top title background image
flash

http://www.607608.bt.ntipak.com/Y2FycmllLnByaWNlQHNlYXJzaGMuY29t#aHR0cHM6Ly9taWNyb3N3YXk2MzV3dXgud24uci5hcHBzcG90LmNvbT91aWQ9Y2FycmllLnByaWNlQHNlYXJzaGMuY29t

Status: finished
Submission Time: 2020-10-15 17:10:14 +02:00
Malicious
Phishing
HTMLPhisher

Comments

Tags

Details

  • Analysis ID:
    298747
  • API (Web) ID:
    492652
  • Analysis Started:
    2020-10-15 17:12:41 +02:00
  • Analysis Finished:
    2020-10-15 17:17:06 +02:00
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 72
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
malicious

IPs

IP Country Detection
198.54.125.47
United States
216.58.215.244
United States

Domains

Name IP Detection
www.607608.bt.ntipak.com
198.54.125.47
microsway635wux.wn.r.appspot.com
216.58.215.244
secure.aadcdn.microsoftonline-p.com
0.0.0.0

URLs

Name Detection
https://microsway635wux.wn.r.appspot.com/tca644vtodmvotwhil5yc5fe.php?id=carrie.price@searshc.com#servicesagreement
https://microsway635wux.wn.r.appspot.com/tca644vtodmvotwhil5yc5fe.php?id=carrie.price
https://microsway635wux.wn.r.appspot.com/tca644vtodmvotwhil5yc5fe.php?id=carrie.price@searshc.com
Click to see the 21 hidden entries
https://microsway635wux.wn.r.appspot.com/office/tca644vtodmvotwhil5yc5fe.php?id=
https://microsway635wux.wn.r.appspot.com/tca644vt
https://microsway635wux.wn.r.appspot.com/tca644vtodmvotwhil5yc5fe.php?id=carrie.price@searshc.com#privacystatement
https://secure.aadcdn.microsoftonline-p.com/ests/2.1.8576.13/content/images/backgrounds/0_a5dbd4393f
https://secure.aadcdn.microsoftonline-p.com/ests/2.1.8576.13/content/images/ellipsis_grey_2b5d393db0
https://secure.aadcdn.microsoftonline-p.com/ests/2.1.8576.13/content/images/microsoft_logo_ee5c8d9fb
https://secure.aadcdn.microsoftonline-p.com/ests/2.1.8576.13/content/images/ellipsis_white_0ad430848
https://secure.aadcdn.microsoftonline-p.com/ests/2.1.8576.13/content/images/backgrounds/0-small_138b
https://getbootstrap.com/)
https://secure.aadcdn.microsoftonline-p.com/ests/2.1.8576.13/content/images/favicon_a_eupayfgghqiai7
http://opensource.org/licenses/MIT).
https://secure.aadcdn.microsoftonline-p.com/ests/2.1.8576.13/content/images/microsoft_logo_ed9c9eb0d
https://secure.aadcdn.microsoftonline-p.com/ests/2.1.8576.13/content/images/ellipsis_white_5ac590ee7
https://secure.aadcdn.microsoftonline-p.com/ests/2.1.8576.13/content/images/ellipsis_grey_5bc252567e
https://github.com/twbs/bootstrap/blob/master/LICENSE)
https://login.microsoftonline.com/jsdisabled
http://www.607608.bt.ntipak.com/favicon.ico
http://www.607608.bt.ntipak.com/Y2FycmllLnByaWNlQHNlYXJzaGMuY29t#aHR0cHM6Ly9taWNyb3N3YXk2MzV3dXgud24
http://www.607608.bt.ntipak.com/Y2FycmllLnByaWNlQHNlYXJzaGMuY29t
https://microsway635wutipak.com/Y2FycmllLnByaWNlQHNlYXJzaGMuY29t#aHR0cHM6Ly9taWNyb3N3YXk2MzV3dXgud24
https://github.com/twbs/bootstrap/graphs/contributors)

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\tca644vtodmvotwhil5yc5fe[1].htm
HTML document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{6E376B8C-0F44-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{6E376B8E-0F44-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
#
Click to see the 12 hidden entries
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{752A0541-0F44-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\converged[1].css
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\ellipsis_white_5ac590ee72bfe06a7cecfd75b588ad73[1].svg
SVG Scalable Vector Graphics image
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\microsoft_logo_ee5c8d9fb6248c938fd0dc19370e90bd[1].svg
SVG Scalable Vector Graphics image
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\ellipsis_grey_2b5d393db04a5e6e1f739cb266e65b4c[1].svg
SVG Scalable Vector Graphics image
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\0-small_138bcee624fa04ef9b75e86211a9fe0d[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 50x28, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\0_a5dbd4393ff6a725c7e62b61df7e72f0[1].jpg
JPEG image data, baseline, precision 8, 1920x1080, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\Y2FycmllLnByaWNlQHNlYXJzaGMuY29t[1].htm
HTML document, ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\favicon[1].htm
HTML document, ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Temp\~DF139188FAC763F433.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF92D441557A858BE9.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFE892F843F491E84F.TMP
data
#