49800
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49920
    Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
    Source: unknownNetwork traffic detected: HTTP traffic on port 49783 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
    Source: unknownNetwork traffic detected: HTTP traffic on port 49838 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
    Source: unknownNetwork traffic detected: HTTP traffic on port 49821 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49881
    Source: unknownNetwork traffic detected: HTTP traffic on port 49815 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49880
    Source: unknownNetwork traffic detected: HTTP traffic on port 49857 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50037
    Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49854 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49801 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49918
    Source: unknownNetwork traffic detected: HTTP traffic on port 49860 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
    Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49875
    Source: unknownNetwork traffic detected: HTTP traffic on port 49818 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49835 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49829 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49880 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49832 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49775 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49920 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49846 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49903
    Source: unknownNetwork traffic detected: HTTP traffic on port 49903 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49900
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: classification engineClassification label: mal52.phis.win@30/0@36/291
    Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://preview.webflow.com/preview/secure-document-59ad7d?utm_medium=preview_link&utm_source=designer&utm_content=secure-document-59ad7d&preview=9a2adf8bcbeeee4bfc926853e0f2eb24&workflow=preview
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2036 --field-trial-handle=1808,i,4806942962402137978,8722282257215584760,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2036 --field-trial-handle=1808,i,4806942962402137978,8722282257215584760,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\GoogleUpdater
    Source: Window RecorderWindow detected: More than 3 window changes detected
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\GoogleUpdater
    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid AccountsWindows Management InstrumentationPath Interception1
    Process Injection
    2
    Masquerading
    OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium2
    Encrypted Channel
    Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
    Process Injection
    LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
    Non-Application Layer Protocol
    Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration2
    Application Layer Protocol
    Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.


    windows-stand
    SourceDetectionScannerLabelLink
    https://preview.webflow.com/preview/secure-document-59ad7d?utm_medium=preview_link&utm_source=designer&utm_content=secure-document-59ad7d&preview=9a2adf8bcbeeee4bfc926853e0f2eb24&workflow=preview0%Avira URL Cloudsafe
    https://preview.webflow.com/preview/secure-document-59ad7d?utm_medium=preview_link&utm_source=designer&utm_content=secure-document-59ad7d&preview=9a2adf8bcbeeee4bfc926853e0f2eb24&workflow=preview0%VirustotalBrowse
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    NameIPActiveMaliciousAntivirus DetectionReputation
    paypal-dynamic.map.fastly.net
    151.101.65.21
    truefalse
      unknown
      apilayer.net
      18.210.254.78
      truefalse
        unknown
        partnerlinks.io
        104.18.31.133
        truefalse
          unknown
          d296je7bbdd650.cloudfront.net
          18.66.91.228
          truefalse
            high
            snippet.growsumo.com
            104.18.2.70
            truefalse
              high
              cdnjs.cloudflare.com
              104.17.24.14
              truefalse
                high
                best-face-serum.com
                69.49.247.78
                truefalse
                  unknown
                  preview.webflow.com
                  54.242.54.202
                  truefalse
                    high
                    www.google.com
                    142.250.185.68
                    truefalse
                      high
                      uploads-ssl.webflow.com
                      18.66.112.117
                      truefalse
                        high
                        grsm.io
                        104.18.10.212
                        truefalse
                          unknown
                          stackpath.bootstrapcdn.com
                          104.18.11.207
                          truefalse
                            high
                            accounts.google.com
                            172.217.18.13
                            truefalse
                              high
                              sessions.bugsnag.com
                              35.190.88.7
                              truefalse
                                high
                                webflow.refersion.com
                                104.18.40.222
                                truefalse
                                  high
                                  maxcdn.bootstrapcdn.com
                                  104.18.10.207
                                  truefalse
                                    high
                                    HHN-efz.ms-acdc.office.com
                                    52.98.171.242
                                    truefalse
                                      high
                                      stripecdn.map.fastly.net
                                      151.101.64.176
                                      truefalse
                                        unknown
                                        d3e54v103j8qbb.cloudfront.net
                                        99.86.1.184
                                        truefalse
                                          high
                                          7bp2kqlfyczm.stspg-customer.com
                                          52.215.192.132
                                          truefalse
                                            unknown
                                            webflow.com
                                            35.169.14.133
                                            truefalse
                                              high
                                              m.stripe.com
                                              54.184.107.160
                                              truefalse
                                                high
                                                www-fastly.glb.paypal.com
                                                151.101.65.21
                                                truefalse
                                                  high
                                                  part-0017.t-0009.fdv2-t-msedge.net
                                                  13.107.237.45
                                                  truefalse
                                                    unknown
                                                    clients.l.google.com
                                                    216.58.212.142
                                                    truefalse
                                                      high
                                                      unpkg.com
                                                      104.16.123.175
                                                      truefalse
                                                        high
                                                        m.stripe.network
                                                        unknown
                                                        unknownfalse
                                                          high
                                                          outlook.live.com
                                                          unknown
                                                          unknownfalse
                                                            high
                                                            www.paypal.com
                                                            unknown
                                                            unknownfalse
                                                              high
                                                              cdn.segment.com
                                                              unknown
                                                              unknownfalse
                                                                high
                                                                clients2.google.com
                                                                unknown
                                                                unknownfalse
                                                                  high
                                                                  code.jquery.com
                                                                  unknown
                                                                  unknownfalse
                                                                    high
                                                                    ow2.res.office365.com
                                                                    unknown
                                                                    unknownfalse
                                                                      high
                                                                      exo.nel.measure.office.net
                                                                      unknown
                                                                      unknownfalse
                                                                        high
                                                                        status.webflow.com
                                                                        unknown
                                                                        unknownfalse
                                                                          high
                                                                          a.clarity.ms
                                                                          unknown
                                                                          unknownfalse
                                                                            unknown
                                                                            www.clarity.ms
                                                                            unknown
                                                                            unknownfalse
                                                                              unknown
                                                                              r4.res.office365.com
                                                                              unknown
                                                                              unknownfalse
                                                                                high
                                                                                api.ipstack.com
                                                                                unknown
                                                                                unknownfalse
                                                                                  unknown
                                                                                  js.stripe.com
                                                                                  unknown
                                                                                  unknownfalse
                                                                                    high
                                                                                    www.sandbox.paypal.com
                                                                                    unknown
                                                                                    unknownfalse
                                                                                      high
                                                                                      www.hotmail.com
                                                                                      unknown
                                                                                      unknownfalse
                                                                                        high
                                                                                        NameMaliciousAntivirus DetectionReputation
                                                                                        https://js.stripe.com/v3/m-outer-93afeeb17bc37e711759584dbfc50d47.html#url=https%3A%2F%2Fpreview.webflow.com%2Fpreview%2Fsecure-document-59ad7d%3Futm_medium%3Dpreview_link%26utm_source%3Ddesigner%26utm_content%3Dsecure-document-59ad7d%26preview%3D9a2adf8bcbeeee4bfc926853e0f2eb24%26workflow%3Dpreview&title=Designer&referrer=&muid=NA&sid=NA&version=6&preview=falsefalse
                                                                                          high
                                                                                          https://outlook.live.com/owa/prefetch.aspxfalse
                                                                                            high
                                                                                            https://preview.webflow.com/preview/secure-document-59ad7d?utm_medium=preview_link&utm_source=designer&utm_content=secure-document-59ad7d&preview=9a2adf8bcbeeee4bfc926853e0f2eb24&workflow=previewfalse
                                                                                              high
                                                                                              https://preview.webflow.com/site/empty.htmlfalse
                                                                                                high
                                                                                                https://m.stripe.network/inner.html#url=https%3A%2F%2Fpreview.webflow.com%2Fpreview%2Fsecure-document-59ad7d%3Futm_medium%3Dpreview_link%26utm_source%3Ddesigner%26utm_content%3Dsecure-document-59ad7d%26preview%3D9a2adf8bcbeeee4bfc926853e0f2eb24%26workflow%3Dpreview&title=Designer&referrer=&muid=NA&sid=NA&version=6&preview=falsefalse
                                                                                                  high
                                                                                                  https://best-face-serum.com/release/Odrivex%203%202/false
                                                                                                    unknown
                                                                                                    https://outlook.live.com/owa/false
                                                                                                      high
                                                                                                      • No. of IPs < 25%
                                                                                                      • 25% < No. of IPs < 50%
                                                                                                      • 50% < No. of IPs < 75%
                                                                                                      • 75% < No. of IPs
                                                                                                      IPDomainCountryFlagASNASN NameMalicious
                                                                                                      142.250.185.99
                                                                                                      unknownUnited States
                                                                                                      15169GOOGLEUSfalse
                                                                                                      2.16.238.152
                                                                                                      unknownEuropean Union
                                                                                                      20940AKAMAI-ASN1EUfalse
                                                                                                      104.18.10.207
                                                                                                      maxcdn.bootstrapcdn.comUnited States
                                                                                                      13335CLOUDFLARENETUSfalse
                                                                                                      152.199.19.160
                                                                                                      unknownUnited States
                                                                                                      15133EDGECASTUSfalse
