flash

INV-14th September 2020-2222122212684822.htm

Status: finished
Submission Time: 16.09.2020 00:24:27
Malicious
Phishing
Trojan
HTMLPhisher

Comments

Tags

Details

  • Analysis ID:
    286030
  • API (Web) ID:
    467247
  • Analysis Started:
    16.09.2020 00:24:28
  • Analysis Finished:
    16.09.2020 00:30:58
  • MD5:
    b617865837fee4d48a2fb978ea4d2e10
  • SHA1:
    e760ff992726459d27e1bdb4bc0d59cdc09b5929
  • SHA256:
    a9561608a7ffa81f4d5c635cd94a6d0ca494065ba2bfc44288cf284035384d79
  • Technologies:
Full Report Engine Info Verdict Score Reports

System: w10x64 Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
72/100

malicious
9/71

IPs

IP Country Detection
45.12.32.36
Netherlands
173.212.192.75
Germany

Domains

Name IP Detection
dtliquq.duckdns.org
45.12.32.36
assets.onestore.ms
0.0.0.0
freepnglogos.com
173.212.192.75
Click to see the 5 hidden entries
code.jquery.com
0.0.0.0
p.sfx.ms
0.0.0.0
spoprod-a.akamaihd.net
0.0.0.0
ajax.aspnetcdn.com
0.0.0.0
www.freepnglogos.com
0.0.0.0

URLs

Name Detection
https://digital-girlz.com/wp-includes/bookmarks.php
https://www.modalap.com/wp-includes/bookmarks.php
https://signin.kissmetrics.com/privacy/#controls
Click to see the 87 hidden entries
https://login.skype.com/login
https://bugs.webkit.org/show_bug.cgi?id=136851
https://www.acuityads.com/opt-out/
https://jsperf.com/thor-indexof-vs-for/5
https://bugs.jquery.com/ticket/12359
https://www.optimizely.com/legal/opt-out/
https://privacy.micros/Desktop/INV-14th%20September%202020-2222122212684822.htm
https://www.youradchoices.ca/fr
https://web.archive.org/web/20100324014747/http://blindsignals.com/index.php/2009/07/jquery-delay/
http://www.amazon.com/
https://html.spec.whatwg.org/#strip-and-collapse-whitespace
http://www.asp.net/ajaxlibrary/CDN.ashx.
https://www.getkidsbehindscience.com/wp-includes/bookmarks.php
https://promisesaplus.com/#point-75
https://web.archive.org/web/20141116233347/http://fluidproject.org/blog/2008/01/09/getting-setting-a
http://www.twitter.com/
https://drafts.csswg.org/cssom/#common-serializing-idioms
https://html.spec.whatwg.org/multipage/forms.html#concept-fe-disabled
https://bugs.webkit.org/show_bug.cgi?id=29084
https://infra.spec.whatwg.org/#strip-and-collapse-ascii-whitespace
https://html.spec.whatwg.org/multipage/forms.html#concept-option-disabled
https://github.com/jquery/jquery/pull/557)
https://www.privacyshield.gov/welcome
https://ondemand.webtrends.com/support/optout.asp
https://bugs.chromium.org/p/chromium/issues/detail?id=378607
https://github.com/jrburke/requirejs/wiki/Updating-existing-libraries#wiki-anon
https://www.appsflyer.com/optout
https://privacy.micros
https://www.appnexus.com/
https://bugzilla.mozilla.org/show_bug.cgi?id=687787
https://bugs.chromium.org/p/chromium/issues/detail?id=470258
https://bestkitchenstuff.com/wp-includes/bookmarks.php
https://bugs.jquery.com/ticket/13378
https://www.youradchoices.ca
https://priv-policy.imrworldwide.com/priv/browser/us/en/optout.html
https://promisesaplus.com/#point-64
http://github.com/requirejs/almond/LICENSE
http://www.reddit.com/
https://jennysstyle.com/wp-includes/bookmarks.php
https://www.youronlinechoices.com/
https://bestcryptocurrencybooks.com/wp-includes/bookmarks.php
https://promisesaplus.com/#point-61
https://www.here.com/)
https://www.aboutads.info/
https://www.adjust.com/opt-out/
http://www.nytimes.com/
https://drafts.csswg.org/cssom/#resolved-values
https://just-perfect-gifts.com/wp-includes/bookmarks.php
https://shopaholic.world/wp-includes/bookmarks.php
https://bugs.chromium.org/p/chromium/issues/detail?id=589347
https://developer.yahoo.com/flurry/end-user-opt-out/
https://html.spec.whatwg.org/#nonce-attributes
http://fontello.com
https://html.spec.whatwg.org/multipage/syntax.html#attributes-2
https://promisesaplus.com/#point-59
https://www.xbox.com
https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/adequacy-protectio
https://jsperf.com/getall-vs-sizzle/2
https://promisesaplus.com/#point-57
https://github.com/eslint/eslint/issues/3229
https://www.clicktale.net/disable.html
https://rb.gy/3hwn8f
https://promisesaplus.com/#point-54
https://html.spec.whatwg.org/multipage/forms.html#category-listed
https://html.spec.whatwg.org/multipage/scripting.html#selector-disabled
https://developer.mozilla.org/en-US/docs/CSS/display
https://jquery.org/license
https://jquery.com/
http://fontello.comiconsRegulariconsiconsVersion
https://topfivex.com/wp-includes/bookmarks.php
http://www.youtube.com/
https://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager.html
https://bugs.webkit.org/show_bug.cgi?id=137337
https://html.spec.whatwg.org/multipage/scripting.html#selector-enabled
http://www.wikipedia.com/
https://men-and-womens-fashion.com/wp-includes/bookmarks.php
https://promisesaplus.com/#point-48
http://www.live.com/
https://github.com/h5bp/html5-boilerplate/blob/master/src/css/main.css
https://www.linkedin.com/legal/privacy-policy
https://github.com/jquery/sizzle/pull/225
https://bugs.jquery.com/ticket/4833
https://github.com/whatwg/html/issues/2369
https://sizzlejs.com/
https://bugs.chromium.org/p/chromium/issues/detail?id=449857
https://js.foundation/
https://bugs.jquery.com/ticket/13393

