Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://Ontariogov.onmicrosoft.com

Overview

General Information

Sample URL:http://Ontariogov.onmicrosoft.com
Analysis ID:1524531
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 4584 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5228 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2220 --field-trial-handle=2160,i,12445135164632047739,5507286661348154879,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6268 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://Ontariogov.onmicrosoft.com" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: ontariogov.onmicrosoft.com
Source: global trafficDNS traffic detected: DNS query: google.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: classification engineClassification label: unknown0.win@19/0@12/3
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2220 --field-trial-handle=2160,i,12445135164632047739,5507286661348154879,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://Ontariogov.onmicrosoft.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2220 --field-trial-handle=2160,i,12445135164632047739,5507286661348154879,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
google.com
142.250.185.78
truefalse
    unknown
    www.google.com
    142.250.186.36
    truefalse
      unknown
      fp2e7a.wpc.phicdn.net
      192.229.221.95
      truefalse
        unknown
        ontariogov.onmicrosoft.com
        unknown
        unknownfalse
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          142.250.186.36
          www.google.comUnited States
          15169GOOGLEUSfalse
          239.255.255.250
          unknownReserved
          unknownunknownfalse
          IP
          192.168.2.4
          Joe Sandbox version:41.0.0 Charoite
          Analysis ID:1524531
          Start date and time:2024-10-02 23:06:16 +02:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 1m 59s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:browseurl.jbs
          Sample URL:http://Ontariogov.onmicrosoft.com
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:5
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • EGA enabled
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Detection:UNKNOWN
          Classification:unknown0.win@19/0@12/3
          Cookbook Comments:
          • URL browsing timeout or error
          • URL not reachable
          • Exclude process from analysis (whitelisted): SIHClient.exe, svchost.exe
          • Excluded IPs from analysis (whitelisted): 142.250.185.67, 142.250.185.142, 108.177.15.84, 34.104.35.123, 184.28.90.27, 4.175.87.197, 93.184.221.240, 192.229.221.95, 20.3.187.198
          • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, clientservices.googleapis.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, wu.azureedge.net, clients2.google.com, ocsp.digicert.com, e16604.g.akamaiedge.net, bg.apr-52dd2-0503.edgecastdns.net, cs11.wpc.v0cdn.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, hlb.apr-52dd2-0.edgecastdns.net, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net, fs.microsoft.com, accounts.google.com, ctldl.windowsupdate.com.delivery.microsoft.com, wu.ec.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, fe3.delivery.mp.microsoft.com, edgedl.me.gvt1.com, clients.l.google.com
          • Not all processes where analyzed, report is missing behavior information
          • Report size getting too big, too many NtSetInformationFile calls found.
          • VT rate limit hit for: http://Ontariogov.onmicrosoft.com
          No simulations
          No context
          No context
          No context
          No context
          No context
          No created / dropped files found
          No static file info
          TimestampSource PortDest PortSource IPDest IP
          Oct 2, 2024 23:07:01.075443983 CEST49675443192.168.2.4173.222.162.32
          Oct 2, 2024 23:07:10.684192896 CEST49675443192.168.2.4173.222.162.32
          Oct 2, 2024 23:07:13.002351999 CEST49737443192.168.2.4142.250.186.36
          Oct 2, 2024 23:07:13.002458096 CEST44349737142.250.186.36192.168.2.4
          Oct 2, 2024 23:07:13.002536058 CEST49737443192.168.2.4142.250.186.36
          Oct 2, 2024 23:07:13.003237963 CEST49737443192.168.2.4142.250.186.36
          Oct 2, 2024 23:07:13.003273964 CEST44349737142.250.186.36192.168.2.4
          Oct 2, 2024 23:07:13.649961948 CEST44349737142.250.186.36192.168.2.4
          Oct 2, 2024 23:07:13.657244921 CEST49737443192.168.2.4142.250.186.36
          Oct 2, 2024 23:07:13.657310009 CEST44349737142.250.186.36192.168.2.4
          Oct 2, 2024 23:07:13.658799887 CEST44349737142.250.186.36192.168.2.4
          Oct 2, 2024 23:07:13.658907890 CEST49737443192.168.2.4142.250.186.36
          Oct 2, 2024 23:07:13.660485983 CEST49737443192.168.2.4142.250.186.36
          Oct 2, 2024 23:07:13.660587072 CEST44349737142.250.186.36192.168.2.4
          Oct 2, 2024 23:07:13.714814901 CEST49737443192.168.2.4142.250.186.36
          Oct 2, 2024 23:07:13.714840889 CEST44349737142.250.186.36192.168.2.4
          Oct 2, 2024 23:07:13.761667967 CEST49737443192.168.2.4142.250.186.36
          Oct 2, 2024 23:07:23.546216011 CEST44349737142.250.186.36192.168.2.4
          Oct 2, 2024 23:07:23.546416998 CEST44349737142.250.186.36192.168.2.4
          Oct 2, 2024 23:07:23.546494007 CEST49737443192.168.2.4142.250.186.36
          Oct 2, 2024 23:07:25.488939047 CEST49737443192.168.2.4142.250.186.36
          Oct 2, 2024 23:07:25.488980055 CEST44349737142.250.186.36192.168.2.4
          TimestampSource PortDest PortSource IPDest IP
          Oct 2, 2024 23:07:09.219538927 CEST53499791.1.1.1192.168.2.4
          Oct 2, 2024 23:07:09.279537916 CEST53597661.1.1.1192.168.2.4
          Oct 2, 2024 23:07:10.400896072 CEST6483153192.168.2.41.1.1.1
          Oct 2, 2024 23:07:10.402582884 CEST6366153192.168.2.41.1.1.1
          Oct 2, 2024 23:07:10.421978951 CEST53648311.1.1.1192.168.2.4
          Oct 2, 2024 23:07:10.427413940 CEST53636611.1.1.1192.168.2.4
          Oct 2, 2024 23:07:10.428199053 CEST6010953192.168.2.41.1.1.1
          Oct 2, 2024 23:07:10.444818974 CEST53538341.1.1.1192.168.2.4
          Oct 2, 2024 23:07:10.457324028 CEST53601091.1.1.1192.168.2.4
          Oct 2, 2024 23:07:10.518327951 CEST6365353192.168.2.48.8.8.8
          Oct 2, 2024 23:07:10.518462896 CEST5215453192.168.2.41.1.1.1
          Oct 2, 2024 23:07:10.525666952 CEST53521541.1.1.1192.168.2.4
          Oct 2, 2024 23:07:10.534811974 CEST53636538.8.8.8192.168.2.4
          Oct 2, 2024 23:07:11.525527954 CEST5265053192.168.2.41.1.1.1
          Oct 2, 2024 23:07:11.525765896 CEST5614753192.168.2.41.1.1.1
          Oct 2, 2024 23:07:11.558840990 CEST53526501.1.1.1192.168.2.4
          Oct 2, 2024 23:07:11.562575102 CEST53561471.1.1.1192.168.2.4
          Oct 2, 2024 23:07:12.993241072 CEST6007053192.168.2.41.1.1.1
          Oct 2, 2024 23:07:12.993499041 CEST5562753192.168.2.41.1.1.1
          Oct 2, 2024 23:07:13.000348091 CEST53600701.1.1.1192.168.2.4
          Oct 2, 2024 23:07:13.000365019 CEST53556271.1.1.1192.168.2.4
          Oct 2, 2024 23:07:16.973380089 CEST5024453192.168.2.41.1.1.1
          Oct 2, 2024 23:07:16.973619938 CEST5819253192.168.2.41.1.1.1
          Oct 2, 2024 23:07:16.982842922 CEST53502441.1.1.1192.168.2.4
          Oct 2, 2024 23:07:16.993449926 CEST53581921.1.1.1192.168.2.4
          Oct 2, 2024 23:07:17.009190083 CEST5006753192.168.2.41.1.1.1
          Oct 2, 2024 23:07:17.018829107 CEST53500671.1.1.1192.168.2.4
          Oct 2, 2024 23:07:27.456903934 CEST53582611.1.1.1192.168.2.4
          Oct 2, 2024 23:07:29.845396042 CEST138138192.168.2.4192.168.2.255
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Oct 2, 2024 23:07:10.400896072 CEST192.168.2.41.1.1.10x50d1Standard query (0)ontariogov.onmicrosoft.comA (IP address)IN (0x0001)false
          Oct 2, 2024 23:07:10.402582884 CEST192.168.2.41.1.1.10x8b86Standard query (0)ontariogov.onmicrosoft.com65IN (0x0001)false
          Oct 2, 2024 23:07:10.428199053 CEST192.168.2.41.1.1.10xfa40Standard query (0)ontariogov.onmicrosoft.comA (IP address)IN (0x0001)false
          Oct 2, 2024 23:07:10.518327951 CEST192.168.2.48.8.8.80xb97eStandard query (0)google.comA (IP address)IN (0x0001)false
          Oct 2, 2024 23:07:10.518462896 CEST192.168.2.41.1.1.10x463eStandard query (0)google.comA (IP address)IN (0x0001)false
          Oct 2, 2024 23:07:11.525527954 CEST192.168.2.41.1.1.10xbc6dStandard query (0)ontariogov.onmicrosoft.comA (IP address)IN (0x0001)false
          Oct 2, 2024 23:07:11.525765896 CEST192.168.2.41.1.1.10x2733Standard query (0)ontariogov.onmicrosoft.com65IN (0x0001)false
          Oct 2, 2024 23:07:12.993241072 CEST192.168.2.41.1.1.10x2d51Standard query (0)www.google.comA (IP address)IN (0x0001)false
          Oct 2, 2024 23:07:12.993499041 CEST192.168.2.41.1.1.10x3a65Standard query (0)www.google.com65IN (0x0001)false
          Oct 2, 2024 23:07:16.973380089 CEST192.168.2.41.1.1.10xf7b6Standard query (0)ontariogov.onmicrosoft.comA (IP address)IN (0x0001)false
          Oct 2, 2024 23:07:16.973619938 CEST192.168.2.41.1.1.10xd194Standard query (0)ontariogov.onmicrosoft.com65IN (0x0001)false
          Oct 2, 2024 23:07:17.009190083 CEST192.168.2.41.1.1.10xde38Standard query (0)ontariogov.onmicrosoft.comA (IP address)IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Oct 2, 2024 23:07:10.525666952 CEST1.1.1.1192.168.2.40x463eNo error (0)google.com142.250.185.78A (IP address)IN (0x0001)false
          Oct 2, 2024 23:07:10.534811974 CEST8.8.8.8192.168.2.40xb97eNo error (0)google.com142.250.184.206A (IP address)IN (0x0001)false
          Oct 2, 2024 23:07:13.000348091 CEST1.1.1.1192.168.2.40x2d51No error (0)www.google.com142.250.186.36A (IP address)IN (0x0001)false
          Oct 2, 2024 23:07:13.000365019 CEST1.1.1.1192.168.2.40x3a65No error (0)www.google.com65IN (0x0001)false
          Oct 2, 2024 23:07:25.424679041 CEST1.1.1.1192.168.2.40xf402No error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
          Oct 2, 2024 23:07:25.424679041 CEST1.1.1.1192.168.2.40xf402No error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false

          Click to jump to process

          Click to jump to process

          Click to jump to process

          Target ID:0
          Start time:17:07:04
          Start date:02/10/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:2
          Start time:17:07:06
          Start date:02/10/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2220 --field-trial-handle=2160,i,12445135164632047739,5507286661348154879,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:false

          Target ID:3
          Start time:17:07:09
          Start date:02/10/2024
          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
          Wow64 process (32bit):false
          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://Ontariogov.onmicrosoft.com"
          Imagebase:0x7ff76e190000
          File size:3'242'272 bytes
          MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
          Has elevated privileges:true
          Has administrator privileges:true
          Programmed in:C, C++ or other language
          Reputation:low
          Has exited:true

          No disassembly