flash

https://osiwaes.web.app/#?HB=c2RzdHVydHpAcGVsbGEuY29t

Status: finished
Submission Time: 16.09.2020 17:18:21
Malicious
Phishing
HTMLPhisher

Comments

Tags

Details

  • Analysis ID:
    286446
  • API (Web) ID:
    468056
  • Analysis Started:
    16.09.2020 17:18:21
  • Analysis Finished:
    16.09.2020 17:21:50
  • Technologies:
Full Report Engine Info Verdict Score Reports

System: w10x64 Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
76/100

malicious

IPs

IP Country Detection
192.99.245.102
Canada
151.101.1.195
United States

Domains

Name IP Detection
osiwaes.web.app
151.101.1.195
kristinaberger.com
192.99.245.102

URLs

Name Detection
https://osiwaes.web.app/#?HB=c2RzdHVydHpAcGVsbGEuY29t
https://osiwaes.web.app/#?HB=c2RzdHVydHpAcGVsbGEuY29tRoot
https://kristinaberger.com/so/images/favicon.ico~
Click to see the 6 hidden entries
https://kristinaberger.com/so
https://kristinaberger.com/so/uike1cn7azmd36pb5wtvro8j.php?1dmi9rvpk7b253oahs8jnl0uytgxz4wqf6cemnve0
https://kristinaberger.com/so/images/favicon.ico
https://kristinaberger.com/so/?HB=c2RzdHVydHpAcGVsbGEuY29t
https://kristinaberger.com/so/images/favicon.ico~(
https://kristinabergerp/#?HB=c2RzdHVydHpAcGVsbGEuY29t.com/so/uike1cn7azmd36pb5wtvro8j.php?1dmi9rvpk7

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\uike1cn7azmd36pb5wtvro8j[1].htm
HTML document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{67D7A3BC-F87B-11EA-90E3-ECF4BB570DC9}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{67D7A3BE-F87B-11EA-90E3-ECF4BB570DC9}.dat
Microsoft Word Document
#
Click to see the 20 hidden entries
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{6E340F6D-F87B-11EA-90E3-ECF4BB570DC9}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\dikxvqf\imagestore.dat
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\ellipsis_white[1].svg
SVG Scalable Vector Graphics image
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\forgetpass[1].png
PNG image data, 121 x 20, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\so[1].htm
HTML document, ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\5LPPX9IV.htm
HTML document, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\arrow_left[1].svg
SVG Scalable Vector Graphics image
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\favicon[1].ico
MS Windows icon resource - 6 icons, 128x128, 16 colors, 72x72, 16 colors
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\passwrd[1].png
PNG image data, 69 x 34, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\sigin[1].png
PNG image data, 108 x 32, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\small-background[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 50x28, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\conv[1].css
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\ellipsis_grey[1].svg
SVG Scalable Vector Graphics image
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\mcsft_logo[1].svg
SVG Scalable Vector Graphics image
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\big-background[1].jpg
JPEG image data, baseline, precision 8, 1920x1080, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\enterpass[1].png
PNG image data, 170 x 29, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\firstmsg[1].png
PNG image data, 353 x 41, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Temp\~DF27225D241113C1D5.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF76259A8F6CC5D92A.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFF6A05EE2A8E945BA.TMP
data
#