flash

https://217251.8b.io/

Status: finished
Submission Time: 13.01.2021 21:30:34
Malicious
Phishing
HTMLPhisher

Comments

Tags

Details

  • Analysis ID:
    339355
  • API (Web) ID:
    580644
  • Analysis Started:
    13.01.2021 21:33:40
  • Analysis Finished:
    13.01.2021 21:38:25
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports
New

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
64/100

malicious

IPs

IP Country Detection
108.177.119.132
United States
51.79.98.105
Canada
52.7.227.232
United States
Click to see the 2 hidden entries
104.24.105.39
United States
104.24.104.39
United States

Domains

Name IP Detection
app.8b.io
104.24.104.39
avenirhomes.com
51.79.98.105
r.8b.io
104.24.105.39
Click to see the 4 hidden entries
proxy-8b-io-1762796164.us-east-1.elb.amazonaws.com
52.7.227.232
cdn-content.ampproject.org
108.177.119.132
cdn.ampproject.org
0.0.0.0
217251.8b.io
0.0.0.0

URLs

Name Detection
https://217251.8b.io/
https://avenirhomes.com/Paymentadvice/new/s/?signin=d41d8cd98f00b204e9800998ecf8427e&auth=c8fa2f9b74a88a59da9f7a1011b291d5be2837acfe48d4a938453ee0e10ca1e981936170
https://217251.8b.io/Root
Click to see the 24 hidden entries
https://app.8b.io/app/themes/webamp/projects/company/assets/images/logo.pngn
https://r.8b.io/217251/images/background5-h_kjvcr6x2.jpg
https://3p.ampproject.net
https://avenirhomes.com/Paymentadvice/new/
https://cdn.ampproject.org/v0/amp-analytics-0.1.js
https://217251.8b.io/
https://github.com/ampproject/amphtml/blob/master/spec/amp-iframe-origin-policy.md
https://217251.8b.io/L
https://cdn.ampproject.org/v0.js
https://cdn.ampproject.org
https://log.amp.dev/?v=012012301722001&id=
https://avenirhomes.coL
https://app.8b.io/app/themes/webamp/projects/company/assets/images/logo.png
https://mths.be/cssescape
https://avenirhomes.com/favicon.icoJ=
https://us-central1-amp-error-reporting.cloudfunctions.net/r
https://8b.com
https://amp.dev/documentation/guides-and-tutorials/develop/style_and_layout/control_layout
https://avenirhomes.com/Paymentadvice/new
https://avenirhomes.co
http://github.com/janl/mustache.js
https://avenirhomes.com/Paymentadvice/new/s/?signin=d41d8cd98f00b204e9800998ecf8427e&auth=c8fa2f9b74
https://cdn.ampproject.org/v0/amp-mustache-0.2.js
https://us-central1-amp-error-reporting.cloudfunctions.net/r-beta

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\s[1].htm
HTML document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\EQAWN5DV\217251.8b[1].xml
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{2D1690CF-562A-11EB-90E5-ECF4BB2D2496}.dat
Microsoft Word Document
#
Click to see the 24 hidden entries
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{2D1690D1-562A-11EB-90E5-ECF4BB2D2496}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{331FBFBE-562A-11EB-90E5-ECF4BB2D2496}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\wlm7n14\imagestore.dat
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\amp-auto-lightbox-0.1[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\amp-mustache-0.2[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\logo[1].png
PNG image data, 226 x 48, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\new[1].htm
HTML document, ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\amp-intersection-observer-polyfill-0.1[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\background5-h_kjvcr6x2[1].jpg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 1024x1001, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\css[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\logo[1].png
PNG image data, 150 x 150, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\amp-analytics-0.1[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\css[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\footer-logo-min-150x141[1].png
PNG image data, 150 x 141, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\v0[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\T08OXF6I.htm
HTML document, ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\ahcfv8qz1zt6hCC5G4F_P4ASlU-YoA[1].woff
Web Open Font Format, TrueType, length 27548, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\amp-loader-0.1[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\css[1].css
ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\pdf[1].png
PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Temp\datB730.tmp
Web Open Font Format, TrueType, length 2532, version 2.24904
#
C:\Users\user\AppData\Local\Temp\~DF50AF0D1DD5FFBE3A.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFAE0AF0D2B2A94533.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFCBDCB001D3AD68B8.TMP
data
#