top title background image
flash

Citrix_NewAudioMessage.htm

Status: finished
Submission Time: 2020-05-26 18:18:40 +02:00
Malicious
Phishing

Comments

Tags

Details

  • Analysis ID:
    233156
  • API (Web) ID:
    362501
  • Analysis Started:
    2020-05-26 18:19:47 +02:00
  • Analysis Finished:
    2020-05-26 18:26:29 +02:00
  • MD5:
    858bcd8cd944e69d78e7873edd319917
  • SHA1:
    566ba34b18962286703e793394c5ece98c83fef2
  • SHA256:
    ffaba8a1a385683875c953dfbaa1331de02ed76ea290bcb169e0cbf692d97cbc
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 72
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 6/59

IPs

IP Country Detection
194.146.59.69
Serbia
104.24.96.80
United States
169.62.254.82
United States
Click to see the 6 hidden entries
151.101.1.195
United States
104.16.125.175
United States
192.229.221.185
United States
152.199.23.37
United States
67.199.248.10
United States
104.16.132.229
United States

Domains

Name IP Detection
xcfd54dcx-delightful-wallaby-gv.us-south.cf.appdomain.cloud
169.62.254.82
cs1100.wpc.omegacdn.net
152.199.23.37
newof9a.bestnewsworld.info
104.24.96.80
Click to see the 11 hidden entries
mastramix.com
194.146.59.69
cdnjs.cloudflare.com
104.16.132.229
bit.ly
67.199.248.10
cs1227.wpc.alphacdn.net
192.229.221.185
cvbv54fsaz.web.app
151.101.1.195
unpkg.com
104.16.125.175
signup.live.com
0.0.0.0
secure.aadcdn.microsoftonline-p.com
0.0.0.0
aadcdn.msftauth.net
0.0.0.0
acctcdn.msauth.net
0.0.0.0
client.hip.live.com
0.0.0.0

URLs

Name Detection
https://acctcdn.msauth.net/lightweightsignuppackage_0X_OeuNzgHTFzjeHra9GEg2.js?v=1
https://xcfd54dcx-delightful-wallaby-gv.us-south.cf.appdomain.cloud/hg67rdf/
http://www.json.org/json2.js
Click to see the 39 hidden entries
https://xcfd54dcx-delightful-wallaby-gv.us-south.cf.appdomain.cloud/hg67rdf/bre=3w9dfg8od?email=#/hQ
https://secure.aadcdn.microsoftonline-p.com/ests/2.1.6669.4/content/images/favicon_a.ico~
http://www.opensource.org/licenses/mit-license.php)
https://secure.aadcdn.microsoftonline-p.com/ests/2.1.6669.4/content/images/favicon_a.ico
https://privacy.micros
https://acctcdn.msauth.net/images/2_vD0yppaJX3jBnfbHF1hqXQ2.svg)
http://www.youtube.com/
https://acctcdn.msauth.net/knockout_3.3.0_dEa3k0VBCPkhFZG_zjQkHw2.js?v=1
http://www.twitter.com/
http://www.wikipedia.com/
https://acctcdn.msauth.net/images/favicon.ico?v=2
https://github.com/hgoebl/mobile-detect.js
http://www.live.com/
https://xcfd54dcx-delightful-wallaby-gv.us-south.cf.appdomain.cloud/hg67rdf/?bbre=3w9dfg8od?email=#y
http://feross.org
http://www.reddit.com/
http://jquery.com/
https://secure.aadcdn.microsoftonline-p.com/ests/2.1.6669.4/content/images/favicon_a.ico~(
https://signup.live.co
http://www.nytimes.com/
https://signup.live.com/signup?wa=wsignin1.0&rpsnv=13&ct=1526624083&rver=6.7.6640.0&wp=MBI_SSL&wrepl
http://jquery.org/license
https://signup.live.com/
https://acctcdn.msauth.net/images/microsoft_logo_7lyNn7YkjJOP0NwZNw6QvQ2.svg
https://xcfd54dcx-delightful-wallaby-gv.us-south.cf.appdomain.cloud/hg67rdf/?bbre=3w9dfg8od?email=
https://acctcdn.msauth.net
https://acctcdn.msauth.net/images/favicon.ico?v=2~
http://sizzlejs.com/
https://xcfd54dcx-delightful-wallaby-gv.us-south.cf.appdomain.cloud/hg67rdf/?bbre=3w9dfg8od?email=#/
https://npms.io/search?q=ponyfill.
https://acctcdn.msauth.net/lwsignupstringscountrybirthdate_en-us_pVtahKS9WUIZdNqg1DDhHg2.js?v=1
https://acctcdn.msauth.net/jquerypackage_1.10_5V7LAuc3bNAQx2QQfr1RPw2.js?v=1
http://www.amazon.com/
http://knockoutjs.com/
https://acctcdn.msauth.net/converged_ux_v2_yQBDHQcAqS8iDHRzxz-bBw2.css?v=1
https://github.com/douglascrockford/JSON-js
https://signup.live.com/error.aspx?errcode=1045&mkt=en-US
https://acctcdn.msauth.net/images/favicon.ico?v=2~(
http://opensource.org/licenses/mit-license.php)

