Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
https://contract.nacap-holding.com/gas25/

Overview

General Information

Sample URL:https://contract.nacap-holding.com/gas25/
Analysis ID:1592451
Infos:
Errors
  • URL not reachable

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample

Classification

  • System is w10x64
  • chrome.exe (PID: 5756 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 1804 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2380 --field-trial-handle=2308,i,15495079991361432959,12914561289198759290,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6460 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://contract.nacap-holding.com/gas25/" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://contract.nacap-holding.com/gas25/Avira URL Cloud: detection malicious, Label: phishing
Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownTCP traffic detected without corresponding DNS query: 217.20.57.34
Source: unknownTCP traffic detected without corresponding DNS query: 217.20.57.34
Source: unknownTCP traffic detected without corresponding DNS query: 217.20.57.34
Source: unknownTCP traffic detected without corresponding DNS query: 217.20.57.34
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: contract.nacap-holding.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: classification engineClassification label: mal48.win@18/0@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2380 --field-trial-handle=2308,i,15495079991361432959,12914561289198759290,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://contract.nacap-holding.com/gas25/"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2380 --field-trial-handle=2308,i,15495079991361432959,12914561289198759290,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
https://contract.nacap-holding.com/gas25/100%Avira URL Cloudphishing
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
www.google.com
142.250.185.100
truefalse
    high
    contract.nacap-holding.com
    90.156.255.181
    truefalse
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      239.255.255.250
      unknownReserved
      unknownunknownfalse
      142.250.185.100
      www.google.comUnited States
      15169GOOGLEUSfalse
      90.156.255.181
      contract.nacap-holding.comRussian Federation
      25532MASTERHOST-ASMoscowRussiaRUfalse
      IP
      192.168.2.4
      Joe Sandbox version:42.0.0 Malachite
      Analysis ID:1592451
      Start date and time:2025-01-16 06:54:42 +01:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 2m 12s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:browseurl.jbs
      Sample URL:https://contract.nacap-holding.com/gas25/
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:7
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Detection:MAL
      Classification:mal48.win@18/0@4/4
      Cookbook Comments:
      • URL browsing timeout or error
      • URL not reachable
      • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
      • Excluded IPs from analysis (whitelisted): 142.250.186.131, 142.250.185.174, 74.125.71.84, 142.250.184.238, 142.250.186.78, 142.250.186.46, 2.22.50.144, 184.30.131.245, 142.250.186.110, 142.250.185.238, 142.250.185.131, 142.250.181.238, 184.28.90.27, 20.109.210.53
      • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, ocsp.digicert.com, accounts.google.com, redirector.gvt1.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, www.gstatic.com, fe3cr.delivery.mp.microsoft.com
      • Not all processes where analyzed, report is missing behavior information