                                                                                                      216.58.212.142
                                                                                                      clients.l.google.comUnited States
                                                                                                      15169GOOGLEUSfalse
                                                                                                      172.217.18.13
                                                                                                      accounts.google.comUnited States
                                                                                                      15169GOOGLEUSfalse
                                                                                                      18.66.112.117
                                                                                                      uploads-ssl.webflow.comUnited States
                                                                                                      3MIT-GATEWAYSUSfalse
                                                                                                      35.169.14.133
                                                                                                      webflow.comUnited States
                                                                                                      14618AMAZON-AESUSfalse
                                                                                                      52.98.171.242
                                                                                                      HHN-efz.ms-acdc.office.comUnited States
                                                                                                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                      35.190.88.7
                                                                                                      sessions.bugsnag.comUnited States
                                                                                                      15169GOOGLEUSfalse
                                                                                                      104.16.123.175
                                                                                                      unpkg.comUnited States
                                                                                                      13335CLOUDFLARENETUSfalse
                                                                                                      142.250.181.234
                                                                                                      unknownUnited States
                                                                                                      15169GOOGLEUSfalse
                                                                                                      23.96.225.71
                                                                                                      unknownUnited States
                                                                                                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                      104.18.40.222
                                                                                                      webflow.refersion.comUnited States
                                                                                                      13335CLOUDFLARENETUSfalse
                                                                                                      69.16.175.10
                                                                                                      unknownUnited States
                                                                                                      20446HIGHWINDS3USfalse
                                                                                                      54.242.54.202
                                                                                                      preview.webflow.comUnited States
                                                                                                      14618AMAZON-AESUSfalse
                                                                                                      54.184.107.160
                                                                                                      m.stripe.comUnited States
                                                                                                      16509AMAZON-02USfalse
                                                                                                      204.79.197.212
                                                                                                      unknownUnited States
                                                                                                      8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                      95.101.111.130
                                                                                                      unknownEuropean Union
                                                                                                      12956TELEFONICATELXIUSESfalse
                                                                                                      18.66.91.228
                                                                                                      d296je7bbdd650.cloudfront.netUnited States
                                                                                                      3MIT-GATEWAYSUSfalse
                                                                                                      69.49.247.78
                                                                                                      best-face-serum.comUnited States
                                                                                                      46606UNIFIEDLAYER-AS-1USfalse
                                                                                                      104.17.24.14
                                                                                                      cdnjs.cloudflare.comUnited States
                                                                                                      13335CLOUDFLARENETUSfalse
                                                                                                      142.250.185.67
                                                                                                      unknownUnited States
                                                                                                      15169GOOGLEUSfalse
                                                                                                      142.250.185.68
                                                                                                      www.google.comUnited States
                                                                                                      15169GOOGLEUSfalse
                                                                                                      34.104.35.123
                                                                                                      unknownUnited States
                                                                                                      15169GOOGLEUSfalse
                                                                                                      18.210.254.78
                                                                                                      apilayer.netUnited States
                                                                                                      14618AMAZON-AESUSfalse
                                                                                                      99.86.1.184
                                                                                                      d3e54v103j8qbb.cloudfront.netUnited States
                                                                                                      16509AMAZON-02USfalse
                                                                                                      104.18.10.212
                                                                                                      grsm.ioUnited States
                                                                                                      13335CLOUDFLARENETUSfalse
                                                                                                      104.18.2.70
                                                                                                      snippet.growsumo.comUnited States
