flash

server.exe

Status: finished
Submission Time: 2023-03-20 15:15:26 +01:00
Malicious
Trojan
Evader
Ursnif

Comments

Tags

  • agenziaentrate
  • exe
  • gozi
  • isfb
  • mef
  • mise
  • ursnif

Details

  • Analysis ID:
    830657
  • API (Web) ID:
    1197753
  • Analysis Started:
    2023-03-20 15:25:14 +01:00
  • Analysis Finished:
    2023-03-20 15:32:35 +01:00
  • MD5:
    386839452984e2eda4151746d57ea19b
  • SHA1:
    b9c43085f6b63db8a02b4764c4d75699efa9d074
  • SHA256:
    f139bc8f71a483ba058e2577ef5952b85a74cebd302632a121e4bbc0d96bb953
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

malicious

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
100/100

malicious
13/39

IPs

IP Country Detection
62.173.142.81
Russian Federation
193.233.175.113
Russian Federation

Domains

Name IP Detection
checklist.skype.com
0.0.0.0

URLs

Name Detection
http://193.233.175.113/drew/V9a0o6ef3/Au9_2F9Ppi_2FsgXZknJ/9gyATvTasA37TGnwf_2/FF8_2FeHTfCbmbSNhIELze/nTrHQt_2F5xY5/R3GxHbhE/YI67FVPjLAHvMvQCPm1ZB2r/hUITXAVF6y/1AwvZRZpD_2BX4_2B/OLj6it5W6CBi/bb63MeG6yuy/QmyD_2FX_2F1Ss/xqhYIyVOpHg2U1VNG_2Fq/xK7Nn_2Fqm4MHDMP/QwAVZmc5HxKcFpM/zNu_2F2WLah1WqJIoz/_2Fgr_2B0/Yx87G29pDT1ZwKwi4aHO/N92d2eUOVnKaenJHbAo/y89RoyrX/My.jlk
http://62.173.142.81/drew/L41ZdaozWB/9G_2FCBbfzGg7ByXT/_2Bg8QMbKe0e/hoJ4ZQmshRx/yrzS4Fo3MBljQG/zLPIZfVEynjc1_2BzcNzJ/VlCSBaC_2BsWiOk3/S_2FVtn98ADwViF/w4EuoTZ6r2ouB5CbJQ/OJAYX7gGB/SPaOx4IeK2WgwzyMW0mh/a6bMYaMIQJb9DwJ1_2B/abyaGtCr0edo_2BHNpcXcS/i41T8cYfwvY4g/ixrgvBpj/x9Y_2FoxbDLce5swL7_2FuZ/twfMwTZOCD/kYv7KY9tbIJovwRgo/dob_2F_2FGBd/pRbVJOI3b/HRL7.jlk
http://193.23