top title background image
flash

CSA73881.exe

Status: finished
Submission Time: 2022-08-08 14:24:09 +02:00
Malicious
Trojan
Evader
FormBook

Comments

Tags

  • exe
  • formbook

Details

  • Analysis ID:
    680378
  • API (Web) ID:
    1047884
  • Analysis Started:
    2022-08-08 14:24:10 +02:00
  • Analysis Finished:
    2022-08-08 14:36:21 +02:00
  • MD5:
    3ed3236517a40602d654555bc912d926
  • SHA1:
    16dc042b543fe473703e711844f508d353d6d6af
  • SHA256:
    3702b6cfa76e492d56bd9da5f99f7ff805e32c16b3840ee66bb13a812f5d3155
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 8/92
malicious
malicious

IPs

IP Country Detection
103.224.182.210
Australia
75.2.26.18
United States
34.102.136.180
United States

Domains

Name IP Detection
www.browardhomeappraisal.com
75.2.26.18
www.comgmaik.com
103.224.182.210
www.segurambiental.com
0.0.0.0
Click to see the 3 hidden entries
www.esrfy.xyz
0.0.0.0
www.merendri.com
0.0.0.0
segurambiental.com
34.102.136.180

URLs

Name Detection
www.northpierangling.info/mh76/
http://www.browardhomeappraisal.com/mh76/?Axo=ZKvJ8T01Uu5swSUTolvzZP3eEu33eLq9PUpXuYL3kSIE+YGu43QnDiKj3vyinvzv5HiX&e0Dd=gPHX06
http://www.comgmaik.com/mh76/?Axo=0EXE3m3wBb2Nxgj7DVqNl/WDAC0gNsnNDZKaZxMvJErakGZtakhmesbqHtechaZLzHZ4&e0Dd=gPHX06
Click to see the 7 hidden entries
http://www.segurambiental.com/mh76/?Axo=j8MnV1AauDvQLYEDQHkxR7wEsLuzS8wOqoRJGUEtb1NYKXHLD1QrWCJCw/4m9jwcj9zX&e0Dd=gPHX06
https://www.nuget.org/packages/Newtonsoft.Json.Bson
http://google.com)Exvkpxtvtblcdcgising7Uvadca.Properties.Resources
http://ww38.comgmaik.com/mh76/?Axo=0EXE3m3wBb2Nxgj7DVqNl/WDAC0gNsnNDZKaZxMvJErakGZtakhmesbqHtechaZLz
http://google.com
http://james.newtonking.com/projects/json
https://www.newtonsoft.com/jsonschema

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\CSA73881.exe.log
ASCII text, with CRLF line terminators
#