Windows Analysis Report
http://141.8.192.169

Overview

General Information

Sample URL: http://141.8.192.169
Analysis ID: 1592079
Infos:

Detection

Score: 20
Range: 0 - 100
Whitelisted: false
Confidence: 60%

Signatures

AI detected suspicious URL
Detected non-DNS traffic on DNS port

Classification

Phishing

barindex
Source: URL Joe Sandbox AI: AI detected IP in URL: http://141.8.192.169
Source: http://141.8.192.169/ HTTP Parser: No favicon
Source: global traffic TCP traffic: 192.168.2.4:53611 -> 1.1.1.1:53
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 141.8.192.169
Source: unknown TCP traffic detected without corresponding DNS query: 141.8.192.169
Source: unknown TCP traffic detected without corresponding DNS query: 141.8.192.169
Source: unknown TCP traffic detected without corresponding DNS query: 141.8.192.169
Source: unknown TCP traffic detected without corresponding DNS query: 141.8.192.169
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 141.8.192.169
Source: unknown TCP traffic detected without corresponding DNS query: 141.8.192.169
Source: unknown TCP traffic detected without corresponding DNS query: 141.8.192.169
Source: unknown TCP traffic detected without corresponding DNS query: 141.8.192.169
Source: unknown TCP traffic detected without corresponding DNS query: 141.8.192.169
Source: unknown TCP traffic detected without corresponding DNS query: 141.8.192.169
Source: unknown TCP traffic detected without corresponding DNS query: 141.8.192.169
Source: unknown TCP traffic detected without corresponding DNS query: 141.8.192.169
Source: unknown TCP traffic detected without corresponding DNS query: 141.8.192.169
Source: unknown TCP traffic detected without corresponding DNS query: 141.8.192.169
Source: unknown TCP traffic detected without corresponding DNS query: 141.8.192.169
Source: unknown TCP traffic detected without corresponding DNS query: 141.8.192.169
Source: unknown TCP traffic detected without corresponding DNS query: 141.8.192.169
Source: unknown TCP traffic detected without corresponding DNS query: 141.8.192.169
Source: unknown TCP traffic detected without corresponding DNS query: 2.22.50.131
Source: unknown TCP traffic detected without corresponding DNS query: 2.22.50.131
Source: unknown TCP traffic detected without corresponding DNS query: 141.8.192.169
Source: unknown TCP traffic detected without corresponding DNS query: 141.8.192.169
Source: unknown TCP traffic detected without corresponding DNS query: 141.8.192.169
