flash

http://romanosgroup.com/signaturebreads/

Status: finished
Submission Time: 23.09.2020 22:38:25
Malicious
Phishing
HTMLPhisher

Comments

Tags

Details

  • Analysis ID:
    289319
  • API (Web) ID:
    473747
  • Analysis Started:
    23.09.2020 22:38:26
  • Analysis Finished:
    23.09.2020 22:41:53
  • Technologies:
Full Report Management Report Engine Info Verdict Score Reports

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
68/100

IPs

IP Country Detection
162.219.251.215
United States
151.139.128.8
United States
104.17.78.107
United States

Domains

Name IP Detection
kit-free.fontawesome.com
151.139.128.8
romanosgroup.com
162.219.251.215
kit.fontawesome.com
151.139.128.8
Click to see the 4 hidden entries
cdnjs.cloudflare.com
104.17.78.107
stackpath.bootstrapcdn.com
0.0.0.0
code.jquery.com
0.0.0.0
maxcdn.bootstrapcdn.com
0.0.0.0

URLs

Name Detection
http://romanosgroup.com/signaturebreads/
http://romanosgroup.com/signaturebreads/r
http://romanosgroup.com/signaturebreads/images/outlook1.png
Click to see the 32 hidden entries
http://ianlunn.github.io/Hover/)
http://romanosgroup.com/favicon.ico
https://code.jquery.com/jquery-3.2.1.slim.min.js
https://code.jquery.com/jquery-3.1.1.min.js
http://romanosgroup.com/signaturebreads/Root
https://kit-free.fontawesome.com
http://romanosgroup.com/signaturebreads/images/onedrive-white.png
https://stackpath.bootstrapcdn.com/bootstrap/4.1.3/js/bootstrap.min.js
http://romanosgroup.com/signaturebreads/images/office3651.png
https://getbootstrap.com/)
https://fontawesome.comhttps://fontawesome.comFont
https://code.jquery.com/jquery-3.3.1.js
https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/css/bootstrap.min.css
http://romanosgroup.com/signaturebreads/images/onedrive-w.png
https://fontawesome.com/license/free
http://romanosgroup.com/signaturebreads/images/gmail.png
https://fontawesome.com
http://romanosgroup.com/signaturebreads/css/album.css
http://romanosgroup.com/signaturebreads/video/onedrive.mp4
https://github.com/twbs/bootstrap/graphs/contributors)
https://cdnjs.cloudflare.com/ajax/libs/popper.js/1.12.9/umd/popper.min.js
https://getbootstrap.com)
http://romanosgroup.com/signaturebreads/
http://ianlunn.co.uk/
https://github.com/twbs/bootstrap/blob/master/LICENSE)
https://github.com/IanLunn/Hover
http://opensource.org/licenses/MIT).
https://kit.fontawesome.com/585b051251.js
https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/js/bootstrap.min.js
http://romanosgroup.com/signaturebreads/css/hover.css
http://romanosgroup.com/wp-content/uploads/2016/01/cropped-R-icon-32x32.png
http://gmail.com/

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\signaturebreads[1].htm
HTML document, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{453E5780-FE28-11EA-90E3-ECF4BB570DC9}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{453E5782-FE28-11EA-90E3-ECF4BB570DC9}.dat
Microsoft Word Document
#
Click to see the 26 hidden entries
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{453E5783-FE28-11EA-90E3-ECF4BB570DC9}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\dikxvqf\imagestore.dat
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5\mms\G81196IX\onedrive[1].dat
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\585b051251[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\bootstrap.min[1].css
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\bootstrap.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\jquery-3.1.1.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\jquery-3.2.1.slim.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\cropped-R-icon-32x32[1].png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\css[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\free-fa-regular-400[1].eot
Embedded OpenType (EOT), Font Awesome 5 Free Regular family
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\free-fa-solid-900[1].eot
Embedded OpenType (EOT), Font Awesome 5 Free Solid family
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\hover[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\jquery.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\bootstrap.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\gmail[1].png
PNG image data, 1280 x 1280, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\office3651[1].png
PNG image data, 187 x 188, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\onedrive-w[1].png
PNG image data, 242 x 167, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\popper.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\album[1].css
assembler source, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\free-v4-shims.min[1].css
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\free.min[1].css
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\outlook1[1].png
PNG image data, 26 x 26, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Temp\~DF6E262A4D9EA9CCCE.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF8937E33E22D4D415.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF95E58EF3FA653376.TMP
data
#