flash

https://dkf29e43q1.z13.web.core.windows.net/

Status: finished
Submission Time: 30.07.2020 05:12:30
Malicious
Phishing
HTMLPhisher

Comments

Tags

Details

  • Analysis ID:
    253792
  • API (Web) ID:
    403128
  • Analysis Started:
    30.07.2020 05:12:30
  • Analysis Finished:
    30.07.2020 05:17:49
  • Technologies:
Full Report Engine Info Verdict Score Reports

System: w10x64 Windows 10 64 bit v1803 with Office Professional Plus 2016, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
48/100

IPs

IP Country Detection
52.239.247.97
United States
45.79.77.20
United States
185.55.225.144
Iran (ISLAMIC Republic Of)
Click to see the 1 hidden entries
104.16.132.229
United States

Domains

Name IP Detection
asf-ris-prod-neurope.northeurope.cloudapp.azure.com
168.63.67.155
cdnjs.cloudflare.com
104.16.132.229
jsonip.com
45.79.77.20
Click to see the 4 hidden entries
simsiz.ir
185.55.225.144
web.mnz20prdstr05a.store.core.windows.net
52.239.247.97
dkf29e43q1.z13.web.core.windows.net
0.0.0.0
g.msn.com
0.0.0.0

URLs

Name Detection
https://bugs.webkit.org/show_bug.cgi?id=136851
http://jquery.org/license
https://jsperf.com/thor-indexof-vs-for/5
Click to see the 46 hidden entries
https://bugs.jquery.com/ticket/12359
https://web.archive.org/web/20100324014747/http://blindsignals.com/index.php/2009/07/jquery-delay/
https://dkf29e43q1.z13.web.core.windows.net/Root
http://www.amazon.com/
https://html.spec.whatwg.org/#strip-and-collapse-whitespace
https://promisesaplus.com/#point-75
https://web.archive.org/web/20141116233347/http://fluidproject.org/blog/2008/01/09/getting-setting-a
http://www.twitter.com/
https://drafts.csswg.org/cssom/#common-serializing-idioms
https://bugs.webkit.org/show_bug.cgi?id=29084
https://github.com/jquery/jquery/pull/557)
https://simsiz.ir/%25&
https://bugs.chromium.org/p/chromium/issues/detail?id=378607
https://github.com/jrburke/requirejs/wiki/Updating-existing-libraries#wiki-anon
https://simsiz.ir/%25%26%40%25%5E%26
https://bugzilla.mozilla.org/show_bug.cgi?id=687787
https://getjsonip.com/#docs
https://bugs.chromium.org/p/chromium/issues/detail?id=470258
https://bugs.jquery.com/ticket/13378
https://promisesaplus.com/#point-64
http://www.reddit.com/
https://promisesaplus.com/#point-61
https://dkf29e43q1.z13.web.core.windows.net/
http://www.nytimes.com/
https://drafts.csswg.org/cssom/#resolved-values
https://bugs.chromium.org/p/chromium/issues/detail?id=589347
https://bugzilla.mozilla.org/show_bug.cgi?id=649285
https://promisesaplus.com/#point-59
https://jsperf.com/getall-vs-sizzle/2
https://promisesaplus.com/#point-57
https://getjsonip.com/#plus
https://promisesaplus.com/#point-54
https://simsiz.ir/%25&
https://developer.mozilla.org/en-US/docs/CSS/display
https://jquery.org/license
https://jquery.com/
http://www.youtube.com/
https://bugs.webkit.org/show_bug.cgi?id=137337
http://www.wikipedia.com/
https://promisesaplus.com/#point-48
http://www.live.com/
https://github.com/jquery/sizzle/pull/225
https://bugzilla.mozilla.org/show_bug.cgi?id=491668
https://simsiz.ir/%25&.web.core.windows.net/
https://sizzlejs.com/
https://bugs.chromium.org/p/chromium/issues/detail?id=449857

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\s[1].htm
HTML document, ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{0C6C6134-D25E-11EA-90E0-ECF4BB862DED}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{0C6C6136-D25E-11EA-90E0-ECF4BB862DED}.dat
Microsoft Word Document
#
Click to see the 18 hidden entries
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{12F3B517-D25E-11EA-90E0-ECF4BB862DED}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-314712940\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\CUP0UHNX.json
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\jquery[1].js
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\NCXPK2J1.htm
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\%25&@%25^&_%25^&^%25undefined[1].htm
HTML document, ASCII text
#
C:\Users\user\AppData\Local\Temp\~DF54133953B2AA9D3B.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF96E58849668DDFA7.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFA30D3F0DFF21D6E0.TMP
data
#