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{C1FBE96F-F7ED-11EA-90E2-ECF4BB862DED}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{C1FBE971-F7ED-11EA-90E2-ECF4BB862DED}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{C1FBE972-F7ED-11EA-90E2-ECF4BB862DED}.dat
Microsoft Word Document
#
Click to see the 40 hidden entries
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-314712940\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\ynfz0jx\imagestore.dat
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\89-504773[1].css
UTF-8 Unicode text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\fe-a5cf09[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\jquery-3.4.1[1].js
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\latest[1].woff
Web Open Font Format, TrueType, length 33556, version 0.0
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\microsoft-logos-png-images-free-download-22[1].png
PNG image data, 2000 x 427, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\css2[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\latest[1].eot
Embedded OpenType (EOT), Segoe UI Light family
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\latest[2].eot
Embedded OpenType (EOT), Segoe UI family
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\latest[3].eot
Embedded OpenType (EOT), Segoe UI Semibold family
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\mem5YaGs126MiZpBA-UN_r8-Vg[1].woff
Web Open Font Format, TrueType, length 56908, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\mem8YaGs126MiZpBA-U1UQ[1].woff
Web Open Font Format, TrueType, length 55268, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\shell.min[1].css
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\favicon[2].ico
MS Windows icon resource - 6 icons, 128x128, 16 colors, 72x72, 16 colors
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\icons[1].eot
Embedded OpenType (EOT), icons family
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\jquery-1.11.2.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\pdf[1].png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\privacystatement[1].htm
HTML document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\RE1Mu3b[1].png
PNG image data, 216 x 46, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\app[1].css
ASCII text, with very long lines, with CRLF, LF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\encrypt[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\override[1].css
ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\print-icon[1].png
PNG image data, 16 x 16, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\script[1].js
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\script[2].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\style[1].css
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Temp\datAA7E.tmp
Web Open Font Format, TrueType, length 2532, version 2.24904
#
C:\Users\user\AppData\Local\Temp\~DF434C2D71B6FCAD61.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFC99B38CAB732DCFF.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFDEBDB5E1F0523965.TMP
data
#