top title background image
flash

FixDefError.exe

Status: finished
Submission Time: 2023-03-19 00:16:07 +01:00
Malicious
Trojan
Adware
Spyware
Evader
Miner
Xmrig

Comments

Tags

  • exe

Details

  • Analysis ID:
    829697
  • API (Web) ID:
    1196796
  • Analysis Started:
    2023-03-19 00:16:08 +01:00
  • Analysis Finished:
    2023-03-19 00:27:45 +01:00
  • MD5:
    1b664f2a0bede6c47e44ca8c0aad3de7
  • SHA1:
    2dc3169220411d03be438047a3c33696b4371d2b
  • SHA256:
    908641c2c756b0a2762e4883f7defb050e1baa09d44be8cdad34c5aa562d65d9
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 27/69
malicious
Score: 21/26
malicious

IPs

IP Country Detection
149.154.167.220
United Kingdom
142.251.209.36
United States
104.237.62.211
United States
Click to see the 3 hidden entries
198.251.88.130
United States
140.82.121.3
United States
185.199.111.133
Netherlands

Domains

Name IP Detection
api4.ipify.org
104.237.62.211
github.com
140.82.121.3
rentry.co
198.251.88.130
Click to see the 4 hidden entries
raw.githubusercontent.com
185.199.111.133
www.google.com
142.251.209.36
api.telegram.org
149.154.167.220
api.ipify.org
0.0.0.0

URLs

Name Detection
http://www.fontbureau.com/designers?
http://fontfabrik.com
http://www.galapagosdesign.com/staff/dennis.htm
Click to see the 97 hidden entries
http://github.com
https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gri?pv=1&r=
http://www.typography.netD
https://dev.ditu.live.com/mapcontrol/logging.ashx
http://www.carterandcone.com
https://dev.virtualearth.net/mapcontrol/HumanScaleServices/GetBubbles.ashx?n=
http://www.goodfont.co.kr
http://www.tiro.com
http://www.carterandcone.comams
https://github.com
https://api.telegram.org4
https://t0.ssl.ak.dynamic.tiles.virtualearth.net/comp/gen.ashx
https://dev.virtualearth.net/REST/v1/Routes/Driving
http://www.fontbureau.com/designersJ
http://www.founder.com.cn/cn/bThe
http://www.fontbureau.com/designers/?
http://www.fontbureau.com/designersG
https://dynamic.api.tiles.ditu.live.com/odvs/gd?pv=1&r=
https://dev.ditu.live.com/REST/v1/JsonFilter/VenueMaps/data/
http://www.fontbureau.com-s
https://dynamic.api.tiles.ditu.live.com/odvs/gdv?pv=1&r=
https://xmrig.com/benchmark/%s
https://ecn.dev.virtualearth.net/REST/v1/Imagery/Copyright/
http://www.urwpp.deF
http://www.fontbureau.com/designers/frere-jones.
https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gdi?pv=1&r=
https://xmrig.com/wizard%s
http://www.tiro.comu
http://www.agfamonotype.
http://www.fontbureau.com
http://www.apache.org/licenses/LICENSE-2.0
https://dynamic.t0.tiles.ditu.live.com/comp/gen.ashx
http://www.sandoll.co.kreV
https://api.ipify.org/
http://www.fontbureau.com/designerss
https://dev.ditu.live.com/webservices/v1/LoggingService/LoggingService.svc/Log?
http://www.sakkal.com
http://www.urwpp.de
https://apis.google.com
http://www.sandoll.co.kr
http://www.fonts.com
http://www.google.com
https://github.com4
http://www.fontbureau.com773.
http://www.fontbureau.com/designersa
http://www.tiro.comlic;
http://www.fontbureau.com/designersm
https://github.com/ETHMonsterM/ETHMonsterM/raw/main/cpm.exe
https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gdv?pv=1&r=
https://render.githubusercontent.com
http://www.galapagosdesign.com/
https://rentry.co
http://www.bingmapsportal.com
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
http://www.zhongyicts.com.cn
http://www.urwpp.deDPlease
http://www.urwpp.de-
https://raw.githubusercontent.com/ETHMonsterM/ETHMonsterM/main/cpm.exe
https://api.ipify.org8:
http://www.galapagosdesign.com/DPlease
http://pesterbdd.com/images/Pester.png
https://dev.virtualearth.net/REST/v1/Transit/Schedules/
http://www.fontbureau.comgrita
http://www.founder.com.cn/cn/cThe
http://www.fontbureau.comueom8
https://dev.ditu.live.com/REST/v1/Imagery/Copyright/
http://www.sajatypeworks.com
http://www.fontbureau.com/designers
https://dev.virtualearth.net/REST/v1/Routes/Walking
https://t0.tiles.ditu.live.com/tiles/gen
https://dev.ditu.live.com/REST/v1/Traffic/Incidents/
https://dev.ditu.live.com/REST/v1/Routes/
https://dev.virtualearth.net/REST/v1/Locations
http://raw.githubusercontent.com
https://dev.virtualearth.net/REST/v1/Routes/Transit
https://raw.githubusercontent.com
https://dynamic.t
http://www.fontbureau.comgr
https://dev.virtualearth.net/REST/v1/JsonFilter/VenueMaps/data/
http://www.fontbureau.com/designers/frere-jones.html
https://rentry.co/ptvejbuqtrwjccinhzedhttxvtbtyxuk/raw
http://www.carterandcone.coml
http://www.carterandcone.comn
https://github.com/Pester/Pester
https://ecn.dev.virtualearth.net/mapcontrol/mapconfiguration.ashx?name=native&v=
https://api.telegram.org/bot
https://%s.xboxlive.com
https://xmrig.com/wizard
https://t0.ssl.ak.dynamic.tiles.virtualearth.net/odvs/gd?pv=1&r=
https://raw.githubusercontent.com4
http://www.fontbureau.comicta
https://dev.virtualearth.net/REST/v1/Routes/
https://raw.githubusercontent.com/ETHMonsterM/ETHMonsterM/main/wnnrg.sys
https://rentry.co/poxonjnntyfzjniyneuqfcjhmytxhlxN
https://go.micro
http://www.founder.com.cn/cnTF
http://www.apache.org/licenses/LICENSE-2.0.html

Dropped files

Name File Type Hashes Detection
C:\ProgramData\RuntimeBrokerData\RegSvc.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\ProgramData\RuntimeBrokerData\RuntimeBroker.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\ProgramData\RuntimeBrokerData\WinRing0x64.sys
PE32+ executable (native) x86-64, for MS Windows
#
Click to see the 22 hidden entries
C:\ProgramData\RuntimeBrokerData\svhost.exe
PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows
#
C:\Windows\System32\drivers\etc\hosts
ASCII text, with CRLF, LF line terminators
#
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\FixDefError.exe.log
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\ProgramStarter.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Users\user\AppData\Local\Packages\ActiveSync\LocalState\DiagOutputDir\SyncVerbose.etl
data
#
C:\mib.bin
ASCII text, with very long lines (484), with CRLF line terminators
#
C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Logs\dosvc.20230319_071724_277.etl
data
#
C:\Users\user\AppData\Local\packages\ActiveSync\LocalState\DiagOutputDir\UnistackCritical.etl.0001 (copy)
data
#
C:\Users\user\AppData\Local\packages\ActiveSync\LocalState\DiagOutputDir\UnistackCircular.etl.0001 (copy)
data
#
C:\Users\user\AppData\Local\packages\ActiveSync\LocalState\DiagOutputDir\SyncVerbose.etl.0001 (copy)
data
#
C:\Users\user\AppData\Local\Temp\mib.bin
ASCII text, with very long lines (484), with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_nxcm1fgp.u3u.psm1
very short file (no magic)
#
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_nooqsj1v.gcj.ps1
very short file (no magic)
#
C:\Users\user\AppData\Local\Packages\ActiveSync\LocalState\DiagOutputDir\UnistackCritical.etl
data
#
C:\Users\user\AppData\Local\Packages\ActiveSync\LocalState\DiagOutputDir\UnistackCircular.etl
data
#
C:\ProgramData\MicrosoftSystemCache\clib.bin
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\ModuleAnalysisCache
data
#
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\ProgramStarter.exe.log
ASCII text, with CRLF line terminators
#
C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration_Temp.1.etl
data
#
C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration.001.etl (copy)
data
#
C:\ProgramData\MicrosoftSystemCache\mib.bin
ASCII text, with very long lines (484), with CRLF line terminators
#