flash

rzN2ckYW24.exe

Status: finished
Submission Time: 2022-11-03 12:15:41 +01:00
Malicious
Trojan
Spyware
Evader
AgentTesla

Comments

Tags

  • AgentTesla
  • exe

Details

  • Analysis ID:
    736948
  • API (Web) ID:
    1104288
  • Analysis Started:
    2022-11-03 12:20:04 +01:00
  • Analysis Finished:
    2022-11-03 12:31:13 +01:00
  • MD5:
    44159444c9bc9980871b80b3ae071ffb
  • SHA1:
    baf57ff497d2e202a1a119e8719e44c0aa100475
  • SHA256:
    9e4f0e0a10a778fb94e7631c17082b44bf75170d7ca81b393574fd3f4c004f47
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

malicious

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
100/100

malicious
21/70

malicious
13/41

IPs

IP Country Detection
149.154.167.220
United Kingdom
3.220.57.224
United States

Domains

Name IP Detection
api.ipify.org.herokudns.com
3.220.57.224
api.telegram.org
149.154.167.220
api.ipify.org
0.0.0.0

URLs

Name Detection
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.ziphttps://www
http://www.fontbureau.coma
http://www.jiyu-kobo.co.jp/jp/
Click to see the 63 hidden entries
https://api.telegram.org/bot5577155192:AAEz6ZTkghx2RsdTxeeE-sDulPHc5WQblVg/sendDocument
http://www.jiyu-kobo.co.jp//ra
http://www.galapagosdesign.com/staff/dennis.htmp
http://wmwpuO0P35oL9Q.com
http://en.wikipedia
http://www.fontbureau.comcomp
http://www.fontbureau.comd
http://www.fontbureau.comitum
http://www.fontbureau.comF
http://www.fontbureau.com
http://www.apache.org/licenses/LICENSE-2.0
https://api.telegram.org4Tkh
https://api.ipify.org/
http://www.fontbureau.commTTF
http://www.sakkal.com
http://en.w
http://www.carterandcone.coml
http://www.fontbureau.com/designers/cabarga.htmlN
http://www.founder.com.cn/cn
http://www.fontbureau.com/designers/frere-jones.html
http://www.fontbureau.com/designers/cabarga.html
http://www.fontbureau.comcomF
http://www.fontbureau.comm
http://www.jiyu-kobo.co.jp/
http://www.fontbureau.comp
http://www.fontbureau.com/designers8
http://www.fontbureau.comals
http://www.founder.com.cn/cns-ea
http://api.telegram.org
http://www.jiyu-kobo.co.jp/b
http://www.jiyu-kobo.co.jp/a-d
http://www.founder.com.cB
https://api.telegram.org/bot5577155192:AAEz6ZTkghx2RsdTxeeE-sDulPHc5WQblVg/5596534279%discordapi%yyy
http://www.goodfont.co.kr
http://www.fontbureau.com/designers
http://www.jiyu-kobo.co.jp/dz
http://www.tiro.com
https://api.ipify.orgappdatajVuurjVuur.exe/http://TMVuQQ.com
https://api.telegram.org/bot5577155192:AAEz6ZTkghx2RsdTxeeE-sDulPHc5WQblVg/
http://www.fontbureau.com/designersS
http://www.fontbureau.com/designers?
http://www.sakkal.comrm
https://api.telegram.org
http://www.founder.com.cn/cn/bThe
http://www.fontbureau.com/designers/?
http://www.sajatypeworks.comiv
http://www.fontbureau.com/designersG
http://127.0.0.1:HTTP/1.1
http://www.sajatypeworks.com
http://www.typography.netD
http://www.founder.com.cn/cn/cThe
http://www.galapagosdesign.com/staff/dennis.htm
https://api.ipify.org
http://fontfabrik.com
http://DynDns.comDynDNSnamejidpasswordPsi/Psi
http://www.galapagosdesign.com/DPlease
http://www.jiyu-kobo.co.jp/Y0
http://www.fonts.com
http://www.sandoll.co.kr
http://www.sajatypeworks.coma
http://www.urwpp.deDPlease
http://www.zhongyicts.com.cn
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\rzN2ckYW24.exe.log
ASCII text, with CRLF line terminators
#