top title background image
flash

RemitSwift119353 xlsx.htm

Status: finished
Submission Time: 2021-04-12 09:27:11 +02:00
Malicious
Phishing
Evader
HTMLPhisher

Comments

Tags

Details

  • Analysis ID:
    385276
  • API (Web) ID:
    672670
  • Analysis Started:
    2021-04-12 09:29:49 +02:00
  • Analysis Finished:
    2021-04-12 09:37:15 +02:00
  • MD5:
    ca3a56c1d6eebe70576bb7196f53b1d0
  • SHA1:
    72d5d6ef29bd345f17dcff7c299f47558e745d3e
  • SHA256:
    3a6422545bcba48ce42dcbce1838b7042d8e5546f2ae527af18e7cd8b53ee879
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 88
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 12/59

IPs

IP Country Detection
217.160.0.18
Germany
192.229.221.185
United States
152.199.23.37
United States

Domains

Name IP Detection
cs1100.wpc.omegacdn.net
152.199.23.37
cs1227.wpc.alphacdn.net
192.229.221.185
raktaxis.co.uk
217.160.0.18
Click to see the 5 hidden entries
logincdn.msauth.net
0.0.0.0
clientconfig.passport.net
0.0.0.0
aadcdn.msftauth.net
0.0.0.0
ajax.aspnetcdn.com
0.0.0.0
privacy.microsoft
0.0.0.0

URLs

Name Detection
https://privacy.microsoft./en-GB/privacystatement
file:///C:/Users/user/Desktop/RemitSwift119353%20xlsx.htm
file:///C:/Users/user/Desktop/RemitSwift119353%20xlsx.htm?rand=13InboxLightaspxn.1774256418&fid.4.1252899642&fid=1&fav.1&rand.13InboxLight.aspxn.1774256418&fid.1252899642&fid.1&fav.1&email=gunnar.grech@go.com.mt&loginpage=&.rand=13InboxLight.aspx?n=1774256418&fid=4
Click to see the 17 hidden entries
https://mixer.com/contact
https://www.skype.com/go/store.reactivate.credit
https://privacy.microsoft./en-GB/privacystatementsx.htm?rand=13InboxLightaspxn.1774256418&fid.4.1252
http://github.com/requirejs/almond/LICENSE
https://www.skype.com/go/emergency/
https://ec.europa.eu/consumers/odr);
https://www.skype.com/go/emergency
https://www.microsoft.
https://privacy.microsoft./en-GB/privacystatement
https://www.skype.com/go/legal
https://privacy.micros
https://www.xbox.com/xbox-game-studios)
https://www.xbox.com/xbox-game-studios
https://www.skype.com/go/legal.broadcast
https://ec.europa.eu/consumers/odr
https://aka.ms/redeemrewards
https://www.skype.com/go/allrates

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\servicesagreement[1].htm
HTML document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\~DFFED1E8E288005E12.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFA4B72BDCB6871BC2.TMP
data
#
Click to see the 28 hidden entries
C:\Users\user\AppData\Local\Temp\~DF21D4BF00FAEEC794.TMP
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\mwfmdl2-v3.54[1].woff
Web Open Font Format, TrueType, length 26288, version 0.0
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\jquery-1.7.2.min[1].js
HTML document, UTF-8 Unicode text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\favicon[1].ico
MS Windows icon resource - 6 icons, 128x128, 16 colors, 72x72, 16 colors
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\errorPageStrings[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\RE1Mu3b[1].png
PNG image data, 216 x 46, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\0_pdvuot_2pyxh5ith335y8a2[1].jpg
JPEG image data, baseline, precision 8, 1920x1080, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\wcp-consent[1].js
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\script[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\override[1].css
ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\down[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\NewErrorPageTemplate[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\17-f90ef1[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{FB42B5BF-9B60-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\latest[2].eot
Embedded OpenType (EOT), Segoe UI Light family
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\latest[1].eot
Embedded OpenType (EOT), Segoe UI family
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\httpErrorPagesScripts[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\dnserror[1]
HTML document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\d7-808fb1[1].css
UTF-8 Unicode text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\style[1].css
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\script[1].js
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\microsoft_logo_ee5c8d9fb6248c938fd0dc19370e90bd[1].svg
SVG Scalable Vector Graphics image
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\arrow_px_up[1].gif
GIF image data, version 89a, 7 x 9
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\Print[1].png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\Converged_v21033_AZXChPIB5jI3ijrmoNll5w2[1].css
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\gee00pr\imagestore.dat
data
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{FB42B5C2-9B60-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{FB42B5C1-9B60-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
#