top title background image
flash

test.html.html

Status: finished
Submission Time: 2019-11-09 08:25:38 +01:00
Suspicious
Spyware

Comments

Tags

Details

  • Analysis ID:
    188711
  • API (Web) ID:
    275730
  • Analysis Started:
    2019-11-09 08:25:39 +01:00
  • Analysis Finished:
    2019-11-09 08:34:12 +01:00
  • MD5:
    0da5c534258b8ec0085f69031c10dcee
  • SHA1:
    4401ca678d76a91e6db9c76ec6f4c52a8078e8a3
  • SHA256:
    7d158ea494009b23fee457f2a15a6d315958765fa8a416593704219bf412b95b
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
suspicious
Score: 20
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Domains

Name IP Detection
ow2.res.office365.com
0.0.0.0

URLs

Name Detection
http://www.google.it/
http://www.jiyu-kobo.co.jp/k
http://joseoncode.com)
Click to see the 97 hidden entries
https://github.com/fanatid)
https://outlook.live.com/calendar/
https://static-asm.secure.skypeassets.com/pes/v1/tabs/002_noname_57603e6d-9854-4a25-bdea-90c92033304
https://github.com/xyc/react-inspector.git)
http://sads.myspace.com/
http://www.jiyu-kobo.co.jp/u
http://www.amazon.de/
http://search.auction.co.kr/
https://lpcres.delve.office.com/lpc/versionless/light-bulb_bd76f8e75f19c4c8dd9c3573713b372a.svg)
http://www.jiyu-kobo.co.jp/y
https://ow2.res.office365.com/owamail/2019110503.08/resources/fonts/office365icons.eot?);y
https://ow2.res.office365.com/owa
http://www.jiyu-kobo.co.jp/;
https://ow2.res.office365.com/owamail/2019110503.08/scripts/owa.owa-account-store-init.js
https://ow2.res.office365.com/owamail/2019110503.08/scripts/owa.31.js
http://www.ask.com/
http://www.microsofttranslator.com/BVPrev.aspx?ref=IE8Activity
http://github.com/substack/vm-browserify.git)
https://ow2.res.office365.com/owamail/2019110503.08/resources/fonts/segoeui-semilight.ttf)
http://buscar.ozu.es/
https://github.com/OfficeDev/office-ui-fabric-reac
http://search.msn.co.jp/results.aspx?q=
http://uk.search.yahoo.com/
http://www.soso.com/
http://www.google.si/
http://search.nifty.com/
https://static-asm.secure.skypeassets.com/pes/v1/tabs/002_noname_9370eb76-8df9-4000-855e-847a3de8206
http://www.gmarket.co.kr/
http://search.yahoo.co.jp/favicon.ico
http://openimage.interpark.com/interpark.ico
https://ow2.res.office365.com/owamail/2019110503.08/resources/images/favicons/mail-seen.ico
http://search.sify.com/
https://ow2.res.office365.com/owamail/2019110503.08/scripts/owa.RecipientSuggestions.jsnload
http://www.ozu.es/favicon.ico
https://github.com/Microsoft/WastedRendersDetector.git)--
https://ow2.res.office365.com/owamail/2019110503.08/scripts/owa.RecipientPermissionChecker~SharingDa
https://github.com/dfahlander/Dexie.js.git)
https://ow2.res.office365.com/owamail/2019110503.08/scripts/../resources/images/fileType_sprite-f206
https://outlook.live.com/people/
http://www.rambler.ru/favicon.ico
http://list.taobao.com/browse/search_visual.htm?n=15&q=
http://google.pchome.com.tw/
https://github.com/unshiftio/yeast.git)
http://browse.guardian.co.uk/favicon.ico
http://www.pchome.com.tw/favicon.ico
https://github.com/facebook/regenerator/tree/master/packages/regenerator-runtime)
http://github.com/bl00mber)
https://ow2.res.office365.com/owamail/2019110503.08/scripts/../resources/images/letsgo-cloud-east-8b
http://www.jiyu-kobo.co.jp/0
https://ow2.res.office365.com/owamail/2019110503.08/scripts/owa.RecipientSuggestions.js
http://img.shopzilla.com/shopzilla/shopzilla.ico
https://github.com/reactjs/reselect.git)
https://ow2.res.office365.com/owamail/2019110503.08/resources/fonts/o365icons-mdl2.ttf)
http://in.search.yahoo.com/
https://res.delve.office.com/delve/versionless/lpc-icons-v06.woff);)e
https://ow2.res.office365.com/owamail/2019110503.08/resources/fonts/segoeui-semilight.eot?#iefix)
http://www.hiddentao.com/)
http://fr.search.yahoo.com/
https://ow2.res.office365.com/owamail/2019110503.08/scripts/owa.CalendarNotesEditor.jswnload
https://ow2.res.office365.com/owamail/2019110503.08/scripts/owa.vendors~SharingDialog~addon-sp-defer
https://ow2.res.office365.com/owamail/20191105
https://github.com/mathiasbynens/esrever.git)
http://www.dailymail.co.uk/
https://ow2.res.office365.com/owamail/2019110503.08/resources/fonts/o365icons-mdl2.woff)
https://github.com/crypto-browserify/browserify-des.git)
https://ow2.res.office365.com/owamail/2019110503.08/resources/fonts/segoeui-semibold.eot?#iefix
https://ow2.res.office365.com/owamail/2019110503.08/scripts/owa.SearchDiagnostics.js
https://nym1-ib.adnxs.com/it?an_audit=0&referrer=https%3A%2F%2Foutlook.live.com%2Fmail%2Finbox%2
http://www.merlin.com.pl/favicon.ico
http://www.mercadolivre.com.br/
http://search.chol.com/favicon.ico
https://ow2.res.office365.com/assets/mail/pwa/v1/pngs/apple-touch-icon.pngmail-seen.icotypeimage/x-i
https://github.com/component/emitter.git)
https://outlook.live.com/956087b3-c717-4925-b991-41d52541c217
http://cgi.search.biglobe.ne.jp/favicon.ico
http://search.hanafos.com/favicon.ico
https://github.com/JedWatson/classnames.git)
https://ow2.res.office365.com/owamail/2019110503.08/scripts/owa.TriageAct/m
http://it.search.dada.net/favicon.ico
http://www.etmall.com.tw/favicon.ico
https://ow2.res.office365.com/owamail/2019110503.08/scripts/owa.vendors~CloudCache.js
http://www.ya.com/favicon.ico
http://www.sandoll.co.krt-pt
https://ow2.res.office365.com/owamail/2019110503.08/scripts/../resources/images/fileType_s
https://ow2.res.office365.com/owamail/2019110503.08/scripts/../resou
http://www.sandoll.co.kr;
https://ow2.res.office365.com/owamail/2019110503.08/scripts/owa.30.js
http://busca.igbusca.com.br//app/static/images/favicon.ico
https://ow2.res.office365.com/owamail/2019110503.08/scripts/owa.DateTimePicker.js
https://ow2.res.office365.com/owamail/2019110503.08/resources/fonts/segoeui-light.eot?#iefixK
https://ow2.res.office365.com/owamail/20191
http://www.reddit.com/
https://github.com/crypto-browserify/randomfill.git)
http://msk.afisha.ru/
https://ow2.res.office365.com/owamail/2019110503.08/scripts/owa.vendors~OptOutDialog.js
https://github.com/mobxjs/mobx-react.git)
https://static-asm.secure.skypeassets.com/pes/v1/tabs/002_noname_ce685519-413b-48cb-b0b5-4c836f7e8fa