Source: unknown TCP traffic detected without corresponding DNS query: 141.8.192.169
Source: unknown TCP traffic detected without corresponding DNS query: 2.22.50.131
Source: unknown TCP traffic detected without corresponding DNS query: 2.22.50.131
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET / HTTP/1.1Host: 141.8.192.169Connection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /favicon.ico HTTP/1.1Host: 141.8.192.169Connection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://141.8.192.169/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: global traffic DNS traffic detected: DNS query: cp.sprinthost.ru
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not FoundServer: openrestyDate: Wed, 15 Jan 2025 17:24:19 GMTContent-Type: text/htmlTransfer-Encoding: chunkedConnection: keep-aliveVary: Accept-EncodingContent-Encoding: gzipData Raw: 33 61 62 61 0d 0a 1f 8b 08 00 00 00 00 00 00 03 ed 9d 6d 8f 64 c7 75 98 bf eb 57 b4 47 30 24 c5 9a de ee be f7 76 df de 17 22 c6 c8 06 03 0c 11 03 52 16 30 bf 10 b3 33 bd bb 6d cd ce 4c 66 7a b9 4b 13 02 24 25 76 02 38 81 82 44 48 02 04 b1 69 07 f9 e4 2f 8c 64 46 b4 25 51 00 7f c1 ec 5f f0 2f c9 f3 9c 7a e9 9e d9 d9 17 3a 06 82 00 4d 41 1c 9e be 75 eb 56 9d 3a 75 de ab ce dd df fa ce 3f df fb de 1f fe c1 ef 0d 1e af 9e 1c bf f3 b5 bb fe 19 1c 1f 9c 3c ba b7 b3 38 d9 f1 87 c5 c1 d1 3b 5f 1b f0 cf dd 27 8b d5 c1 e0 f0 f1 c1 f9 c5 62 75 6f e7 5f 7c ef f7 77 7b 5a c4 a3 d5 72 75 bc 78 e7 f2 cf 5f fc db cb cf 2f ff d7 e5 df 5d 7e 3a 68 47 ed e8 ee ad f4 60 e3 fd 93 83 27 8b 7b 3b 1f 2e 17 cf ce 4e cf 57 3b 83 c3 d3 93 d5 e2 84 fe 9e 2d 8f 56 8f ef 1d 2d 3e 5c 1e 2e 76 03 f8 f6 60 79 b2 5c 2d 0f 8e 77 2f 0e 0f 8e 17 f7 c6 c3 51 f9 de c5 ea 23 bb 7d 70 7a f4 d1 b7 1f 8f bf 7d f6 f1 d9 c1 d1 d1 f2 e4 d1 ed d1 9d 27 07 e7 8f 96 27 b7 47 3f f8 27 1f 3f a4 ef dd 87 07 4f 96 c7 1f dd fe dd 73 3a fa f6 c5 c1 c9 c5 ee c5 e2 7c f9 f0 4e 3c 8c 7e 6e 9f 9c 9e 3f 39 38 4e bf 3c 5b 2c 1f 3d 5e dd 6e 47 a3 1f 0c 9f 9d 1f 9c 9d 2d ce bf 5d fe 63 30 cc a3 fd 38 c6 77 7b 3c 1a fd f6 9d a3 e5 c5 d9 f1 c1 47 b7 79 f3 c1 f7 97 ab dd 07 a7 cf 5f fa ed e1 f1 62 e3 c7 27 a7 7f 7c b5 d5 93 8b 5d 5b 6c be 19 6f 6c 74 b9 7b 76 70 f8 fd db 87 60 6a 71 5e 7f ff a3 a7 17 ab e5 c3 8f 76 f3 a8 ea e3 fc 81 ab ef e4 8f 5c f9 f1 e6 0e ea c4 af cf 77 79 f2 18 d4 ad 40 f1 f3 b4 42 60 a0 99 9c 3d bf f3 38 21 2d f0 b1 39 e8 d3 f3 25 23 be fd 98 bf 7f 0c 72 c1 f1 e6 d3 a3 e5 f9 e2 70 b5 3c 3d 