flash

https://app.nutshell.com/email/click/26395/320357/1d44aacf1e1cba18aa1efaebcfff2d58a699c357a0545aa63f76afff5625f91e

Status: finished
Submission Time: 12.05.2020 20:58:24
Malicious
Phishing
Trojan
Phisher

Comments

Tags

Details

  • Analysis ID:
    229614
  • API (Web) ID:
    355603
  • Analysis Started:
    12.05.2020 20:58:24
  • Analysis Finished:
    12.05.2020 21:03:14
  • Technologies:
Full Report Management Report Engine Info Verdict Score Reports

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
84/100

malicious

IPs

IP Country Detection
124.217.230.99
Malaysia
69.89.31.230
United States
18.208.37.124
United States

Domains

Name IP Detection
multifoil.com.my
124.217.230.99
app.nutshell.com
18.208.37.124
smallenvelop.com
69.89.31.230

URLs

Name Detection
https://multifoil.com.my/wp-admin/maint/sharepoint/images/favicon.ico~
https://multifoil.com.my/wp-admin/maint/sharepoint/images/favicon.ico~(
https://multifoil.com.my/wp-admin/maint/sharepoint/index.php
Click to see the 11 hidden entries
https://multifoil.com.my/wp-admin/maint/sharepoint/images/favicon.ico
https://multifoil.com.my/wp-admin/maint/sharepoint/login.php?cmd=login_submit&id=d74d65381a7d0899a0e
https://multifoil.com.apis.com/00f/sharepoint.htmmy/wp-admin/maint/sharepoint/login.php?cmd=login_su
http://www.nytimes.com/
http://www.youtube.com/
https://smallenvelop.com/wp-content/uploads/2014/08/Preloader_11.gif
http://www.wikipedia.com/
http://www.amazon.com/
http://www.live.com/
http://www.reddit.com/
http://www.twitter.com/

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\P24S97MI\login[1].htm
HTML document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PKAQFTEH\sharepoint[1].htm
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{9DEA222E-9482-11EA-AAE6-9CC1A2A860C6}.dat
Microsoft Word Document
#
Click to see the 21 hidden entries
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{9DEA2230-9482-11EA-AAE6-9CC1A2A860C6}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{A42B31BD-9482-11EA-AAE6-9CC1A2A860C6}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\v8bxa9r\imagestore.dat
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\5N37O3UG\cloud_storage-32[1].png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\5N37O3UG\gn[1].png
PNG image data, 340 x 38, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\O0N4T4W6\h1[1].png
PNG image data, 1365 x 727, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\O0N4T4W6\h2[1].png
PNG image data, 226 x 54, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\P24S97MI\favicon[1].ico
MS Windows icon resource - 6 icons, 128x128, 16 colors, 72x72, 16 colors
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PKAQFTEH\jquery.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Temp\~DF01AFF9B3AAC323BB.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF3E911D9510C8C191.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFCA8FD2C907D93992.TMP
data
#