flash

Fennec Pharma .docx

Status: finished
Submission Time: 21.11.2020 02:05:58
Malicious
Phishing
HTMLPhisher

Comments

Tags

Details

  • Analysis ID:
    321374
  • API (Web) ID:
    544549
  • Analysis Started:
    21.11.2020 02:05:59
  • Analysis Finished:
    21.11.2020 02:20:17
  • MD5:
    e935876bc1daf073b5730cfef5ee1b6f
  • SHA1:
    2f0444a05ac3eca81313712825fec001efceb3ac
  • SHA256:
    494148b0b3b41783ae059b3344248b7ea1d5ce4a99f00c55f7631f9493d44483
  • Technologies:
Full Report Management Report Engine Info Verdict Score Reports

System: Windows 7 x64 SP1 with Office 2010 SP2 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2)

malicious
48/100

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
Run Condition: Potential for more IOCs and behavior

malicious
64/100

malicious

malicious

IPs

IP Country Detection
54.84.56.113
United States
97.107.137.245
United States
74.125.140.157
United States
Click to see the 2 hidden entries
52.217.4.102
United States
104.16.19.94
United States

Domains

Name IP Detection
workflowy.com
54.84.56.113
us-east-1.linodeobjects.com
97.107.137.245
s3.amazonaws.com
52.217.4.102
Click to see the 10 hidden entries
stats.l.doubleclick.net
74.125.140.157
cdnjs.cloudflare.com
104.16.19.94
ka-f.fontawesome.com
0.0.0.0
code.jquery.com
0.0.0.0
kit.fontawesome.com
0.0.0.0
js-agent.newrelic.com
0.0.0.0
maxcdn.bootstrapcdn.com
0.0.0.0
jamif-cdn3d.us-east-1.linodeobjects.com
0.0.0.0
bam-cell.nr-data.net
0.0.0.0
stats.g.doubleclick.net
0.0.0.0