29 0b 50 1e 3a f9 dd f5 d3 f3 d3 67 77 76 cb 9c 6e e8 b2 3c 7a b9 bf 32 e7 ab 7d dd d0 7d 21 9f f1 a4 3f 7b 3e 18 4f f9 17 94 b4 3c d9 cd 33 8b cf 43 84 87 df 64 8e 1f 3e 1e ec 0e a2 e5 b7 36 db dc f4 78 73 ba 17 cb 3f 96 42 f3 62 05 05 d4 59 dd f0 8c e7 bb 37 bd b2 26 b3 b4 94 79 0d 5f 49 14 17 b4 5a ec 3e 58 ac 9e 2d 16 27 eb 2f 5e 7d f7 0a 71 94 1e af 53 c7 d5 9e ce 4e 2f d8 9c 2c de f9 e2 f8 60 b5 fc 70 f1 32 d9 0c 86 c7 8b 87 6c b2 e5 d1 e2 e3 b2 4d 56 07 0f 8e 17 85 60 da 6e 74 f6 fc b5 ef 0d 86 8b f3 f3 d3 f3 dd 07 c7 a7 87 df af 9d 14 b4 2e 4f 8e 97 27 4c ee 86 2d 97 1f bd bc f3 6e 7a 87 e9 6f b4 df ec 6e b3 9b 1b 28 fb c3 c5 f9 6a c9 c2 ff 83 e8 fa f0 f4 f8 e9 93 8d 25 c9 a4 bd ee f3 ab 10 76 ee ec 1a 6d a7 5f df 1e c3 1f 7c 20 7f 4e 8c 13 e2 5b dc 9e b0 40 77 02 c9 65 8f 37 fd 6f df a1 db d3 f3 db 5f 1f 8d 46 77 4e 21 a4 e5 ea a3 db c3 59 e6 bc ac c6 6a 75 fa e4 36 db e3 ce b3 c7 cb d5 62 37 e8 e6 f6 d9 f9 62 d7 8e be ea 60 06 0f d2 70 32 63 9e 6d 7c 73 fc 55 fa 5a 9c 6c 4c 6b dc 5e 9f d6 7c 18 9c ec a6 99 b5 d7 66 d6 fe 63 4c 6d 71 f2 9a 89 0d e7 5f 65 66 47 8b 8b c3 7f d0 92 f5 37 2e d0 06 7b ef e6 e0 e4 ab 0e 65 70 f0 f1 06 16 57 8b e7 ab dd a3 c5 e1 e9 39 4c 22 58 fd c9 e2 ce 83
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not FoundServer: openrestyDate: Wed, 15 Jan 2025 17:24:20 GMTContent-Type: text/htmlTransfer-Encoding: chunkedConnection: keep-aliveVary: Accept-EncodingContent-Encoding: gzipData Raw: 33 61 62 61 0d 0a 1f 8b 08 00 00 00 00 00 00 03 ed 9d 6d 8f 64 c7 75 98 bf eb 57 b4 47 30 24 c5 9a de ee be f7 76 df de 17 22 c6 c8 06 03 0c 11 03 52 16 30 bf 10 b3 33 bd bb 6d cd ce 4c 66 7a b9 4b 13 02 24 25 76 02 38 81 82 44 48 02 04 b1 69 07 f9 e4 2f 8c 64 46 b4 25 51 00 7f c1 ec 5f f0 2f c9 f3 9c 7a e9 9e d9 d9 17 3a 06 82 00 4d 41 1c 9e be 75 eb 56 9d 3a 75 de ab ce dd df fa ce 3f df fb de 1f fe c1 ef 0d 1e af 9e 1c bf f3 b5 bb fe 19 1c 1f 9c 3c ba b7 b3 38 d9 f1 87 c5 c1 d1 3b 5f 1b f0 cf dd 27 8b d5 c1 e0 f0 f1 c1 f9 c5 62 75 6f e7 5f 7c ef f7 77 7b 5a c4 a3 d5 72 75 bc 78 e7 f2 cf 5f fc db cb cf 2f ff d7 e5 df 5d 7e 3a 68 47 ed e8 ee ad f4 60 e3 fd 93 83 27 8b 7b 3b 1f 2e 17 cf ce 4e cf 57 3b 83 c3 d3 93 d5 e2 84 fe 9e 2d 8f 56 8f ef 1d 2d 3e 5c 1e 2e 76 03 f8 f6 60 79 b2 5c 2d 0f 8e 77 2f 0e 0f 8e 17 f7 c6 c3 51 f9 de c5 ea 23 bb 7d 70 7a f4 d1 b7 1f 8f bf 7d f6 f1 d9 c1 d1 d1 f2 e4 d1 ed d1 9d 27 07 e7 8f 96 27 b7 47 3f f8 27 1f 3f a4 ef dd 87 07 4f 96 c7 1f dd fe dd 73 3a fa f6 c5 c1 c9 c5 ee c5 e2 