top title background image
flash

2C.TA9.HTML

Status: finished
Submission Time: 2021-08-03 21:12:50 +02:00
Malicious
Phishing
Trojan
Captcha Phish Phisher

Comments

Tags

Details

  • Analysis ID:
    458909
  • API (Web) ID:
    826478
  • Analysis Started:
    2021-08-03 21:12:50 +02:00
  • Analysis Finished:
    2021-08-03 21:20:06 +02:00
  • MD5:
    f992926d793e7f037e2e67b509074c7c
  • SHA1:
    1bedb7efec16ebece693e664be8bd4dbb9eec089
  • SHA256:
    b3359fc613eabce35295396413a7ec332676c4e7b8e73f6060ad0bc0591f0e4a
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 68
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

IPs

IP Country Detection
111.90.141.176
Malaysia
216.58.208.174
United States
216.58.212.131
United States
Click to see the 5 hidden entries
216.58.205.77
United States
104.18.11.207
United States
239.255.255.250
Reserved
216.58.208.129
United States
142.250.180.164
United States

Domains

Name IP Detection
globalfoundries.com.re3jp-wrz.xyz
111.90.141.176
stackpath.bootstrapcdn.com
104.18.11.207
gstaticadssl.l.google.com
216.58.212.131
Click to see the 6 hidden entries
accounts.google.com
216.58.205.77
www.google.com
142.250.180.164
clients.l.google.com
216.58.208.174
googlehosted.l.googleusercontent.com
216.58.208.129
clients2.googleusercontent.com
0.0.0.0
clients2.google.com
0.0.0.0

URLs

Name Detection
http://globalfoundries.com.re3jp-wrz.xyz/main/
http://globalfoundries.com.re3jp-wrz.xyz
https://www.google.com/recaptcha/api2/bframe?hl=en&v=ecapuzyywmdXQ5gJHS3JQiXe&k=6LfE21AbAAAAABuaxwNL
Click to see the 46 hidden entries
https://payments.google.com/payments/v4/js/integrator.js
https://www.google.com;
https://hangouts.google.com/
http://globalfoundries.com.re3jp-wrz.xyz/?e=eric.lutz
http://globalfoundries.com.re3jp-wrz.xyz/main/1
https://google.com/
http://globalfoundries.com.re3jp-wrz.xyz/main/2
https://developers.google.com/recaptcha/docs/faq#my-computer-or-network-may-be-sending-automated-que
https://stackpath.bootstrapcdn.com
https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfE21AbAAAAABuaxwNLt5GCnVJ7gdUxL6W8nOFp&co=aHR0
https://play.google.com/log?format=json&hasfast=true
https://ogs.google.com
http://globalfoundries.com.re3jp-wrz.xyzh
https://support.google.com/chromecast/answer/2998456
https://clients2.googleusercontent.com
https://csp.withgoogle.com/csp/report-to/IdentityListAccountsHttp/external
https://www.google.com/recaptcha/api2/bframe?hl=en&v=ecapuzyywmdXQ5gJHS3JQiXe&k=6LfE21AbAAAAABuaxwNLt5GCnVJ7gdUxL6W8nOFp&cb=g6ylkpiplfg8
http://globalfoundries.com.re3jp-wrz.xyz/main
https://www.google.com/
https://feedback.googleusercontent.com
http://re3jp-wrz.xyz/
https://clients2.google.com/service/update2/crx
http://globalfoundries.com.re3jp-wrz.xyz/favicon.ico
http://globalfoundries.com.re3jp-wrz.xyz/main/
https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfE21AbAAAAABuaxwNLt5GCnVJ7gdUxL6W8nOFp&co=aHR0cDovL2dsb2JhbGZvdW5kcmllcy5jb20ucmUzanAtd3J6Lnh5ejo4MA..&hl=en&v=ecapuzyywmdXQ5gJHS3JQiXe&size=normal&cb=d6j6dp5xa3ao
https://play.google.com
http://globalfoundries.com.re3jp-wrz.xyz/main2
https://www.google.com/log?format=json&hasfast=true
http://globalfoundries.com.re3jp-wrz.xyz/main/main.php
https://sandbox.google.com/payments/v4/js/integrator.js
https://www.google.com
https://www.google.com//
http://globalfoundries.com.re3jp-wrz.xyz/mainN
https://accounts.google.com
https://support.google.com/chromecast/troubleshooter/2995236
https://www.google.comh
http://globalfoundries.com.re3jp-wrz.xyz/?e=eric.lutz@globalfoundries.com
http://globalfoundries.com.re3jp-wrz.xyz/main/2:
https://apis.google.com
https://www.google.com/recaptcha/api2/
http://globalfoundries.com.re3jp-wrz.xyz/main2:
https://clients2.google.com
https://support.google.com/recaptcha
http://globalfoundries.com.re3jp-wrz.xyz/main//
https://dns.google
https://www.google.com0(http://globalfoundries.com.re3jp-wrz.xyzh