                                                                                                      13335CLOUDFLARENETUSfalse
                                                                                                      104.45.184.134
                                                                                                      unknownUnited States
                                                                                                      8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                      104.18.11.207
                                                                                                      stackpath.bootstrapcdn.comUnited States
                                                                                                      13335CLOUDFLARENETUSfalse
                                                                                                      239.255.255.250
                                                                                                      unknownReserved
                                                                                                      unknownunknownfalse
                                                                                                      142.250.185.131
                                                                                                      unknownUnited States
                                                                                                      15169GOOGLEUSfalse
                                                                                                      151.101.65.21
                                                                                                      paypal-dynamic.map.fastly.netUnited States
                                                                                                      54113FASTLYUSfalse
                                                                                                      13.107.237.45
                                                                                                      part-0017.t-0009.fdv2-t-msedge.netUnited States
                                                                                                      8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                                                                      142.250.181.228
                                                                                                      unknownUnited States
                                                                                                      15169GOOGLEUSfalse
                                                                                                      52.215.192.132
                                                                                                      7bp2kqlfyczm.stspg-customer.comUnited States
                                                                                                      16509AMAZON-02USfalse
                                                                                                      104.18.31.133
                                                                                                      partnerlinks.ioUnited States
                                                                                                      13335CLOUDFLARENETUSfalse
                                                                                                      151.101.64.176
                                                                                                      stripecdn.map.fastly.netUnited States
                                                                                                      54113FASTLYUSfalse
                                                                                                      142.250.184.234
                                                                                                      unknownUnited States
                                                                                                      15169GOOGLEUSfalse
                                                                                                      IP
                                                                                                      192.168.2.5
                                                                                                      127.0.0.1
                                                                                                      Joe Sandbox Version:36.0.0 Rainbow Opal
                                                                                                      Analysis ID:807406
                                                                                                      Start date and time:2023-02-14 17:21:43 +01:00
                                                                                                      Joe Sandbox Product:CloudBasic
                                                                                                      Overall analysis duration:
                                                                                                      Hypervisor based Inspection enabled:false
                                                                                                      Report type:full
                                                                                                      Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                                                                                      Sample URL:https://preview.webflow.com/preview/secure-document-59ad7d?utm_medium=preview_link&utm_source=designer&utm_content=secure-document-59ad7d&preview=9a2adf8bcbeeee4bfc926853e0f2eb24&workflow=preview
                                                                                                      Analysis system description:Windows 10 64 bit version 1909 (MS Office 2019, IE 11, Chrome 104, Firefox 88, Adobe Reader DC 21, Java 8 u291, 7-Zip)
                                                                                                      Number of analysed new started processes analysed:5
                                                                                                      Number of new started drivers analysed:0
                                                                                                      Number of existing processes analysed:0
                                                                                                      Number of existing drivers analysed:0
                                                                                                      Number of injected processes analysed:0
                                                                                                      Technologies:
                                                                                                      • EGA enabled
                                                                                                      Analysis Mode:stream
                                                                                                      Analysis stop reason:Timeout
                                                                                                      Detection:MAL
                                                                                                      Classification:mal52.phis.win@30/0@36/291
                                                                                                      • Exclude process from analysis (whitelisted): SIHClient.exe
                                                                                                      • Excluded IPs from analysis (whitelisted): 40.126.31.67, 20.190.159.0, 40.126.31.69, 20.190.159.73, 20.190.159.23, 20.190.159.64, 20.190.159.71, 40.126.31.73, 142.250.185.131, 34.104.35.123, 142.250.181.234, 142.250.185.99
                                                                                                      • Excluded domains from analysis (whitelisted): fonts.googleapis.com, prda.aadg.msidentity.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, login.live.com, fonts.gstatic.com, clientservices.googleapis.com, login.msa.msidentity.com, www.tm.a.prd.aadg.trafficmanager.net, www.tm.lg.prod.aadmsa.trafficmanager.net
                                                                                                      • Not all processes where analyzed, report is missing behavior information
                                                                                                      • Report size getting too big, too many NtWriteVirtualMemory calls found.
                                                                                                      No created / dropped files found
                                                                                                      No static file info