top title background image
flash

https://forms.office.com/Pages/ResponsePage.aspx?id=VLbYcMYDuUyg5Fu1GgngF2qgGJ2DPsBNgIIm2_Goqd9UNjAwRDMwS0VVVERWM1VRN0Q4STk4SERVTi4u

Status: finished
Submission Time: 2020-08-12 13:50:02 +02:00
Malicious
Phishing
HTMLPhisher

Comments

Tags

Details

  • Analysis ID:
    262870
  • API (Web) ID:
    422349
  • Analysis Started:
    2020-08-12 13:52:09 +02:00
  • Analysis Finished:
    2020-08-12 13:59:15 +02:00
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 48
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Domains

Name IP Detection
forms.office.com
0.0.0.0
c.office.com
0.0.0.0
assets.onestore.ms
0.0.0.0
Click to see the 3 hidden entries
ajax.aspnetcdn.com
0.0.0.0
cdn.forms.office.net
0.0.0.0
lists.office.com
0.0.0.0

URLs

Name Detection
http://www.nytimes.com/
https://www.clicktale.net/disable.html
https://cdn.forms.office.net/forms/scripts/dists/response-page.cachegroup-nerve.min.938fc5c.js
Click to see the 72 hidden entries
https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/adequacy-protectio
https://www.xbox.com
http://api.jqueryui.com/category/ui-core/
http://fontello.com
https://reactjs.org/docs/error-decoder.html?invariant=
https://developer.yahoo.com/flurry/end-user-opt-out/
http://amsul.github.io/pickadate.js
https://github.com/agoldis/webpack-require-from#troubleshooting
https://www.adjust.com/opt-out/
https://www.aboutads.info/
http://www.apache.org/licenses/LICENSE-2.0
https://www.skype.com/go/store.reactivate.credit
https://forms.office.com/Pages/ResponsePage.aspx?id=VLbYcMYDuUyg5Fu1GgngF2qgGJ2DPsBNgRoot
https://www.here.com/)
https://mixer.com/contact
https://www.youronlinechoices.com/
https://www.microsoft.
https://cdn.forms.office.net/forms%22
https://cdn.forms.office.net/forms/scripts/dists/response-page.min.0492f8e.js
https://www.linkedin.com/legal/privacy-policy
https://github.com/h5bp/html5-boilerplate/blob/master/src/css/main.css
http://www.live.com/
https://www.skype.com/legal/broadcast
http://www.wikipedia.com/
https://fb.me/react-polyfills
http://amsul.github.io/pickadate.js/date.htm
https://forms.office.com/formapi/api/embed?url=https%3a%2f%2fforms.office.com%2fPages%2fResponsePage
https://mixer.com/about/tos
https://www.skype.com/go/legal
https://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager.html
http://www.youtube.com/
https://github.com/gjunge/rateit.js
http://fontello.comiconsRegulariconsiconsVersion
https://www.skype.com/go/allrates
https://cdn.forms.office.net/forms/css/dist/response-page-customize-fabric-bootstrap.min.7c5c4af.css
https://www.optimizely.com/legal/opt-out/
http://www.twitter.com/
https://www.xbox.com/en-US/Legal/CodeOfConduct
http://www.asp.net/ajaxlibrary/CDN.ashx.
http://www.amazon.com/
https://www.adr.org
http://jqueryui.com
https://www.youradchoices.ca/fr
http://amsul.ca
http://underscorejs.org
https://cdn.forms.office.net/forms/scripts/vendors/combinedmin/basics_osi_v3.min.dcbe987.js
https://privacy.microsom/Pages/ResponsePage.aspx?id=VLbYcMYDuUyg5Fu1GgngF2qgGJ2DPsBNgIIm2_Goqd9UNjAw
https://forms.office.com/Pages/ResponsePage.aspx?id=VLbYcMYDuUyg5Fu1GgngF2qgGJ2DPsBNgIIm2_Goqd9UNjAw
https://cdn.forms.office.net/forms/images/favicon.ico~
http://jquery.org/license
https://www.skype.com/go/ustax
https://www.acuityads.com/opt-out/
https://login.skype.com/login
https://signin.kissmetrics.com/privacy/#controls
https://privacy.micros
https://cdn.forms.office.net/forms/images/favicon.ico
http://www.reddit.com/
http://github.com/requirejs/almond/LICENSE
https://priv-policy.imrworldwide.com/priv/browser/us/en/optout.html
https://www.youradchoices.ca
http://www.mpegla.com
https://forms.office.com/formapi/api/70d8b654-03c6-4cb9-a0e4-5bb51a09e017/users/9d18a06a-3e83-4dc0-8
https://login.microsoftonline.com/common/oauth2/authorize?response_mode=form_post
https://aka.ms/redeemrewards
https://www.appsflyer.com/optout
https://github.com/SoapBox/linkifyjs
https://www.skype.com
https://skype.com/go/myaccount
https://ondemand.webtrends.com/support/optout.asp
https://www.privacyshield.gov/welcome
https://raw.githubusercontent.com/stefanpenner/es6-promise/master/LICENSE
https://aka.ms/taxservice

