top title background image
flash

http://alaskan-legend.ru/js/?email=fake_email@gotcha.com

Status: finished
Submission Time: 2020-02-04 17:37:00 +01:00
Malicious

Comments

Tags

Details

  • Analysis ID:
    205717
  • API (Web) ID:
    308917
  • Analysis Started:
    2020-02-04 17:37:55 +01:00
  • Analysis Finished:
    2020-02-04 17:46:05 +01:00
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 48
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 5/72

IPs

IP Country Detection
108.179.252.142
United States
217.112.35.47
United Kingdom
217.112.35.74
United Kingdom

Domains

Name IP Detection
manotaco.com.br
108.179.252.142
www.manotaco.com.br
0.0.0.0
arm-wingchun.ru
217.112.35.47
Click to see the 2 hidden entries
alaskan-legend.ru
217.112.35.74
site-cdn.onenote.net
0.0.0.0

URLs

Name Detection
http://www.manotaco.com.br/update/roundcube/images/favicon.ico
http://arm-wingchun.ru/img/fox/1b3a7c5d2b7e9a//login_files/styles.min.css
http://arm-wingchun.ru/img/fox/1b3a7c5d2b7e9a//?email=fake_email@gotcha.com
Click to see the 14 hidden entries
http://www.twitter.com/
http://www.reddit.com/
http://alaskan-legend.ru/js/?email=fake_email@gotcha.com
http://danken.com.tw
http://www.live.com/
http://www.amazon.com/
http://www.wikipedia.com/
http://arm-wingchun.ru/img/fox/1b3a7c5d2b7e9a//login_files/user.png
http://arm-wingchun.ru/img/fox/1b3a7c5d2b7e9a//kmluzblo3svvp5pa36sl3ma9.php?rand=13InboxLightaspxn.1774256418&fid.4.1252899642&fid=1&fav.1&rand.13InboxLight.aspxn.1774256418&fid.1252899642&fid.1&fav.1&email=fake_email@gotcha.com&.rand=13InboxLight.aspx?n=1774256418&fid=4
http://www.youtube.com/
http://arm-wingchun.ru/img/fox/1b3a7c5d2b7e9a//kmluzblo3svvp5pa36sl3ma9.php?rand=13InboxLightaspxn.1
http://arm-wingchun.ru/favicon.ico
http://www.nytimes.com/
http://arm-wingchun.ru/img/fox/1b3a7c5d2b7e9a//login_files/webmail.png

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\~DFD102B56EF830ACF2.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFB624EA1C36B8FFD3.TMP
data
#
Click to see the 21 hidden entries
C:\Users\user\AppData\Local\Temp\~DF68B5486FF448E30D.TMP
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\W2BICE6W\user[1].png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\T7L7U67X\styles.min[1].css
ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\T7L7U67X\favicon[1].ico
PNG image data, 16 x 16, 4-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KGYEP10B\kmluzblo3svvp5pa36sl3ma9[1].htm
HTML document, ASCII text, with CRLF, LF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KGYEP10B\favicon[1].ico
MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\webmail[1].png
PNG image data, 122 x 20, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\9ky2px6\imagestore.dat
data
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
PNG image data, 16 x 16, 4-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-314712940\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{677DB043-47B8-11EA-AAE2-44C1B3FB757B}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{5FC8FD14-47B8-11EA-AAE2-44C1B3FB757B}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{5FC8FD12-47B8-11EA-AAE2-44C1B3FB757B}.dat
Microsoft Word Document
#