top title background image
flash

Doc11245.htm

Status: finished
Submission Time: 2022-08-11 05:09:56 +02:00
Malicious
Phishing
HTMLPhisher

Comments

Tags

Details

  • Analysis ID:
    682139
  • API (Web) ID:
    1049645
  • Analysis Started:
    2022-08-11 05:09:57 +02:00
  • Analysis Finished:
    2022-08-11 05:14:35 +02:00
  • MD5:
    2fa3df486add30fd5c12d9ee3a5e088e
  • SHA1:
    9600358cacfc53884a710e38a81aa1dab958c5a7
  • SHA256:
    06c091ff47d7799ced70ca32326e8bbf393fef4fc44e6274ddf58fd5eb92d5a0
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 80
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 14/88
malicious

IPs

IP Country Detection
162.240.215.126
United States
104.17.24.14
United States
104.18.10.207
United States
Click to see the 5 hidden entries
142.250.186.173
United States
185.85.13.154
Russian Federation
239.255.255.250
Reserved
142.250.185.142
United States
142.251.36.35
United States

Domains

Name IP Detection
iwujch.cf
162.240.215.126
stackpath.bootstrapcdn.com
104.18.10.207
gstaticadssl.l.google.com
142.251.36.35
Click to see the 7 hidden entries
accounts.google.com
142.250.186.173
cdnjs.cloudflare.com
104.17.24.14
maxcdn.bootstrapcdn.com
104.18.10.207
me.kis.v2.scr.kaspersky-labs.com
185.85.13.154
clients.l.google.com
142.250.185.142
clients2.google.com
0.0.0.0
code.jquery.com
0.0.0.0

URLs

Name Detection
https://znrton.gq/new/Odrivenew/file/Odrivex/next.php
file:///C:/Users/user/Desktop/Doc11245.htm
https://iwujch.cf/ado/Odrivenew/file/next.php
Click to see the 26 hidden entries
https://www.google.com/images/x2.gif
https://clients2.google.com/service/update2/crx
https://clients2.google.com
https://www-googleapis-staging.sandbox.google.com
https://www.google.com/
https://www.google.com/accounts/OAuthLogin?issueuberauth=1
https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/js/bootstrap.min.js
https://apis.google.com
https://clients2.googleusercontent.com
https://accounts.google.com
https://cdnjs.cloudflare.com/ajax/libs/popper.js/1.12.9/umd/popper.min.js
https://www.google.com/images/dot2.gif
https://www.google.com
https://accounts.google.com/MergeSession
https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/css/bootstrap.min.css
https://github.com/google/closure-library/wiki/goog.module:-an-ES6-module-like-alternative-to-goog.p
https://sandbox.google.com/payments/v4/js/integrator.js
https://me.kis.v2.scr.kaspersky-labs.com/FD126C42-EBFA-4E12-B309-BB3FDD723AC1/main.js?attr=LBLzR8kxf
https://stackpath.bootstrapcdn.com/bootstrap/4.1.3/js/bootstrap.min.js
https://payments.google.com/payments/v4/js/integrator.js
https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard
https://code.jquery.com/jquery-3.2.1.slim.min.js
https://www.google.com/images/cleardot.gif
https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=92.0.4515.107&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1&x=id%3Dpkedcjkdefgpdelpbcmbmeomcjbeemfm%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1
https://ogs.google.com
https://www.google.com/intl/en-US/chrome/blank.html

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\hr\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\pt_PT\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\pt_BR\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
Click to see the 97 hidden entries
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\pl\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\nl\messages.json
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\nb\messages.json
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\lv\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\lt\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\ko\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\ja\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\it\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\id\messages.json
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\hu\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\ro\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\hi\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\fr\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\fil\messages.json
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\fi\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\et\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\es_419\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\es\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\en_GB\messages.json
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\en\messages.json
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\el\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\de\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_metadata\verified_contents.json
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\images\topbar_floating_button_pressed.png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\images\topbar_floating_button_maximize.png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\images\topbar_floating_button_hover.png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\images\topbar_floating_button_close.png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\images\topbar_floating_button.png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\images\icon_16.png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\images\icon_128.png
PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\images\flapper.gif
GIF image data, version 89a, 30 x 30
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\html\craw_window.html
HTML document, ASCII text
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\css\craw_window.css
ASCII text
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\craw_window.js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\craw_background.js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\da\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\zh_TW\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\zh_CN\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\vi\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\uk\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\tr\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\th\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\sv\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\sr\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\sl\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\sk\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\ru\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Network Persistent State (copy)
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\GPUCache\data_1
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\11298af9-ca87-4913-90df-e36f3f324c25.tmp
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Session Storage\MANIFEST-000001
PGP\011Secret Key -
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Session Storage\CURRENT (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Session Storage\000001.dbtmp
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Network Persistent State (copy)
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\GPUCache\data_1
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\5ade4b7f-6346-4de7-bcd8-d0f705025fd5.tmp
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences (copy)
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Preferences (copy)
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State (copy)
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Session Storage\000001.dbtmp
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_1\_metadata\computed_hashes.json
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\9a453915-f6b6-48ee-8e06-d73fb1df0326.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\7a4628b9-b5ff-4e62-ac67-9353b89bdb9d.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\5a60856f-f623-4d96-a4f2-dfde67537cc2.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\5668f941-21eb-45ec-8447-ad1322ae6c2a.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\3d422c6e-850d-43cc-9116-54e57add4d5d.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\2c788f32-1960-49c7-a2cb-0f863c0463f8.tmp
very short file (no magic)
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\06bb092b-83a5-4b87-be5c-ae7869be22e2.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\968eded4-213e-4335-8466-c66fa7fa0bf4.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\82358cdb-3f4f-43e0-90e8-7c222e2b8204.tmp
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\ba6e816a-a7ec-42ed-9118-3ca6a6afc810.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\cs\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\ca\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir6556_1886960998\CRX_INSTALL\_locales\bg\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\aab5c5a0-bfcb-4902-88b4-98d03d3918df.tmp
Google Chrome extension, version 3
#
C:\Users\user\AppData\Local\Temp\a71db759-a905-4b5d-933a-d92732b82381.tmp
gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT)
#
C:\Users\user\AppData\Local\Temp\96a21478-8f2c-4225-8449-e4eca0901cc7.tmp
gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT)
#
C:\Users\user\AppData\Local\Temp\8138a6f7-2e08-49b9-a602-b096471339dc.tmp
gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT)
#
C:\Users\user\AppData\Local\Temp\54069964-70f0-4c11-9903-6a9285329d2a.tmp
gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT)
#
C:\Users\user\AppData\Local\Temp\2cf6ce9a-7d44-44e3-ac14-b6a67341c71f.tmp
gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT)
#
C:\Users\user\AppData\Local\Temp\1769dc19-002a-4a4c-ba86-40abba487afc.tmp
gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT)
#
C:\Users\user\AppData\Local\Temp\13965899-5c90-4780-a345-e6c9514e1b65.tmp
very short file (no magic)
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\d4b41f5d-c77b-412a-b2ea-1c95dd26dc1e.tmp
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\357d26ee-551f-4bfd-be33-4c96fc3487fc.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Module Info Cache (copy)
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Local State (copy)
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Version
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Browser
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000006.dbtmp
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\c0e9559e-64e1-40ae-8b85-9c47a69e9a7d.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\b0aae087-072e-4344-8288-fa4a44e44a48.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\a15ed646-c88c-46a5-a073-10b6533a5e05.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Session Storage\MANIFEST-000001
PGP\011Secret Key -
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Session Storage\CURRENT (copy)
ASCII text
#