flash

http://sufacturaciondigital.com/

Status: finished
Submission Time: 26.06.2020 09:27:47
Malicious
Phishing
Evader
Phisher

Comments

Tags

Details

  • Analysis ID:
    241651
  • API (Web) ID:
    379021
  • Analysis Started:
    26.06.2020 09:27:47
  • Analysis Finished:
    26.06.2020 09:32:13
  • Technologies:
Full Report Engine Info Verdict Score Reports

System: Windows 10 64 bit (version 1803) with Office 2016, Adobe Reader DC 19, Chrome 70, Firefox 63, Java 8.171, Flash 30.0.0.113

malicious
60/100

IPs

IP Country Detection
107.180.28.220
United States
104.16.203.237
United States
199.91.155.24
United States

Domains

Name IP Detection
www.mediafire.com
104.16.203.237
download2283.mediafire.com
199.91.155.24
sufacturaciondigital.com
107.180.28.220

URLs

Name Detection
http://www.nytimes.com/
http://sufacturaciondigital.com/Root
http://sufacturaciondigital.com/
Click to see the 10 hidden entries
http://www.youtube.com/
http://www.wikipedia.com/
https://www.mediafire.com/file/3r4odpj7juk2fre/EDP-Fact26062020.zip
http://www.amazon.com/
http://www.componentace.com
http://www.live.com/
http://www.indyproject.org/
http://sufacturaciondigital.com/favicon.ico
http://www.reddit.com/
http://www.twitter.com/

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KSU5XQMC\W41LJ0R6.htm
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\cilmpwvb.mqf\EDP-Cobros-26062020.exe
PE32 executable (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{07BEE12F-B7CA-11EA-AADE-C25F135D3C65}.dat
Microsoft Word Document
#
Click to see the 20 hidden entries
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{07BEE131-B7CA-11EA-AADE-C25F135D3C65}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{11930054-B7CA-11EA-AADE-C25F135D3C65}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VINVDFP6\EDP-Fact26062020.zip.llbpv43.partial
Zip archive data, at least v2.0 to extract
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VINVDFP6\EDP-Fact26062020.zip.llbpv43.partial:Zone.Identifier
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VINVDFP6\EDP-Fact26062020.zip:Zone.Identifier
very short file (no magic)
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VINVDFP6\EDP-Fact26062020[1].zip
Zip archive data, at least v2.0 to extract
#
C:\Users\user\AppData\Local\Temp\cilmpwvb.mqf\~~
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\Temp\tzuxiklv.mhe\unarchiver.log
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\~DF16630E746FA8912B.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF83E01032596ECC33.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFFF25192D4C4F69D1.TMP
data
#