top title background image
flash

https://outacts-shrinkhead-tinging.s3.us-west-002.backblazeb2.com/index.html

Status: finished
Submission Time: 2021-10-27 07:02:23 +02:00
Malicious
Phishing
HTMLPhisher

Comments

Tags

Details

  • Analysis ID:
    509917
  • API (Web) ID:
    877489
  • Analysis Started:
    2021-10-27 07:02:24 +02:00
  • Analysis Finished:
    2021-10-27 07:10:08 +02:00
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 72
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
clean
0/100

Third Party Analysis Engines

malicious

IPs

IP Country Detection
172.217.168.46
United States
172.217.168.13
United States
142.250.203.97
United States
Click to see the 3 hidden entries
239.255.255.250
Reserved
152.199.21.175
United States
206.190.215.254
United States

Domains

Name IP Detection
outacts-shrinkhead-tinging.s3.us-west-002.backblazeb2.com
206.190.215.254
accounts.google.com
172.217.168.13
sni1gl.wpc.alphacdn.net
152.199.21.175
Click to see the 9 hidden entries
clients.l.google.com
172.217.168.46
googlehosted.l.googleusercontent.com
142.250.203.97
clients2.googleusercontent.com
0.0.0.0
signup.live.com
0.0.0.0
clients2.google.com
0.0.0.0
aadcdn.msauth.net
0.0.0.0
fpt.live.com
0.0.0.0
acctcdn.msauth.net
0.0.0.0
acctcdn.msftauth.net
0.0.0.0

URLs

Name Detection
https://outacts-shrinkhead-tinging.s3.us-west-002.backblazeb2.com/index.html2
https://outacts-shrinkhead-tinging.s3.us-west-002.backblazeb2.com/index.htmlSign
https://outacts-shrinkhead-tinging.s3.us-west-002.backblazeb2.com/login.html?jakoizn=6rz7tPMcGrEPCSYpe&ela=Lsb9ZjT2NKAoTFFhp8mKnKyTYRF6&jdj=1fBz6KczD68s8txqKTibKsELURW6&jzan=Ilk5RhyUJJgPL438zH8qJpUPP16Gqk&ebecvu=zAcrVETCs5M9XFxMMm9mmrpDTJc&hbtpistp=peHxyTjIp8XoiTx8ce
Click to see the 97 hidden entries
https://outacts-shrinkhead-tinging.s3.us-west-002.backblazeb2.com/index.html
https://outacts-shrinkhead-tinging.s3.us-west-002.backblazeb2.com/index.html-
https://outacts-shrinkhead-tinging.s3.us-west-002.backblazeb2.com/login.html?jakoizn=6rz7tPMcGrEPCSYpe&ela=Lsb9ZjT2NKAoTFFhp8mKnKyTYRF6&jdj=1fBz6KczD68s8txqKTibKsELURW6&jzan=Ilk5RhyUJJgPL438zH8qJpUPP16Gqk&ebecvu=zAcrVETCs5M9XFxMMm9mmrpDTJc&hbtpistp=peHxyTjIp8XoiTx8ce
https://outacts-shrinkhead-tinging.s3.us-west-002.backblazeb2.com/index.htmlTN5sWdnSRJ8oFte4N_Ymdi-E
http://angularjs.org
https://github.com/angular/material
https://signup.live.com/signup#
https://clients2.google.com/cr/report
https://accounts.google.com
https://meet.google.com
https://apis.google.com
https://signup.live.com/Resources/images/favicon.ico
https://www-googleapis-staging.sandbox.google.com
https://hangouts.clients6.google.com
https://aadcdn.msauth.net/shared/1.0/content/images/backgrounds/2_bc3d32a696895f78c19df6c717586a5d.s
https://login.microsoftonline.com
https://clients2.googleusercontent.com/crx/blobs/Acy1k0bLIjHsvnKaKN_oRpVaYYvFs25d7GKYF1WXrT6yizCMksBO0c_ggE0B6tx6HPRHe6q1GOEe3_NcIbSiGG8kXeLMUY0sAKVvC6R89zvKM13s5VqoAMZSmuUgjQL5vlygJuArQghXXE_qTL7NlQ/extension_8520_615_0_5.crx
https://accounts.google.com/MergeSession
https://signup.live.com/Resources/images/microsoft_logo_7lyNn7YkjJOP0NwZNw6QvQ2.svg
https://sandbox.google.com/payments/v4/js/integrator.js
https://login.windows-ppe.net
https://acctcdn.msauth.net/converged_ux_v2_kGcCYmU0rW3A6Zc7U1O8nw2.css?v=1
https://www.google.com/log?format=json&hasfast=true
https://aadcdn.msauth.net/shared/1.0/content/images/microsoft_logo_ee5c8d9fb6248c938fd0dc19370e90bd.
https://play.google.com
https://clients2.google.com/service/update2/crx
https://signup.live.com/Resources/images/2_vD0yppaJX3jBnfbHF1hqXQ2.svg
https://acctcdn.msauth.net/oneds_Xr2D7Nex80v7A-8bxF8jgQ2.js?v=1
https://acctcdn.msauth.net/knockout_3.3.0_X1BYS2jZMbi7hfUj8VuqFA2.js?v=1W
https://csp.withgoogle.com/csp/report-to/IdentityListAccountsHttp/external
https://clients2.googleusercontent.com
https://acctcdn.msauth.net/images/favicon.ico?v=2
https://acctcdn.msauth.net/lwsignupstringscountrybirthdate_en-us_Hu9XQvsxbdtI5Cn8ywiXCA2.js?v=1
https://support.google.com/chromecast/answer/2998456
https://csp.withgoogle.com/csp/hosted-libraries-pushersCross-Origin-Resource-Policy:
https://acctcdn.msauth.net/lightweightsignuppackage_MMbzWcmclCMEyYNgK6Xfbg2.js?v=1a
https://aadcdn.msauth.net/shared/1.0/content/images/ellipsis_635a63d500a92a0b8497cdc58d0f66b1.svg
https://meetings.clients6.google.com
https://csp.withgoogle.com/csp/report-to/hosted-libraries-pushers
https://acctcdn.msauth.net/images/2_vD0yppaJX3jBnfbHF1hqXQ2.svg
http://pki.goog/gsr1/gsr1.crt02
https://hangouts.google.com/
https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard
https://aadcdn.msauth.net/ests/2.1/content/cdnbundles/ux.converged.login.strings-en.min_yruqtyo0qslo
https://aadcdn.msauth.net/ests/2.1/content/images/favicon_a_eupayfgghqiai7k9sol6lg2.ico
https://signup.live.com/
https://ogs.google.com
https://www.google.com/intl/en-US/chrome/blank.html
http://www.apache.org/licenses/LICENSE-2.0
https://clients2.google.com
https://hangouts.google.com/hangouts/_/logpref
https://acctcdn.msauth.net/datarequestpackage_h-_7C7UzwdefXJT9njDBTQ2.js
https://github.com/google/closure-library/wiki/goog.module:-an-ES6-module-like-alternative-to-goog.p
https://dns.google
https://www.google.com/tools/feedback
https://acctcdn.msauth.net/images/dropdown_caret_KXSZjGsyILZaoTf0sI9X-A2.svg
https://github.com/madler/zlib/blob/master/zlib.h
https://acctcdn.msauth.net/images/2_vD0yppaJX3jBnfbHF1hqXQ2.svgZ
https://acctcdn.msauth.net/jqueryshim_tGLkJ9mWEbN2n0ToVG2gvQ2.js?v=1
https://aadcdn.msauth.net/shared/1.0/content/images/ellipsis_grey_2b5d393db04a5e6e1f739cb266e65b4c.s
https://www.google.com/accounts/OAuthLogin?issueuberauth=1
https://creativecommons.org/publicdomain/zero/1.0/.
https://support.google.com/chromecast/troubleshooter/2995236
http://crls.pki.goog/gts1c3/QOvJ0N1sT2A.crl0
https://acctcdn.msauth.net/knockout_3.3.0_X1BYS2jZMbi7hfUj8VuqFA2.js?v=1
https://www.google.com
http://pki.goog/repo/certs/gtsr1.der04
https://preprod-hangouts-googleapis.sandbox.google.com
https://acctcdn.msauth.net/lightweightsignuppackage_MMbzWcmclCMEyYNgK6Xfbg2.js?v=1
https://outacts-shrinkhead-tinging.s3.us-west-002.backblazeb2.com/login.html?jakoizn=6rz7tPMcGrEPCSY
http://www.ietf.org/id/draft-holmer-rmcat-transport-wide-cc-extensions-01
https://outacts-shrinkhead-tinging.s3.us-west-002.backblazeb2.com
https://crash.corp.google.com/samples?reportid=&q=
https://apis.google.com/js/client.js
https://acctcdn.msauth.net/
https://signup.live.com
http://crl.pki.goog/gsr1/gsr1.crl0;
https://acctcdn.msauth.net/lwsignupstringscountrybirthdate_en-us_Hu9XQvsxbdtI5Cn8ywiXCA2.js?v=1bV
https://clients6.google.com
https://feedback.googleusercontent.com
https://www.google.com/
https://docs.google.com
https://fpt.live.com/?session_id=b58882512b7c40d78c42f4d88f1affac&CustomerId=33e01921-4d64-4f8c-a055
http://tools.ietf.org/html/rfc1950
https://aadcdn.msauth.net/ests/2.1/content/images/favicon_a_eupayfgghqiai7k9sol6lg2.icoChIKBw3RW1FSG
https://play.google.com/log?format=json&hasfast=true
https://www.google.com/images/cleardot.gif
https://www.google.com/images/dot2.gif
https://www.google.com/images/x2.gif
https://csp.withgoogle.com/csp/hosted-libraries-pushers
https://pki.goog/repository/0
http://crl.pki.goog/gtsr1/gtsr1.crl0W
https://www.google.com;
https://payments.google.com/payments/v4/js/integrator.js
https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=85.0.4183.121&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1&x=id%3Dpkedcjkdefgpdelpbcmbmeomcjbeemfm%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1
http://www.ietf.org/id/draft-holmer-rmcat-transport-wide-cc-extensions
https://acctcdn.msauth.net/images/microsoft_logo_7lyNn7YkjJOP0NwZNw6QvQ2.svg

Dropped files

No malicious files found. See full and IOC report for all dropped files.