top title background image
flash

https://aplusserve.com/wp-content/plugins/antara/failed/encr-p-t-e-d/?email=maggiemk.wong@juliusbaer.com

Status: finished
Submission Time: 2020-10-19 13:54:05 +02:00
Malicious
Phishing
HTMLPhisher

Comments

Tags

Details

  • Analysis ID:
    300143
  • API (Web) ID:
    495380
  • Analysis Started:
    2020-10-19 13:54:05 +02:00
  • Analysis Finished:
    2020-10-19 13:57:54 +02:00
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 56
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 5/67

IPs

IP Country Detection
159.138.111.125
Singapore
193.223.56.121
Switzerland

Domains

Name IP Detection
www.juliusbaer.com
193.223.56.121
www.aplusserve.com
159.138.111.125
aplusserve.com
159.138.111.125
Click to see the 1 hidden entries
juliusbaer.com
193.223.56.121

URLs

Name Detection
https://aplusserve.com
https://aplusserve.com/wp-content/plugins/antara/failed/encr-p-t-e-d/j2rwrw4hlj4z3xx7obq3z6f05b0667db8de1f3311a701d6d5082b982.php?email=
https://aplusserve.com/wp-content/plugins/antara/failed/encr-p-t-e-d/j2rwrw4hlj4z3xx7obq3z6f05b0667d
Click to see the 4 hidden entries
https://aplusserve.com/wp-content/plugins/antara/failed/encr-p-t-e-d/69j2toziawwezj1zk3sroe2u5b0667db8de1f3311a701d6d5082b982.php?email=maggiemk.wong@juliusbaer.com
https://aplusserve.com/wp-content/plugins/antara/failed/encr-p-t-e-d/69j2toziawwezj1zk3sroe2u5b0667d
http://juliusbaer.com/favicon.ico
http:///favicon.ico

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\j2rwrw4hlj4z3xx7obq3z6f05b0667db8de1f3311a701d6d5082b982[1].htm
HTML document, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\69j2toziawwezj1zk3sroe2u5b0667db8de1f3311a701d6d5082b982[1].htm
HTML document, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{57990996-124D-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
#
Click to see the 7 hidden entries
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{57990998-124D-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{5FF86A4F-124D-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\styles[1].css
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\cropped-aplus_Logo-1-e1531476601249-1-32x32[1].jpg
[TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS2 Windows, datetime=2009:08:31 15:05:59], baseline, precision 8, 32x32, frames 3
#
C:\Users\user\AppData\Local\Temp\~DF7586FF3F0AD7BAC8.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFE44968938B2DD306.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFED801D2262465988.TMP
data
#