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\c3-92aca2[1].css
UTF-8 Unicode text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\override[1].css
ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\privacystatement[1].htm
HTML document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
#
Click to see the 58 hidden entries
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\response-page.chunk.ir.a4f8f20[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\response_v2.min.d40c871[1].js
UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\4d-6e4c52[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\aria_odata.min.831dd67[1].js
ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\c3-92aca2[1].css
UTF-8 Unicode text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\fabricmdl2icons-3.70-20200721.subset[1].woff
Web Open Font Format, TrueType, length 15368, version 3.45875
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\favicon[1].ico
MS Windows icon resource - 3 icons, 32x32, 32 bits/pixel, 24x24, 32 bits/pixel
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\favicon[2].ico
MS Windows icon resource - 6 icons, 128x128, 16 colors, 72x72, 16 colors
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\icons[1].eot
Embedded OpenType (EOT), icons family
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\latest[1].eot
Embedded OpenType (EOT), Segoe UI Light family
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\override[1].css
ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\4d-6e4c52[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\ResponsePage[1].htm
HTML document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\mwfmdl2-v3.54[1].woff
Web Open Font Format, TrueType, length 26288, version 0.0
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\jquery-1.7.2.min[1].js
HTML document, UTF-8 Unicode text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\jsll-4[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\latest[1].eot
Embedded OpenType (EOT), Segoe UI Semibold family
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\mscc-0.4.2.min[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\print-icon[1].png
PNG image data, 16 x 16, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\response-page-customize-fabric-bootstrap.min.7c5c4af[1].css
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\response-page.cachegroup-nerve.min.938fc5c[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\script[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\script[2].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\style[1].css
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\style[2].css
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Temp\~DF88DF4BB32ADA2AF1.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF98964F92062029AB.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFFE59714DB27A140A.TMP
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\Print[1].png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{D05831F9-DCDD-11EA-90E0-ECF4BB570DC9}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{D05831FB-DCDD-11EA-90E0-ECF4BB570DC9}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{D6C55EFD-DCDD-11EA-90E0-ECF4BB570DC9}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-314712940\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\dikxvqf\imagestore.dat
data
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\HIS0IHR2\forms.office[1].xml
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\app[1].css
ASCII text, with very long lines, with CRLF, LF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\arrow_px_up[1].gif
GIF image data, version 89a, 7 x 9
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\basics_osi_v3.min.dcbe987[1].js
ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\favicon[1].ico
MS Windows icon resource - 6 icons, 128x128, 16 colors, 72x72, 16 colors
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\response-page.chunk.postsubmit.aa0b037[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\response-page.chunk.quiz.d8f2b6f[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\response-page.min.0492f8e[1].js
UTF-8 Unicode text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\script[1].js
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\shell.min[1].css
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\RE1Mu3b[1].png
PNG image data, 216 x 46, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\default[1].htm
HTML document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\jquery-1.11.2.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\latest[1].eot
Embedded OpenType (EOT), Segoe UI family
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\mscc-0.4.2.min[1].css
ASCII text, with very long lines, with no line terminators
#