Windows Analysis Report


General Information

Sample URL:
Analysis ID: 1592314


Score: 56
Range: 0 - 100
Whitelisted: false
Confidence: 100%


AI detected phishing page
Antivirus / Scanner detection for submitted sample
Detected non-DNS traffic on DNS port
HTML body contains low number of good links
HTML body contains password input but no form action
HTML body with high number of embedded images detected
HTML title does not match URL
None HTTPS page querying sensitive user data (password, username or email)
Suspicious form URL found
Uses Javascript AES encryption / decryption (likely to hide suspicious Javascript code)


AV Detection

Source: Avira URL Cloud: detection malicious, Label: phishing


Source: Joe Sandbox AI: Score: 8 Reasons: The brand 'FTX' is a well-known cryptocurrency exchange platform., The URL '' does not match the legitimate domain ''., The domain '' does not appear to be directly associated with FTX., The presence of a subdomain 'restructuring' could indicate a specific service or department, but it is not a known subdomain of FTX., The use of a different domain name suggests potential phishing, especially when combined with a well-known brand like FTX. DOM: 1.0.pages.csv
Source: Joe Sandbox AI: Score: 8 Reasons: The brand 'FTX' is a well-known cryptocurrency exchange platform., The URL '' does not match the legitimate domain ''., The domain '' does not appear to be directly associated with FTX., The presence of a subdomain 'restructuring' could indicate a specific service or department, but it is not a known FTX domain., The use of a password input field on a non-legitimate domain is a common phishing tactic. DOM: 2.1.pages.csv
Source: Joe Sandbox AI: Score: 8 Reasons: The brand FTX is a well-known cryptocurrency exchange platform., The URL '' does not match the legitimate domain ''., The domain '' does not appear to be directly associated with FTX., The presence of a password input field on a non-matching domain is suspicious., The URL structure suggests a potential phishing attempt by using a subdomain that could mislead users. DOM: 2.2.pages.csv
Source: HTTP Parser: Number of links: 0
Source: HTTP Parser: Number of links: 0
Source: HTTP Parser: Number of links: 0
Source: HTTP Parser: Number of links: 0
Source: HTTP Parser: <input type="password" .../> found but no <form action="...
Source: HTTP Parser: Total embedded image size: 40172
Source: HTTP Parser: Total embedded image size: 40172
Source: HTTP Parser: Total embedded image size: 40172
Source: HTTP Parser: Title: Recovery User Login | FTX does not match URL
Source: HTTP Parser: Title: Recovery User Login | FTX does not match URL
Source: HTTP Parser: Title: Recovery User Login | FTX does not match URL
Source: HTTP Parser: Has password / email / username input fields
Source: HTTP Parser: Has password / email / username input fields
Source: HTTP Parser: Has password / email / username input fields
Source: HTTP Parser: Form action: withdraw-desktop.php
Source: HTTP Parser: Form action: withdraw-desktop.php
Source: HTTP Parser: Form action: withdraw-desktop.php
Source: HTTP Parser: (function(global,factory){typeof exports==="object"&&typeof module!=="undefined"?module.exports=factory():typeof define==="function"&&define.amd?define(factory):(global=typeof globalthis!=="undefined"?globalthis:global||self,global.ethers=factory())})(this,function(){"use strict";var commonjsglobal=typeof globalthis!=="undefined"?globalthis:typeof window!=="undefined"?window:typeof global!=="undefined"?global:typeof self!=="undefined"?self:{};function getdefaultexportfromcjs(x){return x&&x.__esmodule&&,
Source: HTTP Parser: Iframe src:
Source: HTTP Parser: Iframe src:
Source: HTTP Parser: <input type="password" .../> found
Source: HTTP Parser: No <meta name="author".. found
Source: HTTP Parser: No <meta name="author".. found
Source: HTTP Parser: No <meta name="author".. found
Source: HTTP Parser: No <meta name="author".. found
Source: HTTP Parser: No <meta name="author".. found
Source: HTTP Parser: No <meta name="author".. found
Source: HTTP Parser: No <meta name="copyright".. found
Source: HTTP Parser: No <meta name="copyright".. found
Source: HTTP Parser: No <meta name="copyright".. found
Source: HTTP Parser: No <meta name="copyright".. found
Source: HTTP Parser: No <meta name="copyright".. found
Source: HTTP Parser: No <meta name="copyright".. found
Source: HTTP Parser: No <meta name="copyright".. found
Source: HTTP Parser: No <meta name="copyright".. found
Source: unknown HTTPS traffic detected: -> version: TLS 1.2
Source: unknown HTTPS traffic detected: -> version: TLS 1.2
Source: unknown HTTPS traffic detected: -> version: TLS 1.2
Source: unknown HTTPS traffic detected: -> version: TLS 1.2
Source: unknown HTTPS traffic detected: -> version: TLS 1.2
Source: unknown HTTPS traffic detected: -> version: TLS 1.2
Source: global traffic TCP traffic: ->
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: unknown UDP traffic detected without corresponding DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: global traffic DNS traffic detected: DNS query:
Source: classification engine Classification label:
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2196 --field-trial-handle=2172,i,1068430186067100722,1295673490143735359,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" ""
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2196 --field-trial-handle=2172,i,1068430186067100722,1295673490143735359,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs