flash

문서.exe.exe

Status: finished
Submission Time: 08.04.2020 02:50:01
Malicious
Ransomware
Trojan
Spyware
Evader
Remcos

Comments

Tags

Details

  • Analysis ID:
    221042
  • API (Web) ID:
    338841
  • Analysis Started:
    08.04.2020 02:50:02
  • Analysis Finished:
    08.04.2020 02:59:28
  • MD5:
    498cdce9322243dbf283771f0dc116f7
  • SHA1:
    417c51d1dad24baad06b0d9ff8540d36ba43c716
  • SHA256:
    515000d1d1ddb654d6f0d15bf38b5fec214ac05568998494dfc6b3fac6a7c7db
  • Technologies:
Full Report Engine Info Verdict Score Reports

malicious

System: Windows 7 SP1 (with Office 2010 SP2, IE 11, FF 54, Chrome 60, Acrobat Reader DC 17, Java 8.0.1440.1, Flash 30.0.0.113)

malicious
100/100

malicious
28/72

malicious
11/47

IPs

IP Country Detection
172.111.188.199
United States

URLs

Name Detection
http://tempuri.org/DataSet1.xsd

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Temp\tmpDE9B.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\remcos\logs.dat
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\wGXDwL.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
Click to see the 1 hidden entries
C:\Users\user\AppData\Roaming\wGXDwL.exe:Zone.Identifier
ASCII text, with CRLF line terminators
#