top title background image
flash

https://mobile1austin.com/Title-docs/RD-FITT

Status: finished
Submission Time: 2021-01-27 20:32:43 +01:00
Malicious
Phishing
HTMLPhisher

Comments

Tags

Details

  • Analysis ID:
    345209
  • API (Web) ID:
    592332
  • Analysis Started:
    2021-01-27 20:36:12 +01:00
  • Analysis Finished:
    2021-01-27 20:41:42 +01:00
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 68
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious

IPs

IP Country Detection
162.241.70.248
United States
151.101.1.192
United States
192.229.221.185
United States
Click to see the 1 hidden entries
104.16.18.94
United States

Domains

Name IP Detection
microsoftwindows.112.2o7.net
15.237.76.117
cdnjs.cloudflare.com
104.16.18.94
cs1227.wpc.alphacdn.net
192.229.221.185
Click to see the 10 hidden entries
liveperson.map.fastly.net
151.101.1.192
mobile1austin.com
162.241.70.248
stackpath.bootstrapcdn.com
0.0.0.0
logincdn.msauth.net
0.0.0.0
code.jquery.com
0.0.0.0
publisher.liveperson.net
0.0.0.0
maxcdn.bootstrapcdn.com
0.0.0.0
assets.onestore.ms
0.0.0.0
ajax.aspnetcdn.com
0.0.0.0
mem.gfx.ms
0.0.0.0

URLs

Name Detection
https://mobile1austin.com/Title-docs/RD-FITT/
https://mobile1austin.com/Title-docs/RD-FITT/Root
https://mobile1austin.com/Title-docs/RD-FITT/
Click to see the 85 hidden entries
https://lpcdn.lpsnmedia.net/le_unified_window/9.12.0.19-release_4769/resources/loader_on_warmGray5_7
https://cdnjs.cloudflare.com/ajax/libs/popper.js/1.12.9/umd/popper.min.js
https://schema.org/ItemList
http://github.com/requirejs/domReady
https://release.moscnuat.com
https://mem.gfx.ms
https://getbootstrap.com/)
https://www.clicktale.net/disable.html
https://www.microsoftstore.com.cn/software/microsoft-365
https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/adequacy-protectio
https://www.xbox.com
https://stackpath.bootstrapcdn.com/bootstrap/4.1.3/js/bootstrap.min.js
https://mobile1austin.com/Title-Root
https://www.youtube.com/user/MicrosoftCH
https://aka.ms/kinectprivacy/
https://www.microsoftstore.com.cn/surface
http://fontello.com
https://developer.yahoo.com/flurry/end-user-opt-out/
https://www.microsoftstore.com.cn/hardware/xbox
https://www.microsoftstore.com.cn/cart
https://www.xbox.com/
https://www.microsoftstore.com.cn/microsoft-365/microsoft-365
https://www.xbox.com/Legal/ThirdPartyDataSharing
https://support.xbox.com/help/friends-social-activity/community/use-safety-settings
https://aka.ms/DPA
https://channel9.msdn.com/
http://schema.org/Organization
https://www.linkedin.com/legal/privacy-policy
