top title background image
flash

https://alraheef.net/piainsure

Status: finished
Submission Time: 2020-07-30 19:22:28 +02:00
Malicious
Phishing
HTMLPhisher

Comments

Tags

Details

  • Analysis ID:
    254345
  • API (Web) ID:
    404233
  • Analysis Started:
    2020-07-30 19:23:16 +02:00
  • Analysis Finished:
    2020-07-30 19:30:09 +02:00
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 48
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

IPs

IP Country Detection
192.185.57.89
United States
104.26.7.160
United States

Domains

Name IP Detection
microsoftwindows.112.2o7.net
15.236.175.233
www.termsfeed.com
104.26.7.160
alraheef.net
192.185.57.89
Click to see the 3 hidden entries
assets.onestore.ms
0.0.0.0
ajax.aspnetcdn.com
0.0.0.0
mem.gfx.ms
0.0.0.0

URLs

Name Detection
https://www.youtube.com/user/MicrosoftCH
https://schema.org/ItemList
http://github.com/requirejs/domReady
Click to see the 72 hidden entries
http://github.com/kriskowal/q/raw/master/LICENSE
https://mem.gfx.ms
https://alraheef.net/piainsure/Root
http://www.apache.org/licenses/LICENSE-2.0.
https://www.clicktale.net/disable.html
https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/adequacy-protectio
https://www.xbox.com
https://twitter.com/microsoft_ch
https://www.microsoft.iainsure/home/?sslchannel=true&sessionid=TFoFEtcsni83M5l2U1n4BRufsyjn6qRZ6fFKI
http://fontello.com
https://developer.yahoo.com/flurry/end-user-opt-out/
http://github.com/requirejs/requirejs/LICENSE
https://onedrive.live.com/about/de-ch/
https://microsoftwindows.112.2o7.net
http://www.nytimes.com/
https://www.adjust.com/opt-out/
http://www.wikipedia.com/
http://jquery.com/
https://channel9.msdn.com/
http://schema.org/Organization
https://www.linkedin.com/legal/privacy-policy
https://github.com/h5bp/html5-boilerplate/blob/master/src/css/main.css
http://www.live.com/
http://github.com/aFarkas/lazysizes
https://www.xbox.com/
https://github.com/js-cookie/js-cookie
https://www.aboutads.info/
https://typingdna.com/scripts/typingdna.js
https://www.linkedin.com/company/1035
https://alraheef.net/piainsure/iainsure/home/?sslchannel=true&sessionid=TFoFEtcsni83M5l2U1n4BRufsyjn
https://www.microsoft.
https://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager.html
http://www.youtube.com/
https://alraheef.neRoot
http://fontello.comiconsRegulariconsiconsVersion
https://www.optimizely.com/legal/opt-out/
https://www.TermsFeed.com
https://raw.github.com/facebook/regenerator/master/LICENSE
http://www.asp.net/ajaxlibrary/CDN.ashx.
http://www.amazon.com/
https://www.skype.com/de/
https://www.youradchoices.ca/fr
https://assets.onestore.ms
https://products.office.com/de-ch/academic/compare-office-365-education-plans
http://sizzlejs.com/
http://www.twitter.com/
https://alraheef.net/piainsure/
http://jquery.org/license
https://www.acuityads.com/opt-out/
https://login.skype.com/login
https://www.onenote.com/?omkt=de-CH
https://signin.kissmetrics.com/privacy/#controls
https://outlook.live.com/owa/
https://dev.windows.com/de-de/
https://www.instagram.com/microsoftch/
http://www.apache.org/licenses/LICENSE-2.0
https://www.here.com/)
https://www.youronlinechoices.com/
http://www.reddit.com/
http://github.com/requirejs/almond/LICENSE
https://priv-policy.imrworldwide.com/priv/browser/us/en/optout.html
https://www.youradchoices.ca
https://api.typingdna.com/scripts/typingdna.js
http://typingdna.com
https://support.okta.com/help/articles/Knowledge_Article/24532952-Platforms---Browser-and-OS-Support
https://privacy.micros
https://www.appsflyer.com/optout
https://ondemand.webtrends.com/support/optout.asp
https://www.privacyshield.gov/welcome
http://www.opensource.org/licenses/mit-license.html
https://mem.gfx.ms/meversion?partner=MSHomePage&market=de-ch&uhf=1
https://alraheef.net/piainsure/home/?sslchannel=true&sessionid=TFoFEtcsni83M5l2U1n4BRufsyjn6qRZ6fFKI

