top title background image
flash

https://securemailcenter.citigroup.com/branding/citi/emx/images/emailBanner.gif

Status: finished
Submission Time: 2021-06-11 06:49:00 +02:00
Clean

Comments

Tags

Details

  • Analysis ID:
    433023
  • API (Web) ID:
    800627
  • Analysis Started:
    2021-06-11 06:49:00 +02:00
  • Analysis Finished:
    2021-06-11 06:52:26 +02:00
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
clean
Score: 0
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

IPs

IP Country Detection
192.193.154.4
United States

Domains

Name IP Detection
securemailcenter.citigroup.com
192.193.154.4

URLs

Name Detection
https://securemailcenter.citigroup.com/branding/citi/emx/images/emailBanner.gif
http://www.wikipedia.com/
http://www.amazon.com/
Click to see the 7 hidden entries
http://www.nytimes.com/
http://www.live.com/
https://securemailcenter.citigroup.com/branding/citi/emx/images/emailBanner.gif
http://www.reddit.com/
http://www.twitter.com/
http://www.youtube.com/
https://securemailcenter.citigroup.com/branding/citi/emx/images/emailBanner.gifRoot

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{72BD4AA8-CA70-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{72BD4AAA-CA70-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{72BD4AAB-CA70-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
#
Click to see the 13 hidden entries
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\emailBanner[1].gif
GIF image data, version 89a, 150 x 68
#
C:\Users\user\AppData\Local\Temp\~DF280D04EE554E50CF.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF2B830054C2999F0C.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF4E2977DE7B6AC2F0.TMP
data
#