flash

PDF.shtml

Status: finished
Submission Time: 2022-11-29 17:40:52 +01:00
Malicious
Phishing
HTMLPhisher

Comments

Tags

Details

  • Analysis ID:
    756145
  • API (Web) ID:
    1123421
  • Analysis Started:
    2022-11-29 17:40:53 +01:00
  • Analysis Finished:
    2022-11-29 17:48:35 +01:00
  • MD5:
    bc087e3bee347cf72d1d098ac0217ad3
  • SHA1:
    25ca68af27719867d3ae9ec4af84a7fa481a8800
  • SHA256:
    6480bae314fd0166ea5d47f7101269ad891ff2768ab36506c1b899372a74442d
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
52/100

IPs

IP Country Detection
13.107.219.60
United States
104.18.10.207
United States
142.250.203.110
United States
Click to see the 6 hidden entries
146.59.209.152
Norway
172.217.168.45
United States
172.217.168.36
United States
239.255.255.250
Reserved
192.229.221.185
United States
104.17.25.14
United States

Domains

Name IP Detection
cryptosaursnft.com
146.59.209.152
accounts.google.com
172.217.168.45
cdnjs.cloudflare.com
104.17.25.14
Click to see the 13 hidden entries
maxcdn.bootstrapcdn.com
104.18.10.207
part-0032.t-0009.t-msedge.net
13.107.246.60
www.google.com
172.217.168.36
cs1227.wpc.alphacdn.net
192.229.221.185
clients.l.google.com
142.250.203.110
part-0032.t-0009.fbs1-t-msedge.net
13.107.219.60
c.s-microsoft.com
0.0.0.0
clients2.google.com
0.0.0.0
code.jquery.com
0.0.0.0
cdn.jsdelivr.net
0.0.0.0
assets.onestore.ms
0.0.0.0
i.s-microsoft.com
0.0.0.0
ajax.aspnetcdn.com
0.0.0.0

URLs

Name Detection
file:///C:/Users/user/Desktop/PDF.shtml
https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1
https://maxcdn.bootstrapcdn.com/font-awesome/4.7.0/css/font-awesome.min.css
Click to see the 5 hidden entries
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/4.7.0/css/font-awesome.css
https://cryptosaursnft.com/wp-admin/host9/f12eac5.php
https://cryptosaursnft.com/wp-admin/host9/admin/js/mj.php?ar=ZGVmYXVsdA==
https://maxcdn.bootstrapcdn.com/font-awesome/4.7.0/fonts/fontawesome-webfont.woff2?v=4.7.0
https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard