Windows Analysis Report
http://pay.cogencyglobal.com

Overview

General Information

Sample URL: http://pay.cogencyglobal.com
Analysis ID: 1526555
Infos:

Detection

Score: 3
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Form action URLs do not match main URL
Found iframes
HTML body contains low number of good links
HTML page contains hidden javascript code
HTML title does not match URL
Program does not show much activity (idle)
Stores files to the Windows start menu directory

Classification

Source: https://www.cogencyglobal.com/contact-us-cogency-global HTTP Parser: Form action: https://forms.hsforms.com/submissions/v3/public/submit/formsnext/multipart/153028/718ae184-bb42-4ecf-acd6-14a98dbaad69 cogencyglobal hsforms
Source: https://www.cogencyglobal.com/contact-us-cogency-global HTTP Parser: Form action: https://forms.hsforms.com/submissions/v3/public/submit/formsnext/multipart/153028/718ae184-bb42-4ecf-acd6-14a98dbaad69 cogencyglobal hsforms
Source: https://www.cogencyglobal.com/contact-us-cogency-global HTTP Parser: Iframe src: https://www.googletagmanager.com/ns.html?id=GTM-PS4ZMZL
Source: https://www.cogencyglobal.com/contact-us-cogency-global HTTP Parser: Iframe src: https://td.doubleclick.net/td/rul/991315551?random=1728201316983&cv=11&fst=1728201316983&fmt=3&bg=ffffff&guid=ON&async=1&gtm=45be4a20v9112880412za200&gcd=13l3l3l3l1l1&dma=0&tag_exp=101671035~101747727&u_w=1280&u_h=1024&url=https%3A%2F%2Fwww.cogencyglobal.com%2Fcontact-us-cogency-global&hn=www.googleadservices.com&frm=0&tiba=COGENCY%20GLOBAL&npa=0&pscdl=noapi&auid=1250427623.1728201305&uaa=x86&uab=64&uafvl=Google%2520Chrome%3B117.0.5938.132%7CNot%253BA%253DBrand%3B8.0.0.0%7CChromium%3B117.0.5938.132&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1&data=event%3Dgtag.config
Source: https://www.cogencyglobal.com/contact-us-cogency-global HTTP Parser: Iframe src: https://td.doubleclick.net/td/rul/991315551?random=1728201321704&cv=11&fst=1728201321704&fmt=3&bg=ffffff&guid=ON&async=1&gtm=45be4a20v9112880412za200&gcd=13r3r3r3r5l1&dma=0&tag_exp=101671035~101747727&u_w=1280&u_h=1024&url=https%3A%2F%2Fwww.cogencyglobal.com%2Fcontact-us-cogency-global&hn=www.googleadservices.com&frm=0&tiba=COGENCY%20GLOBAL&did=dZTQ1Zm&gdid=dZTQ1Zm&npa=0&pscdl=noapi&auid=1250427623.1728201305&uaa=x86&uab=64&uafvl=Google%2520Chrome%3B117.0.5938.132%7CNot%253BA%253DBrand%3B8.0.0.0%7CChromium%3B117.0.5938.132&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1&data=event%3Dgtag.config
Source: https://www.cogencyglobal.com/contact-us-cogency-global HTTP Parser: Iframe src: https://www.googletagmanager.com/ns.html?id=GTM-PS4ZMZL
Source: https://www.cogencyglobal.com/contact-us-cogency-global HTTP Parser: Iframe src: https://td.doubleclick.net/td/rul/991315551?random=1728201316983&cv=11&fst=1728201316983&fmt=3&bg=ffffff&guid=ON&async=1&gtm=45be4a20v9112880412za200&gcd=13l3l3l3l1l1&dma=0&tag_exp=101671035~101747727&u_w=1280&u_h=1024&url=https%3A%2F%2Fwww.cogencyglobal.com%2Fcontact-us-cogency-global&hn=www.googleadservices.com&frm=0&tiba=COGENCY%20GLOBAL&npa=0&pscdl=noapi&auid=1250427623.1728201305&uaa=x86&uab=64&uafvl=Google%2520Chrome%3B117.0.5938.132%7CNot%253BA%253DBrand%3B8.0.0.0%7CChromium%3B117.0.5938.132&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1&data=event%3Dgtag.config
Source: https://pay.cogencyglobal.com/singleinvoicepayment HTTP Parser: Number of links: 1
Source: https://pay.cogencyglobal.com/SingleInvoicePayment/ HTTP Parser: Number of links: 1
Source: https://www.cogencyglobal.com/terms-of-use HTTP Parser: Base64 decoded: <svg version="1.1" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" x="0px" y="0px" width="348.333px" height="348.333px" viewBox="0 0 348.333 348.334" style="enable-background:new 0 0 348.333 348.334;" xml:space="preserve"><g>...
