flash

https://www.kilpatrick-executive.com/xfile1/

Status: finished
Submission Time: 13.01.2021 19:42:25
Malicious
Phishing
HTMLPhisher

Comments

Tags

Details

  • Analysis ID:
    339279
  • API (Web) ID:
    580479
  • Analysis Started:
    13.01.2021 19:42:25
  • Analysis Finished:
    13.01.2021 19:45:37
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports
New

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
68/100

IPs

IP Country Detection
91.213.11.127
Romania
104.16.19.94
United States

Domains

Name IP Detection
cdnjs.cloudflare.com
104.16.19.94
kilpatrick-executive.com
91.213.11.127
ka-f.fontawesome.com
0.0.0.0
Click to see the 5 hidden entries
code.jquery.com
0.0.0.0
www.kilpatrick-executive.com
0.0.0.0
kit.fontawesome.com
0.0.0.0
maxcdn.bootstrapcdn.com
0.0.0.0
favicon.ico
0.0.0.0

URLs

Name Detection
https://www.kilpatrick-executive.com/xfile1/z
https://www.kilpatrick-executive.com/xfile1/
https://www.kilpatrick-executive.com/xfile1/$Share
Click to see the 22 hidden entries
https://www.kilpatrick-executive.com/xfile1/
https://www.kilpatrick-executive.com/xfile1/Root
https://www.kilpatrick-executive.com/favicon.ico
http://ianlunn.github.io/Hover/)
https://ka-f.fontawesome.com
https://code.jquery.com/jquery-3.2.1.slim.min.js
https://code.jquery.com/jquery-3.1.1.min.js
https://code.jquery.com/jquery-3.3.1.js
https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/css/bootstrap.min.css
https://fontawesome.com/license/free
https://fontawesome.com
https://kit.fontawesome.com
https://github.com/twbs/bootstrap/graphs/contributors)
https://cdnjs.cloudflare.com/ajax/libs/popper.js/1.12.9/umd/popper.min.js
https://login.microsoftonline.com/common/login
https://getbootstrap.com)
http://ianlunn.co.uk/
https://github.com/twbs/bootstrap/blob/master/LICENSE)
https://github.com/IanLunn/Hover
http://opensource.org/licenses/MIT).
https://kit.fontawesome.com/585b051251.js
https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/js/bootstrap.min.js

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\xfile1[1].htm
HTML document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\585b051251[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\adobe[1].jpg
JPEG image data, JFIF standard 1.02, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 400x400, frames 3
#
Click to see the 23 hidden entries
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\hover[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\office3651[1].png
PNG image data, 187 x 188, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\w-logo-blue-white-bg[1].png
PNG image data, 80 x 80, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Temp\~DF242C40FDCA1BED89.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF88F6808F3CD3FE9E.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF951FE95ED34B02A2.TMP
data
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{9EC321F1-561A-11EB-90E5-ECF4BB570DC9}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{9EC321F3-561A-11EB-90E5-ECF4BB570DC9}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{9EC321F4-561A-11EB-90E5-ECF4BB570DC9}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\dikxvqf\imagestore.dat
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\gmail[1].png
PNG image data, 1280 x 1280, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\jquery-3.1.1.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\jquery-3.2.1.slim.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\other1[1].png
PNG image data, 190 x 187, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\popper.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\8[1].jpg
[TIFF image data, big-endian, direntries=12, height=709, bps=0, PhotometricIntepretation=RGB, orientation=upper-left, width=1200], baseline, precision 8, 1200x646, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\bootstrap.min[1].css
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\bootstrap.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\jquery.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\css[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\free-v4-shims.min[1].css
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\free.min[1].css
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\outlook1[1].png
PNG image data, 26 x 26, 8-bit/color RGBA, non-interlaced
#