top title background image
flash

OR098765458900009876540.exe

Status: finished
Submission Time: 2022-05-27 12:12:08 +02:00
Malicious
Trojan
Evader
AgentTesla

Comments

Tags

  • AgentTesla
  • exe

Details

  • Analysis ID:
    635066
  • API (Web) ID:
    1002570
  • Analysis Started:
    2022-05-27 12:12:20 +02:00
  • Analysis Finished:
    2022-05-27 12:21:08 +02:00
  • MD5:
    cb490dd90ce8d9d11aadb9765abbe5e5
  • SHA1:
    1557b8f1f9c2879a8de75689530f78d796d8fc04
  • SHA256:
    c0f90aecb695c93c21e13bbb346f794928bd4dfdde1c3c88c70f62acaf1d368e
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 28/70
malicious
Score: 11/41

URLs

Name Detection
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Temp\dktozm.exe
PE32 executable (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Roaming\wyimvgfphnjxg\vxmtbmahtsqaf.exe
PE32 executable (GUI) Intel 80386, for MS Windows
#
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_vxmtbmahtsqaf.ex_cb9e76617add17783445895d2c3df37ac7ad2b_79937427_0fb4cdeb\Report.wer
Little-endian UTF-16 Unicode text, with CRLF line terminators
#
Click to see the 10 hidden entries
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_vxmtbmahtsqaf.ex_cb9e76617add17783445895d2c3df37ac7ad2b_79937427_1794bb3d\Report.wer
Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER9F88.tmp.dmp
Mini DuMP crash report, 14 streams, Fri May 27 19:13:54 2022, 0x1205a4 type
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERA536.tmp.WERInternalMetadata.xml
XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERAA19.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERC0CB.tmp.dmp
Mini DuMP crash report, 14 streams, Fri May 27 19:14:03 2022, 0x1205a4 type
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERC5BE.tmp.WERInternalMetadata.xml
XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERC745.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\hgwowmqnjcs91i7x
data
#
C:\Users\user\AppData\Local\Temp\nsa28F1.tmp
data
#
C:\Users\user\AppData\Local\Temp\tweziehjnh
data
#