flash

Coronavirus Disease (COVID-19) CURE.exe

Status: finished
Submission Time: 20.03.2020 02:08:14
Malicious
Trojan
Evader
HawkEye

Comments

Tags

Details

  • Analysis ID:
    216732
  • API (Web) ID:
    330475
  • Analysis Started:
    20.03.2020 02:08:15
  • Analysis Finished:
    20.03.2020 02:14:42
  • MD5:
    8983fb4725e345acb1f8daf425a7abe7
  • SHA1:
    129ee2d1d260ea67b4f820e126329004088bb3a8
  • SHA256:
    c20d77fc6f197d2b0fb98dc2e14e5642c1a7db3673035e49a8891c476b156d63
  • Technologies:
Full Report Engine Info Verdict Score Reports

malicious

System: Windows 10 64 bit (version 1803) with Office 2016, Adobe Reader DC 19, Chrome 70, Firefox 63, Java 8.171, Flash 30.0.0.113

malicious
100/100

malicious
35/71

malicious
19/31

IPs

IP Country Detection
66.171.248.178
United States

Domains

Name IP Detection
208.168.6.0.in-addr.arpa
0.0.0.0
bot.whatismyipaddress.com
66.171.248.178

URLs

Name Detection
http://pomf.cat/upload.php&https://a.pomf.cat/
http://www.founder.com.cn/cn/bThe
http://www.founder.com.cn/cnS
Click to see the 57 hidden entries
http://www.tiro.com
http://www.goodfont.co.kr
http://www.carterandcone.com
http://www.sandoll.co.kr$
http://www.sajatypeworks.com
http://www.typography.netD
http://www.founder.com.cn/cn/cThe
http://www.typography.netF
https://a.pomf.cat/
http://fontfabrik.com
http://www.jiyu-kobo.co.jp/jp/b
http://www.carterandcone.comue
http://www.typography.net
http://www.sakkal.comh
http://www.jiyu-kobo.co.jp/n-u
http://www.founder.com.cn/cnighYa
http://www.ascendercorp.com/typedesigners.html
http://www.fonts.com
http://www.sandoll.co.kr
http://bot.whatismyipaddress.com
http://www.founder.com.cn/cn/f
http://www.nirsoft.net/
http://www.zhongyicts.com.cn
http://www.ascendercorp.com/typedesigners.html$e
http://www.founder.com.cn/cnei
http://www.tiro.comlG
http://www.carterandcone.como.
http://www.sakkal.com
http://www.founder.com.cn/cnfou
http://www.apache.org/licenses/LICENSE-2.0
http://pomf.cat/upload.php
http://www.typography.net=n9
http://www.jiyu-kobo.co.jp/T
http://www.jiyu-kobo.co.jp/P
http://www.jiyu-kobo.co.jp/sd
http://www.typography.netrz
http://www.jiyu-kobo.co.jp/jp/p
http://www.jiyu-kobo.co.jp/F
http://www.sandoll.co.krN.TTF
http://www.jiyu-kobo.co.jp/jp/
http://www.founder.com.cn/cnpu
http://en.wikip
http://en.w
http://bot.whatismyipaddress.com/
http://www.carterandcone.comlg
http://www.carterandcone.coml
http://www.carterandcone.comof
http://www.founder.com.cn/cn
http://www.jiyu-kobo.co.jp/p
http://www.jiyu-kobo.co.jp/
http://www.jiyu-kobo.co.jp/l
http://www.zhongyicts.com.cno.
http://www.jiyu-kobo.co.jp/b
http://www.tiro.comic
http://www.carterandcone.comJh
http://bot.whatismyipaddress.comx&
http://pomf.cat/upload.phpCContent-Disposition:

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\CLR_v2.0_32\UsageLogs\Coronavirus Disease (COVID-19) CURE.exe.log
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\CLR_v2.0_32\UsageLogs\MSBuild.exe.log
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\47b80686-5bce-b861-1d58-20829f456353
ASCII text, with no line terminators
#