Windows Analysis Report
https://tampoesdeferrofundido.com.br/redirect.php?v=2455b0ad034ad02

Overview

General Information

Sample URL: https://tampoesdeferrofundido.com.br/redirect.php?v=2455b0ad034ad02
Analysis ID: 1527900

Detection

Score: 52
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

AI detected phishing page
Phishing site detected (based on image similarity)
Detected non-DNS traffic on DNS port
Stores files to the Windows start menu directory

Classification

Phishing

barindex
Source: https://platypustours.net.au/8G56zf/ LLM: Score: 9 Reasons: The brand 'Microsoft' is a well-known global technology company., The legitimate domain for Microsoft is 'microsoft.com'., The provided URL 'platypustours.net.au' does not match the legitimate domain for Microsoft., The URL 'platypustours.net.au' appears unrelated to Microsoft and suggests a different business focus, likely a travel or tour company., There is no indication that 'platypustours.net.au' is associated with Microsoft, which raises suspicion., The presence of a generic input field labeled 'Your Answer' is unusual for a Microsoft-related site, which typically has more specific input fields. DOM: 0.0.pages.csv
Source: https://platypustours.net.au/8G56zf/ Matcher: Found strong image similarity, brand: MICROSOFT
Source: https://platypustours.net.au/8G56zf/ HTTP Parser: No favicon
Source: unknown HTTPS traffic detected: 4.175.87.197:443 -> 192.168.2.16:53612 version: TLS 1.2
Source: global traffic TCP traffic: 192.168.2.16:53593 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53593 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53593 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53593 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53593 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53593 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53593 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53593 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53593 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53593 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53593 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53593 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:53593 -> 1.1.1.1:53
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 2.19.126.137
Source: unknown TCP traffic detected without corresponding DNS query: 2.16.100.168
Source: unknown TCP traffic detected without corresponding DNS query: 2.19.126.137
Source: unknown TCP traffic detected without corresponding DNS query: 2.16.100.168
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.221.95
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.221.95
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: global traffic DNS traffic detected: DNS query: tampoesdeferrofundido.com.br
Source: global traffic DNS traffic detected: DNS query: platypustours.net.au
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53605
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53604
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53603
Source: unknown Network traffic detected: HTTP traffic on port 49706 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53602 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53600 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53607
Source: unknown Network traffic detected: HTTP traffic on port 53604 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49704 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53602
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53601
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53600
Source: unknown Network traffic detected: HTTP traffic on port 53598 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53614
Source: unknown Network traffic detected: HTTP traffic on port 53603 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53601 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53598
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53597
Source: unknown Network traffic detected: HTTP traffic on port 53605 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53607 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53612
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53610
Source: unknown Network traffic detected: HTTP traffic on port 53612 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53614 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53610 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53597 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49706
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49704
Source: unknown HTTPS traffic detected: 4.175.87.197:443 -> 192.168.2.16:53612 version: TLS 1.2
Source: classification engine Classification label: mal52.phis.win@18/8@8/113
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2168 --field-trial-handle=1964,i,3174417204599748744,2607148825556754023,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://tampoesdeferrofundido.com.br/redirect.php?v=2455b0ad034ad02"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2168 --field-trial-handle=1964,i,3174417204599748744,2607148825556754023,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs