We are hiring! Windows Kernel Developer (Remote), apply here!
flash

Order_002376662-579588_Date 24082022.exe

Status: finished
Submission Time: 2022-08-31 23:46:07 +02:00
Malicious
Trojan
Evader
GuLoader

Comments

Tags

  • exe
  • signed

Details

  • Analysis ID:
    694559
  • API (Web) ID:
    1062033
  • Analysis Started:
    2022-08-31 23:50:13 +02:00
  • Analysis Finished:
    2022-09-01 00:13:41 +02:00
  • MD5:
    8c2a59bd88b7e2c26045a604ed544288
  • SHA1:
    7efb014d57608ff6a2805baf4dd7c150792e6eb4
  • SHA256:
    0d4b100e641aad426a916cb326d20f8fe44e32ca38f7a85c505135036c6b44af
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
64/100

System: Windows 10 64 bit 20H2 Native physical Machine for testing VM-aware malware (Office 2019, IE 11, Chrome 93, Firefox 91, Adobe Reader DC 21, Java 8 Update 301
Run Condition: Suspected Instruction Hammering

malicious
80/100

malicious
35/71

malicious
5/18

malicious
17/26

IPs

IP Country Detection
45.8.132.92
Germany

Domains

Name IP Detection
mnhckm.tk
45.8.132.92

URLs

Name Detection
http://crl.certum.pl/ctnca2.crl0l
http://repository.certum.pl/ctnca2.cer09
http://crl.certum.pl/ctsca2021.crl0o
Click to see the 9 hidden entries
http://nsis.sf.net/NSIS_Error
http://repository.certum.pl/ctnca.cer09
http://nsis.sf.net/NSIS_ErrorError
http://repository.certum.pl/ctsca2021.cer0
http://crl.certum.pl/ctnca.crl0k
http://subca.ocsp-certum.com05
http://www.certum.pl/CPS0
http://subca.ocsp-certum.com02
http://subca.ocsp-certum.com01

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Temp\nsa7CF6.tmp\System.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Sigtelinjens\Tvtningerne\Forhaanet.Nab
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Sigtelinjens\Tvtningerne\Holograph\Towy\Dgnrytmers\GPUPowerSavingConfigEditor.dll
PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
#
Click to see the 4 hidden entries
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Sigtelinjens\Tvtningerne\Holograph\Towy\Dgnrytmers\face-cool.png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Sigtelinjens\Tvtningerne\Kalligraferendes\Quantisers\Aqua_20.bmp
JPEG image data, JFIF standard 1.01, resolution (DPI), density 100x100, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=3], baseline, precision 8, 110x110, frames 3
#
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Sigtelinjens\Tvtningerne\Noneffervescently.Cre
data
#
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Sigtelinjens\Tvtningerne\Tilegnelserne\Suppegrydernes79\iso_3166-1.json
UTF-8 Unicode text
#