flash

https://securemailcenter.citigroup.com/branding/citi/emx/images/emailBanner.gif

Status: finished
Submission Time: 11.06.2021 06:49:00
Clean

Comments

Tags

Details

  • Analysis ID:
    433023
  • API (Web) ID:
    800627
  • Analysis Started:
    11.06.2021 06:49:00
  • Analysis Finished:
    11.06.2021 06:52:26
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

clean
0/100

IPs

IP Country Detection
192.193.154.4
United States

Domains

Name IP Detection
securemailcenter.citigroup.com
192.193.154.4

URLs

Name Detection
https://securemailcenter.citigroup.com/branding/citi/emx/images/emailBanner.gif
http://www.wikipedia.com/
http://www.amazon.com/
Click to see the 7 hidden entries
http://www.nytimes.com/
http://www.live.com/
https://securemailcenter.citigroup.com/branding/citi/emx/images/emailBanner.gif
http://www.reddit.com/
http://www.twitter.com/
http://www.youtube.com/
https://securemailcenter.citigroup.com/branding/citi/emx/images/emailBanner.gifRoot

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{72BD4AA8-CA70-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{72BD4AAA-CA70-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{72BD4AAB-CA70-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
#
Click to see the 13 hidden entries
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\emailBanner[1].gif
GIF image data, version 89a, 150 x 68
#
C:\Users\user\AppData\Local\Temp\~DF280D04EE554E50CF.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF2B830054C2999F0C.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF4E2977DE7B6AC2F0.TMP
data
#