=
We are hiring! Windows Kernel Developer (Remote), apply here!
flash

https://www.trekkdesigngroup.online

Status: finished
Submission Time: 2022-06-30 21:15:14 +02:00
Malicious
Phishing
HTMLPhisher

Comments

Tags

Details

  • Analysis ID:
    655293
  • API (Web) ID:
    1022798
  • Analysis Started:
    2022-06-30 21:15:15 +02:00
  • Analysis Finished:
    2022-06-30 21:21:30 +02:00
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
64/100

malicious

malicious

IPs

IP Country Detection
104.18.10.207
United States
142.251.36.238
United States
142.251.36.205
United States
Click to see the 8 hidden entries
52.48.59.54
United States
151.101.2.79
United States
38.242.134.24
United States
52.210.19.9
United States
104.18.11.207
United States
54.154.76.92
United States
239.255.255.250
Reserved
104.17.25.14
United States

Domains

Name IP Detection
jimdo-dolphin-static-assets-prod.freetls.fastly.net
151.101.2.79
stackpath.bootstrapcdn.com
104.18.11.207
gstaticadssl.l.google.com
142.251.36.227
Click to see the 12 hidden entries
accounts.google.com
142.251.36.205
cdnjs.cloudflare.com
104.17.25.14
jimdo-storage.freetls.fastly.net
151.101.2.79
maxcdn.bootstrapcdn.com
104.18.10.207
thestlouisblues.com
38.242.134.24
clients.l.google.com
142.251.36.238
dolphin-render-ce5083-1529577379-1289163597.eu-west-1.elb.amazonaws.com
52.210.19.9
at.jimdo-platform-eks.net
54.154.76.92
clients2.google.com
0.0.0.0
code.jquery.com
0.0.0.0
www.trekkdesigngroup.online
0.0.0.0
fonts.jimstatic.com
0.0.0.0

URLs

Name Detection
https://thestlouisblues.com/doc/
https://thestlouisblues.com/doc/css/share-point.css
https://www.trekkdesigngroup.online/about/
Click to see the 48 hidden entries
https://www.trekkdesigngroup.online/imprint/
https://thestlouisblues.com/doc/images/logo.png
https://thestlouisblues.com/doc/
https://thestlouisblues.com/doc/images/logo_strip.png
https://www.trekkdesigngroup.online/cookie-settings/
https://thestlouisblues.com/doc/images/box.PNG
https://www.trekkdesigngroup.online/
https://thestlouisblues.com/doc/images/pdf.png
https://jimdo-dolphin-static-assets-prod.freetls.fastly.net/renderer/static/7bc340391ff879c7dd40.js
https://jimdo-storage.freetls.fastly.net/image/313511311/8455d926-cb8a-4401-928b-ec4fe27494e3.jpg?format=pjpg&quality=80,90&auto=webp&disable=upscale&width=800&height=533
https://www.google.com/images/cleardot.gif
https://at.jimdo-platform-eks.net/events
https://play.google.com
https://www.trekkdesigngroup.online/favicon.ico
https://jimdo-dolphin-static-assets-prod.freetls.fastly.net/renderer/static/55ae49ade666a31f836e.css
https://sandbox.google.com/payments/v4/js/integrator.js
https://accounts.google.com/MergeSession
https://www.google.com
https://www.trekkdesigngroup.online/cookie-settings/
https://accounts.google.com
https://apis.google.com
https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/js/bootstrap.min.js
https://www.google.com/accounts/OAuthLogin?issueuberauth=1
https://www.trekkdesigngroup.online/2
https://www.trekkdesigngroup.online/imprint/
https://www-googleapis-staging.sandbox.google.com
https://clients2.google.com
https://www.trekkdesigngroup.online/contact/
https://dns.google
https://github.com/google/closure-library/wiki/goog.module:-an-ES6-module-like-alternative-to-goog.p
https://www.google.com/intl/en-US/chrome/blank.html
https://ogs.google.com
https://thestlouisblues.com/favicon.ico
https://at.jimdo-platform-eks.net/cf
https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=85.0.4183.121&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1&x=id%3Dpkedcjkdefgpdelpbcmbmeomcjbeemfm%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1
https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard
https://payments.google.com/payments/v4/js/integrator.js
https://stackpath.bootstrapcdn.com/bootstrap/4.1.3/js/bootstrap.min.js
https://www.google.com/images/x2.gif
https://thestlouisblues.com/doc
https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/css/bootstrap.min.css
https://www.google.com/images/dot2.gif
https://cdnjs.cloudflare.com/ajax/libs/popper.js/1.12.9/umd/popper.min.js
https://clients2.googleusercontent.com
https://www.trekkdesigngroup.online/
https://www.trekkdesigngroup.online/about/
https://www.google.com/
https://clients2.google.com/service/update2/crx

Dropped files

Name File Type Hashes Detection
C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\14e23506-ac41-428f-970d-5e33427ff689.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\29255d63-927f-4b6f-ae46-8e3a1b9b02b0.tmp
ASCII text, with very long lines, with no line terminators
#
Click to see the 97 hidden entries
C:\Users\user\AppData\Local\Google\Chrome\User Data\5342d236-b93f-4635-a2ca-26c5975fa34a.tmp
SysEx File -
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\57c08e80-8251-418d-8127-699664144929.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\5d2c19d2-d1f9-45ce-8b2b-1273475251e3.tmp
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\17479bf1-e47e-419c-b00b-f841cdafc199.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\27058494-f2e6-4e83-b8ef-e5a681a3c37c.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\8750bdd4-8a4f-47b2-9130-55556371737b.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\8dc07f0c-f2d6-42a3-9976-5ede9128e770.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_metadata\computed_hashes.json
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\000003.log
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG.old (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State (copy)
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Preferences (copy)
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences (copy)
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\12ab03c7-34f6-4bb9-a5c4-0f36ca9dc7d7.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\GPUCache\data_1
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Network Persistent State (copy)
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\767fc365-abff-4521-a7ff-22e7dcebc033.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Network Persistent State (copy)
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\a6aa61b8-46ad-43b8-8033-35163324a167.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\bd0cbc99-103a-4ab8-b305-1441d47a8df0.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\be86d6c6-dddd-4ac1-804a-a202e5f04d71.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\c38ffe5d-09ed-4e01-82d7-07275066f0f8.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\d9dbeb97-288a-4ec8-a235-b3f41cc7dd36.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000004.dbtmp
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\db38715e-125f-4bae-9372-095aa98eab9e.tmp
very short file (no magic)
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\eacaf335-7bc1-42cd-a6a5-931e1f91e0d8.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\fac8166b-b58b-46d0-898e-86f7740f1af8.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Browser
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Version
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Local State (copy)
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Module Info Cache (copy)
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\baf2e63f-66d0-4d01-95a5-c130ea21d4e1.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\eb9b5c97-16a5-4e36-8b39-254c74478718.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\f1c11fd4-204a-467f-982b-83e534495b14.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Temp\62712acc-1b35-4522-b3ec-d6c858c6dbaf.tmp
Google Chrome extension, version 3
#
C:\Users\user\AppData\Local\Temp\64fa9257-c8ce-4990-bd83-af46a2a90b23.tmp
very short file (no magic)
#
C:\Users\user\AppData\Local\Temp\916_684278386\LICENSE
ASCII text
#
C:\Users\user\AppData\Local\Temp\916_684278386\_metadata\verified_contents.json
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Temp\916_684278386\crl-set
data
#
C:\Users\user\AppData\Local\Temp\916_684278386\manifest.fingerprint
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\916_684278386\manifest.json
ASCII text
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\62712acc-1b35-4522-b3ec-d6c858c6dbaf.tmp
Google Chrome extension, version 3
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\bg\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\ca\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\cs\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\da\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\de\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\el\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\en\messages.json
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\en_GB\messages.json
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\es\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\es_419\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\et\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\fi\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\fil\messages.json
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\fr\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\hi\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\hr\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\hu\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\id\messages.json
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\it\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\ja\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\ko\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\lt\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\lv\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\nb\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\nl\messages.json
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\pl\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\pt_BR\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\pt_PT\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\ro\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\ru\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\sk\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\sl\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\sr\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\sv\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\th\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\tr\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\uk\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\vi\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\zh_CN\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_locales\zh_TW\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\_metadata\verified_contents.json
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\craw_background.js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\craw_window.js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\css\craw_window.css
ASCII text
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\html\craw_window.html
HTML document, ASCII text
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\images\flapper.gif
GIF image data, version 89a, 30 x 30
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\images\icon_128.png
PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\images\icon_16.png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\images\topbar_floating_button.png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\images\topbar_floating_button_close.png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Temp\scoped_dir916_1861928941\CRX_INSTALL\images\topbar_floating_button_hover.png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
#