Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://sodexojobs.at

Overview

General Information

Sample URL:http://sodexojobs.at
Analysis ID:1592530
Infos:
Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 3732 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
    • chrome.exe (PID: 5772 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2136 --field-trial-handle=1956,i,7543126829972680218,16152946217166529976,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • chrome.exe (PID: 6592 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://sodexojobs.at" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.32
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: sodexojobs.atConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: sodexojobs.atConnection: keep-aliveCache-Control: max-age=0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: sodexojobs.at
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: classification engineClassification label: unknown0.win@18/0@4/4
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2136 --field-trial-handle=1956,i,7543126829972680218,16152946217166529976,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://sodexojobs.at"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2136 --field-trial-handle=1956,i,7543126829972680218,16152946217166529976,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://sodexojobs.at0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://sodexojobs.at/0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
sodexojobs.at
194.64.100.124
truefalse
    unknown
    www.google.com
    142.250.181.228
    truefalse
      high
      NameMaliciousAntivirus DetectionReputation
      http://sodexojobs.at/false
      • Avira URL Cloud: safe
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      239.255.255.250
      unknownReserved
      unknownunknownfalse
      194.64.100.124
      sodexojobs.atGermany
      51862PROFITBRICKS-ASDEfalse
      142.250.181.228
      www.google.comUnited States
      15169GOOGLEUSfalse
      IP
      192.168.2.4
      Joe Sandbox version:42.0.0 Malachite
      Analysis ID:1592530
      Start date and time:2025-01-16 09:01:13 +01:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 2m 2s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:browseurl.jbs
      Sample URL:http://sodexojobs.at
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:7
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Detection:UNKNOWN
      Classification:unknown0.win@18/0@4/4
      Cookbook Comments:
      • URL browsing timeout or error
      • URL not reachable
      • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe, svchost.exe
      • Excluded IPs from analysis (whitelisted): 172.217.18.99, 142.250.185.110, 108.177.15.84, 142.250.184.206, 142.250.181.238, 172.217.18.110, 84.201.210.23, 142.250.186.78, 184.30.131.245, 199.232.214.172, 184.28.90.27, 4.175.87.197
      • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, ocsp.digicert.com, accounts.google.com, redirector.gvt1.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
      • Not all processes where analyzed, report is missing behavior information
      • VT rate limit hit for: http://sodexojobs.at
      No simulations
      No context
      No context
      No context
      No context
      No context
      No created / dropped files found
      No static file info
      TimestampSource PortDest PortSource IPDest IP
      Jan 16, 2025 09:02:07.926933050 CET49675443192.168.2.4173.222.162.32
      Jan 16, 2025 09:02:14.591810942 CET49738443192.168.2.4142.250.181.228
      Jan 16, 2025 09:02:14.591918945 CET44349738142.250.181.228192.168.2.4
      Jan 16, 2025 09:02:14.592025995 CET49738443192.168.2.4142.250.181.228
      Jan 16, 2025 09:02:14.592279911 CET49738443192.168.2.4142.250.181.228
      Jan 16, 2025 09:02:14.592304945 CET44349738142.250.181.228192.168.2.4
      Jan 16, 2025 09:02:15.243648052 CET44349738142.250.181.228192.168.2.4
      Jan 16, 2025 09:02:15.244014978 CET49738443192.168.2.4142.250.181.228
      Jan 16, 2025 09:02:15.244081974 CET44349738142.250.181.228192.168.2.4
      Jan 16, 2025 09:02:15.245780945 CET44349738142.250.181.228192.168.2.4
      Jan 16, 2025 09:02:15.245862961 CET49738443192.168.2.4142.250.181.228
      Jan 16, 2025 09:02:15.247451067 CET49738443192.168.2.4142.250.181.228
      Jan 16, 2025 09:02:15.247548103 CET44349738142.250.181.228192.168.2.4
      Jan 16, 2025 09:02:15.300612926 CET49738443192.168.2.4142.250.181.228
      Jan 16, 2025 09:02:15.300640106 CET44349738142.250.181.228192.168.2.4
      Jan 16, 2025 09:02:15.347502947 CET49738443192.168.2.4142.250.181.228
      Jan 16, 2025 09:02:17.065932989 CET4974080192.168.2.4194.64.100.124
      Jan 16, 2025 09:02:17.066660881 CET4974180192.168.2.4194.64.100.124
      Jan 16, 2025 09:02:17.070842981 CET8049740194.64.100.124192.168.2.4
      Jan 16, 2025 09:02:17.070933104 CET4974080192.168.2.4194.64.100.124
      Jan 16, 2025 09:02:17.071194887 CET4974080192.168.2.4194.64.100.124
      Jan 16, 2025 09:02:17.071556091 CET8049741194.64.100.124192.168.2.4
      Jan 16, 2025 09:02:17.071636915 CET4974180192.168.2.4194.64.100.124
      Jan 16, 2025 09:02:17.076030970 CET8049740194.64.100.124192.168.2.4
      Jan 16, 2025 09:02:25.135963917 CET44349738142.250.181.228192.168.2.4
      Jan 16, 2025 09:02:25.136118889 CET44349738142.250.181.228192.168.2.4
      Jan 16, 2025 09:02:25.136243105 CET49738443192.168.2.4142.250.181.228
      Jan 16, 2025 09:02:26.056500912 CET49738443192.168.2.4142.250.181.228
      Jan 16, 2025 09:02:26.056570053 CET44349738142.250.181.228192.168.2.4
      Jan 16, 2025 09:02:38.437835932 CET8049741194.64.100.124192.168.2.4
      Jan 16, 2025 09:02:38.437874079 CET8049740194.64.100.124192.168.2.4
      Jan 16, 2025 09:02:38.438021898 CET4974180192.168.2.4194.64.100.124
      Jan 16, 2025 09:02:38.438025951 CET4974080192.168.2.4194.64.100.124
      Jan 16, 2025 09:02:38.438278913 CET4974080192.168.2.4194.64.100.124
      Jan 16, 2025 09:02:38.443110943 CET8049740194.64.100.124192.168.2.4
      Jan 16, 2025 09:02:38.498889923 CET4974180192.168.2.4194.64.100.124
      Jan 16, 2025 09:02:38.505140066 CET8049741194.64.100.124192.168.2.4
      Jan 16, 2025 09:02:39.481726885 CET4974980192.168.2.4194.64.100.124
      Jan 16, 2025 09:02:39.481786013 CET4975080192.168.2.4194.64.100.124
      Jan 16, 2025 09:02:39.487015009 CET8049749194.64.100.124192.168.2.4
      Jan 16, 2025 09:02:39.487180948 CET4974980192.168.2.4194.64.100.124
      Jan 16, 2025 09:02:39.487273932 CET8049750194.64.100.124192.168.2.4
      Jan 16, 2025 09:02:39.487436056 CET4975080192.168.2.4194.64.100.124
      Jan 16, 2025 09:02:39.594537973 CET4975080192.168.2.4194.64.100.124
      Jan 16, 2025 09:02:39.599464893 CET8049750194.64.100.124192.168.2.4
      TimestampSource PortDest PortSource IPDest IP
      Jan 16, 2025 09:02:11.518495083 CET53618791.1.1.1192.168.2.4
      Jan 16, 2025 09:02:11.673082113 CET53499081.1.1.1192.168.2.4
      Jan 16, 2025 09:02:12.690762043 CET53567981.1.1.1192.168.2.4
      Jan 16, 2025 09:02:14.583240986 CET5525253192.168.2.41.1.1.1
      Jan 16, 2025 09:02:14.583412886 CET5864653192.168.2.41.1.1.1
      Jan 16, 2025 09:02:14.590542078 CET53586461.1.1.1192.168.2.4
      Jan 16, 2025 09:02:14.590564013 CET53552521.1.1.1192.168.2.4
      Jan 16, 2025 09:02:17.045310974 CET4987853192.168.2.41.1.1.1
      Jan 16, 2025 09:02:17.045572996 CET6499753192.168.2.41.1.1.1
      Jan 16, 2025 09:02:17.059931993 CET53649971.1.1.1192.168.2.4
      Jan 16, 2025 09:02:17.065215111 CET53498781.1.1.1192.168.2.4
      Jan 16, 2025 09:02:26.125101089 CET138138192.168.2.4192.168.2.255
      Jan 16, 2025 09:02:29.592958927 CET53547221.1.1.1192.168.2.4
      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
      Jan 16, 2025 09:02:14.583240986 CET192.168.2.41.1.1.10xea42Standard query (0)www.google.comA (IP address)IN (0x0001)false
      Jan 16, 2025 09:02:14.583412886 CET192.168.2.41.1.1.10x2a5aStandard query (0)www.google.com65IN (0x0001)false
      Jan 16, 2025 09:02:17.045310974 CET192.168.2.41.1.1.10xbdf4Standard query (0)sodexojobs.atA (IP address)IN (0x0001)false
      Jan 16, 2025 09:02:17.045572996 CET192.168.2.41.1.1.10x6ca5Standard query (0)sodexojobs.at65IN (0x0001)false
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
      Jan 16, 2025 09:02:14.590542078 CET1.1.1.1192.168.2.40x2a5aNo error (0)www.google.com65IN (0x0001)false
      Jan 16, 2025 09:02:14.590564013 CET1.1.1.1192.168.2.40xea42No error (0)www.google.com142.250.181.228A (IP address)IN (0x0001)false
      Jan 16, 2025 09:02:17.065215111 CET1.1.1.1192.168.2.40xbdf4No error (0)sodexojobs.at194.64.100.124A (IP address)IN (0x0001)false
      • sodexojobs.at
      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      0192.168.2.449740194.64.100.124805772C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      Jan 16, 2025 09:02:17.071194887 CET428OUTGET / HTTP/1.1
      Host: sodexojobs.at
      Connection: keep-alive
      Upgrade-Insecure-Requests: 1
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
      Accept-Encoding: gzip, deflate
      Accept-Language: en-US,en;q=0.9