URLs

Name Detection
https://jamif-cdn3d.us-east-1.linodeobjects.com/dfce06801e1a85d6d06f1fdd4475dacd.html
https://jamif-cdn3d.us-east-1.linodeobjects.com/dfce06801e1a85d6d06f1fdd4475dacd.html
http://weather.service.msn.com/data.aspx
Click to see the 97 hidden entries
https://sizzlejs.com/
https://word.uservoice.com/forums/304948-word-for-ipad-iphone-ios
https://workflowy.com/signup/?next=/s/this-document-is-too/Tdcv9KOl0AuohEPI
https://autodiscover-s.outlook.com/autodiscover/autodiscover.xml
https://clients.config.office.net/user/v1.0/ios
https://ka-f.fontawesome.com
https://bugs.jquery.com/ticket/12359
https://o365auditrealtimeingestion.manage.office.com
https://workflowy.com/s/this-document-is-too/Tdcv9KOl0AuohEPI#/7686a5f8c6e6
https://workflowy.com/media/i/favicon.ico
https://outlook.office365.com/api/v1.0/me/Activities
https://clients.config.office.net/user/v1.0/android/policies
http://www.amazon.com/
https://workflowy.com/s/this-document-is-too/Tdcv9KOl0AuohEPInThis
https://entitlement.diagnostics.office.com
https://pf.directory.live.com/profile/mine/WLX.Profiles.IC.json
http://www.twitter.com/
https://storage.live.com/clientlogs/uploadlocation
https://fontawesome.com/license/free
https://ukrainianpolicy.ru/Dee23ope11nov/next.php
https://www.google.%/ads/ga-audiences?
https://github.com/jquery/jquery/pull/557)
https://bugs.chromium.org/p/chromium/issues/detail?id=378607
https://graph.windows.net/
https://devnull.onenote.com
https://messaging.office.com/
https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Bing
https://skyapi.live.net/Activity/
http://www.nytimes.com/
https://drafts.csswg.org/cssom/#resolved-values
https://bugs.chromium.org/p/chromium/issues/detail?id=589347
https://workflowy.com/s/this-document-is-too/Tdcv9KOl0AuohEPI
https://visio.uservoice.com/forums/368202-visio-on-devices
https://code.jquery.com/jquery-3.1.1.min.js
https://onedrive.live.com/embed?
https://augloop.office.com
https://html.spec.whatwg.org/multipage/syntax.html#attributes-2
https://promisesaplus.com/#point-59
https://promisesaplus.com/#point-57
https://github.com/eslint/eslint/issues/3229
https://promisesaplus.com/#point-54
https://workflowy.com/s/this-doRoot
https://code.jquery.com/jquery-3.3.1.js
https://html.spec.whatwg.org/multipage/scripting.html#selector-disabled
https://api.diagnostics.office.com
https://jquery.org/license
https://store.office.de/addinstemplate
https://getbootstrap.com)
https://api.powerbi.com/v1.0/myorg/datasets
https://workflowy.com/referrals/
https://shell.suite.office.com:1443
https://stats.g.doubleclick.net/g/collect
https://code.jquery.com/jquery-3.2.1.slim.min.js
https://insertmedia.bing.office.net/images/officeonlinecontent/browse?cp=Flickr
https://cdn.entity.
https://dev.virtualearth.net/REST/V1/GeospatialEndpoint/
https://web.archive.org/web/20100324014747/http://blindsignals.com/index.php/2009/07/jquery-delay/
https://rpsticket.partnerservices.getmicrosoftkey.com
https://lookup.onenote.com/lookup/geolocation/v1
https://fontawesome.comhttps://fontawesome.comFont
https://html.spec.whatwg.org/multipage/forms.html#concept-fe-disabled
https://syncservice.protection.outlook.com/PolicySync/PolicySync.svc/SyncFile
https://na01.oscs.protection.outlook.com/api/SafeLinksApi/GetPolicy
https://api.aadrm.com/
https://infra.spec.whatwg.org/#strip-and-collapse-ascii-whitespace
https://fontawesome.com
https://workflowy.com/s/this-document-is-too/Tdcv9KOl0AuohEPI
https://github.com/twbs/bootstrap/graphs/contributors)
https://github.com/jrburke/requirejs/wiki/Updating-existing-libraries#wiki-anon
https://dataservice.protection.outlook.com/PsorWebService/v1/ClientSyncFile/MipPolicies
https://api.microsoftstream.com/api/
https://insertmedia.bing.office.net/images/hosted?host=office&adlt=strict&hostType=Immersive
https://cr.office.com
https://bugzilla.mozilla.org/show_bug.cgi?id=687787
https://stats.g.doubleclick.net/j/collect
https://bugs.chromium.org/p/chromium/issues/detail?id=470258
https://kit.fontawesome.com/585b051251.js
https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/js/bootstrap.min.js
http://www.reddit.com/
https://res.getmicrosoftkey.com/api/redemptionevents
https://tasks.office.com
https://officeci.azurewebsites.net/api/
https://store.office.cn/addinstemplate
https://workflowy.com/s/this-document-is-too/Tdcv9KOl0AuohEPI#/7686a5f8c6e6
https://wus2-000.pagecontentsync.
https://nam.learningtools.onenote.com/learningtoolsapi/v2.0/getfreeformspeech
https://www.odwebp.svc.ms
https://jsperf.com/getall-vs-sizzle/2
https://api.powerbi.com/v1.0/myorg/groups
https://web.microsoftstream.com/video/
https://graph.windows.net
https://jquery.com/
https://stats.g.doubleclick.net/j/collect?
https://pf.directory.live.com/profile/mine/System.ShortCircuitProfile.json
https://github.com/twbs/bootstrap/blob/master/LICENSE)
https://stats.g.doubleclick.net/g/collect?v=2&
https://webdir.online.lync.com/autodiscover/autodiscoverservice.svc/root/

