top title background image
flash

New remittance Scif Shared Document (TGVL973NGZ2A).pdf

Status: finished
Submission Time: 2021-12-03 01:30:33 +01:00
Malicious

Comments

Tags

Details

  • Analysis ID:
    533086
  • API (Web) ID:
    900608
  • Analysis Started:
    2021-12-03 01:30:34 +01:00
  • Analysis Finished:
    2021-12-03 01:38:35 +01:00
  • MD5:
    443da430a468d140d6d3ce96af04682b
  • SHA1:
    1de2a4d95a4b771452b316eaff7b118fc5db3f7b
  • SHA256:
    96db3e46b5b3fe5b0e5d88ce317c2c317563ae2f766116def53c67492401bd38
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 52
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious

IPs

IP Country Detection
34.117.59.81
United States
142.250.203.110
United States
169.46.89.154
United States
Click to see the 6 hidden entries
172.217.168.45
United States
142.250.203.97
United States
239.255.255.250
Reserved
172.217.168.3
United States
52.55.94.26
United States
67.199.248.10
United States

Domains

Name IP Detection
gstaticadssl.l.google.com
172.217.168.3
889ftr-https-redirrectcase-dynamic-forms.us-south.cf.appdomain.cloud
169.46.89.154
accounts.google.com
172.217.168.45
Click to see the 7 hidden entries
bit.ly
67.199.248.10
373573-3847.glitch.me
52.55.94.26
ipinfo.io
34.117.59.81
clients.l.google.com
142.250.203.110
googlehosted.l.googleusercontent.com
142.250.203.97
clients2.googleusercontent.com
0.0.0.0
clients2.google.com
0.0.0.0

