top title background image
flash

https://f000.backblazeb2.com/file/cybernews-bot-3ae031b2/index.html

Status: finished
Submission Time: 2021-03-04 21:42:21 +01:00
Malicious
Phishing
HTMLPhisher

Comments

Tags

Details

  • Analysis ID:
    363573
  • API (Web) ID:
    629200
  • Analysis Started:
    2021-03-04 21:42:22 +01:00
  • Analysis Finished:
    2021-03-04 21:47:33 +01:00
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 56
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

IPs

IP Country Detection
172.67.206.183
United States
146.59.152.166
Norway
104.153.233.177
United States

Domains

Name IP Detection
f000.backblazeb2.com
104.153.233.177
plutosmto.com
172.67.206.183
i.ibb.co
146.59.152.166

URLs

Name Detection
https://f000.backblazeb2.com/file/cybernews-bot-3ae031b2/
https://f000.backblazeb2.com/file/cybernews-bot-3ae031b2/index.html
https://f000.backblazeb2.com/file/cybernews-bot-3ae031b2/index.html
Click to see the 27 hidden entries
https://f000.backblazeb2.com/file/cybernews-bot-3ae031b2/index.htmlRoot
https://plutosmto.com/email-list/dropox18/images/8.png
https://i.ibb.co/TtTg9r7/icon.png
https://plutosmto.com/email-list/dropox18/images/9.png
http://www.reddit.com/
https://plutosmto.com/email-list/dropox18/css/bootstrap.min.css
http://www.live.com/
http://www.wikipedia.com/
https://plutosmto.com/email-list/dropox18/images/5.png
https://f000.backb2.com/file/cybernews-bot-3ae031b2/ndex.htmlRoot
https://github.com/twbs/bootstrap/blob/master/LICENSE)
https://plutosmto.com/email-list/dropox18/css/style.css
http://getbootstrap.com)
http://www.youtube.com/
https://f000.backblaze
https://f000.backb2.com/file/cybernews-bot-3ae031b2/index.htmlRoot
https://plutosmto.com/email-list/dropox18/images/4.png
https://f000.backRoot
https://i.ibb.co/TtTg9r7/icon.pngM
https://plutosmto.com/email-list/dropox18/images/7.png
https://owy.mn/35MDuDz
http://www.twitter.com/
https://plutosmto.com/email-list/dropox18/images/3.png
http://www.amazon.com/
https://f000.backblazeb2.com/file/cybernews-bot-3ae031b2/ndex.html
https://plutosmto.com/email-list/dropox18/images/6.png
http://www.nytimes.com/

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\jquery.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\1[1].png
PNG image data, 1921 x 1086, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\5[1].png
PNG image data, 512 x 92, 8-bit/color RGBA, non-interlaced
#
Click to see the 34 hidden entries
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\9[1].png
PNG image data, 512 x 72, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\down[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\httpErrorPagesScripts[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\7[1].png
PNG image data, 512 x 82, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\8[1].png
PNG image data, 512 x 67, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\background_gradient[1]
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 1x800, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\bootstrap.min[1].css
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\style[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\3[1].png
PNG image data, 630 x 167, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\6[1].png
PNG image data, 512 x 85, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\bullet[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\errorPageStrings[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\http_400[1]
HTML document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\~DF7122CBD5AB624E6A.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFEAB4620B4967CC1D.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFFFE7CB61E25586DB.TMP
data
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{3677D61E-7D2A-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{3677D61F-7D2A-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{3677D61C-7D2A-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\gee00pr\imagestore.dat
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\4[1].png
PNG image data, 512 x 77, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\ErrorPageTemplate[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\icon[1].png
PNG image data, 640 x 595, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\index[1].htm
HTML document, ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\info_48[1]
PNG image data, 47 x 48, 8-bit/color RGBA, non-interlaced
#