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\dfce06801e1a85d6d06f1fdd4475dacd[1].htm
HTML document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\PTS75JZM\workflowy[1].xml
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{4F0DC65C-2BE2-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
#
Click to see the 74 hidden entries
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{4F0DC65E-2BE2-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{66CF5440-2BE2-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\ynfz0jx\imagestore.dat
data
#
C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\CAFA8CBC-8827-49EF-9BA3-5B2EB2C2B7DA
XML 1.0 document, UTF-8 Unicode text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\2D18C2DB.png
PNG image data, 96 x 96, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\2F482720.png
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\47E6D66C.wmf
Targa image data - Map - RLE 65536 x 65536 x 0 "\004"
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\75F7C857.png
PNG image data, 510 x 280, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\93CABA2E.png
PNG image data, 172 x 40, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\F860BCA1.png
PNG image data, 96 x 96, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.Word\~WRS{FABF639E-4792-4112-BF52-2B5E333F7251}.tmp
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.Word\~WRS{FE51252F-4CD4-4977-A57E-E1D5999F0844}.tmp
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\ZJH_2F3Xi0SopxxCuN7EKeDY[1].jpg
JPEG image data, baseline, precision 8, 1920x1080, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\css[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\css[2].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\document_view.min[1].js
UTF-8 Unicode text, with very long lines, with NEL line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\ga[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\login[1].htm
HTML document, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\mem5YaGs126MiZpBA-UN_r8OUuhv[1].woff
Web Open Font Format, TrueType, length 18668, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\mem8YaGs126MiZpBA-UFVZ0d[1].woff
Web Open Font Format, TrueType, length 18100, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\rC56cpX1uS2qJKOxJ-5Sb8u-[1].svg
SVG Scalable Vector Graphics image
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\585b051251[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\6f0b670eddaac85c5e4a[1].js
UTF-8 Unicode text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\Tdcv9KOl0AuohEPI[1].htm
HTML document, ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\adf9fc155506e2fa3fbf[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\bootstrap.min[1].css
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\bootstrap.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\eaeea54ab7[1].js
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\logo-bullet-lines-blue[1].svg
SVG Scalable Vector Graphics image
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\reset[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\signup[1].htm
HTML document, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\site.min[1].js
UTF-8 Unicode text, with very long lines, with LF, NEL line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\eaeea54ab7[1].gif
GIF image data, version 89a, 1 x 1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\favicon[1].ico
MS Windows icon resource - 6 icons, 256x256, 32 bits/pixel, 128x128, 32 bits/pixel
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\jquery-3.1.1.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\jquery-3.2.1.slim.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\jquery-3.3.1[1].js
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\jquery.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\js[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\login[1].htm
HTML document, ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\mem5YaGs126MiZpBA-UN7rgOUuhv[1].woff
Web Open Font Format, TrueType, length 18900, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\mem5YaGs126MiZpBA-UN8rsOUuhv[1].woff
Web Open Font Format, TrueType, length 19072, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\nr-1184.min[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\Tdcv9KOl0AuohEPI[1].htm
HTML document, ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\analytics[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\e42577a28f6c3e306a7f[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\eaeea54ab7[1].gif
GIF image data, version 89a, 1 x 1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\eaeea54ab7[1].js
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\free-fa-regular-400[1].eot
Embedded OpenType (EOT), Font Awesome 5 Free Regular family
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\free-fa-solid-900[1].eot
Embedded OpenType (EOT), Font Awesome 5 Free Solid family
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\free-v4-shims.min[1].css
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\free.min[1].css
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\js[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\js[2].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\popper.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\print[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\signup[1].htm
HTML document, ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Temp\mso7346.tmp
GIF image data, version 89a, 15 x 15
#
C:\Users\user\AppData\Local\Temp\~DF058B1B9EB731C27D.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF36F3C25722F1499C.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF6E9E146EF88F1592.TMP
data
#
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Fennec Pharma .docx.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Sep 30 14:03:41 2020, mtime=Sat Nov 21 09:13:47 2020, atime=Sat Nov 21 09:13:44 2020, length=49414, window=hide
#
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
data
#
C:\Users\user\Desktop\~$nnec Pharma .docx
data
#