      • VT rate limit hit for: https://contract.nacap-holding.com/gas25/
      No simulations
      No context
      No context
      No context
      No context
      No context
      No created / dropped files found
      No static file info
      TimestampSource PortDest PortSource IPDest IP
      Jan 16, 2025 06:55:39.011358976 CET49675443192.168.2.4173.222.162.32
      Jan 16, 2025 06:55:40.426750898 CET49737443192.168.2.4142.250.185.100
      Jan 16, 2025 06:55:40.426875114 CET44349737142.250.185.100192.168.2.4
      Jan 16, 2025 06:55:40.426963091 CET49737443192.168.2.4142.250.185.100
      Jan 16, 2025 06:55:40.427237988 CET49737443192.168.2.4142.250.185.100
      Jan 16, 2025 06:55:40.427261114 CET44349737142.250.185.100192.168.2.4
      Jan 16, 2025 06:55:41.085261106 CET44349737142.250.185.100192.168.2.4
      Jan 16, 2025 06:55:41.085649967 CET49737443192.168.2.4142.250.185.100
      Jan 16, 2025 06:55:41.085710049 CET44349737142.250.185.100192.168.2.4
      Jan 16, 2025 06:55:41.087388039 CET44349737142.250.185.100192.168.2.4
      Jan 16, 2025 06:55:41.087477922 CET49737443192.168.2.4142.250.185.100
      Jan 16, 2025 06:55:41.088629007 CET49737443192.168.2.4142.250.185.100
      Jan 16, 2025 06:55:41.088738918 CET44349737142.250.185.100192.168.2.4
      Jan 16, 2025 06:55:41.136537075 CET49737443192.168.2.4142.250.185.100
      Jan 16, 2025 06:55:41.136626959 CET44349737142.250.185.100192.168.2.4
      Jan 16, 2025 06:55:41.183285952 CET49737443192.168.2.4142.250.185.100
      Jan 16, 2025 06:55:42.747484922 CET49739443192.168.2.490.156.255.181
      Jan 16, 2025 06:55:42.747517109 CET4434973990.156.255.181192.168.2.4
      Jan 16, 2025 06:55:42.747591972 CET49739443192.168.2.490.156.255.181
      Jan 16, 2025 06:55:42.747843981 CET49740443192.168.2.490.156.255.181
      Jan 16, 2025 06:55:42.747874022 CET4434974090.156.255.181192.168.2.4
      Jan 16, 2025 06:55:42.748034954 CET49739443192.168.2.490.156.255.181
      Jan 16, 2025 06:55:42.748050928 CET4434973990.156.255.181192.168.2.4
      Jan 16, 2025 06:55:42.748054981 CET49740443192.168.2.490.156.255.181
      Jan 16, 2025 06:55:42.748291016 CET49740443192.168.2.490.156.255.181
      Jan 16, 2025 06:55:42.748302937 CET4434974090.156.255.181192.168.2.4
      Jan 16, 2025 06:55:50.979156017 CET44349737142.250.185.100192.168.2.4
      Jan 16, 2025 06:55:50.979305029 CET44349737142.250.185.100192.168.2.4
      Jan 16, 2025 06:55:50.979378939 CET49737443192.168.2.4142.250.185.100
      Jan 16, 2025 06:55:51.957964897 CET49737443192.168.2.4142.250.185.100
      Jan 16, 2025 06:55:51.958029032 CET44349737142.250.185.100192.168.2.4
      Jan 16, 2025 06:55:54.936916113 CET8049723217.20.57.34192.168.2.4
      Jan 16, 2025 06:55:54.937108040 CET4972380192.168.2.4217.20.57.34
      Jan 16, 2025 06:55:54.937108040 CET4972380192.168.2.4217.20.57.34
      Jan 16, 2025 06:55:54.942115068 CET8049723217.20.57.34192.168.2.4
      Jan 16, 2025 06:56:09.794240952 CET8049724217.20.57.34192.168.2.4
      Jan 16, 2025 06:56:09.794378042 CET4972480192.168.2.4217.20.57.34
      Jan 16, 2025 06:56:09.794492960 CET4972480192.168.2.4217.20.57.34
      Jan 16, 2025 06:56:09.799391985 CET8049724217.20.57.34192.168.2.4
      Jan 16, 2025 06:56:12.748137951 CET49739443192.168.2.490.156.255.181
      Jan 16, 2025 06:56:12.748472929 CET4434973990.156.255.181192.168.2.4
      Jan 16, 2025 06:56:12.748676062 CET49739443192.168.2.490.156.255.181
      Jan 16, 2025 06:56:12.751657009 CET49740443192.168.2.490.156.255.181
      Jan 16, 2025 06:56:12.752058029 CET4434974090.156.255.181192.168.2.4
