flash

server.exe

Status: finished
Submission Time: 2023-03-15 15:15:12 +01:00
Malicious
Trojan
Evader
Ursnif

Comments

Tags

  • agenziaentrate
  • exe
  • gozi
  • isfb
  • ITA
  • mef
  • mise
  • ursnif

Details

  • Analysis ID:
    827096
  • API (Web) ID:
    1194195
  • Analysis Started:
    2023-03-15 15:17:20 +01:00
  • Analysis Finished:
    2023-03-15 15:23:49 +01:00
  • MD5:
    d966642aac4f23e0ec3cb978b949fd9d
  • SHA1:
    c841e25cf191d5a327d6917731333d61f7b4ad0d
  • SHA256:
    38befee4c4513de47e667544d9f705f56c195393b116fcd154755c1f7815ae55
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

malicious

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
100/100

malicious
37/69

malicious
15/39

IPs

IP Country Detection
5.44.43.17
Russian Federation
31.41.44.108
Russian Federation

Domains

Name IP Detection
checklist.skype.com
0.0.0.0

URLs

Name Detection
http://31.41.
http://5.44.43.17/drew/f9GHjdJnehI_2BX/Ne5g2ordmIOToC91gh/mNbzuN3c2/5AW_2FtlsPkVoHj0AzU6/Pm6UGSYAVX5awiiNdCX/eNOyKJzs_2F6vuQoDvWCQ0/1kQi8Yq7709M2/upQopQi2/s9QJW0HP19fXNX5NpkaC7rS/XtTUHeQq7L/Mwx2fdHiqqVJIhw5T/ErHqsGRIPLQF/P1EQ7mB71HQ/eppTj5uvam1edz/PvmLkUCCoHuafjeSLYKxe/uQzSahqYp69cTJ2o/M6RFmPe3MSlVrTk/KwEVVAo6CnR9Fpgg/f20Iv.jlk