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\LOG.old (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old. (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG
ASCII text
#
Click to see the 97 hidden entries
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000003.log
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Secure Preferenceswe (copy)
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Secure Preferencesjs (copy)
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences (copy)
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Reporting and NEL-journal
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Reporting and NEL
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\QuotaManager-journal
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\QuotaManager
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\PreferencesxC (copy)
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Preferences (copy)
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\LOG
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State3} (copy)
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State (copy)
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\000003.log
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Last Tabsfi (copy)
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Last Session.. (copy)
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\History-journal
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\History
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\GPUCache\data_1
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old.. (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000003.log
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\f961e598-159c-400b-ad4d-1c28a1f2da7a.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Session Storage\LOG.old. (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Session Storage\LOG
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Session Storage\000003.log
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Platform Notifications\LOG.old (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Platform Notifications\LOG
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Network Persistent Statemp (copy)
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Local Storage\leveldb\LOG.old (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Local Storage\leveldb\LOG
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG.old.. (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\c4efc7a7-9cba-4c2b-9a6e-543d7e0eda9d.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Session Storage\LOG.olds (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Session Storage\LOG
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Session Storage\000003.log
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Platform Notifications\LOG.old (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Platform Notifications\LOG
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Network Persistent State.. (copy)
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Local Storage\leveldb\LOG.old (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Local Storage\leveldb\LOG
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\GPUCache\data_1
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\2ac25d6d-1923-4138-9300-bb6904b06f52.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\index-dir\the-real-index. (copy)
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\index-dir\temp-index
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\fda7754d5c73444b_0
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\91d236c78c5c0d9e_0
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\3c7acdd10ffafea6_0
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOG.old= (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOG
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\9ade4e32-cf8d-4469-a77d-cb7cf3d72a58.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\99d34c1e-7c71-43e3-814f-45646eb3b683.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\2f2d22c2-576f-41c6-89a4-b83384a788c6.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cookies
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\176a017c-fcb6-4e5f-a9b8-27f9f119ba69.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\126bc297-d800-4896-afce-e215ca745d14.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\04e8fdad-3fbd-4712-a05d-fe44441933b4.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\9cdb966d-3277-4f41-9b1f-a2a3985c6fd0.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\91244ff0-f9e2-4329-ac54-aca68524523c.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\7a780cb5-6ca3-49ef-8a54-490254abe60b.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\50721b56-bd53-437f-afa1-cfe1b5e01116.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\4b7bd6e5-7593-4e8e-bb64-a2f67602ec50.tmp
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\34c748d0-fb27-411c-87ba-5cd05a91da1c.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\23a6f767-8d45-4d3a-a592-7eb6b46145ff.tmp
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Favicons
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\Origins\MANIFEST-000001
PGP\011Secret Key -
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\Origins\LOG
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\Origins\CURRENT. (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\Origins\000003.log
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\File System\Origins\000001.dbtmp
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG.oldg (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG.old (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\000003.log
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Favicons-journal
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\029972cf-e06c-4049-8040-b3d7c8f8b672.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\8520.615.0.5_1\_metadata\computed_hashes.json
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_metadata\computed_hashes.json
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG.old* (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\000003.log
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\LOG.old. (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\LOG
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\000003.log
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Current Tabs
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Current Session
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cookies-journal
data
#