top title background image
flash

PI & PACKING LIST.exe

Status: finished
Submission Time: 2022-11-30 01:54:08 +01:00
Malicious
Trojan
Spyware
Evader
FormBook

Comments

Tags

  • exe
  • formbook

Details

  • Analysis ID:
    756334
  • API (Web) ID:
    1123614
  • Analysis Started:
    2022-11-30 01:54:10 +01:00
  • Analysis Finished:
    2022-11-30 02:03:21 +01:00
  • MD5:
    36fbb21511e87e8dddc8916cc2dc9367
  • SHA1:
    eda2fa3fe4b62fe3d564cf492cc31a875e8f1922
  • SHA256:
    937c7c476bb363e55fdf1ff275c87de91ec0f550072e9a759387cc95e6c78c83
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 40/70
malicious
Score: 20/26
malicious

IPs

IP Country Detection
35.78.89.117
United States
162.43.120.154
United States
178.128.239.245
Netherlands
Click to see the 2 hidden entries
209.99.64.33
United States
142.250.203.115
United States

Domains

Name IP Detection
www.nu2uresale.store
209.99.64.33
www.p-soils.com
162.43.120.154
www.zkjk888.com
35.78.89.117
Click to see the 4 hidden entries
www.cpitherapy.com
178.128.239.245
www.bengalindex.com
0.0.0.0
www.gebouwpas.online
0.0.0.0
ghs.googlehosted.com
142.250.203.115

URLs

Name Detection
http://www.p-soils.com/m5oe/?l48xI=OgbUJyD2Cs0iavfQBCvIOQvZdrfaRUMlkbnSDVoQDO79KZkwY+JyOZ2XW8xl2hee24/cs1yqqL6PnYlAwwwxD54r6/IzPRoMsg==&y8dt=cR-TJP3pr48
www.singglostudio.com/m5oe/
http://www.zkjk888.com/m5oe/?l48xI=lXL2hA4gPGXGkrsXCHLs63wEyc6+ZxTcosJkE7OIAbbgzBCGQ1RLZhLXXwLUr0PxIclnwkI7OF+QM6Klss4VWWvRg6rabD2uNg==&y8dt=cR-TJP3pr48
Click to see the 49 hidden entries
http://www.nu2uresale.store/m5oe/
http://www.cpitherapy.com/m5oe/?l48xI=Kdt0ttn6jBvm5dVCPGsq4sF6gZwVhJORDr+IW0q2lJvFs7kzNd/E4xjIZ8hkWN2nAiXaUCaRapMtLMo79OBUYLpofMwqWu/G3g==&y8dt=cR-TJP3pr48
http://www.cpitherapy.com/m5oe/
http://www.nu2uresale.store/m5oe/?l48xI=U9+cid+ik5YJF3jF27GFdJRqVXeG7FP+UvbSj6ZytGipCLvwOYSuUs/u1hqVfurTuH6/pVSyY1dCVh8DyPcg4wzd/AwTcksoYQ==&y8dt=cR-TJP3pr48
http://www.p-soils.com/m5oe/
https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
http://www.autoitscript.com/autoit3/J
https://www.google.com/images/branding/product/ico/googleg_lodp.ico
http://www.fontbureau.com
http://www.apache.org/licenses/LICENSE-2.0
https://search.yahoo.com/favicon.icohttps://search.yahoo.com/search
https://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas_sfp&command=
http://www.carterandcone.coml
http://www.sandoll.co.kr
https://ac.ecosia.org/autocomplete?q=
https://search.yahoo.com?fr=crmas_sfp
http://www.fontbureau.com/designers/cabarga.htmlN
http://www.founder.com.cn/cn
http://www.fontbureau.com/designers/frere-jones.html
http://amh.sh/
http://www.jiyu-kobo.co.jp/
http://www.fontbureau.como
http://www.fontbureau.com/designers8
http://www.bengalindex.com/m5oe/?l48xI=yrQlZi/yeQekXtziTibn9LfL5FHN0Y47PbY+gegrHfqcLEwJAZ2lhKdA1OTtZbcFcNKVJgIODn1wmw2XGX+PWpMZIoIdVyV5wA==&y8dt=cR-TJP3pr48
https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
http://35.78.89.117
http://www.sajatypeworks.com
http://www.fontbureau.com/designersG
https://duckduckgo.com/ac/?q=
http://www.fontbureau.com/designers/?
http://www.founder.com.cn/cn/bThe
http://www.fontbureau.com/designers?
http://www.bengalindex.com/m5oe/
https://search.yahoo.com?fr=crmas_sfpf
http://www.tiro.com
http://www.fontbureau.com/designers
http://amh.sh
http://www.goodfont.co.kr
http://www.sakkal.com
http://www.typography.netD
http://www.founder.com.cn/cn/cThe
http://www.galapagosdesign.com/staff/dennis.htm
http://fontfabrik.com
https://www.bengalindex.com/m5oe/?l48xI=yrQlZi/yeQekXtziTibn9LfL5FHN0Y47PbY
http://www.galapagosdesign.com/DPlease
http://www.fonts.com
https://duckduckgo.com/chrome_newtab
http://www.urwpp.deDPlease
http://www.zhongyicts.com.cn

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\PI & PACKING LIST.exe.log
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\71M40-2OQ
SQLite 3.x database, last written using SQLite version 3038005, page size 2048, file counter 4, database pages 45, cookie 0x3d, schema 4, UTF-8, version-valid-for 4
#