7c f9 f0 4e 3c 8c 7e 6e 9f 9c 9e 3f 39 38 4e bf 3c 5b 2c 1f 3d 5e dd 6e 47 a3 1f 0c 9f 9d 1f 9c 9d 2d ce bf 5d fe 63 30 cc a3 fd 38 c6 77 7b 3c 1a fd f6 9d a3 e5 c5 d9 f1 c1 47 b7 79 f3 c1 f7 97 ab dd 07 a7 cf 5f fa ed e1 f1 62 e3 c7 27 a7 7f 7c b5 d5 93 8b 5d 5b 6c be 19 6f 6c 74 b9 7b 76 70 f8 fd db 87 60 6a 71 5e 7f ff a3 a7 17 ab e5 c3 8f 76 f3 a8 ea e3 fc 81 ab ef e4 8f 5c f9 f1 e6 0e ea c4 af cf 77 79 f2 18 d4 ad 40 f1 f3 b4 42 60 a0 99 9c 3d bf f3 38 21 2d f0 b1 39 e8 d3 f3 25 23 be fd 98 bf 7f 0c 72 c1 f1 e6 d3 a3 e5 f9 e2 70 b5 3c 3d 29 0b 50 1e 3a f9 dd f5 d3 f3 d3 67 77 76 cb 9c 6e e8 b2 3c 7a b9 bf 32 e7 ab 7d dd d0 7d 21 9f f1 a4 3f 7b 3e 18 4f f9 17 94 b4 3c d9 cd 33 8b cf 43 84 87 df 64 8e 1f 3e 1e ec 0e a2 e5 b7 36 db dc f4 78 73 ba 17 cb 3f 96 42 f3 62 05 05 d4 59 dd f0 8c e7 bb 37 bd b2 26 b3 b4 94 79 0d 5f 49 14 17 b4 5a ec 3e 58 ac 9e 2d 16 27 eb 2f 5e 7d f7 0a 71 94 1e af 53 c7 d5 9e ce 4e 2f d8 9c 2c de f9 e2 f8 60 b5 fc 70 f1 32 d9 0c 86 c7 8b 87 6c b2 e5 d1 e2 e3 b2 4d 56 07 0f 8e 17 85 60 da 6e 74 f6 fc b5 ef 0d 86 8b f3 f3 d3 f3 dd 07 c7 a7 87 df af 9d 14 b4 2e 4f 8e 97 27 4c ee 86 2d 97 1f bd bc f3 6e 7a 87 e9 6f b4 df ec 6e b3 9b 1b 28 fb c3 c5 f9 6a c9 c2 ff 83 e8 fa f0 f4 f8 e9 93 8d 25 c9 a4 bd ee f3 ab 10 76 ee ec 1a 6d a7 5f df 1e c3 1f 7c 20 7f 4e 8c 13 e2 5b dc 9e b0 40 77 02 c9 65 8f 37 fd 6f df a1 db d3 f3 db 5f 1f 8d 46 77 4e 21 a4 e5 ea a3 db c3 59 e6 bc ac c6 6a 75 fa e4 36 db e3 ce b3 c7 cb d5 62 37 e8 e6 f6 d9 f9 62 d7 8e be ea 60 06 0f d2 70 32 63 9e 6d 7c 73 fc 55 fa 5a 9c 6c 4c 6b dc 5e 9f d6 7c 18 9c ec a6 99 b5 d7 66 d6 fe 63 4c 6d 71 f2 9a 89 0d e7 5f 65 66 47 8b 8b c3 7f d0 92 f5 37 2e d0 06 7b ef e6 e0 e4 ab 0e 65 70 f0 f1 06 16 57 8b e7 ab dd a3 c5 e1 e9 39 4c 22 58 fd c9 e2 ce 83
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53714
Source: unknown Network traffic detected: HTTP traffic on port 53714 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49738
Source: unknown Network traffic detected: HTTP traffic on port 49738 -> 443
Source: classification engine Classification label: sus20.win@16/4@4/5
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2092 --field-trial-handle=2032,i,11569269191890836372,7136015587659939751,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://141.8.192.169"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2092 --field-trial-handle=2032,i,11569269191890836372,7136015587659939751,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs