We are hiring! Windows Kernel Developer (Remote), apply here!
flash

https://files.cchsfs.com/doc/atx/2021/Help/Content/Both-SSource/Installation/Downloading%20ATX.htm

Status: finished
Submission Time: 2022-08-31 23:38:01 +02:00
Clean

Comments

Tags

Details

  • Analysis ID:
    694551
  • API (Web) ID:
    1062028
  • Analysis Started:
    2022-08-31 23:40:22 +02:00
  • Analysis Finished:
    2022-08-31 23:56:45 +02:00
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

System: Windows 7 x64 SP1 with Office 2010 SP1 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2)

clean
2/100

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
Run Condition: Potential for more IOCs and behavior

clean
2/100

IPs

IP Country Detection
239.255.255.250
Reserved
216.58.215.238
United States
142.250.203.100
United States
Click to see the 2 hidden entries
152.199.21.175
United States
142.250.203.109
United States

Domains

Name IP Detection
accounts.google.com
142.250.203.109
www.google.com
142.250.203.100
clients.l.google.com
216.58.215.238
Click to see the 3 hidden entries
sni1gl.wpc.edgecastcdn.net
152.199.21.175
files.cchsfs.com
0.0.0.0
clients2.google.com
0.0.0.0

URLs

Name Detection
file:///C:/Users/user/Desktop/download/Downloading%20ATX.htm.html
https://support.atxinc.com/
https://files.cchsfs.com/doc/atx/2021/Help/Content/Both-SSource/Installation/Downloading%20ATX.htmS
Click to see the 10 hidden entries
http://www.madcapsoftware.com/Schemas/MadCap.xsd
https://files.cchsfs.com/doc/atx/2021/Help/Content/Both-SSource/Installation/Downloading%20ATX.htm(
https://files.cchsfs.com/doc/atx/2021/Help/Content/Both-SSource/Installation/Downloading%20ATX.htmJ
https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard
https://www.google.com/jsapi
https://files.cchsfs.com/doc/atx/2021/Help/Content/Both-SSource/Installation/Downloading%20ATX.htmW
https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=84.0.4147.135&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1&x=id%3Dpkedcjkdefgpdelpbcmbmeomcjbeemfm%26v%3D0.0.0.0%26installedby%3Dother%26uc
https://files.cchsfs.com/doc/atx/2021/Help/Content/Both-SSource/Installation/Downloading%20ATX.htm:
https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=84.0.4147.135&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1&x=id%3Dpkedcjkdefgpdelpbcmbmeomcjbeemfm%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1
https://files.cchsfs.com/doc/atx/2021/Help/Content/Both-SSource/Installation/Downloading%20ATX.htm

Dropped files

Name File Type Hashes Detection
C:\Users\user\Desktop\cmdline.out
ASCII text, with CRLF line terminators
#
C:\Users\user\Desktop\download\Downloading ATX.htm
HTML document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
#