      Jan 16, 2025 06:56:12.752293110 CET49740443192.168.2.490.156.255.181
      Jan 16, 2025 06:56:13.835346937 CET49749443192.168.2.490.156.255.181
      Jan 16, 2025 06:56:13.835381031 CET4434974990.156.255.181192.168.2.4
      Jan 16, 2025 06:56:13.835439920 CET49749443192.168.2.490.156.255.181
      Jan 16, 2025 06:56:13.835676908 CET49750443192.168.2.490.156.255.181
      Jan 16, 2025 06:56:13.835779905 CET4434975090.156.255.181192.168.2.4
      Jan 16, 2025 06:56:13.835843086 CET49750443192.168.2.490.156.255.181
      Jan 16, 2025 06:56:13.837531090 CET49750443192.168.2.490.156.255.181
      Jan 16, 2025 06:56:13.837569952 CET4434975090.156.255.181192.168.2.4
      Jan 16, 2025 06:56:13.837694883 CET49749443192.168.2.490.156.255.181
      Jan 16, 2025 06:56:13.837709904 CET4434974990.156.255.181192.168.2.4
      TimestampSource PortDest PortSource IPDest IP
      Jan 16, 2025 06:55:37.328069925 CET53549501.1.1.1192.168.2.4
      Jan 16, 2025 06:55:37.355485916 CET53491711.1.1.1192.168.2.4
      Jan 16, 2025 06:55:38.334788084 CET53618551.1.1.1192.168.2.4
      Jan 16, 2025 06:55:40.418560982 CET5881253192.168.2.41.1.1.1
      Jan 16, 2025 06:55:40.418683052 CET5163953192.168.2.41.1.1.1
      Jan 16, 2025 06:55:40.425438881 CET53588121.1.1.1192.168.2.4
      Jan 16, 2025 06:55:40.425666094 CET53516391.1.1.1192.168.2.4
      Jan 16, 2025 06:55:42.727576971 CET5961653192.168.2.41.1.1.1
      Jan 16, 2025 06:55:42.728039026 CET5046453192.168.2.41.1.1.1
      Jan 16, 2025 06:55:42.745695114 CET53596161.1.1.1192.168.2.4
      Jan 16, 2025 06:55:42.746977091 CET53504641.1.1.1192.168.2.4
      Jan 16, 2025 06:55:55.223541975 CET53545481.1.1.1192.168.2.4
      Jan 16, 2025 06:55:55.630271912 CET138138192.168.2.4192.168.2.255
      Jan 16, 2025 06:56:12.722719908 CET53551911.1.1.1192.168.2.4
      Jan 16, 2025 06:56:14.207052946 CET53556111.1.1.1192.168.2.4
      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
      Jan 16, 2025 06:55:40.418560982 CET192.168.2.41.1.1.10x8996Standard query (0)www.google.comA (IP address)IN (0x0001)false
      Jan 16, 2025 06:55:40.418683052 CET192.168.2.41.1.1.10xfb1dStandard query (0)www.google.com65IN (0x0001)false
      Jan 16, 2025 06:55:42.727576971 CET192.168.2.41.1.1.10xa3e2Standard query (0)contract.nacap-holding.comA (IP address)IN (0x0001)false
      Jan 16, 2025 06:55:42.728039026 CET192.168.2.41.1.1.10x6b57Standard query (0)contract.nacap-holding.com65IN (0x0001)false
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      Jan 16, 2025 06:55:40.425438881 CET1.1.1.1192.168.2.40x8996No error (0)www.google.com142.250.185.100A (IP address)IN (0x0001)false
      Jan 16, 2025 06:55:40.425666094 CET1.1.1.1192.168.2.40xfb1dNo error (0)www.google.com65IN (0x0001)false
      Jan 16, 2025 06:55:42.745695114 CET1.1.1.1192.168.2.40xa3e2No error (0)contract.nacap-holding.com90.156.255.181A (IP address)IN (0x0001)false

      Click to jump to process

      Click to jump to process

      Click to jump to process

      Target ID:0
      Start time:00:55:33
      Start date:16/01/2025
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:2
      Start time:00:55:34
      Start date:16/01/2025
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2380 --field-trial-handle=2308,i,15495079991361432959,12914561289198759290,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:3
      Start time:00:55:41
      Start date:16/01/2025
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://contract.nacap-holding.com/gas25/"
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:true

      No disassembly