https://logo.clearbit.com/
https://github.com/h5bp/html5-boilerplate/blob/master/src/css/main.css
http://github.com/aFarkas/lazysizes
https://twitter.com/microsoft_ch
https://github.com/twbs/bootstrap/blob/master/LICENSE)
https://www.microsoftstore.com.cn/hardware/accessories/surface
https://www.linkedin.com/company/1035
https://www.microsoft.
https://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager.html
https://support.xbox.com/help/family-online-safety/online-safety/manage-online-safety-and-privacy-se
https://getbootstrap.com)
http://fontello.comiconsRegulariconsiconsVersion
https://va.msg.liveperson.net
http://www.asp.net/ajaxlibrary/CDN.ashx.
https://privacy.micros
https://www.appsflyer.com/optout
https://www.microsoftstore.com.cn/xbox
https://ondemand.webtrends.com/support/optout.asp
https://github.com/twbs/bootstrap/graphs/contributors)
https://www.privacyshield.gov/welcome
https://va.idp.liveperson.net
https://mem.gfx.ms/meversion?partner=MSHomePage&market=de-ch&uhf=1
https://publisher.liveperson.net/iframe-le-tag/iframe.html?lpsite=60270350&lpsection=store-sales
https://www.microsoftstore.com.cn/hardware/accessories/xbox
https://www.appnexus.com/
https://www.skype.com/de/
https://www.youradchoices.ca/fr
https://assets.onestore.ms
https://products.office.com/de-ch/academic/compare-office-365-education-plans
https://www.optimizely.com/legal/opt-out/
https://code.jquery.com/jquery-3.2.1.slim.min.js
https://www.acuityads.com/opt-out/
https://login.skype.com/login
https://www.onenote.com/?omkt=de-CH
https://signin.kissmetrics.com/privacy/#controls
https://www.here.com/)
https://lpcdn.lpsnmedia.net
http://github.com/requirejs/requirejs/LICENSE
https://www.xbox.com/legal/codeofconduct
https://www.xbox.com/managedatacollection
https://onedrive.live.com/about/de-ch/
https://microsoftwindows.112.2o7.net
https://www.adjust.com/opt-out/
https://www.aboutads.info/
http://www.apache.org/licenses/LICENSE-2.0
https://www.microsoftstore.com.cn/checkout
https://outlook.live.com/owa/
https://www.youronlinechoices.com/
http://github.com/requirejs/almond/LICENSE
https://priv-policy.imrworldwide.com/priv/browser/us/en/optout.html
https://www.youradchoices.ca
https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/js/bootstrap.min.js
http://opensource.org/licenses/MIT).
https://publisher.liveperson.net
https://publisher.liveperson.net/iframe-le-tag/iframe.html?lpsite=60270350&lpsection=store-sales-de-
https://www.microsoftstore.com.cn/hardware/surface
https://www.instagram.com/microsoftch/

