top title background image
flash

PDF.shtml

Status: finished
Submission Time: 2022-11-29 17:40:52 +01:00
Malicious
Phishing
HTMLPhisher

Comments

Tags

Details

  • Analysis ID:
    756145
  • API (Web) ID:
    1123421
  • Analysis Started:
    2022-11-29 17:40:53 +01:00
  • Analysis Finished:
    2022-11-29 17:48:35 +01:00
  • MD5:
    bc087e3bee347cf72d1d098ac0217ad3
  • SHA1:
    25ca68af27719867d3ae9ec4af84a7fa481a8800
  • SHA256:
    6480bae314fd0166ea5d47f7101269ad891ff2768ab36506c1b899372a74442d
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 52
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

IPs

IP Country Detection
13.107.219.60
United States
104.18.10.207
United States
142.250.203.110
United States
Click to see the 6 hidden entries
146.59.209.152
Norway
172.217.168.45
United States
172.217.168.36
United States
239.255.255.250
Reserved
192.229.221.185
United States
104.17.25.14
United States

Domains

Name IP Detection
cryptosaursnft.com
146.59.209.152
accounts.google.com
172.217.168.45
cdnjs.cloudflare.com
104.17.25.14
Click to see the 13 hidden entries
maxcdn.bootstrapcdn.com
104.18.10.207
part-0032.t-0009.t-msedge.net
13.107.246.60
www.google.com
172.217.168.36
cs1227.wpc.alphacdn.net
192.229.221.185
clients.l.google.com
142.250.203.110
part-0032.t-0009.fbs1-t-msedge.net
13.107.219.60
c.s-microsoft.com
0.0.0.0
clients2.google.com
0.0.0.0
code.jquery.com
0.0.0.0
cdn.jsdelivr.net
0.0.0.0
assets.onestore.ms
0.0.0.0
i.s-microsoft.com
0.0.0.0
ajax.aspnetcdn.com
0.0.0.0

URLs

Name Detection
file:///C:/Users/user/Desktop/PDF.shtml
https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1
https://maxcdn.bootstrapcdn.com/font-awesome/4.7.0/css/font-awesome.min.css
Click to see the 5 hidden entries
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/4.7.0/css/font-awesome.css
https://cryptosaursnft.com/wp-admin/host9/f12eac5.php
https://cryptosaursnft.com/wp-admin/host9/admin/js/mj.php?ar=ZGVmYXVsdA==
https://maxcdn.bootstrapcdn.com/font-awesome/4.7.0/fonts/fontawesome-webfont.woff2?v=4.7.0
https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard