flash

server.exe

Status: finished
Submission Time: 2023-03-20 12:45:18 +01:00
Malicious
Trojan
Evader
Ursnif

Comments

Tags

  • agenziaentrate
  • exe
  • gozi
  • isfb
  • ITA
  • mef
  • mise
  • ursnif

Details

  • Analysis ID:
    830504
  • API (Web) ID:
    1197604
  • Analysis Started:
    2023-03-20 12:52:20 +01:00
  • Analysis Finished:
    2023-03-20 13:00:03 +01:00
  • MD5:
    7e7372ed34c76cbeca4461bd6dbbfe62
  • SHA1:
    5825f7a6272108b061a557171da9b8ef6b780028
  • SHA256:
    0fa7c98d793b8c71d6ba29bde4fd449e497b246f92ab30403330fae3d8cb6ffd
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

malicious

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
100/100

malicious
32/69

malicious
13/39

IPs

IP Country Detection
62.173.142.81
Russian Federation

Domains

Name IP Detection
checklist.skype.com
0.0.0.0

URLs

Name Detection
http://62.173.142.81/drew/jYbXWzWzJZxMu/0bg7r4Fu/6FNvR8ClwgmU3K9eRFHwCZL/V4EUt2dyR_/2FQulKxQ_2Fze8eK3/SMO5Yl_2BPuQ/_2B49snui7_/2FLOe3Ko6as8fp/MUgDOSfZU6Dpa1I7o0j5G/VqQD_2Bumqn4Myfm/_2BQL_2BhR1HszY/TocLn3p8sVmtowm_2B/6OTZGgFfO/9qQJL2OyxO9xGC6r3J84/1Hw_2BXN3URNn_2FRiR/XmeYSNTVgprtLxVnjmtt4h/zq1_2FWGL3ouV/wUq7EqUY/xzZwPH0P8XChlht1ulV1_2F/xZqgBgTuj5/XO.jlk
http://checklist.skype.com/drew/atXnm1oMbB5L4Ntl5FgyfO/iEVslQ74abg_2/FW6J1whk/ejMAXerGRdbDd_2FjU9B8H
http://62.173.142.81/drew/jYbXWzWzJZxMu/0bg7r4Fu/6FNvR8ClwgmU3K9eRFHwCZL/V4EUt2dyR_/2FQulKxQ_2Fze8eK
Click to see the 4 hidden entries
http://62.173.142.81/
http://62.173
http://checklist.skype.com/
http://checklist.skype.com/drew/atXnm1oMbB5L4Ntl5Fgy