top title background image
flash

gsPzUI8EV8RoSMt.exe

Status: finished
Submission Time: 2023-03-20 11:51:07 +01:00
Malicious
Trojan
Evader
FormBook

Comments

Tags

  • exe

Details

  • Analysis ID:
    830457
  • API (Web) ID:
    1197556
  • Analysis Started:
    2023-03-20 11:52:43 +01:00
  • Analysis Finished:
    2023-03-20 12:04:28 +01:00
  • MD5:
    bf7689cacf1c7ec05684d27628538b3d
  • SHA1:
    9186ece8e710a0d849834538b711fe90cb830c71
  • SHA256:
    85b572a6060bf6d434ab978aa1447096c11f84bcd329d71364de8daf261a4660
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 26/69
malicious
Score: 10/39
malicious

IPs

IP Country Detection
194.50.194.150
United Kingdom

Domains

Name IP Detection
www.qdtlmj.com
194.50.194.150

URLs

Name Detection
http://www.qdtlmj.com/us38/?7n=ZVfFkidWioZ1z242CMU5NErFVagRqFscjwTZw32dpH9T5nOFHAt7D4fNn/kr4Wxh+xCU&5jJX=q8td9Nm
http://www.ntiled.net/us38/
http://www.customgiveawaysplus.com/us38/
Click to see the 95 hidden entries
http://www.codshipin.com/us38/
http://www.codshipin.com/us38/www.bhukroofingandbuilding.co.uk
http://www.ntiled.net/us38/www.artificial-grass-61758.com
http://www.customgiveawaysplus.com/us38/www.codshipin.com
www.pickleontop.net/us38/
http://www.artificial-grass-61758.comReferer:
http://www.sandoll.co.kr
http://www.galapagosdesign.com/staff/dennis.htm
http://fontfabrik.com
http://www.bhukroofingandbuilding.co.uk
http://www.artificial-grass-61758.com/us38/
http://www.fatherlandistanbul.comReferer:
http://www.fonts.com
http://www.fontbureau.com/designersG
http://www.bameit.xyzReferer:
http://www.typography.netD
http://www.pickleontop.net
http://www.goodfont.co.kr
http://push.zhanzhang.baidu.com/push.js
http://www.ntiled.netReferer:
http://www.tiro.com
http://www.fontbureau.com/designers?
http://www.founder.com.cn/cn/bThe
http://www.fontbureau.com/designers/?
http://www.fatherlandistanbul.com
http://www.qdtlmj.comReferer:
http://www.pickleontop.net/us38/www.91ye260.xyz
http://www.loxnorth.com/us38/
http://www.artificial-grass-61758.com/us38/www.loxnorth.com
http://www.fontbureau.com/designers8
http://www.jiyu-kobo.co.jp/
http://www.fontbureau.comm
http://www.bameit.xyz/us38/www.qdtlmj.com
http://www.founder.com.cn/cn
http://www.fontbureau.com/designers/cabarga.htmlN
http://www.mymof.uk/us38/
http://www.loxnorth.com
http://www.artificial-grass-61758.com
https://zz.bdstatic.com/linksubmit/push.js
http://www.lightscript.ru/us38/www.ntiled.net
http://www.jggfj.com
http://www.fatherlandistanbul.com/us38/
http://www.efefcorn.buzz/us38/www.huntergatherer.store
http://www.fontbureau.com
http://www.apache.org/licenses/LICENSE-2.0
http://www.sakkal.com
http://www.lightscript.ru/us38/
http://www.efefcorn.buzz/us38/
http://www.lightscript.ruReferer:
http://www.91ye260.xyz
http://www.pickleontop.netReferer:
http://www.qdtlmj.com/us38/
http://www.jggfj.com/us38/
http://www.zhongyicts.com.cn
http://www.urwpp.deDPlease
http://www.pickleontop.net/us38/
http://www.codshipin.com
http://www.galapagosdesign.com/DPlease
http://www.91ye260.xyz/us38/www.fatherlandistanbul.com
http://www.customgiveawaysplus.com
http://www.efefcorn.buzzReferer:
http://www.91ye260.xyz/us38/
http://www.jggfj.com/us38/www.efefcorn.buzz
http://www.customgiveawaysplus.comReferer:
http://www.founder.com.cn/cn/cThe
http://www.sajatypeworks.com
http://www.mymof.uk
http://www.fatherlandistanbul.com/us38/www.customgiveawaysplus.com
http://www.fontbureau.comgreta(
http://www.fontbureau.com/designers
http://www.jggfj.comReferer:
http://www.bhukroofingandbuilding.co.uk/us38/
http://www.efefcorn.buzz
http://www.loxnorth.com/us38/www.jggfj.com
http://www.ntiled.net
http://www.fontbureau.commto
http://www.qdtlmj.com
http://www.lightscript.ru
http://www.fontbureau.com/designers/frere-jones.html
http://www.qdtlmj.com/us38/www.lightscript.ru
http://www.loxnorth.comReferer:
http://www.91ye260.xyzReferer:
http://www.founder.com.cn/cn/
http://www.carterandcone.coml
http://www.codshipin.comReferer:
http://www.bameit.xyz
http://www.huntergatherer.storeReferer:
http://www.huntergatherer.store
http://www.bhukroofingandbuilding.co.ukReferer:
http://www.bhukroofingandbuilding.co.uk/us38/www.mymof.uk
http://www.bameit.xyz/us38/
http://www.mymof.ukReferer:
http://www.huntergatherer.store/us38/www.pickleontop.net
http://www.autoitscript.com/autoit3/J
http://www.huntergatherer.store/us38/

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\gsPzUI8EV8RoSMt.exe.log
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
JSON data
#