flash

notif.5581.xls

Status: finished
Submission Time: 23.09.2020 18:39:04
Malicious
Spreader
Exploiter
Evader
Hidden Macro 4.0

Comments

Tags

Details

  • Analysis ID:
    289231
  • API (Web) ID:
    473572
  • Analysis Started:
    23.09.2020 18:39:05
  • Analysis Finished:
    23.09.2020 18:46:12
  • MD5:
    f9b6cf62fa1ba79e74b7ae3e412ccde0
  • SHA1:
    cb5a5d56dda147951ed940814100b21769d1f567
  • SHA256:
    ff38a7c0c301e273a6c2197ad35f3d458c9c8e660048dbceb7dfb05932d41340
  • Technologies:
Full Report Management Report Engine Info Verdict Score Reports

System: Windows 7 x64 SP1 with Office 2010 SP2 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2)

malicious
100/100

IPs

IP Country Detection
104.27.137.242
United States

Domains

Name IP Detection
beautifulday.site
104.27.137.242

URLs

Name Detection
http://www.windows.com/pctv.
http://investor.msn.com
http://www.msnbc.com/news/ticker.txt
Click to see the 27 hidden entries
https://lh3.googleusercontent.com/ogw/default-user=s96
http://crl.entrust.net/server1.crl0
https://gomag.site/wp-index.phpE
http://ocsp.entrust.net03
https://beautifulday.site/wp-index.php
http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
http://pki.goog/gsr2/GTS1O1.crt0
http://www.diginotar.nl/cps/pkioverheid0
https://beautifulday.site/wp-index.phpa6
http://ocsp.pki.goog/gsr202
http://www.hotmail.com/oe
https://pki.goog/repository/0
https://beautifulday.site/wp-index.php6
https://gomag.site/wp-index.php
http://crl.pkioverheid.nl/DomOvLatestCRL.crl0
https://beautifulday.site/wp-index.phpvbs
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
https://lh3.googleusercontent.com/ogw/default-user=s24
http://ocsp.pki.goog/gts1o1core0
http://investor.msn.com/
http://crl.pki.goog/GTS1O1core.crl0
http://www.%s.comPA
https://gomag.site/wp-index.phpz
https://beautifulday.site/
http://crl.pki.goog/gsr2/gsr2.crl0?
https://secure.comodo.com/CPS0
http://servername/isapibackend.dll

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Temp\KEc.html
HTML document, ISO-8859 text, with very long lines
#
C:\Users\user\AppData\Local\Temp\KdHUdD1.vbs
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\SFGG6bFs.vbs
ASCII text, with CRLF, CR line terminators
#
Click to see the 7 hidden entries
C:\Users\user\AppData\Local\Temp\egBLrMHS.vbs
ASCII text, with CRLF, CR line terminators
#
C:\Users\user\AppData\Local\Temp\6CDE0000
data
#
C:\Users\user\AppData\Local\Temp\FCbEqFS.txt
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Tue Oct 17 10:04:00 2017, mtime=Thu Sep 24 00:39:41 2020, atime=Thu Sep 24 00:39:41 2020, length=12288, window=hide
#
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\notif.5581.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Aug 26 14:08:10 2020, mtime=Thu Sep 24 00:39:41 2020, atime=Thu Sep 24 00:39:41 2020, length=152064, window=hide
#
C:\Users\user\Desktop\0DDE0000
Applesoft BASIC program data, first line number 16
#