      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
      1192.168.2.449750194.64.100.124805772C:\Program Files\Google\Chrome\Application\chrome.exe
      TimestampBytes transferredDirectionData
      Jan 16, 2025 09:02:39.594537973 CET454OUTGET / HTTP/1.1
      Host: sodexojobs.at
      Connection: keep-alive
      Cache-Control: max-age=0
      Upgrade-Insecure-Requests: 1
      User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
      Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
      Accept-Encoding: gzip, deflate
      Accept-Language: en-US,en;q=0.9


      Click to jump to process

      Click to jump to process

      Click to jump to process

      Target ID:0
      Start time:03:02:03
      Start date:16/01/2025
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:2
      Start time:03:02:09
      Start date:16/01/2025
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2136 --field-trial-handle=1956,i,7543126829972680218,16152946217166529976,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:false

      Target ID:3
      Start time:03:02:16
      Start date:16/01/2025
      Path:C:\Program Files\Google\Chrome\Application\chrome.exe
      Wow64 process (32bit):false
      Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://sodexojobs.at"
      Imagebase:0x7ff76e190000
      File size:3'242'272 bytes
      MD5 hash:45DE480806D1B5D462A7DDE4DCEFC4E4
      Has elevated privileges:true
      Has administrator privileges:true
      Programmed in:C, C++ or other language
      Reputation:low
      Has exited:true

      No disassembly