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\home[1].htm
HTML document, UTF-8 Unicode text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\RE4xq3A[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPCM), density 37x37, segment length 16, progressive, precision 8, 1259x472, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\print-icon[1].png
PNG image data, 16 x 16, 8-bit/color RGB, non-interlaced
#
Click to see the 76 hidden entries
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\mscc-0.4.2.min[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\mscc-0.4.2.min[1].css
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\meversion[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\latest[1].woff
Web Open Font Format, TrueType, length 35900, version 0.0
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\jquery-1.11.2.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\icons[1].eot
Embedded OpenType (EOT), icons family
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\cookie-consent[1].js
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\1e-fd610f[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\RE4vkSt[1].wdp
JPEG-XR
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\RE4rzs9[1].wdp
JPEG-XR
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\RE4h13d[1].wdp
JPEG-XR
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\RE2PjIw[1].wdp
JPEG-XR
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\twitter[1].png
PNG image data, 32 x 32, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\style[1].css
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\privacystatement[1].htm
HTML document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\override[1].css
ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\okta-sign-in.min[1].js
UTF-8 Unicode text, with very long lines, with LF, NEL line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\de-ch[1].htm
HTML document, UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
#
C:\Users\user\AppData\Local\Temp\~DFA2214F434181C022.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF4DD3AB17E97DA5CC.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF0982CD0D8CB1FB82.TMP
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\youtube[1].png
PNG image data, 32 x 32, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\social[1].css
UTF-8 Unicode text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\piainsure[1].htm
HTML document, ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\linkedin[1].png
PNG image data, 32 x 32, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\jquery-3.3.1.min[1].js
ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\instagram[1].png
PNG image data, 32 x 32, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\okta-sign-in.min[1].css
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\clipart1110398[1].png
PNG image data, 460 x 390, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\RE4xFAr[1].wdp
JPEG-XR
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\RE4tj4A[1].wdp
JPEG-XR
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\RE4rriw[1].png
PNG image data, 40 x 40, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\RE4pxBu[1].png
PNG image data, 40 x 40, 8-bit gray+alpha, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\RE4pndL[1].png
PNG image data, 40 x 40, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\RE4pkvE[1].png
PNG image data, 40 x 40, 8-bit gray+alpha, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\RE4mYUO[1].wdp
JPEG-XR
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\RE3NOmL[1].wdp
JPEG-XR
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\RW54P2[1].wdp
JPEG-XR
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\RE4u5ku[1].wdp
JPEG-XR
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\RE1Mu3b[1].png
PNG image data, 216 x 46, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\4d-6e4c52[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\1x1clear[1].gif
GIF image data, version 89a, 1 x 1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\12-b98955[1].css
UTF-8 Unicode (with BOM) text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\dikxvqf\imagestore.dat
data
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\cartcount[1].htm
HTML document, ASCII text, with CRLF, LF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-314712940\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{EF03C499-D2D4-11EA-90E0-ECF4BB570DC9}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{E87ED753-D2D4-11EA-90E0-ECF4BB570DC9}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\social[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\mwfmdl2-v3.54[1].woff
Web Open Font Format, TrueType, length 26288, version 0.0
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\meBoot.min[1].js
ASCII text, with very long lines, with CRLF, LF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\loginpage-theme.7138a0eb969c6a25c2d39004ad54df8a[1].css
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\favicon[2].ico
MS Windows icon resource - 6 icons, 128x128, 16 colors, 72x72, 16 colors
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\favicon[1].ico
MS Windows icon resource - 6 icons, 128x128, 16 colors, 72x72, 16 colors
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\facebook[1].png
PNG image data, 32 x 32, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\app[1].css
ASCII text, with very long lines, with CRLF, LF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\RE4sQDc[1].png
PNG image data, 40 x 40, 2-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\12-b98955[1].css
UTF-8 Unicode text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{E87ED751-D2D4-11EA-90E0-ECF4BB570DC9}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\shell.min[1].css
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\script[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\piainsure[1].htm
HTML document, ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\meCore.min[1].js
ASCII text, with very long lines, with CRLF, LF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\latest[3].eot
Embedded OpenType (EOT), Segoe UI Light family
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\latest[2].eot
Embedded OpenType (EOT), Segoe UI Semibold family
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\latest[1].eot
Embedded OpenType (EOT), Segoe UI family
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\e3-082b89[1].js
ASCII text, with very long lines, with no line terminators
#