top title background image
flash

https://u14434959.ct.sendgrid.net/ls/click?upn=RoH6YjBva3fqR05e7CWs9jU8zveKwLp59mrXHeMg-2F7YzCwlizcOcalp71DcOrH2gZk9kBjkqaL-2BFZ5Pg5CicgrMbNmzM7hma0kUHh2Cz5KOII5AWaRbiL4GaamOVfs42YSRPYcf-2FwdfWc7mspSnZIbRDvNDdhmNmev5b3QSf-2FDcLwkZ2FIzM3AcV12AAlXSNgHRz_surlT6tjxMO4sUs3XBofmBE3-2FpQsLFabbIHq7dY9YGbTs3MMN8Zi2xn6pmB-2F7rbUIdbk-2FMtGiJlH04ZY2LPh-2B5kozctTsQVAviLtPmz8c9tcjMzWu-2FdaE7JGAYc7iOD8X9Dv-2BgQoYabq5SDujZ402-2B32srV0hSZzW3DnHroKN-2B7IAwVjBnLvNeKsugM0quLF3alfLvnjnxQ8t-2FcvyS8EA7cXUdpXc7Vckk6Ixhhds6I-3D

Status: finished
Submission Time: 2020-05-28 17:15:31 +02:00
Malicious

Comments

Tags

Details

  • Analysis ID:
    233910
  • API (Web) ID:
    363971
  • Analysis Started:
    2020-05-28 17:15:31 +02:00
  • Analysis Finished:
    2020-05-28 17:19:58 +02:00
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 48
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious

IPs

IP Country Detection
167.89.123.16
United States
88.198.36.203
Germany

Domains

Name IP Detection
u14434959.ct.sendgrid.net
167.89.123.16
psilikomania.gr
88.198.36.203

URLs

Name Detection
https://psilikomania.gr//SFGH/cgn-in/login.php?l=_JeHFUq_VJOXK0QWHtoGYDw_Product-UserID&userid=marke
http://www.wikipedia.com/
http://www.amazon.com/
Click to see the 9 hidden entries
https://psilikomania.gr//SFGH/cgn-in/ogin.php?l=_JeHFUq_VJOXK0QWHtoGYDw_Product-UserID&userid=market
http://www.nytimes.com/
http://www.live.com/
http://www.reddit.com/
http://www.twitter.com/
http://www.youtube.com/
https://r//SFGH/cgn-in/ogin.php?l=_JeHFUq_VJOXK0QWHtoGYDw_Product-UserID&userid=marketing
https://psilikomania.g
https://psilikomania.gr//SFGH/cgn-in/login_files/logo.png

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\6aw4uvh\imagestore.dat
data
#
C:\Users\user\AppData\Local\Temp\~DFE5E7E505A1D01931.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF8DE19D211B9DC100.TMP
data
#
Click to see the 22 hidden entries
C:\Users\user\AppData\Local\Temp\~DF2575C161EF83BC09.TMP
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VTIIBVU5\top[1].png
PNG image data, 304 x 15, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VTIIBVU5\logo[1].png
PNG image data, 45 x 45, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VTIIBVU5\bottom[1].png
PNG image data, 304 x 15, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VINVDFP6\loginBasic[1].css
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VINVDFP6\cgn-in[1].htm
HTML document, ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\V5D02472\loginAdvanced[1].css
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KSU5XQMC\middle[1].png
HTML document, ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KSU5XQMC\login[1].htm
HTML document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KSU5XQMC\background[1].png
HTML document, ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{8FD3E705-A141-11EA-AADD-C25F135D3C65}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{8FD3E708-A141-11EA-AADD-C25F135D3C65}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{8FD3E707-A141-11EA-AADD-C25F135D3C65}.dat
Microsoft Word Document
#