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VINVDFP6\jquery.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VINVDFP6\signup[1].htm
HTML document, ASCII text, with very long lines, with CRLF, LF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VINVDFP6\mobile-detect.min[1].js
ASCII text, with very long lines
#
Click to see the 63 hidden entries
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VINVDFP6\microsoft_logo_7lyNn7YkjJOP0NwZNw6QvQ2[1].svg
SVG Scalable Vector Graphics image
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VINVDFP6\microsoft_logo[1].svg
SVG Scalable Vector Graphics image
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VINVDFP6\lwsignupstringscountrybirthdate_en-us_pVtahKS9WUIZdNqg1DDhHg2[1].js
HTML document, UTF-8 Unicode text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VINVDFP6\lightweightsignuppackage_0X_OeuNzgHTFzjeHra9GEg2[1].js
UTF-8 Unicode text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VINVDFP6\knockout_3.3.0_dEa3k0VBCPkhFZG_zjQkHw2[1].js
ASCII text, with very long lines, with CRLF, LF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VINVDFP6\jquerypackage_1.10_5V7LAuc3bNAQx2QQfr1RPw2[1].js
UTF-8 Unicode text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VTIIBVU5\0-small_138bcee624fa04ef9b75e86211a9fe0d[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 50x28, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VINVDFP6\html5shiv.min[1].js
HTML document, ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VINVDFP6\es6-promise.auto.min[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VINVDFP6\converged_ux_v2_yQBDHQcAqS8iDHRzxz-bBw2[1].css
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VINVDFP6\80ea4c177a1b4c60970b7059fe4f8842nbr1590169163[1].js
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\V5D02472\vue.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\V5D02472\vee-validate.min[1].js
UTF-8 Unicode text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\V5D02472\mscc-0.4.2.min[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\V5D02472\microsoft_logo_7lyNn7YkjJOP0NwZNw6QvQ2[1].svg
SVG Scalable Vector Graphics image
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VTIIBVU5\0_a5dbd4393ff6a725c7e62b61df7e72f0[1].jpg
JPEG image data, baseline, precision 8, 1920x1080, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VTIIBVU5\39oebGZ[1].htm
HTML document, ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VTIIBVU5\8952338047c05de6a771d939a026ab9enbr1590169163[1].css
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VTIIBVU5\datarequestpackage_dT3VZJ_4lD5UykUFoE8W2w2[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VTIIBVU5\dnserror[1]
HTML document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VTIIBVU5\ellipsis_grey[1].svg
SVG Scalable Vector Graphics image
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VTIIBVU5\httpErrorPagesScripts[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VTIIBVU5\vue-i18n.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VTIIBVU5\vue-router.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VTIIBVU5\xxposnto[1].htm
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VTIIBVU5\xxposnto[2].htm
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\~DF324092D59E5A7C3B.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF5A06AF1EABCFED1D.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF761EAEC487F9AA6B.TMP
data
#
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\7WLTZJROOSDKFQXF5O3H.temp
data
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KSU5XQMC\NewErrorPageTemplate[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KSU5XQMC\2_vD0yppaJX3jBnfbHF1hqXQ2[1].svg
SVG Scalable Vector Graphics image
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KSU5XQMC\2Jmn3lA[1].htm
HTML document, ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\6aw4uvh\imagestore.dat
data
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KSU5XQMC\a3107e4d4ae0ea783cd1177c52f1e6301590169160[1].js
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{5C4A08A6-9FB8-11EA-AADD-C25F135D3C65}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{52E0D00F-9FB8-11EA-AADD-C25F135D3C65}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{52E0D00D-9FB8-11EA-AADD-C25F135D3C65}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\D1YBPPLZ\xcfd54dcx-delightful-wallaby-gv.us-south.cf.appdomain[1].xml
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KSU5XQMC\aljsappso4e789ce73f1fac863a468dd36814ed28[1].js
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KSU5XQMC\axios.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KSU5XQMC\down[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KSU5XQMC\favicon[2].ico
MS Windows icon resource - 6 icons, 128x128, 16 colors, 72x72, 16 colors
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KSU5XQMC\favicon_a[1].ico
MS Windows icon resource - 6 icons, 128x128, 16 colors, 72x72, 16 colors
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KSU5XQMC\lodash.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KSU5XQMC\mscc-0.4.2.min[1].css
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KSU5XQMC\vuex.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\V5D02472\2_vD0yppaJX3jBnfbHF1hqXQ2[1].svg
SVG Scalable Vector Graphics image
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\V5D02472\37_533e293f0c8947ada653b47c00e394e2[1].png
PNG image data, 342 x 72, 4-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\V5D02472\4e789ce73f1fac863a468dd36814ed28[1].js
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\V5D02472\80ea4c177a1b4c60970b7059fe4f8842nbr1590169163[1].css
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\V5D02472\dropdown_caret_KXSZjGsyILZaoTf0sI9X-A2[1].svg
SVG Scalable Vector Graphics image
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\V5D02472\errorPageStrings[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\V5D02472\favicon[2].ico
MS Windows icon resource - 6 icons, 128x128, 16 colors, 72x72, 16 colors
#