top title background image
flash

Quotation - Optical Eyeglasses.xlsx

Status: finished
Submission Time: 2022-08-08 17:18:12 +02:00
Malicious
Trojan
Spyware
Exploiter
Evader
AgentTesla

Comments

Tags

  • xlsx

Details

  • Analysis ID:
    680486
  • API (Web) ID:
    1047987
  • Analysis Started:
    2022-08-08 17:25:26 +02:00
  • Analysis Finished:
    2022-08-08 17:33:25 +02:00
  • MD5:
    936a314411e4a93f2dd6a01b51216ef3
  • SHA1:
    47483467b595bdd9a49b577f457d84bcdb3b1c3b
  • SHA256:
    0897c1227e00e63196869de72f0e4436e8493a7ee095be94a914d4e547d6ac2e
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 7 x64 SP1 with Office 2010 SP1 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2)

Third Party Analysis Engines

malicious
Score: 21/60
malicious
Score: 13/41
malicious

IPs

IP Country Detection
198.12.89.152
United States

URLs

Name Detection
http://198.12.89.152/mon/mon.exehhC:
ftp://ftp.alonsorojasmudanzasnacionales.com/okok
http://198.12.89.152/mon/mon.exe
Click to see the 6 hidden entries
http://127.0.0.1:HTTP/1.1
http://ZSkVPd.com
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
http://77qlBFDgeMeBhXCCMul.org
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.ziphttps://www
http://DynDns.comDynDNSnamejidpasswordPsi/Psi

Dropped files

Name File Type Hashes Detection
C:\Users\Public\Regasm_svchost.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Users\user\Desktop\~$Quotation - Optical Eyeglasses.xlsx
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\mon[1].exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
Click to see the 20 hidden entries
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\9FBCD146.wmf
ms-windows metafont .wmf
#
C:\Users\user\AppData\Local\Temp\~DF62A311AB9E677AE5.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF411CBDC8CE3B6E4A.TMP
CDFV2 Encrypted
#
C:\Users\user\AppData\Local\Temp\~DF2848124F9857A45C.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF1E34B02C6542BFCB.TMP
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\FAC7EB4B.wmf
ms-windows metafont .wmf
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\F75A4C75.wmf
ms-windows metafont .wmf
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\D1391828.png
PNG image data, 114 x 111, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\C7CE848F.wmf
ms-windows metafont .wmf
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\BB6E2A09.png
PNG image data, 577 x 201, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\9C0AAE91.png
PNG image data, 577 x 201, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\85A0278A.wmf
ms-windows metafont .wmf
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\755CFE03.wmf
ms-windows metafont .wmf
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\67B5846D.wmf
ms-windows metafont .wmf
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\6044B544.wmf
ms-windows metafont .wmf
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\5E39D4D0.png
PNG image data, 114 x 111, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\3AB4071C.wmf
ms-windows metafont .wmf
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\3A41A35E.wmf
ms-windows metafont .wmf
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\1797FF2.wmf
ms-windows metafont .wmf
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\109ABFC7.wmf
ms-windows metafont .wmf
#