flash

https://linkprotect.cudasvc.com/url?a=https%3a%2f%2fm95gjcfm.web.app?email=caschweri@groupemutuel.ch&c=E,1,hYcZ5hEZoc7XZWoQbHhhjJZj-RsTj296-tSvIc-n9Gioz6ME_cFbBP4tllGg2amUOju2Haa3enTsPX3TmjuR4IEE6CsDqJrBoABeI-D6MGG4YQ,,&typo=3510:55%20AM

Status: finished
Submission Time: 16.09.2020 11:20:50
Malicious
Phishing
HTMLPhisher

Comments

Tags

Details

  • Analysis ID:
    286254
  • API (Web) ID:
    467673
  • Analysis Started:
    16.09.2020 11:20:51
  • Analysis Finished:
    16.09.2020 11:24:41
  • Technologies:
Full Report Engine Info Verdict Score Reports

System: w10x64 Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
64/100

malicious

malicious

malicious

IPs

IP Country Detection
99.84.94.58
United States
23.111.9.35
United States
3.123.155.16
United States
Click to see the 2 hidden entries
151.101.1.195
United States
104.17.79.107
United States

Domains

Name IP Detection
d26p066pn2w0s0.cloudfront.net
99.84.94.58
cdnjs.cloudflare.com
104.17.79.107
fontawesome-cdn.fonticons.netdna-cdn.com
23.111.9.35
Click to see the 6 hidden entries
m95gjcfm.web.app
151.101.1.195
linkprotect.cudasvc.com
3.123.155.16
stackpath.bootstrapcdn.com
0.0.0.0
use.fontawesome.com
0.0.0.0
cdn.jsdelivr.net
0.0.0.0
logo.clearbit.com
0.0.0.0

URLs

Name Detection
https://july-06.nw.r.appspot.com/app.php
https://fontawesome.com
https://stackpath.bootstrapcdn.com/bootstrap/4.3.1/js/bootstrap.min.js
Click to see the 16 hidden entries
https://github.com/twbs/bootstrap/graphs/contributors)
https://stackpath.bootstrapcdn.com/bootstrap/4.3.1/js/bootstrap.bundle.min.js
https://use.fontawesome.com/releases/v5.6.1/css/all.css
https://www.jsdelivr.com/using-sri-with-dynamic-files
https://stackpath.bootstrapcdn.com/bootstrap/4.3.1/css/bootstrap.min.css
http://fontello.com
https://cdn.jsdelivr.net/npm/jquery.session
https://github.com/twbs/bootstrap/blob/master/LICENSE)
http://fontello.comFont
https://stackpath.bootstrapcdn.com/bootstrap/4.1.3/js/bootstrap.min.js
https://logo.clearbit.com/
https://getbootstrap.com/)
https://cdnjs.cloudflare.com/ajax/libs/jquery/3.3.1/jquery.min.js
https://logo.clearbit.com/office.com
https://m95gjcfm.web.app/?email=caschweri
https://fontawesome.com/license/free

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\JHPJXE3O.htm
HTML document, ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{74BD55EE-F849-11EA-90E2-ECF4BB862DED}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{74BD55F0-F849-11EA-90E2-ECF4BB862DED}.dat
Microsoft Word Document
#
Click to see the 18 hidden entries
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{74BD55F1-F849-11EA-90E2-ECF4BB862DED}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\bootstrap.min[1].css
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\bootstrap.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\bootstrap.min[2].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\fa-solid-900[1].eot
Embedded OpenType (EOT), Font Awesome 5 Free family
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\all[1].css
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\app[1].css
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\bootstrap.bundle.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\fa-regular-400[1].eot
Embedded OpenType (EOT), Font Awesome 5 Free family
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\jquery.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\jquery.min[2].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\jquery.session.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\bg5[1].png
PNG image data, 1366 x 623, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\jquery.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\office[1].png
PNG image data, 128 x 128, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Temp\~DF26497196E0ECA79E.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFF9FAE187133D352D.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFFB527AB2A0434644.TMP
data
#