top title background image
flash

https://271439.cobirosite.com/

Status: finished
Submission Time: 2023-03-21 00:47:54 +01:00
Malicious
Phishing
HTMLPhisher

Comments

Tags

Details

  • Analysis ID:
    831016
  • API (Web) ID:
    1198115
  • Analysis Started:
    2023-03-21 00:47:54 +01:00
  • Analysis Finished:
    2023-03-21 00:53:23 +01:00
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 76
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
malicious

IPs

IP Country Detection
142.250.186.45
United States
172.217.18.14
United States
52.109.13.64
United States
Click to see the 10 hidden entries
172.217.18.4
United States
172.67.152.102
United States
104.21.54.42
United States
239.255.255.250
Reserved
104.18.6.185
United States
52.222.214.9
United States
192.229.221.95
United States
35.190.80.1
United States
172.217.16.196
United States
52.109.76.141
United States

Domains

Name IP Detection
a.nel.cloudflare.com
35.190.80.1
accounts.google.com
142.250.186.45
challenges.cloudflare.com
104.18.6.185
Click to see the 7 hidden entries
media.cobiro.com
52.222.214.9
www.google.com
142.250.186.100
hh0mtbdj9f64031a8f7f879.sigadi.ru
172.67.152.102
prod-router.cobiro.workers.dev
104.21.54.42
clients.l.google.com
172.217.18.14
clients2.google.com
0.0.0.0
271439.cobirosite.com
0.0.0.0

URLs

Name Detection
https://hh0mtbdj9f64031a8f7f879.sigadi.ru/ID-6418f0e2af19b
https://271439.cobirosite.com/
https://271439.cobirosite.com/8306b64e-ea98-4158-8eee-204f0d79f12a.css
Click to see the 62 hidden entries
https://271439.cobirosite.com/
https://hh0mtbdj9f64031a8f7f879.sigadi.ru/ID-6418f0e2af19b
https://271439.cobirosite.com/favicon.ico
https://hh0mtbdj9f64031a8f7f879.sigadi.ru/js/ctgkdx59njcppdwfbkcqjnwr5
https://271439.cobirosite.com/8306b64e-ea98-4158-8eee-204f0d79f12a.js
https://a.nel.cloudflare.com/report/v3?s=aW9%2Bxr3YkF8n%2BjbNQUdf8%2FimakRns%2FFsV18RkoMkMrXnKWpZBgXqqKzvkJ8WTbhK7t6McaTSaGJ%2BRJbi1WgQt%2Fr%2Bp%2Bk8HkVvn1oCaXxWXJ1Lremha4PFqmYZdWBxvgZqKrmmsKh2Jwk%3D
https://www.cloudflare.com/website-terms/
https://media.cobiro.com/images/a5be6e77-9b87-48de-9e9f-f705ebb37c11.webp?width=2560px
https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard
https://hh0mtbdj9f64031a8f7f879.sigadi.ru/APP-U5GPIZ/n5dwqncfktpw5cgpxkdrbjj9c
https://googleads.g.doubleclick.net
https://hh0mtbdj9f64031a8f7f879.sigadi.ru/favicon.ico
https://getbootstrap.com/)
https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw
https://cct.google/taggy/agent.js
https://hh0mtbdj9f64031a8f7f879.sigadi.ru/cdn-cgi/challenge-platform/h/g/scripts/pica.js
https://media.cobiro.com/error-page/icon-build.svg
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/350hd/0x4AAAAAAAAjq6WYeRDKmebM/light/normal
https://hh0mtbdj9f64031a8f7f879.sigadi.ru/cdn-cgi/challenge-platform/h/g/scripts/alpha/invisible.js?ts=1679342400
https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.102&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1
https://www.merchant-center-analytics.goog/mc/collect
https://td.doubleclick.net
https://hh0mtbdj9f64031a8f7f879.sigadi.ru/cdn-cgi/challenge-platform/h/g/cv/result/7ab1d92a6fac9153
https://hh0mtbdj9f64031a8f7f879.sigadi.ru/
https://hh0mtbdj9f64031a8f7f879.sigadi.ru/x/p5cpkkdqgdr9jxbw5ncwfcjnt
https://hh0mtbdj9f64031a8f7f879.sigadi.ru/cdn-cgi/challenge-platform/h/g/orchestrate/managed/v1?ray=7ab1d8eda99635df
https://github.com/twbs/bootstrap/blob/master/LICENSE)
https://stats.g.doubleclick.net/g/collect?v=2&
https://hh0mtbdj9f64031a8f7f879.sigadi.ru/
https://media.cobiro.com/error-page/favicon.ico
https://media.cobiro.com/error-page/icon-domain.svg
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/pat/7ab1d8feaeca691b/1679356125505/6415a47ceedad2f748ae19a20389c1e9e14e5b3caf157a609d3d00a4894680e9/s5Kp__OWAS8SxWr
https://hh0mtbdj9f64031a8f7f879.sigadi.ru/ASSETS/img/m_.svg
https://stats.g.doubleclick.net/g/collect
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/orchestrate/chl_api/v1?ray=7ab1d8feaeca691b
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/350hd/0x4AAAAAAAAjq6WYeRDKmebM/light/normal
https://www.cloudflare.com/privacypolicy/
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/flow/ov1/1356602515:1679355110:EtCCJZINfDNVZaxY6meWZesT5skXLn1hf7eOmkFkgK0/7ab1d8feaeca691b/d1489ea3a7fd4ad
https://cobiro.com/domains
https://media.cobiro.com/error-page/under-construction-background.jpeg
https://hh0mtbdj9f64031a8f7f879.sigadi.ru/ASSETS/img/sig-op.svg
https://hh0mtbdj9f64031a8f7f879.sigadi.ru/cdn-cgi/styles/challenges.css
https://media.cobiro.com/images/a5be6e77-9b87-48de-9e9f-f705ebb37c11.webp?width=1080px
https://www.youtube.com/iframe_api
https://github.com/twbs/bootstrap/graphs/contributors)
https://media.cobiro.com/error-page/icon-advertising.svg
https://media.cobiro.com/error-page/logo-cobiro.svg
https://media.cobiro.com/images/a5be6e77-9b87-48de-9e9f-f705ebb37c11.webp?width=1920px
https://hh0mtbdj9f64031a8f7f879.sigadi.ru/cdn-cgi/challenge-platform/h/g/img/7ab1d8eda99635df/1679356121973/E7Dtgm4DKXspiM9
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/img/7ab1d8feaeca691b/1679356125509/jG-YDUWHZmJhn8N
https://hh0mtbdj9f64031a8f7f879.sigadi.ru/boot/9bcpwwjj5dtf5qkgnrpcncxdk
https://media.cobiro.com/images/a5be6e77-9b87-48de-9e9f-f705ebb37c11.webp?width=400px
https://cobiro.com/website
https://hh0mtbdj9f64031a8f7f879.sigadi.ru/ic/gcnpf5wpd5dqjkncwjkc9xtrb
https://media.cobiro.com/images/a5be6e77-9b87-48de-9e9f-f705ebb37c11.webp?width=200px
https://www.cloudflare.com/en-gb/products/turnstile/?utm_source=turnstile&utm_campaign=widget
https://hh0mtbdj9f64031a8f7f879.sigadi.ru/cdn-cgi/images/trace/managed/js/transparent.gif?ray=7ab1d8eda99635df
https://hh0mtbdj9f64031a8f7f879.sigadi.ru/cdn-cgi/challenge-platform/h/g/pat/7ab1d8eda99635df/1679356121974/e3b01c142e344330299c3d42ab192c2a0131b3d3e5fa078de4b6d2287145661e/Y8_NIB-7-_rheOk
https://hh0mtbdj9f64031a8f7f879.sigadi.ru/cdn-cgi/challenge-platform/h/g/flow/ov1/992221000:1679354830:2yQqRvlGN7S4gfDfO01nS-L4AqaibDzQpA12k-PJAhQ/7ab1d8eda99635df/8493bbc48a0427b
https://cobiro.com/google-search/
https://hh0mtbdj9f64031a8f7f879.sigadi.ru/jq/pktqpn5dbrxjwg5cfdkcw9cnj
https://media.cobiro.com/assets/css/reset.css

