flash

Copie a bonului de plata.exe

Status: finished
Submission Time: 2022-11-29 12:47:06 +01:00
Malicious
Trojan
Spyware
Evader
FormBook, DBatLoader

Comments

Tags

  • exe
  • ModiLoader

Details

  • Analysis ID:
    755986
  • API (Web) ID:
    1123262
  • Analysis Started:
    2022-11-29 12:47:07 +01:00
  • Analysis Finished:
    2022-11-29 12:58:32 +01:00
  • MD5:
    eb8c68c29d6131d6b903dd268d6ff0ef
  • SHA1:
    61dfb557d2e792229060bdeb21285f65daf48492
  • SHA256:
    d1798c288b296009d8049ca5364b29b079d59fadc870af65e92fe5fa23bdcec5
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

malicious

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
100/100

malicious
18/70

malicious
8/41

malicious

malicious

IPs

IP Country Detection
5.183.8.25
Germany
212.32.237.90
Netherlands

Domains

Name IP Detection
www.jam-nins.com
5.183.8.25
www.stillwatersagawork.com
212.32.237.90
onedrive.live.com
0.0.0.0
Click to see the 1 hidden entries
ppq0oq.ph.files.1drv.com
0.0.0.0

URLs

Name Detection
www.xctech.world/3nop/
http://www.stillwatersagawork.com/3nop/
http://www.jam-nins.com/3nop/?lR-DA=FNGt6FUR7BoC+Wk2mT/OXzHG9rfZBcI/fjySAuf4KaFOaHLtldhTTP3Ojf6osS08NYIgkgrbcw==&5j=6leTg0VPe4i
Click to see the 13 hidden entries
http://www.jam-nins.com/3nop/
http://www.stillwatersagawork.com/3nop/?lR-DA=uizPEf3ZCIKf+0vjz41ZIbJXQmeLMi3XcgBA4XxBdLh6ZlOYX2KmQQVjEXygOMnK9OyVSVhb/w==&5j=6leTg0VPe4i
http://www.autoitscript.com/autoit3/J
https://ppq0oq.ph.files.1drv.com/y
https://onedrive.live.com/download?cid=E0CF7F9E6AAF27EF&resid=E0CF7F9E6AAF27EF%21845&authkey=AIl8u0A
https://ppq0oq.ph.files.1drv.com/y4mTq5RZ8ohnMX6xf7NDPAPVNhWu7XDJIy7fIuYHyTqr4rWZJ8CBMittNjykZHXcnJ_
http://www.stillwatersagawork.com
https://ppq0oq.ph.files.1drv.com/
https://onedrive.live.com/download?cid=E0CF7F9E6AAF27EF&resid=E0CF7F9E6AAF27EF%21845&authkey=AIl8u0Az19Gihis
https://ppq0oq.ph.files.1drv.com/y4mSOYNl8PReN028zDgtLGTbNYcgZC2HyHGQN3fPTRemBgwyzYyJn9Rzn0pByB78UZm
https://onedrive.live.com/
http://survey-smiles.com
https://ppq0oq.ph.files.1drv.com/t

Dropped files

Name File Type Hashes Detection
C:\Users\Public\Libraries\Ndvmyrkf.exe
PE32 executable (GUI) Intel 80386, for MS Windows
#
C:\Users\Public\Libraries\Ndvmyrkf.exe:Zone.Identifier
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\DB1
SQLite 3.x database, last written using SQLite version 3038005, page size 2048, file counter 2, database pages 23, cookie 0x19, schema 4, UTF-8, version-valid-for 2
#
Click to see the 7 hidden entries
C:\Users\user\AppData\Roaming\9N30RODQ\9N3logri.ini
data
#
C:\Users\user\AppData\Roaming\9N30RODQ\9N3logrv.ini
data
#
C:\Users\Public\Libraries\Ndvmyrkf
data
#
C:\Users\Public\Libraries\fkrymvdN.url
MS Windows 95 Internet shortcut text (URL=<file:"C:\\Users\\Public\\Libraries\\Ndvmyrkf.exe">), ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\Ndvmyrkfoxm[1]
data
#
C:\Users\user\AppData\Roaming\9N30RODQ\9N3logim.jpeg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 1280x1024, components 3
#
C:\Users\user\AppData\Roaming\9N30RODQ\9N3logrg.ini
Targa image data - RGB - RLE 109 x 101 x 32 +114 +111 "R"
#