top title background image
flash

ProjectFunding_450726_Jun01.js

Status: finished
Submission Time: 2023-06-01 17:44:20 +02:00
Malicious
Trojan
Evader
Qbot

Comments

Tags

  • js

Details

  • Analysis ID:
    880006
  • API (Web) ID:
    1246978
  • Analysis Started:
    2023-06-01 17:53:26 +02:00
  • Analysis Finished:
    2023-06-01 18:18:24 +02:00
  • MD5:
    a657553449746c482dacfe3b19119b7a
  • SHA1:
    630b815d443f8f7ef7e4c4c7c100de1cd8a7ed53
  • SHA256:
    44e029dd6210c4906a82e1f16dd5ebed434efd225dafb92fc560e6ff6d1ee948
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 80
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
malicious
Score: 92
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Run Condition: Without Instrumentation

IPs

IP Country Detection
103.42.86.42
India
122.186.210.254
India
27.109.19.90
India
Click to see the 97 hidden entries
89.129.109.27
Spain
45.243.142.31
Egypt
82.125.44.236
France
81.229.117.95
Sweden
98.145.23.67
United States
70.28.50.223
Canada
103.139.242.6
India
116.120.145.170
Korea Republic of
116.74.163.130
India
105.184.209.194
South Africa
122.184.143.86
India
201.244.108.183
Colombia
90.104.151.37
France
76.16.49.134
United States
41.186.88.38
Rwanda
85.104.105.67
Turkey
69.242.31.249
United States
76.178.148.107
United States
201.143.215.69
Mexico
205.237.67.69
Canada
86.132.236.117
United Kingdom
75.143.236.149
United States
50.68.204.71
Canada
172.115.17.50
United States
77.86.98.236
United Kingdom
113.11.92.30
Bangladesh
92.9.45.20
United Kingdom
93.147.235.8
Italy
198.2.51.242
United States
31.53.29.235
United Kingdom
103.123.223.133
India
77.126.99.230
Israel
71.38.155.217
United States
89.79.229.50
Poland
102.156.10.183
Tunisia
65.95.141.84
Canada
92.154.17.149
France
86.176.83.44
United Kingdom
176.142.207.63
France
199.27.66.213
United States
79.168.224.165
Portugal
47.199.241.39
United States
12.172.173.82
United States
83.249.198.100
Sweden
45.62.70.33
Canada
50.68.186.195
Canada
14.192.241.76
Malaysia
70.50.83.216
Canada
100.4.163.158
United States
86.168.210.41
United Kingdom
41.227.190.59
Tunisia
84.35.26.14
Netherlands
184.181.75.148
United States
70.49.205.198
Canada
47.34.30.133
United States
117.195.17.148
India
69.160.121.6
Jamaica
72.205.104.134
United States
173.88.135.179
United States
165.120.169.171
United States
24.234.220.88
United States
114.143.176.236
India
213.64.33.92
Sweden
161.142.103.187
Malaysia
89.32.156.5
Italy
125.99.69.178
India
80.167.196.79
Denmark
184.182.66.109
United States
84.215.202.8
Norway
86.195.14.72
France
83.110.223.61
United Arab Emirates
147.147.30.126
United Kingdom
80.12.88.148
France
85.61.165.153
Spain
95.45.50.93
Ireland
47.205.25.170
United States
94.204.202.106
United Arab Emirates
103.101.203.177
Singapore
85.57.212.13
Spain
88.126.94.4
France
124.122.47.148
Thailand
75.109.111.89
United States
96.87.28.170
United States
103.144.201.48
unknown
76.86.31.59
United States
92.149.250.113
France
98.187.21.2
United States
81.101.185.146
United Kingdom
125.99.76.102
India
178.175.187.254
Moldova Republic of
96.56.197.26
United States
64.121.161.102
United States
79.92.15.6
France
68.203.69.96
United States
82.131.141.209
Hungary
217.195.153.225
Netherlands
96.114.21.40
United States

Domains

Name IP Detection
xfinity.com
96.114.21.40
garokelka.com
217.195.153.225
www.xfinity.com
0.0.0.0

URLs

Name Detection
https://garokelka.com/$
https://garokelka.com/yjxcii.msi0C:
https://www.xfinity.com/mobile/policies/broadband-disclosures
Click to see the 8 hidden entries
https://www.xfinity.com/learn/internet-service/acp
https://www.xfinity.com/networkmanagement
https://garokelka.com/yjxcii.msi-825014416310365950
https://%/%.msi%InstallProduct
https://garokelka.com/yjxcii.msill.mui
https://garokelka.com/yjxcii.msi
https://xfinity.com/
https://garokelka.com/

Dropped files

Name File Type Hashes Detection
C:\Windows\Temp\~DF2A70DF5CEC56BF5D.TMP
Composite Document File V2 Document, Cannot read section info
#
C:\Windows\Temp\~DFD99EF38F4A03F6CF.TMP
data
#
C:\Windows\Temp\~DFC37A16C50B7C8BD7.TMP
data
#
Click to see the 16 hidden entries
C:\Windows\Temp\~DFBDB1CFA03CBC6FC5.TMP
Composite Document File V2 Document, Cannot read section info
#
C:\Windows\Temp\~DFB376DA478E956195.TMP
Composite Document File V2 Document, Cannot read section info
#
C:\Windows\Temp\~DF95BD744A4429F4FF.TMP
Composite Document File V2 Document, Cannot read section info
#
C:\Windows\Temp\~DF883F1083607F70C3.TMP
data
#
C:\Windows\Temp\~DF8619ED3253D39042.TMP
data
#
C:\Windows\Temp\~DF79B335FA0EB48BA5.TMP
Composite Document File V2 Document, Cannot read section info
#
C:\Windows\Temp\~DF6E755A35FD255ACB.TMP
data
#
C:\Config.Msi\4fa97f.rbs
data
#
C:\Windows\Temp\~DF22471B5A50AA2E97.TMP
data
#
C:\Windows\Installer\inprogressinstallinfo.ipi
Composite Document File V2 Document, Cannot read section info
#
C:\Windows\Installer\MSIAA1B.tmp
data
#
C:\Windows\Installer\MSI319E.tmp
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Adobe Acrobat PDF Browser Plugin 4.8.25, Author: Adobe Inc., Keywords: Installer, Comments: Adobe Acro (…)
#
C:\Windows\Installer\4fa980.msi
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Adobe Acrobat PDF Browser Plugin 4.8.25, Author: Adobe Inc., Keywords: Installer, Comments: Adobe Acro (…)
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\national[1].htm
HTML document, ASCII text, with very long lines (65212)
#
C:\Users\user\AppData\Local\AdobeAcrobatPDFBrowserPlugin\notify.vbs
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\AdobeAcrobatPDFBrowserPlugin\main.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#