flash

http://mail.gogler.com

Status: finished
Submission Time: 15.10.2020 01:28:45
Malicious
Phishing
Phisher

Comments

Tags

Details

  • Analysis ID:
    298361
  • API (Web) ID:
    491830
  • Analysis Started:
    15.10.2020 01:28:45
  • Analysis Finished:
    15.10.2020 01:33:17
  • Technologies:
Full Report Management Report Engine Info Verdict Score Reports

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
48/100

IPs

IP Country Detection
103.224.182.228
Australia
103.224.182.206
Australia
23.111.9.35
United States
Click to see the 4 hidden entries
172.217.23.22
United States
216.58.207.129
United States
157.245.69.255
United States
134.209.199.255
United States

Domains

Name IP Detection
mail.gogler.com
103.224.182.228
i.ytimg.com
172.217.23.22
photos-ugc.l.googleusercontent.com
216.58.207.129
Click to see the 9 hidden entries
fontawesome-cdn.fonticons.netdna-cdn.com
23.111.9.35
guided-finance.com
157.245.69.255
bidr.trellian.com
103.224.182.206
trusted-clicker.com
134.209.199.255
s.ytimg.com
216.58.207.142
use.fontawesome.com
0.0.0.0
yt3.ggpht.com
0.0.0.0
favicon.ico
0.0.0.0
www.youtube-nocookie.com
0.0.0.0

URLs

Name Detection
https://guided-finance.com/privacy-policy.php?lang=en
https://guided-finance.com/terms-conditions.php?lang=en
https://guided-finance.com/contact.php?lang=en
Click to see the 42 hidden entries
https://guided-finance.com/
https://guided-finance.com/#form-box
https://guided-finance.com/terms-conditions.php?lang=en
https://www.youtube.com/generate_204?cpn=
https://guided-finance.com/contact.php?lang=en
https://youtube.com/api/drm/fps?ek=uninitialized
https://guided-finance.com/uxlHnKhTxg25HK0w3Dr.com/nlp/index.php?url_bnm_redirect=https%3A%2F%2Fguid
http://fontello.com
http://mail.gogler.com/
http://fontello.comFont
https://guided-finance.com/contact.php?lang=enng=en~
https://trusted-clicker.com/nlp/index.php?url_bnm_redirect=https%3A%2F%2Fguided-finance.com%2Fcom/ux
http://bidr.trellian.com/javascript/jscheck.js
http://bidr.trellian.com/r2.php?e=qzBy2CbrFCx2iAr9Vom1yMJkNrujzMGZPy3VYUlpMZzf6hLupCgM7k6EvOADUiLRTg
http://youtube.com/streaming/otf/durations/112015
https://guided-finance.com/
http://youtube.com/yt/2012/10/10
https://geoip-db.com/jsonp
https://guided-finance.com/privacy-policy.php?lang=en
http://bidr.trellian.com/r.php?u=https%3A%2F%2Ftrusted-clicker.com%2Fredirect.php%3Fkid%3Djmm8NqFgbkLemBSr8L7m51ttDOHOGD%26cpv%3D0.005%26kw%3D.ch.subp.nonadult%26subid%3D1752607287%26sid%3D20201015102934b8b2e659df9333a17e&s=j
http://youtube.com/streaming/metadata/segment/102015
https://youtu.be/
https://fontawesome.com
https://trusted-clicker.com/nlp/index.php?duplication=1&url_bnm_redirect=https://guided-finance.com/
http://bidr.trellian.com/favicon.ico
https://admin.youtube.com
https://guided-finance.com/nlp/index.php?url_bnm_redirect=https%3A%2F%2Fguided-finance.com%2Fcom/uxl
https://fontawesome.com/license
http://www.youtube.com/videoplayback
https://guided-finance.com/.Invest
http://bidr.trellian.com/r.php?u=https%3A%2F%2Ftrusted-clicker.com%2Fredirect.php%3Fkid%3Djmm8NqFgbk
http://bidr.trellian.c
https://www.tradingview.com/symbols/NASDAQ-AMZN/
https://guided-finance.com/contact.php?lang=enng=en
https://automattic.com/privacy/.
http://www.youtube.com/watch?v=rdJ-H6FjUDE
http://youtube.com/drm/2012/10/10
https://www.iplocate.io/api/lookup
https://www.youtube.com/watch?v=rdJ-H6FjUDE
https://www.youtube-nocookie.com/embed/rdJ-H6FjUDE
https://guided-finance.com/#form-box
https://guided-finance.com/uxlHnKhTxg25HK0wy6WfHJTExi74JvQUPacmWPTVioChY1Ood%2B9M7HxFstX3b92gcravlbq