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VINVDFP6\httpErrorPagesScripts[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\V5D02472\dnserrordiagoff[1]
HTML document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\V5D02472\errorPageStrings[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
Click to see the 30 hidden entries
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\V5D02472\httpErrorPagesScripts[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\V5D02472\owa.vendors~OptOutDialog[1].js
UTF-8 Unicode text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VINVDFP6\NewErrorPageTemplate[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VINVDFP6\dnserror[1]
HTML document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VINVDFP6\down[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VINVDFP6\errorPageStrings[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\V5D02472\NewErrorPageTemplate[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VTIIBVU5\dnserrordiagoff[1]
HTML document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VTIIBVU5\errorPageStrings[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VTIIBVU5\httpErrorPagesScripts[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\dat345.tmp
Web Open Font Format, TrueType, length 2356, version 3.28180
#
C:\Users\user\AppData\Local\Temp\~DF32CA5484BC399A29.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF4C0CD5EE22B87A95.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFEDC7BE792C83752D.TMP
data
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{B6288E7D-030D-11EA-AADB-C25F135D3C65}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KSU5XQMC\fileType_sprite-f206d80520036a5a38289af596fafb86[1].png
PNG image data, 537 x 508, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KSU5XQMC\errorPageStrings[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KSU5XQMC\dnserrordiagoff[2]
HTML document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KSU5XQMC\dnserrordiagoff[1]
HTML document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{C00C09E6-030D-11EA-AADB-C25F135D3C65}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{B6288E7F-030D-11EA-AADB-C25F135D3C65}.dat
Microsoft Word Document
#