Source: https://pay.cogencyglobal.com/singleinvoicepayment HTTP Parser: Title: Pay Invoice does not match URL
Source: https://pay.cogencyglobal.com/SingleInvoicePayment/ HTTP Parser: Title: Pay Invoice does not match URL
Source: https://www.cogencyglobal.com/contact-us-cogency-global HTTP Parser: No favicon
Source: https://www.cogencyglobal.com/contact-us-cogency-global HTTP Parser: No favicon
Source: https://pay.cogencyglobal.com/singleinvoicepayment HTTP Parser: No <meta name="author".. found
Source: https://pay.cogencyglobal.com/SingleInvoicePayment/ HTTP Parser: No <meta name="author".. found
Source: https://pay.cogencyglobal.com/singleinvoicepayment HTTP Parser: No <meta name="author".. found
Source: https://pay.cogencyglobal.com/SingleInvoicePayment/ HTTP Parser: No <meta name="author".. found
Source: https://pay.cogencyglobal.com/singleinvoicepayment HTTP Parser: No <meta name="copyright".. found
Source: https://pay.cogencyglobal.com/SingleInvoicePayment/ HTTP Parser: No <meta name="copyright".. found
Source: https://pay.cogencyglobal.com/singleinvoicepayment HTTP Parser: No <meta name="copyright".. found
Source: https://pay.cogencyglobal.com/SingleInvoicePayment/ HTTP Parser: No <meta name="copyright".. found
Source: https://www.cogencyglobal.com/contact-us-cogency-global HTTP Parser: No <meta name="copyright".. found
Source: https://www.cogencyglobal.com/contact-us-cogency-global HTTP Parser: No <meta name="copyright".. found
Source: chromecache_524.2.dr String found in binary or memory: var videoEmbedLink = "https://www.youtube.com/embed/"+cleanVideoID+"?autoplay="+YouTubePopUpOptions.autoplay+""; equals www.youtube.com (Youtube)
Source: chromecache_329.2.dr, chromecache_334.2.dr String found in binary or memory: http://fontawesome.io
Source: chromecache_329.2.dr, chromecache_334.2.dr String found in binary or memory: http://fontawesome.io/license
Source: chromecache_299.2.dr String found in binary or memory: http://hubs.ly/H0702_H0
Source: chromecache_524.2.dr String found in binary or memory: http://wp-time.com/youtube-popup-jquery-plugin/
Source: chromecache_507.2.dr String found in binary or memory: http://www.cogencyglobal.com
Source: chromecache_507.2.dr String found in binary or memory: http://www.cogencyglobal.com/
Source: chromecache_524.2.dr String found in binary or memory: http://www.gnu.org/licenses/gpl.html
Source: chromecache_524.2.dr String found in binary or memory: http://www.opensource.org/licenses/mit-license.php
Source: chromecache_635.2.dr String found in binary or memory: https://cdn.cookielaw.org/vendorlist/googleData.json
Source: chromecache_635.2.dr String found in binary or memory: https://cdn.cookielaw.org/vendorlist/iab2Data.json
Source: chromecache_635.2.dr String found in binary or memory: https://cdn.cookielaw.org/vendorlist/iabData.json
Source: chromecache_331.2.dr String found in binary or memory: https://cloud.google.com/contact
Source: chromecache_331.2.dr String found in binary or memory: https://cloud.google.com/recaptcha-enterprise/billing-information
Source: chromecache_631.2.dr String found in binary or memory: https://cogencyglobal.com
Source: chromecache_635.2.dr String found in binary or memory: https://cookies-data.onetrust.io/bannersdk/v1/domaingroupcheck
Source: chromecache_644.2.dr String found in binary or memory: https://dev.visualwebsiteoptimizer.com/e.gif?a=625284&s=settings.js&e=
Source: chromecache_331.2.dr String found in binary or memory: https://developers.google.com/recaptcha/docs/faq#are-there-any-qps-or-daily-limits-on-my-use-of-reca
Source: chromecache_331.2.dr String found in binary or memory: https://developers.google.com/recaptcha/docs/faq#localhost_support
