top title background image
flash

download.exe

Status: finished
Submission Time: 2023-03-20 12:59:32 +01:00
Malicious
Trojan
Evader
GuLoader

Comments

Tags

Details

  • Analysis ID:
    830512
  • API (Web) ID:
    1197617
  • Analysis Started:
    2023-03-20 13:00:18 +01:00
  • Analysis Finished:
    2023-03-20 13:30:28 +01:00
  • MD5:
    064fa36da0c2ca360b0906cc5bfe67c6
  • SHA1:
    a6623c33cbd86bdaee063f897bea1692621494e5
  • SHA256:
    6974c5051372213d0e90147660c4b21bfff238e20c6449acb19f1901bf4729c8
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 52
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
malicious
Score: 76
System: Windows 10 64 bit 20H2 Native physical Machine for testing VM-aware malware (Office 2019, Chrome 93, Firefox 91, Adobe Reader DC 21, Java 8 Update 301

Third Party Analysis Engines

malicious

IPs

IP Country Detection
37.139.128.83
Germany

URLs

Name Detection
http://37.139.128.83/2-2
http://nsis.sf.net/NSIS_Error
http://37.139.128.83/2M
Click to see the 12 hidden entries
http://37.139.128.83/2Data
http://37.139.128.83/2k
http://37.139.128.83/2
http://37.139.128.83/2R2
http://37.139.128.83/2W7
http://37.139.128.83/2e
http://www.avast.com0/
http://37.139.128.83/l
http://nsis.sf.net/NSIS_ErrorError
http://37.139.128.83/2gsLMEM8
http://37.139.128.83/2$2
http://37.139.128.83/262hk

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Temp\nse224D.tmp\System.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\Heize\Afreager.For
data
#
C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\Heize\Poserne\Bedugget39.Rus
data
#
Click to see the 2 hidden entries
C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\Heize\lang-1032.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\Heize\microphone-sensitivity-low-symbolic.symbolic.png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
#