Windows Analysis Report
https://fshjjfetalpacksrlfggghhgfgj.taplink.ws/

Overview

General Information

Sample URL: https://fshjjfetalpacksrlfggghhgfgj.taplink.ws/
Analysis ID: 1522628
Infos:

Detection

HTMLPhisher
Score: 56
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Yara detected HtmlPhish29
AI detected landing page (webpage, office document or email)
Phishing site or detected (based on various text indicators)
HTML page contains hidden javascript code
Stores files to the Windows start menu directory

Classification

Phishing

barindex
Source: Yara match File source: 8.11..script.csv, type: HTML
Source: Yara match File source: 9.12..script.csv, type: HTML
Source: Yara match File source: dropped/chromecache_96, type: DROPPED
Source: Yara match File source: dropped/chromecache_117, type: DROPPED
Source: Chrome DOM: 2.6 OCR Text: M ETALPACK sri. SHARED A DOCUMENT WITH YOU PDF CLICK HERE TO VIEW YOUR DOCUMENT METALPACK sri. This document has been scanned for viruses by Norton'" AntiVirus Security Standard Software 2024 by
Source: Chrome DOM: 2.7 OCR Text: METALPACK sri. SHARED A DOCUMENT WITH YOU * *Pages 2 PDF CLICK HERE TO VIEW YOUR DOCUMENT METALPACK sri. This document has been scanned for viruses by Norton'V AntiVirus Security Standard Software 2024 by
Source: https://app.pipefy.com/public/form/41kuSg4l HTTP Parser: Base64 decoded: sv=o365_1_one&rand=NmtDeFk=&uid=USER18092024U19091835
Source: https://app.pipefy.com/public/form/41kuSg4l HTTP Parser: No favicon
Source: https://app.pipefy.com/public/form/41kuSg4l HTTP Parser: No favicon
Source: https://app.pipefy.com/public/form/41kuSg4l HTTP Parser: No favicon
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:54227 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:54232 version: TLS 1.2
Source: unknown HTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.16:54237 version: TLS 1.2
Source: unknown HTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.16:54305 version: TLS 1.2
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.114.59.183
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic DNS traffic detected: DNS query: fshjjfetalpacksrlfggghhgfgj.taplink.ws
Source: global traffic DNS traffic detected: DNS query: a.nel.cloudflare.com
Source: global traffic DNS traffic detected: DNS query: mc.yandex.ru
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: global traffic DNS traffic detected: DNS query: taplink.st
Source: global traffic DNS traffic detected: DNS query: app.pipefy.com
Source: global traffic DNS traffic detected: DNS query: pipestyle.staticpipefy.com
Source: global traffic DNS traffic detected: DNS query: pipeui.staticpipefy.com
Source: global traffic DNS traffic detected: DNS query: assets.staticpipefy.com
Source: global traffic DNS traffic detected: DNS query: ws-mt1.pusher.com
Source: global traffic DNS traffic detected: DNS query: sockjs.pusher.com
Source: global traffic DNS traffic detected: DNS query: js.hcaptcha.com
Source: global traffic DNS traffic detected: DNS query: api-js.mixpanel.com
Source: global traffic DNS traffic detected: DNS query: app-location.pipefy.com
Source: global traffic DNS traffic detected: DNS query: newassets.hcaptcha.com
Source: global traffic DNS traffic detected: DNS query: api2.hcaptcha.com
Source: global traffic DNS traffic detected: DNS query: apm.pipefy.com
Source: global traffic DNS traffic detected: DNS query: dianemccabe.com
Source: unknown Network traffic detected: HTTP traffic on port 54282 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54201 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54224 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54247 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54218 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54304 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54212 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54309
Source: unknown Network traffic detected: HTTP traffic on port 54287 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54308
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54307
Source: unknown Network traffic detected: HTTP traffic on port 54258 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54302
Source: unknown Network traffic detected: HTTP traffic on port 54293 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54301
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54300
Source: unknown Network traffic detected: HTTP traffic on port 54241 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54306
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54305
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54304
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54303
Source: unknown Network traffic detected: HTTP traffic on port 54315 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54276 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54230 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54309 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54322 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54319
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54318
Source: unknown Network traffic detected: HTTP traffic on port 54259 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54312
Source: unknown Network traffic detected: HTTP traffic on port 54242 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54311
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54310
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54317
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54316
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54315
Source: unknown Network traffic detected: HTTP traffic on port 54200 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54314
Source: unknown Network traffic detected: HTTP traffic on port 54316 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54298 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54320
Source: unknown Network traffic detected: HTTP traffic on port 54275 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54321 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54209
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54208
Source: unknown Network traffic detected: HTTP traffic on port 54264 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54281 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54324
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54202
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54323
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54201
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54322
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54200
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54321
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54205
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54204
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54325
Source: unknown Network traffic detected: HTTP traffic on port 54310 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54225 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54210
Source: unknown Network traffic detected: HTTP traffic on port 54270 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54219 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54211 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54286 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54263 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54257 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54292 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54299
Source: unknown Network traffic detected: HTTP traffic on port 54240 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54300 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54323 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54311 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54202 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54223 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54251 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54297 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54199
Source: unknown Network traffic detected: HTTP traffic on port 54269 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54217 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54305 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54213 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54280 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54312 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54252 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54268 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54306 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54285 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54235 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54291 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54317 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54246 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54274 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54209 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54238 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54258
Source: unknown Network traffic detected: HTTP traffic on port 54244 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54257