Source: chromecache_331.2.dr String found in binary or memory: https://developers.google.com/recaptcha/docs/faq#my-computer-or-network-may-be-sending-automated-que
Source: chromecache_635.2.dr String found in binary or memory: https://geolocation.onetrust.com/cookieconsentpub/v1/geo/location
Source: chromecache_630.2.dr String found in binary or memory: https://js.foundation/
Source: chromecache_299.2.dr String found in binary or memory: https://js.hs-analytics.net/analytics/1728201300000/153028.js
Source: chromecache_299.2.dr String found in binary or memory: https://js.hs-banner.com/v2/153028/banner.js
Source: chromecache_299.2.dr String found in binary or memory: https://js.hsadspixel.net/fb.js
Source: chromecache_299.2.dr String found in binary or memory: https://js.hsleadflows.net/leadflows.js
Source: chromecache_299.2.dr String found in binary or memory: https://js.hubspot.com/web-interactives-embed.js
Source: chromecache_331.2.dr String found in binary or memory: https://play.google.com/log?format=json&hasfast=true
Source: chromecache_524.2.dr String found in binary or memory: https://player.vimeo.com/video/
Source: chromecache_331.2.dr String found in binary or memory: https://recaptcha.net
Source: chromecache_331.2.dr String found in binary or memory: https://support.google.com/recaptcha
Source: chromecache_331.2.dr String found in binary or memory: https://support.google.com/recaptcha#6262736
Source: chromecache_331.2.dr String found in binary or memory: https://support.google.com/recaptcha/#6175971
Source: chromecache_331.2.dr String found in binary or memory: https://support.google.com/recaptcha/?hl=en#6223828
Source: chromecache_507.2.dr String found in binary or memory: https://www.cogencyglobal.com
Source: chromecache_631.2.dr String found in binary or memory: https://www.cogencyglobal.com/contact-us-cogency-global
Source: chromecache_507.2.dr String found in binary or memory: https://www.cogencyglobal.com/contact.htm
Source: chromecache_507.2.dr String found in binary or memory: https://www.cogencyglobal.com/disclaimer.htm
Source: chromecache_288.2.dr, chromecache_375.2.dr, chromecache_677.2.dr, chromecache_637.2.dr, chromecache_322.2.dr String found in binary or memory: https://www.google.com/pagead/1p-user-list/991315551/?random
Source: chromecache_331.2.dr String found in binary or memory: https://www.google.com/recaptcha/api2/
Source: chromecache_331.2.dr String found in binary or memory: https://www.gstatic.c..?/recaptcha/releases/xds0rzGrktR88uEZ2JUvdgOY/recaptcha__.
Source: chromecache_678.2.dr String found in binary or memory: https://www.gstatic.com/recaptcha/releases/xds0rzGrktR88uEZ2JUvdgOY/recaptcha__en.js
Source: chromecache_524.2.dr String found in binary or memory: https://www.youtube.com/embed/
Source: chromecache_302.2.dr Binary or memory string: .vBpE8
Source: classification engine Classification label: clean3.win@25/628@0/82
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps Jump to behavior
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2068 --field-trial-handle=1992,i,14054020497396204339,12976560364646201019,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://pay.cogencyglobal.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2068 --field-trial-handle=1992,i,14054020497396204339,12976560364646201019,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: Google Drive.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Automated click: Accept
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Automated click: Accept
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk Jump to behavior
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs