top title background image
flash

5GPueTFF2S.exe

Status: finished
Submission Time: 2022-12-09 10:38:06 +01:00
Malicious
Phishing
Trojan
Spyware
Evader
Amadey, Vidar

Comments

Tags

  • 32
  • exe
  • trojan

Details

  • Analysis ID:
    764034
  • API (Web) ID:
    1131310
  • Analysis Started:
    2022-12-09 10:38:07 +01:00
  • Analysis Finished:
    2022-12-09 10:49:27 +01:00
  • MD5:
    7d124bc23be85d73b1177143f41b5e72
  • SHA1:
    09633b90a0b993fd4dec6d522a1243433fc3ab10
  • SHA256:
    04805512d670fb5f37bdf17bf00aae6976650f82c0b4bd342f3506d204f7aea2
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 14/40
malicious

IPs

IP Country Detection
135.181.10.220
Germany
85.209.135.109
Germany
8.8.8.8
United States
Click to see the 1 hidden entries
88.119.169.157
Lithuania

URLs

Name Detection
http://135.181.10.220:80
http://135.181.10.220:8
85.209.135.109/jg94cVd30f/index.php
Click to see the 28 hidden entries
https://t.me/vmt001
http://135.181.10.220/
http://135.181.10.220/1760jf.
http://ripple-wells-2022.net/yzoyoebw6fqrey/nppshell.exerO
https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
http://mIkUB7ZDt5qfxou902VyKe64v30McOy.LnrmXFtSK2Pynk6VWBPG5Sf1w0AavRp1BVjmQQUkh2vmJkxEZO5UQQZNHAms9
http://135.181.10.220:80/update.zipb1ef1c57276c118008692-d06ed635-68f6-4e9a-955c-90ce-806e6f6e6963
http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#
http://135.181.10.220/update.zip
http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t
https://search.yahoo.com?fr=crmas_sfp
https://ac.ecosia.org/autocomplete?q=
http://135.181.10.220:80https://t.me/vmt001hello2092;open_open
https://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas_sfp&command=
http://135.181.10.220/1760
https://search.yahoo.com/favicon.icohttps://search.yahoo.com/search
https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
https://search.yahoo.com?fr=crmas_sfpf
http://ripple-wells-2022.net/yzoyoebw6fqrey/nppshell.exe
http://135.181.10.220:801760
http://ocsp.sectigo.com0
https://www.google.com/images/branding/product/ico/googleg_lodp.ico
http://135.181.10.220:80/update.zip
https://sectigo.com/CPS0
https://duckduckgo.com/ac/?q=
http://135ple-wells-2022.net/yzoyoebw6fqrey/nppshell.exe
https://duckduckgo.com/chrome_newtab
http://mikub7zdt5qfxou902vyke64v30mcoy.lnrmxftsk2pynk6vwbpg5s/

Dropped files

Name File Type Hashes Detection
C:\ProgramData\75873290272674793137.exe
PE32 executable (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\cred64[1].dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\nppshell[1].exe
PE32 executable (GUI) Intel 80386, for MS Windows
#
Click to see the 10 hidden entries
C:\Users\user\AppData\Local\Temp\03bd543fce\gntuud.exe
PE32 executable (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Roaming\c33e9ad058e5d3\cred64.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\ProgramData\39866407027900499026559352
SQLite 3.x database, last written using SQLite version 3038005, page size 2048, file counter 3, database pages 45, cookie 0x3d, schema 4, UTF-8, version-valid-for 3
#
C:\ProgramData\42740063057692746811967690
SQLite 3.x database, last written using SQLite version 3038005, page size 2048, file counter 2, database pages 23, cookie 0x19, schema 4, UTF-8, version-valid-for 2
#
C:\ProgramData\45707745472676257340529648
SQLite 3.x database, last written using SQLite version 3038005, file counter 4, database pages 36, 1st free page 10, free pages 1, cookie 0x29, schema 4, UTF-8, version-valid-for 4
#
C:\ProgramData\66974910856148417682877849
SQLite 3.x database, last written using SQLite version 3038005, file counter 10, database pages 7, 1st free page 5, free pages 2, cookie 0x13, schema 4, UTF-8, version-valid-for 10
#
C:\ProgramData\70342673400662660148807453
SQLite 3.x database, last written using SQLite version 3038005, file counter 4, database pages 36, 1st free page 10, free pages 1, cookie 0x29, schema 4, UTF-8, version-valid-for 4
#
C:\ProgramData\73647430720841230611985631
SQLite 3.x database, last written using SQLite version 3038005, page size 2048, file counter 3, database pages 45, cookie 0x3d, schema 4, UTF-8, version-valid-for 3
#
C:\Users\user\AppData\Local\Temp\853321935212
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 1280x1024, components 3
#
\Device\ConDrv
ASCII text, with no line terminators
#