top title background image
flash

marzo.txt.url

Status: finished
Submission Time: 2023-03-15 12:30:25 +01:00
Malicious
Trojan
Spyware
Evader
Ursnif

Comments

Tags

Details

  • Analysis ID:
    826967
  • API (Web) ID:
    1194066
  • Analysis Started:
    2023-03-15 12:30:25 +01:00
  • Analysis Finished:
    2023-03-15 12:36:54 +01:00
  • MD5:
    d8dc17b22192b297073d5749a7b49966
  • SHA1:
    606fd516fb85a0fbaa3a2b7ea92feffd5ae41b99
  • SHA256:
    f7b7f524138f10ad3b0d8145997db4ee5c90e7d8f76281cfc4a32bc427833236
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 88
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

IPs

IP Country Detection
5.44.43.17
Russian Federation
192.229.221.95
United States

Domains

Name IP Detection
checklist.skype.com
0.0.0.0

URLs

Name Detection
http://5.44.43.17/
http://5.44.43.17/drew/ZSasVN0fLMcptc05TEVCa/mWgPW7Eo_2Fhz8Y6/Fz7ovUnPPN6ieZv/4FY_2FkRwgHKarRxmu/cK8
http://5.44.43.17/~
Click to see the 3 hidden entries
http://5.44.43.17/b2c5-fe065076e0a1
http://checklist.skype.com/drew/XaKJ910OZ6OkzOiEp1j_2/BGdUIBHp_2FM8Z2X/fEGunvRWGFrRGJ9/FM827N5CFAo37
http://checklist.skype.com/drew/p8a6EJ5vt4U/NrIUl_2BZrXy6_/2BoMtuVkg7FYSQnXs7vFZ/T_2BtMhNb_2F_2Bq/Vr

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Temp\Outlook Logging\OUTLOOK_16_0_13929_20386-20230315T1230440507-6104.etl
data
#
C:\Users\user\AppData\Roaming\Microsoft\Outlook\NoEmail.xml
XML 1.0 document, ASCII text, with very long lines (424), with CRLF line terminators
#
C:\Users\user\Documents\Outlook Files\Outlook Data File - NoEmail.pst
data
#