top title background image
flash

https://217023.8b.io/

Status: finished
Submission Time: 2021-01-13 19:23:36 +01:00
Malicious
Phishing
HTMLPhisher

Comments

Tags

Details

  • Analysis ID:
    339270
  • API (Web) ID:
    580461
  • Analysis Started:
    2021-01-13 19:23:36 +01:00
  • Analysis Finished:
    2021-01-13 19:27:19 +01:00
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 56
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious

IPs

IP Country Detection
108.177.119.132
United States
104.146.245.41
United States
195.181.244.134
Lithuania
Click to see the 2 hidden entries
52.201.120.251
United States
104.24.104.39
United States

Domains

Name IP Detection
app.8b.io
104.24.104.39
lacecompound.com
195.181.244.134
r.8b.io
104.24.104.39
Click to see the 6 hidden entries
proxy-8b-io-1762796164.us-east-1.elb.amazonaws.com
52.201.120.251
cdn-content.ampproject.org
108.177.119.132
17825-ipv4.farm.prod.aa-rt.sharepoint.com
104.146.245.41
vikinggenetics-my.sharepoint.com
0.0.0.0
cdn.ampproject.org
0.0.0.0
217023.8b.io
0.0.0.0

URLs

Name Detection
https://lacecompound.com/sm/mfile/.Sharing
https://lacecompound.com/sm/mfile/L
https://lacecompound.com/sm/mfile/
Click to see the 24 hidden entries
https://lacecompound.com/sm/mfile/Root
https://lacecompound.com/sm/mfile/
https://217023.8b.io/
https://us-central1-amp-error-reporting.cloudfunctions.net/r-beta
https://cdn.ampproject.org/v0/amp-mustache-0.2.js
https://217023.8b.io/Root
https://spoprod-a.akamaihd.net
https://217023.8b.io/
http://github.com/janl/mustache.js
https://lacecompound.c
https://vikinggenetics-my.sharepoint.com/personal/datho_vikinggenetics_com_au/_layouts/15/images/pdf
https://amp.dev/documentation/guides-and-tutorials/develop/style_and_layout/control_layout
https://8b.com
https://us-central1-amp-error-reporting.cloudfunctions.net/r
https://mths.be/cssescape
https://app.8b.io/app/themes/webamp/projects/writer/assets/images/logo1.png
https://log.amp.dev/?v=012012301722001&id=
https://cdn.ampproject.org
https://cdn.ampproject.org/v0.js
https://github.com/ampproject/amphtml/blob/master/spec/amp-iframe-origin-policy.md
https://r.8b.io/217023/images/background5-h_kjukqdlq.jpg
https://cdn.ampproject.org/v0/amp-analytics-0.1.js
https://3p.ampproject.net
https://lacecompound.com/sm/mfile

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\mfile[1].htm
HTML document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\~DFE679E51CD7555755.TMP
data
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\ABBRNDE4\217023.8b[1].xml
ASCII text, with no line terminators
#
Click to see the 21 hidden entries
C:\Users\user\AppData\Local\Temp\~DFBBCE481DAF4343C1.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF35D918A5D4402B2C.TMP
data
#
C:\Users\user\AppData\Local\Temp\datBA90.tmp
Web Open Font Format, TrueType, length 2532, version 2.24904
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\mfile[1].htm
HTML document, ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\amp-auto-lightbox-0.1[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\6aey4Ky-Vb8Ew8IROpQ[1].woff
Web Open Font Format, TrueType, length 30208, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\03OIYGP2.htm
HTML document, ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\logo1[1].png
PNG image data, 150 x 150, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\amp-mustache-0.2[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\amp-intersection-observer-polyfill-0.1[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\css[2].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\css[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\amp-loader-0.1[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\v0[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\pdf[1].png
PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\background5-h_kjukqdlq[1].jpg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 1446x1410, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\amp-analytics-0.1[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\ynfz0jx\imagestore.dat
data
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{FDCDEC84-5617-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{FDCDEC83-5617-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{FDCDEC81-5617-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
#