URLs

Name Detection
https://889ftr-https-redirrectcase-dynamic-forms.us-south.cf.appdomain.cloud/#amJhY3VkQHNjaWYuY29t
https://889ftr-https-redirrectcase-dynamic-forms.us-south.cf.appdomain.cloud/#amJhY3VkQHNjaWYuY29t
https://889ftr-https-redirrectcase-dynamic-forms.us-south.cf.appdomain.cloud/#amJhY3VkQHNjaWYuY29t2
Click to see the 97 hidden entries
https://889ftr-https-redirrectcase-dynamic-forms.us-south.cf.appdomain.cloud/#amJhY3VkQHNjaWYuY29tLo
https://sandbox.google.com/payments/v4/js/integrator.js
https://accounts.google.com
https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/Upload/
https://meet.google.com
https://hangouts.clients6.google.com
https://bit.ly/3rhxy13#amJhY3VkQHNjaWYuY29t
https://889ftr-https-redirrectcase-dynamic-forms.us-south.cf.appdomain.cloud/style.cssM
https://889ftr-https-redirrectcase-dynamic-forms.us-south.cf.appdomain.cloud/
http://www.tcpdf.org
http://www.aiim.org/pdfa/ns/property#P
https://clients2.googleusercontent.com/crx/blobs/Acy1k0bLIjHsvnKaKN_oRpVaYYvFs25d7GKYF1WXrT6yizCMksBO0c_ggE0B6tx6HPRHe6q1GOEe3_NcIbSiGG8kXeLMUY0sAKVvC6R89zvKM13s5VqoAMZSmuUgjQL5vlygJuArQghXXE_qTL7NlQ/extension_8520_615_0_5.crx
http://www.aiim.org/pdfe/ns/id/~
https://accounts.google.com/MergeSession
http://www.npes.org/pdfx/ns/id/
http://cipa.jp/exif/1.0/
https://bit.ly/3rhxy13#amJhY3VkQHNjaWYuY29t2
https://www.google.com/log?format=json&hasfast=true
https://csp.withgoogle.com/csp/apps-themesCross-Origin-Resource-Policy:
http://www.aiim.org/pdfa/ns/type#)
http://www.aiim.org/pdfa/ns/schema#
https://bit.ly/3rhxy13#amJhY3VkQHNjaWYuY29t)
https://www.google.com/images/cleardot.gif
https://clients6.google.com
https://ogs.google.com
http://www.aiim.org/pdfa/ns/id/;
https://meetings.clients6.google.com
https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/Upload/&
http://www.aiim.org/pdfe/ns/id/A
https://hangouts.google.com/
http://www.aiim.org/pdfe/ns/id/
https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard
http://iptc.org/std/Iptc4xmpExt/2008-02-29/
http://www.aiim.org/pdfa/ns/id/
https://373573-3847.glitch.me
http://www.tcpdf.org)#x-ns#
https://clients2.google.com/cr/report
https://www.google.com/intl/en-US/chrome/blank.html
http://www.apache.org/licenses/LICENSE-2.0
http://www.aiim.org/pdfa/ns/property#
https://clients2.google.com
https://www-googleapis-staging.sandbox.google.com
http://www.aiim.org/pdfa/ns/property#F
https://apis.google.com
https://github.com/angular/material
http://www.aiim.org/pdfa/ns/extension/
http://angularjs.org
https://feedback.googleusercontent.com
https://373573-3847.glitch.me/#amJhY3VkQHNjaWYuY29tLogin
https://support.google.com/chromecast/troubleshooter/2995236
http://ns.useplus.org/ldf/xmp/1.0/
https://github.com/google/closure-library/wiki/goog.module:-an-ES6-module-like-alternative-to-goog.p
https://dns.google
https://www.google.com/tools/feedback
https://github.com/madler/zlib/blob/master/zlib.h
https://www.google.com/accounts/OAuthLogin?issueuberauth=1
https://889ftr-https-redirrectcase-dynamic-forms.us-south.cf.appdomain.cloud/favicon.icoChIKBw3njUAO
https://creativecommons.org/publicdomain/zero/1.0/.
https://bit.ly/3rhxy13#amJhY3VkQHNjaWYuY29tLogin
https://hangouts.google.com/hangouts/_/logpref
https://api.echosign.com
https://373573-3847.glitch.me/T(
http://www.aiim.org/pdfa/ns/type#
https://api.echosign.comHei
https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/Upload/i
https://www.google.com
https://preprod-hangouts-googleapis.sandbox.google.com
https://373573-3847.glitch.me/#amJhY3VkQHNjaWYuY29t
http://www.ietf.org/id/draft-holmer-rmcat-transport-wide-cc-extensions-01
https://ipinfo.io/json?token=ae2ec3372db6ec
https://csp.withgoogle.com/csp/report-to/apps-themes
https://crash.corp.google.com/samples?reportid=&q=
https://apis.google.com/js/client.js
https://889ftr-https-redirrectcase-dynamic-forms.us-south.cf.appdomain.cloud/style.css
https://373573-3847.glitch.me/
https://www.google.com/
https://docs.google.com
http://cipa.jp/exif/1.0/(15)P
https://ims-na1.adobelogin.com
http://www.aiim.org/pdfa/ns/schema#a
https://889ftr-https-redirrectcase-dynamic-forms.us-south.cf.appdomain.cloud/favicon.ico
http://iptc.org/std/Iptc4xmpExt/2008-02-29/p
http://tools.ietf.org/html/rfc1950
https://play.google.com/log?format=json&hasfast=true
https://www.google.com/images/dot2.gif
http://cipa.jp/exif/1.0/(15)M
https://373573-3847.glitch.me/#amJhY3VkQHNjaWYuY29t2
https://www.google.com/images/x2.gif
https://373573-3847.glitch.me/Referrer-Policy:
http://iptc.org/std/Iptc4xmpCore/1.0/xmlns/
https://www.google.com;
https://payments.google.com/payments/v4/js/integrator.js
https://bit.ly/3rhxy13
http://www.tcpdf.org)
https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=85.0.4183.121&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1&x=id%3Dpkedcjkdefgpdelpbcmbmeomcjbeemfm%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1
http://www.tcpdf.org.SJ2m
http://www.ietf.org/id/draft-holmer-rmcat-transport-wide-cc-extensions

