top title background image
flash

https://millisboa.com/mil/wp-admin/fridays/

Status: finished
Submission Time: 2020-10-30 19:00:05 +01:00
Malicious
Phishing
HTMLPhisher

Comments

Tags

Details

  • Analysis ID:
    307729
  • API (Web) ID:
    517251
  • Analysis Started:
    2020-10-30 19:00:05 +01:00
  • Analysis Finished:
    2020-10-30 19:03:04 +01:00
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 72
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious

IPs

IP Country Detection
94.46.28.223
Portugal

Domains

Name IP Detection
millisboa.com
94.46.28.223

URLs

Name Detection
https://millisboa.com/mil/wp-admin/fridays/1h3q687vyqke7nm0hfbhi2fe.php?233A421604080853ce3986d99ae7
https://millisboa.com/mil/wp-admin/fridays/images/favicon.png%
https://millisboa.com/mil/wp-admin/fridays/1h3q687vyqke7nm0hfbhi2fe.php?233A421604080853ce3986d99ae74703e604c4f350831d61ce3986d99ae74703e604c4f350831d61ce3986d99ae74703e604c4f350831d61ce3986d99ae74703e604c4f350831d61ce3986d99ae74703e604c4f350831d61&email=&error=

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\1h3q687vyqke7nm0hfbhi2fe[1].htm
HTML document, ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{D80DD956-1AD9-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{D80DD958-1AD9-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
#
Click to see the 10 hidden entries
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{D80DD959-1AD9-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\gee00pr\imagestore.dat
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\0[1].jpg
[TIFF image data, big-endian, direntries=7, xresolution=98, yresolution=106, resolutionunit=2, software=paint.net 4.0.13], baseline, precision 8, 1920x1080, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\favicon[1].png
PNG image data, 640 x 640, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\jquery[1].js
ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\ms-logo-v2[1].jpg
[TIFF image data, little-endian, direntries=0], baseline, precision 8, 107x23, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\style[1].css
ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\~DF257C15DD974D822C.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF9BC2E7E69A1EB4AF.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFB0C0BCB97F6479BE.TMP
data
#