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0MX4YUS9\RD-FITT[1].htm
HTML document, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6M6D1PMD\latest[1].woff2
Web Open Font Format (Version 2), TrueType, length 34052, version 0.0
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VAHFWDJC\94-3cd1e0[1].js
ASCII text, with very long lines, with no line terminators
#
Click to see the 72 hidden entries
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VAHFWDJC\1x1clear[1].gif
GIF image data, version 89a, 1 x 1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6M6D1PMD\twitter[1].png
PNG image data, 32 x 32, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6M6D1PMD\social[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6M6D1PMD\shell.min[1].css
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6M6D1PMD\script[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6M6D1PMD\popper.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6M6D1PMD\override[1].css
ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6M6D1PMD\meCore.min[1].js
ASCII text, with very long lines, with CRLF, LF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VAHFWDJC\RE4qP8j[1].wdp
JPEG-XR
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6M6D1PMD\jquery.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6M6D1PMD\facebook[1].png
PNG image data, 32 x 32, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6M6D1PMD\cartcount[1].htm
HTML document, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6M6D1PMD\bootstrap.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6M6D1PMD\app[1].css
ASCII text, with very long lines, with CRLF, LF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6M6D1PMD\RE4qZxW[1].wdp
JPEG-XR
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6M6D1PMD\RE4Lp94[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 1600x600, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6M6D1PMD\RE4H9G0[1].wdp
JPEG-XR
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VAHFWDJC\latest[2].eot
Embedded OpenType (EOT), Segoe UI Light family
#
C:\Users\user\AppData\Local\Temp\~DFF7B174168F5A2A9B.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF6BD5A81276D497A5.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF17965F7F81DA087C.TMP
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VAHFWDJC\wcp-consent[1].js
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VAHFWDJC\style[1].css
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VAHFWDJC\privacystatement[1].htm
HTML document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VAHFWDJC\mwfmdl2-v3.54[1].woff
Web Open Font Format, TrueType, length 26288, version 0.0
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VAHFWDJC\latest[3].eot
Embedded OpenType (EOT), Segoe UI Semibold family
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6M6D1PMD\RD-FITT[1].htm
HTML document, ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VAHFWDJC\latest[1].eot
Embedded OpenType (EOT), Segoe UI family
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VAHFWDJC\iframe[1].htm
HTML document, ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VAHFWDJC\fb-083993[1].css
UTF-8 Unicode text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VAHFWDJC\favicon[1].ico
MS Windows icon resource - 6 icons, 128x128, 16 colors, 72x72, 16 colors
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VAHFWDJC\bootstrap.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VAHFWDJC\a4-539297[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VAHFWDJC\RE4rzE2[1].wdp
JPEG-XR
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VAHFWDJC\RE4rriw[1].png
PNG image data, 40 x 40, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0MX4YUS9\RE4E4rT[1].wdp
JPEG-XR
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0MX4YUS9\youtube[1].png
PNG image data, 32 x 32, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0MX4YUS9\social[1].css
UTF-8 Unicode text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0MX4YUS9\print-icon[1].png
PNG image data, 16 x 16, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0MX4YUS9\meBoot.min[1].js
ASCII text, with very long lines, with CRLF, LF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0MX4YUS9\latest[1].woff
Web Open Font Format, TrueType, length 35900, version 0.0
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0MX4YUS9\jquery-3.3.1.min[1].js
ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0MX4YUS9\de-ch[1].htm
HTML document, UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0MX4YUS9\RE4sQDc[1].png
PNG image data, 40 x 40, 2-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0MX4YUS9\RE4pndL[1].png
PNG image data, 40 x 40, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2K7JPOQS\MeControl_cfDm2fEwfL1YuSiw8j6tzA2[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0MX4YUS9\RE4DRie[1].png
PNG image data, 1259 x 472, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0MX4YUS9\RE4D5uF[1].png
PNG image data, 1259 x 472, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0MX4YUS9\RE1Mu3b[1].png
PNG image data, 216 x 46, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0MX4YUS9\65-478888[1].css
UTF-8 Unicode (with BOM) text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0MX4YUS9\50-f1e180[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\po60zt0\imagestore.dat
data
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{8025F276-6122-11EB-90E6-ECF4BB82F7E0}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{78D3FB75-6122-11EB-90E6-ECF4BB82F7E0}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2K7JPOQS\instagram[1].png
PNG image data, 32 x 32, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{78D3FB73-6122-11EB-90E6-ECF4BB82F7E0}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2K7JPOQS\okta-sign-in.min[1].css
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2K7JPOQS\meversion[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2K7JPOQS\me[1].htm
HTML document, ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2K7JPOQS\linkedin[1].png
PNG image data, 32 x 32, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2K7JPOQS\jsll-4[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2K7JPOQS\jquery-3.2.1.slim.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2K7JPOQS\jquery-1.11.2.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6M6D1PMD\RE4CFyx[1].wdp
JPEG-XR
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2K7JPOQS\icons[1].eot
Embedded OpenType (EOT), icons family
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2K7JPOQS\favicon[1].ico
MS Windows icon resource - 6 icons, 128x128, 16 colors, 72x72, 16 colors
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2K7JPOQS\e3-082b89[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2K7JPOQS\clipart1110398[1].png
PNG image data, 460 x 390, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2K7JPOQS\RE4pxBu[1].png
PNG image data, 40 x 40, 8-bit gray+alpha, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2K7JPOQS\RE4pkvE[1].png
PNG image data, 40 x 40, 8-bit gray+alpha, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2K7JPOQS\RE4DfTp[1].wdp
JPEG-XR
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2K7JPOQS\RE3NYMe[1].wdp
JPEG-XR
#