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\index[1].htm
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\UKD2FA6V\www.youtube-nocookie[1].xml
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{8BC780E6-0EC0-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
#
Click to see the 69 hidden entries
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{8BC780E8-0EC0-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{941C748C-0EC0-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\0K8Q08JI.htm
HTML document, UTF-8 Unicode text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\KFOjCnqEu92Fr1Mu51S7ACc6CsI[1].woff
Web Open Font Format, TrueType, length 21564, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\KFOlCnqEu92Fr1MmEU9fBBc-[1].woff
Web Open Font Format, TrueType, length 20012, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\KFOmCnqEu92Fr1Mu4mxM[1].woff
Web Open Font Format, TrueType, length 19824, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\S6u9w4BMUTPHh50XSwiPHw[1].woff
Web Open Font Format, TrueType, length 27524, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\S6u9w4BMUTPHh7USSwiPHw[1].woff
Web Open Font Format, TrueType, length 30024, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\all[1].css
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\api[1].css
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\app[1].js
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\base[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\css[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\header-5[1].jpg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1569x325, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\jscheck[1].js
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\normalize.min[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\person-3[1].png
PNG image data, 72 x 72, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\person-7[1].png
PNG image data, 72 x 72, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\slick.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\S6u9w4BMUTPHh6UVSwiPHw[1].woff
Web Open Font Format, TrueType, length 28052, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\S6uyw4BMUTPHjx4wWA[1].woff
Web Open Font Format, TrueType, length 28660, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\box-1[1].png
PNG image data, 16 x 32, 2-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\box-2[1].png
PNG image data, 16 x 32, 2-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\css[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\flags-sprite[1].png
PNG image data, 5630 x 15, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\icon-1[1].png
PNG image data, 64 x 70, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\icon-4[1].png
PNG image data, 70 x 70, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\icon-5[1].png
PNG image data, 71 x 71, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\map[1].png
PNG image data, 1265 x 472, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\section-1-img[1].png
PNG image data, 669 x 388, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\slick-theme[1].css
UTF-8 Unicode text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\terms-conditions[1].htm
HTML document, ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\www-embed-player[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\www-player[1].css
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\KFOkCnqEu92Fr1Mu51xIIzQ[1].woff
Web Open Font Format, TrueType, length 21528, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\ajax-loader[1].gif
GIF image data, version 89a, 32 x 32
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\contact[1].htm
HTML document, ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\embed[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\fa-regular-400[1].eot
Embedded OpenType (EOT), Font Awesome 5 Free family
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\fetch-polyfill[1].js
Pascal source, ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\intro-img[1].png
PNG image data, 261 x 249, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\main[1].js
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\person-4[1].png
PNG image data, 72 x 72, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\person-5[1].png
PNG image data, 72 x 72, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\privacy-policy[1].htm
HTML document, ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\rate-stars[1].png
PNG image data, 100 x 16, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\rdJ-H6FjUDE[1].htm
HTML document, UTF-8 Unicode text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\script[1].js
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\style[1].css
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\arrow[1].png
PNG image data, 146 x 32, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\ecommerce-bg[1].png
PNG image data, 778 x 575, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\fa-solid-900[1].eot
Embedded OpenType (EOT), Font Awesome 5 Free family
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\ico-phone[1].png
PNG image data, 32 x 38, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\icon-2[1].png
PNG image data, 73 x 71, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\icon-3[1].png
PNG image data, 70 x 70, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\index[1].htm
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\jquery.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\modal[1].css
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\pat-diag[1].png
PNG image data, 33 x 42, 1-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\person-1[1].png
PNG image data, 72 x 72, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\r2[1].htm
HTML document, ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\remote[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\retina.min[1].js
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\sddefault[1].jpg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 640x480, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\slick[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\unnamed[1].jpg
[TIFF image data, little-endian, direntries=1, software=Google], baseline, precision 8, 68x68, frames 3
#
C:\Users\user\AppData\Local\Temp\~DF951A36E7CCEC2E7C.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF97D7726DA43DC8B1.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFC4FCA384F20980D5.TMP
data
#