top title background image
flash

https://linkprotect.cudasvc.com/url?a=https%3a%2f%2fm95gjcfm.web.app?email=caschweri@groupemutuel.ch&c=E,1,hYcZ5hEZoc7XZWoQbHhhjJZj-RsTj296-tSvIc-n9Gioz6ME_cFbBP4tllGg2amUOju2Haa3enTsPX3TmjuR4IEE6CsDqJrBoABeI-D6MGG4YQ,,&typo=3510:55%20AM

Status: finished
Submission Time: 2020-09-16 11:20:50 +02:00
Malicious
Phishing
HTMLPhisher

Comments

Tags

Details

  • Analysis ID:
    286254
  • API (Web) ID:
    467673
  • Analysis Started:
    2020-09-16 11:20:51 +02:00
  • Analysis Finished:
    2020-09-16 11:24:41 +02:00
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 64
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
malicious

IPs

IP Country Detection
99.84.94.58
United States
23.111.9.35
United States
3.123.155.16
United States
Click to see the 2 hidden entries
151.101.1.195
United States
104.17.79.107
United States

Domains

Name IP Detection
d26p066pn2w0s0.cloudfront.net
99.84.94.58
cdnjs.cloudflare.com
104.17.79.107
fontawesome-cdn.fonticons.netdna-cdn.com
23.111.9.35
Click to see the 6 hidden entries
m95gjcfm.web.app
151.101.1.195
linkprotect.cudasvc.com
3.123.155.16
stackpath.bootstrapcdn.com
0.0.0.0
use.fontawesome.com
0.0.0.0
cdn.jsdelivr.net
0.0.0.0
logo.clearbit.com
0.0.0.0

URLs

Name Detection
https://july-06.nw.r.appspot.com/app.php
https://cdn.jsdelivr.net/npm/jquery.session
https://fontawesome.com/license/free
Click to see the 16 hidden entries
https://m95gjcfm.web.app/?email=caschweri
https://logo.clearbit.com/office.com
https://cdnjs.cloudflare.com/ajax/libs/jquery/3.3.1/jquery.min.js
https://getbootstrap.com/)
https://logo.clearbit.com/
https://stackpath.bootstrapcdn.com/bootstrap/4.1.3/js/bootstrap.min.js
http://fontello.comFont
https://github.com/twbs/bootstrap/blob/master/LICENSE)
https://fontawesome.com
http://fontello.com
https://stackpath.bootstrapcdn.com/bootstrap/4.3.1/css/bootstrap.min.css
https://www.jsdelivr.com/using-sri-with-dynamic-files
https://use.fontawesome.com/releases/v5.6.1/css/all.css
https://stackpath.bootstrapcdn.com/bootstrap/4.3.1/js/bootstrap.bundle.min.js
https://github.com/twbs/bootstrap/graphs/contributors)
https://stackpath.bootstrapcdn.com/bootstrap/4.3.1/js/bootstrap.min.js

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\JHPJXE3O.htm
HTML document, ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\fa-regular-400[1].eot
Embedded OpenType (EOT), Font Awesome 5 Free family
#
C:\Users\user\AppData\Local\Temp\~DFFB527AB2A0434644.TMP
data
#
Click to see the 18 hidden entries
C:\Users\user\AppData\Local\Temp\~DFF9FAE187133D352D.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF26497196E0ECA79E.TMP
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\office[1].png
PNG image data, 128 x 128, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\jquery.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\bg5[1].png
PNG image data, 1366 x 623, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\jquery.session.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\jquery.min[2].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\jquery.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{74BD55EE-F849-11EA-90E2-ECF4BB862DED}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\bootstrap.bundle.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\app[1].css
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\all[1].css
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\fa-solid-900[1].eot
Embedded OpenType (EOT), Font Awesome 5 Free family
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\bootstrap.min[2].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\bootstrap.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\bootstrap.min[1].css
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{74BD55F1-F849-11EA-90E2-ECF4BB862DED}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{74BD55F0-F849-11EA-90E2-ECF4BB862DED}.dat
Microsoft Word Document
#