flash

Attached pdf.exe

Status: finished
Submission Time: 30.03.2020 05:55:49
Malicious
Trojan
Evader
Remcos

Comments

Tags

Details

  • Analysis ID:
    218797
  • API (Web) ID:
    334475
  • Analysis Started:
    30.03.2020 05:55:50
  • Analysis Finished:
    30.03.2020 06:06:34
  • MD5:
    90de1602c5900c2a81bcbbad0eb754e7
  • SHA1:
    c77362f9d82fba23822c6bac1459c3c75a5a5695
  • SHA256:
    8599ded7ef4b89944c5a5330e8608d9e1ab28acd67706284b617ddca1a7d74ab
  • Technologies:
Full Report Engine Info Verdict Score Reports

System: Windows 10 64 bit (version 1803) with Office 2016, Adobe Reader DC 19, Chrome 70, Firefox 63, Java 8.171, Flash 30.0.0.113

malicious
100/100

malicious
11/71

malicious
6/47

IPs

IP Country Detection
185.244.30.125
Netherlands
216.58.207.65
United States

Domains

Name IP Detection
rex2016.hopto.org
185.244.30.125
jbarn.camdvr.org
0.0.0.0
site-cdn.onenote.net
0.0.0.0
Click to see the 5 hidden entries
rex2015.freeddns.org
0.0.0.0
rex2016.freeddns.org
0.0.0.0
googlehosted.l.googleusercontent.com
216.58.207.65
jbarn.sytes.net
0.0.0.0
doc-0k-04-docs.googleusercontent.com
0.0.0.0

URLs

Name Detection
http://blackman.wp-club.net
http://pki.goog/gsr2/GTS1O1.crt0
https://doc-0k-04-docs.googleusercontent.com/
Click to see the 7 hidden entries
http://pki.goog/gsr2/GTS
http://crl.pki.goog/gsr2/gsr2.crl0?
http://ocsp.pki.goog/gsr202
https://pki.goog/repository/0
http://crl.pki.goog/GTS1O1.crl0
http://ocsp.pki.goog/gts1o10
https://doc-0k-04-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/6dvv3dkp

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Roaming\remcos\logs.dat
ASCII text, with CRLF line terminators
#
C:\Users\user\Cseg\Csegsew.exe
PE32 executable (GUI) Intel 80386, for MS Windows
#
C:\Users\Public\Yako.bat
ASCII text, with CRLF line terminators
#
Click to see the 3 hidden entries
C:\Users\user\Cseg.hta
HTML document, ASCII text, with CRLF line terminators
#
C:\Users\Public\Fcc
ASCII text, with no line terminators
#
C:\Users\Public\Natso.bat
ASCII text, with CRLF line terminators
#