Dropped files

Name File Type Hashes Detection
Chrome Cache Entry: 178
ASCII text, with very long lines (14029)
#
Chrome Cache Entry: 169
ASCII text, with very long lines (32065)
#
Chrome Cache Entry: 170
SVG Scalable Vector Graphics image
#
Click to see the 36 hidden entries
Chrome Cache Entry: 171
HTML document, ASCII text, with very long lines (8524)
#
Chrome Cache Entry: 172
SVG Scalable Vector Graphics image
#
Chrome Cache Entry: 173
GIF image data, version 89a, 1 x 1
#
Chrome Cache Entry: 174
PNG image data, 82 x 29, 8-bit/color RGB, non-interlaced
#
Chrome Cache Entry: 175
ASCII text, with very long lines (65536), with no line terminators
#
Chrome Cache Entry: 176
ASCII text, with very long lines (6858), with no line terminators
#
Chrome Cache Entry: 177
HTML document, ASCII text, with very long lines (4525), with no line terminators
#
Chrome Cache Entry: 168
PNG image data, 94 x 9, 8-bit/color RGB, non-interlaced
#
Chrome Cache Entry: 179
SVG Scalable Vector Graphics image
#
Chrome Cache Entry: 180
ASCII text, with very long lines (6190), with no line terminators
#
Chrome Cache Entry: 181
ASCII text, with very long lines (50758)
#
Chrome Cache Entry: 182
RIFF (little-endian) data, Web/P image, VP8 encoding, 1920x1352, Scaling: [none]x[none], YUV color, decoders should clamp
#
Chrome Cache Entry: 183
ASCII text
#
Chrome Cache Entry: 184
ASCII text
#
Chrome Cache Entry: 185
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
#
Chrome Cache Entry: 186
SVG Scalable Vector Graphics image
#
Chrome Cache Entry: 187
ASCII text, with very long lines (492)
#
Chrome Cache Entry: 159
ASCII text, with very long lines (65536), with no line terminators
#
C:\Users\user\Documents\Outlook Files\Outlook Data File - NoEmail.pst
data
#
Chrome Cache Entry: 151
PNG image data, 82 x 29, 8-bit/color RGB, non-interlaced
#
Chrome Cache Entry: 152
GIF image data, version 89a, 1 x 1
#
Chrome Cache Entry: 153
ASCII text, with no line terminators
#
Chrome Cache Entry: 154
SVG Scalable Vector Graphics image
#
Chrome Cache Entry: 155
RIFF (little-endian) data, Web/P image, VP8 encoding, 1920x1352, Scaling: [none]x[none], YUV color, decoders should clamp
#
Chrome Cache Entry: 156
SVG Scalable Vector Graphics image
#
Chrome Cache Entry: 157
SVG Scalable Vector Graphics image
#
Chrome Cache Entry: 158
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
#
C:\Users\user\AppData\Local\Temp\Outlook Logging\OUTLOOK_16_0_13929_20386-20230321T0048140271-3132.etl
data
#
Chrome Cache Entry: 160
HTML document, ASCII text, with very long lines (937)
#
Chrome Cache Entry: 161
PNG image data, 94 x 9, 8-bit/color RGB, non-interlaced
#
Chrome Cache Entry: 162
SVG Scalable Vector Graphics image
#
Chrome Cache Entry: 163
ASCII text, with very long lines (26607), with no line terminators
#
Chrome Cache Entry: 164
ASCII text, with very long lines (5946), with no line terminators
#
Chrome Cache Entry: 165
Unicode text, UTF-8 text, with very long lines (5043)
#
Chrome Cache Entry: 166
ASCII text, with very long lines (65536), with no line terminators
#
Chrome Cache Entry: 167
ASCII text, with very long lines (21772)
#