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\552b614b-0024-4c1b-9a00-94d8a46216d1.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Current Tabs
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Current Session
data
#
Click to see the 97 hidden entries
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cookies
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\data_3
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\data_2
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\data_1
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\data_0
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOG.old (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOG
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\9ed517bd-e9f9-4d16-b697-889f2c01a612.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\000003.log
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\5366f801-f723-45e0-a8ad-f42070d0c0a8.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\4ea203e0-bab3-456b-a4ad-31d52d4d7b0b.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\361b19f9-af58-4848-a65c-b4879eccdd18.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\30ff9de7-8037-473d-a558-a3c3dcd1e248.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\2bb34554-9280-4816-8aa9-ae221fa99fdf.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\19361086-a36d-4c6b-b1a7-840b4e64a006.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\95aff0f2-50df-4f9a-b6cb-b44cb5a93d9b.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\957dcf57-b976-4c5c-a5d7-4b6b6f7eacbf.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\14b5901d-1eb8-497c-99d2-8b31e328390b.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\0fdacf53-24b8-4334-ade0-47c2a132a59c.tmp
SysEx File -
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG.old (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network Persistent StateV (copy)
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State.. (copy)
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\000003.log
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Last TabsOG (copy)
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Last Sessionxb (copy)
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\History-journal
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\History
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG.olddl (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG
ASCII text
#
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\UserCache.bin
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG.old (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\000003.log
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\8520.615.0.5_1\_metadata\computed_hashes.json
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_metadata\computed_hashes.json
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG.old. (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\000003.log
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\LOG.old} (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\LOG
ASCII text
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\56c4cd218555ae2b_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\983b7a3da8f39a46_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\946896ee27df7947_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\92c56fa2a6c4d5ba_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\927a1596c37ebe5e_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\91cec06bb2836fa5_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\8e417e79df3bf0e9_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\8c84d92a9dbce3e0_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\8c159cc5880890bc_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\86b8040b7132b608_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\71febec55d5c75cd_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\7120c35b509b0fae_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\6fb6d030c4ebbc21_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\aba6710fde0876af_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\560e9c8bff5008d8_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\4a0e94571d979b3c_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\3a4ae3940784292a_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\2a426f11fd8ebe18_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\2798067b152b83c7_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\230e5fe3e6f82b2c_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0f25049d69125b1e_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0ace9ee3d914a5c0_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0998db3a32ab3f41_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0786087c3c360803_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\05349744be1ad4ad_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\fd17b2d8331c91e8_0
data
#
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\AdobeSysFnt19.lst (copy)
PostScript document text
#
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\AdobeFnt16.lst.2964
PostScript document text
#
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages-journal
SQLite Rollback Journal
#
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages
SQLite 3.x database, last written using SQLite version 3024000
#
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ConnectorIcons\icon-211203111009Z-176.bmp
PC bitmap, Windows 3.x format, 107 x -152 x 32
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Visited Links
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\LOG.old (copy)
ASCII text
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\LOG
ASCII text
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\index-dir\the-real-index (copy)
Maple help database
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\index-dir\temp-index
Maple help database
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\febb41df4ea2b63a_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\fdd733564de6fbcb_0
data
#
C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\f971b7eda7fa05c3_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\f941376b2efdd6e6_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\f4a0d4ca2f3b95da_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\f0cf6dfa8a1afa3d_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\de789e80edd740d6_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\d88192ac53852604_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\d449e58cb15daaf1_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\cf3e34002cde7e9c_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\bf0ac66ae1eb4a7f_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\bba29d2e6197e2f4_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\b6d5deb4812ac6e9_0
data
#