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54256
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54255
Source: unknown Network traffic detected: HTTP traffic on port 54221 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54318 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54259
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54261
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54260
Source: unknown Network traffic detected: HTTP traffic on port 54296 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54250 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54265
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54264
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54263
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54262
Source: unknown Network traffic detected: HTTP traffic on port 54273 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54262 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54279 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54269
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54268
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54267
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54266
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54272
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54271
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54270
Source: unknown Network traffic detected: HTTP traffic on port 54227 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54276
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54275
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54274
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54273
Source: unknown Network traffic detected: HTTP traffic on port 54255 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54301 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54261 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54290 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54279
Source: unknown Network traffic detected: HTTP traffic on port 54278 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54278
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54277
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54283
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54282
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54281
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54280
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54287
Source: unknown Network traffic detected: HTTP traffic on port 54245 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54286
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54285
Source: unknown Network traffic detected: HTTP traffic on port 54302 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54233 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54199 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54214 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54239 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54256 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54289
Source: unknown Network traffic detected: HTTP traffic on port 54208 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54288
Source: unknown Network traffic detected: HTTP traffic on port 54222 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54294
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54293
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54292
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54291
Source: unknown Network traffic detected: HTTP traffic on port 54295 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54298
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54297
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54296
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54295
Source: unknown Network traffic detected: HTTP traffic on port 54267 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54290
Source: unknown Network traffic detected: HTTP traffic on port 54307 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54324 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54320 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54219
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54214
Source: unknown Network traffic detected: HTTP traffic on port 54314 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54213
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54212
Source: unknown Network traffic detected: HTTP traffic on port 54205 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54211
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54218
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54217
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54215
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54221
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54220
Source: unknown Network traffic detected: HTTP traffic on port 54277 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54254 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54289 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54308 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54237 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54319 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54283 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54266 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54225
Source: unknown Network traffic detected: HTTP traffic on port 54220 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54224
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54223
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54222
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54227
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54226
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54232
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54230
Source: unknown Network traffic detected: HTTP traffic on port 54272 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54248 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54288 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49678 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54265 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54235
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54233
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54239
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54238
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54237
Source: unknown Network traffic detected: HTTP traffic on port 54226 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54243
Source: unknown Network traffic detected: HTTP traffic on port 54271 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54242
Source: unknown Network traffic detected: HTTP traffic on port 54294 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54241
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54240
Source: unknown Network traffic detected: HTTP traffic on port 54210 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54325 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54260 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49673 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54243 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54247
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54246
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54245
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54244
Source: unknown Network traffic detected: HTTP traffic on port 54204 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54248
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54250
Source: unknown Network traffic detected: HTTP traffic on port 54299 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54254
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54252
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54251
Source: unknown Network traffic detected: HTTP traffic on port 54303 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54232 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54215 -> 443
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:54227 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:54232 version: TLS 1.2
Source: unknown HTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.16:54237 version: TLS 1.2
Source: unknown HTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.16:54305 version: TLS 1.2
Source: classification engine Classification label: mal56.phis.win@19/46@68/210
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2168 --field-trial-handle=1852,i,15151632708212088530,3997094878592568359,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://fshjjfetalpacksrlfggghhgfgj.taplink.ws/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2168 --field-trial-handle=1852,i,15151632708212088530,3997094878592568359,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: Window Recorder Window detected: More than 3 window changes detected

Persistence and Installation Behavior

barindex
Source: https://fshjjfetalpacksrlfggghhgfgj.taplink.ws/ LLM: Page contains button: 'VIEW DOCUMENT HERE' Source: '0.1.pages.csv'
Source: https://app.pipefy.com/public/form/41kuSg4l LLM: Page contains button: 'CLICK HERE TO VIEW YOUR DOCUMENT' Source: '2.4.pages.csv'
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs