top title background image
flash

https://townebank.azurefd.net/voiceindex/#dsmoker@merchantsbangor.com

Status: finished
Submission Time: 2020-04-15 16:31:22 +02:00
Malicious

Comments

Tags

Details

  • Analysis ID:
    222747
  • API (Web) ID:
    342161
  • Analysis Started:
    2020-04-15 16:35:19 +02:00
  • Analysis Finished:
    2020-04-15 16:40:48 +02:00
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 48
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious

IPs

IP Country Detection
192.0.73.2
United States
168.61.159.114
United States
52.239.161.42
United States
Click to see the 1 hidden entries
51.116.96.53
United Kingdom

Domains

Name IP Detection
secure.gravatar.com
192.0.73.2
waws-prod-dm1-123.cloudapp.net
168.61.159.114
blob.byaprdstr14a.store.core.windows.net
52.239.161.42
Click to see the 8 hidden entries
portal-prod-germanywestcentral-02.germanywestcentral.cloudapp.azure.com
51.116.96.53
i1.social.s-msft.com
0.0.0.0
fxtvoicecalling.azurewebsites.net
0.0.0.0
site-cdn.onenote.net
0.0.0.0
townebank.azurefd.net
0.0.0.0
portal.azure.com
0.0.0.0
ajax.aspnetcdn.com
0.0.0.0
msdnshared.blob.core.windows.net
0.0.0.0

URLs

Name Detection
http://manage.windowsAzure.com
https://ajax.aspnetcdn.com/ajax/jQuery/jquery-1.12.1.min.js
https://ajax.aspnetcdn.com/ajax/bootstrap/3.3.5/css/bootstrap.min.css
Click to see the 54 hidden entries
https://portal.azure.com/Content/Dynamic/2T0nXZp38ppy.css
http://www.nytimes.com/
https://msdnshared.blob.core.windows.net/media/MSDNBlogsFS/prod.evol.blogs.msdn.com/CommunityServer.
http://fbappsworld.com
http://timeago.yarp.com/
https://secure.gravatar.com/avatar/548637f12468e6d38874ee4b8d813be0?s=112&d=mm&r=g
http://www.moretrendstyle.com/koreanstyle/
https://api.w.org/
https://i1.social.s-msft.com/profile/u/avatar.jpg?displayname=Jeff
http://gmpg.org/xfn/11
https://portal.azure.com/favicon.ico
https://fxtvoicecalling.azurewebsites.net/voicemail.php#dsmoker
http://www.reddit.com/
https://secure.gravatar.com/avatar/4a47b03dd59347b7806f24f00551f899?s=112&d=mm&r=g
https://blogs.msdn.mic
https://www.google.%/ads/ga-audiences
http://www.youtube.com/
https://secure.gravatar.com/avatar/0bae1f5beafe0ff7ed2946a25fb6de08?s=56&d=mm&r=g
https://github.com/twbs/bootstrap/blob/master/LICENSE)
http://www.wikipedia.com/
http://www.live.com/
https://secure.gravatar.com/avatar/548637f12468e6d38874ee4b8d813be0?s=56&d=mm&r=g
https://secure.gravatar.com/avatar/c40aa3e27e0d9c9abf736198a3df1875?s=56&d=mm&r=g
https://portal.azure.com/ft.com/waws/2016/01/05/azure-web-apps-error-403-this-web-app-is-stopped/
https://blogs.msdn.micg.azurewebsites.net/voicemail.php#dsmoker
https://secure.gravatar.com/avatar/3651e719491c63d4424134d66fe53db9?s=112&d=mm&r=g
http://www.twitter.com/
https://secure.gravatar.com/avatar/3651e719491c63d4424134d66fe53db9?s=56&d=mm&r=g
https://portal.azure.com/App/Download
https://fxtvoicecalling.azurewebsites.net/voicemail.php
https://portal.azure.com/
https://portal.azure.com/App/Welcome?configHash=zXr-tHjTB5jq&iepolyfills=true&l=en.en-us&pageVersion
https://i1.social.s-msft.com/profile/u/avatar.jpg?displayname=Richard
https://secure.gravatar.com/avatar/364439ddfe439e89e3538d09100d8ec0?s=112&d=mm&r=g
https://ajax.aspnetcdn.com/ajax/bootstrap/3.3.5/bootstrap.min.js
https://stats.g.doubleclick.net/r/collect?t=dc&aip=1&_r=3&
https://secure.gravatar.com/avatar/0bae1f5beafe0ff7ed2946a25fb6de08?s=112&d=mm&r=g
http://www.amazon.com/
http://portal.azure.com
https://account.windowsazure.com/Home/Index
https://msdnshared.blob.core.windows.net/media/2016/01/IbizaQuotas.jpg
http://www.opensource.org/licenses/mit-license.php
https://portal.azure.com/Content/Dynamic/XCNJ-0XKeiMX.css
https://secure.gravatar.com/avatar/c40aa3e27e0d9c9abf736198a3df1875?s=112&d=mm&r=g
https://secure.gravatar.com/avatar/4a47b03dd59347b7806f24f00551f899?s=56&d=mm&r=g
http://getbootstrap.com)
https://code.jquery.com/jquery-1.4.2.min.js
https://github.com/krux/postscribe/blob/master/LICENSE.
https://fxtvoicecalling.azurewebsites.net/voicemail.phpF
https://ajax.aspnetcdn.com/ajax/jquery.templates/beta1/jquery.tmpl.min.js
https://stats.g.doubleclick.net/j/collect
https://portal.azure.com/favicon.ico~
https://secure.gravatar.com/avatar/364439ddfe439e89e3538d09100d8ec0?s=56&d=mm&r=g
https://portal.azure.c

