We are hiring! Windows Kernel Developer (Remote), apply here!
flash

Launcher.exe

Status: finished
Submission Time: 2022-11-24 19:35:07 +01:00
Malicious
Trojan

Comments

Tags

  • 185-206-213-32
  • CosmicWay
  • exe
  • FakeGaliXCity
  • RedLineStealer
  • UniverseCity

Details

  • Analysis ID:
    753414
  • API (Web) ID:
    1120697
  • Analysis Started:
    2022-11-24 19:35:08 +01:00
  • Analysis Finished:
    2022-11-24 19:40:57 +01:00
  • MD5:
    ac30d9ee77f4a6e23dea621727579dc5
  • SHA1:
    9dc851e691a4af49882138ee7c5bac1dc126becd
  • SHA256:
    d8f1870f30298302fce860d7c56257f6a11e4689642c3d5367d2392db5356bed
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

malicious

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
48/100

IPs

IP Country Detection
149.154.167.220
United Kingdom

Domains

Name IP Detection
api.telegram.org
149.154.167.220

URLs

Name Detection
http://www.zkysky.com.ar/This
https://github.com/JulietaUla/Montserrat)Montserrat
https://api.telegram.org/bot5802716616:AAH_P81FtM2pxxnBzX9bl8iFQfHnI4qwKEs/sendMessage?chat_id=-1001729137879&text=5.0%20NEW%2020.11.2022%0A%E2%9C%85%D0%A3%D1%81%D0%BF%D0%B5%D1%88%D0%BD%D1%8B%D0%B9%20%D0%B7%D0%B0%D0%BF%D1%83%D1%81%D0%BA%20%D0%BB%D0%B0%D1%83%D0%BD%D1%87%D0%B5%D1%80%D0%B0:%20user%0A%D0%A1%D0%B0%D0%B9%D1%82:%20universecity%0A%D0%94%D0%B0%D1%82%D0%B0%2011/24/2022%207:35:59%20PM&parse_mode=Markdown&disable_web_page_preview=True
Click to see the 28 hidden entries
https://universe-city.io/download/UniverseCity.zip
https://discord.com/invite/universecityGhttps://twitter.com/UniverseCityP2E3https://universe-city.io
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
http://api.telegram.org
http://scripts.sil.org/OFL
http://www.impallari.com
http://foo/Fonts/montserrat-variablefont_wght.ttf
https://discord.com/invite/universecity
http://scripts.sil.org/OFLhttp://scripts.sil.org/OFLDosisExtraLightWeightLightMediumSemiBoldBoldExtr
https://github.com/JulietaUla/Montserrat)
https://api.telegram
http://defaultcontainer/UniverseCity;component/Fonts/dosis.ttf
http://www.zkysky.com.ar/
http://www.impallari.comThis
http://foo/Fonts/dosis.ttf
https://api.telegram.org/bot5802716616:AAH_P81FtM2pxxnBzX9bl8iFQfHnI4qwKEs/sendMessage?chat_id=-1001
https://twitter.com/UniverseCityP2E
http://foo/bar/fonts/montserrat-variablefont_wght.ttf
http://defaultcontainer/UniverseCity;component/Fonts/montserrat-variablefont_wght.ttf
http://defaultcontainer/UniverseCity;component/Images/img_downloadWhite.png
https://universe-city.io/
http://foo/bar/fonts/dosis.ttf
http://scripts.sil.org/OFLhttp://scripts.sil.org/OFLMontserratThinMontserratRomanWeightExtraLightLig
https://api.telegram.org/bot
https://api.telegram.org/bot5802716616:AAH_P81FtM2pxxnBzX9bl8iFQfHnI4qwKEs/sendMessage
https://api.telegram.org
http://foo/Images/img_downloadWhite.png
http://foo/bar/images/img_downloadwhite.png