flash

https://ishift.biz/ALTA/download.html

Status: finished
Submission Time: 10.06.2021 22:02:31
Malicious
Phishing
HTMLPhisher

Comments

Tags

Details

  • Analysis ID:
    432894
  • API (Web) ID:
    800498
  • Analysis Started:
    10.06.2021 22:02:31
  • Analysis Finished:
    10.06.2021 22:07:28
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
60/100

malicious

IPs

IP Country Detection
74.125.140.154
United States
104.27.48.115
United States
45.60.13.52
United States
Click to see the 1 hidden entries
162.241.121.59
United States

Domains

Name IP Detection
ishift.biz
162.241.121.59
w87gi54.x.incapdns.net
45.60.13.52
cdn2.downdetector.com
104.27.48.115
Click to see the 5 hidden entries
stats.l.doubleclick.net
74.125.140.154
lfsdujd.x.incapdns.net
45.60.13.52
cdn.clareitysecurity.net
0.0.0.0
collector.clareity.net
0.0.0.0
stats.g.doubleclick.net
0.0.0.0

URLs

Name Detection
https://ishift.biz/ALTA/download.htmll
https://ishift.biz/ALTA/download.html
https://ishift.biz/ALTA/download.htmlRoot
Click to see the 31 hidden entries
https://ishift.biz/ALTA/download.html
https://cdn.clareitysecurity.net/css/login.css
http://fontawesome.io
http://www.nytimes.com/
https://cdn.clareitysecurity.net/css/font-awesome-4.6.3.min.css
https://cdn.clareitysecurity.net/css/style-xkd.2.css
http://www.amazon.com/
https://cdn.clareitysecurity.net
https://cdn.clareitysecurity.net/sys/alberta/paragon-login-background.png)
https://cdn.clareitysecurity.net/fonts/password.ttf);
https://getbootstrap.com/)
http://www.twitter.com/
http://fontawesome.io/license
https://cdn.clareitysecurity.net/css/bootstrap-4.1.2.min.css
https://cdn.clareitysecurity.net/sys/alberta/paragon-login-bg.png)
https://www.google.%/ads/ga-audiences
https://cdn.clareitysecurity.net/images/linen.png)
https://collector.clareity.net
http://www.youtube.com/
http://getbootstrap.com)
https://cdn.clareitysecurity.net/js/script-xkd.2.js
https://github.com/twbs/bootstrap/blob/master/LICENSE)
https://cdn2.downdetector.com/static/uploads/logo/outlook-com-logo.png
http://www.wikipedia.com/
https://cdn.clareitysecurity.net/images/ajax.gif);width:16px;height:16px;margin:0
https://stats.g.doubleclick.net/j/collect
http://www.live.com/
https://cdn.clareitysecurity.net/js/bootstrap.min.js
https://cdn.clareitysecurity.net/js/jquery-3.3.1.min.js
http://www.reddit.com/
https://cdn.clareitysecurity.net/sys/alberta/googletrack.js

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\download[1].htm
HTML document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{54BE78B6-CA72-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{54BE78B8-CA72-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
#
Click to see the 32 hidden entries
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{54BE78B9-CA72-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\KFOlCnqEu92Fr1MmWUlfBBc-[1].woff
Web Open Font Format, TrueType, length 20396, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\bootstrap.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\fontawesome-webfont[1].eot
Embedded OpenType (EOT), FontAwesome family
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\script-xkd.2[1].js
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\style-xkd.2[1].css
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\bootstrap-4.1.2.min[1].css
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\font-awesome-4.6.3.min[1].css
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\googletrack[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\login[1].css
assembler source, ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\password[1].ttf
TrueType Font data, digitally signed, 20 tables, 1st "DSIG", 67 names, Unicode, type 1 string
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\ALTA[1].htm
HTML document, ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\KFOmCnqEu92Fr1Mu4mxM[1].woff
Web Open Font Format, TrueType, length 20332, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\analytics[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\jquery-3.3.1.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\outlook-com-logo[1].png
PNG image data, 587 x 115, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\KFOlCnqEu92Fr1MmSU5fBBc-[1].woff
Web Open Font Format, TrueType, length 20404, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\css[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\paragon-login-background[1].png
PNG image data, 2100 x 1612, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\paragon-login-bg[1].png
PNG image data, 600 x 461, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Temp\~DF35CFB899C4618C4B.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFD05493EFF0DF9AEE.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFE2C3B5B1199B26B2.TMP
data
#