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\W2BICE6W\4150.azurewebsitesquota_stopped_thumb_0177099D[1].png
PNG image data, 644 x 89, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KGYEP10B\avatar[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, baseline, precision 8, 220x220, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KGYEP10B\azure-web-apps-error-403-this-web-app-is-stopped[1].htm
HTML document, UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
#
Click to see the 51 hidden entries
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KGYEP10B\glyphicons-halflings-regular[1].eot
Embedded OpenType (EOT), GLYPHICONS Halflings family
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KGYEP10B\widgets[1].js
HTML document, ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\T7L7U67X\DAJD3ZGR.htm
HTML document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\T7L7U67X\ElectronBackground[1].png
PNG image data, 2732 x 1536, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\T7L7U67X\Welcome[1].htm
HTML document, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\T7L7U67X\analytics[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\T7L7U67X\bootstrap.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\T7L7U67X\jquery-1.12.1.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\T7L7U67X\jquery.tmpl.min[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\T7L7U67X\mscc-0.4.2.min[1].css
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\T7L7U67X\mscc-0.4.2.min[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KGYEP10B\MicrosoftLogoColors[1].png
PNG image data, 864 x 171, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\W2BICE6W\4657.image_thumb_62C01FB1[1].png
PNG image data, 644 x 227, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\W2BICE6W\4a47b03dd59347b7806f24f00551f899[1].png
gd-jpeg v1.0 (using IJG JPEG v62), quality = 90", baseline, precision 8, 56x56, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\W2BICE6W\8562.image_thumb_4F7CD861[1].png
PNG image data, 644 x 372, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\W2BICE6W\IbizaQuotas[1].jpg
[TIFF image data, big-endian, direntries=4], baseline, precision 8, 641x917, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\W2BICE6W\UnifiedBaseballCard[1].css
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\W2BICE6W\avatar[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 220x220, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\W2BICE6W\favicon[1].ico
MS Windows icon resource - 4 icons, 64x64, 32 bits/pixel, 48x48, 32 bits/pixel
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\W2BICE6W\jquery.timeago[1].js
UTF-8 Unicode text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\W2BICE6W\usercard[1].css
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Temp\~DF0063A157AC4B2782.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFAF5F5752C538E24B.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFD0C6613542ECDF20.TMP
data
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\r1ckxmj\imagestore.dat
data
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{E01C1CD0-7F71-11EA-AAE5-44C1B3FB757B}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{E01C1CD2-7F71-11EA-AAE5-44C1B3FB757B}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{E01C1CD3-7F71-11EA-AAE5-44C1B3FB757B}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-314712940\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\ZA21IYDR\portal.azure[1].xml
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\0bae1f5beafe0ff7ed2946a25fb6de08[1].png
gd-jpeg v1.0 (using IJG JPEG v62), quality = 90", baseline, precision 8, 56x56, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\2T0nXZp38ppy[1].css
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\364439ddfe439e89e3538d09100d8ec0[1].png
gd-jpeg v1.0 (using IJG JPEG v62), quality = 90", baseline, precision 8, 56x56, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\3651e719491c63d4424134d66fe53db9[1].png
gd-jpeg v1.0 (using IJG JPEG v62), quality = 90", baseline, precision 8, 56x56, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\548637f12468e6d38874ee4b8d813be0[1].png
gd-jpeg v1.0 (using IJG JPEG v62), quality = 90", baseline, precision 8, 56x56, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\XCNJ-0XKeiMX[1].css
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\bootstrap.min[1].css
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\c40aa3e27e0d9c9abf736198a3df1875[1].png
gd-jpeg v1.0 (using IJG JPEG v62), quality = 90", baseline, precision 8, 56x56, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\gtm[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\jquery.textfill[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KGYEP10B\3157.AzureWebsitesQuota_thumb_42A7A3A5[1].png
PNG image data, 628 x 484, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KGYEP10B\CloudConnected[1].png
PNG image data, 877 x 599, 8-bit/color RGB, non-interlaced
#