top title background image
flash

Haynes Equipment Company, Inc..html

Status: finished
Submission Time: 2020-09-24 17:59:18 +02:00
Malicious

Comments

Tags

Details

  • Analysis ID:
    289651
  • API (Web) ID:
    474408
  • Analysis Started:
    2020-09-24 17:59:18 +02:00
  • Analysis Finished:
    2020-09-24 18:04:58 +02:00
  • MD5:
    9c69ae992c72a7b32047d26a450b486a
  • SHA1:
    a80b1297fb5d0363b6dda6dd718ed760deda371a
  • SHA256:
    02ed17f8c653fd3c3f861e03ec211e43c3eea953514763635befb8dd8b58904c
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 48
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious

IPs

IP Country Detection
52.204.90.22
United States

Domains

Name IP Detection
urldefense.com
52.204.90.22

URLs

Name Detection
https://urldefense.com/v3/__https://rtyuyikhjghcvxcds.azurewebsites.net/dtZJZe8/hqAdgTT/3rm5zq8/hgfg
https://urldefense.com/jblocked?u=https%3A%2F%2Frtyuyikhjghcvxcds.azurewebsites.net%2FdtZJZe8%2FhqAdgTT%2F3rm5zq8%2Fhgfg.php%3Fbbre%3Dc5f03386978cf62ddb7f2f46e9bd5790&c=gswater_hosted&sig=qkW3qm_7dMDLvdK3oFtWZS95R2fUP_Z2h3KhiAolW4M%3D
file:///C:/Users/user/Desktop/Haynes%20Equipment%20Company,%20Inc..html
Click to see the 10 hidden entries
http://www.nytimes.com/
https://urldefense.com
https://urldefense.com/jblocked?u=https%3A%2F%2Frtyuyikhjghcvxcds.azurewebsites.net%2FdtZJZe8%2FhqAd
http://www.youtube.com/
http://www.wikipedia.com/
http://www.amazon.com/
http://www.live.com/
https://urldefense.com/Desktop/Haynes%20Equipment%20Company
http://www.reddit.com/
http://www.twitter.com/

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\~DFECAF1B3085DD0741.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF9E6BE15C3C19AD8E.TMP
data
#
Click to see the 16 hidden entries
C:\Users\user\AppData\Local\Temp\~DF39C20FA6D5385516.TMP
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\common[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\7f20c8ca096d777e40f90aa4eda970d5[1].jpg
[TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Macintosh, datetime=2005:10:04 08:06:55], baseline, precision 8, 200x45, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\warning[1].png
PNG image data, 64 x 64, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{70828AAD-FECA-11EA-90E2-ECF4BB862DED}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-314712940\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{786AB622-FECA-11EA-90E2-ECF4BB862DED}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{70828AAF-FECA-11EA-90E2-ECF4BB862DED}.dat
Microsoft Word Document
#