top title background image
flash

http://d2idxs80daj9st.cloudfront.net/sd/?c=XGlybQ==&u=8CA2B18D-1572-5966-9561-70320284D1FC&s=3B99BDE3-65DD-4253-A623-7B4D95F12037&o=10.15.6&b=11019551274&clickId=JnvWEv

Status: finished
Submission Time: 2020-09-26 11:51:25 +02:00
Malicious

Comments

Tags

Details

  • Analysis ID:
    290363
  • API (Web) ID:
    475826
  • Analysis Started:
    2020-09-26 11:51:25 +02:00
  • Analysis Finished:
    2020-09-26 11:54:30 +02:00
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 48
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious

IPs

IP Country Detection
13.224.186.215
United States

Domains

Name IP Detection
d2idxs80daj9st.cloudfront.net
13.224.186.215

URLs

Name Detection
http://d2idxs80daj9st.cloudfront.net/sd/?c=XGlybQ==&u=8CA2B18D-1572-5966-9561-70320284D1FC&s=3B99BDE3-65DD-4253-A623-7B4D95F12037&o=10.15.6&b=11019551274&clickId=JnvWEv
http://www.wikipedia.com/
http://www.amazon.com/
Click to see the 8 hidden entries
http://d2idxs80daj9st.cloudfront.net/sd/?c=XGlybQ==&u=8CA2B18D-1572-5966-9561-70320284D1FC&s=3B99BDE3-65DD-4253-A623-7B4D95F12037&o=10.15.6&b=11019551274&clickId=JnvWEv
http://www.nytimes.com/
http://www.live.com/
http://d2idxs80daj9st.cloudfront.net/sd/?c=XGlybQ==&u=8CA2B18D-1572-5966-9561-70320284D1FC&s=3B99BDE
http://www.reddit.com/
http://www.twitter.com/
http://www.youtube.com/
http://d2idxs80daj9st.cloudfront.net/sd/favicon.ico

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{619B25D0-0029-11EB-90E2-ECF4BB862DED}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{619B25D2-0029-11EB-90E2-ECF4BB862DED}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{619B25D3-0029-11EB-90E2-ECF4BB862DED}.dat
Microsoft Word Document
#
Click to see the 13 hidden entries
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-314712940\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\~DF96CF830491AD4B79.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF9CAFE8150B62C081.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFACC5B53877166ED4.TMP
data
#