top title background image
flash

문서.exe.exe

Status: finished
Submission Time: 2020-04-08 02:50:01 +02:00
Malicious
Ransomware
Trojan
Spyware
Evader
Remcos

Comments

Tags

Details

  • Analysis ID:
    221042
  • API (Web) ID:
    338841
  • Analysis Started:
    2020-04-08 02:50:02 +02:00
  • Analysis Finished:
    2020-04-08 02:59:28 +02:00
  • MD5:
    498cdce9322243dbf283771f0dc116f7
  • SHA1:
    417c51d1dad24baad06b0d9ff8540d36ba43c716
  • SHA256:
    515000d1d1ddb654d6f0d15bf38b5fec214ac05568998494dfc6b3fac6a7c7db
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: unknown

Third Party Analysis Engines

malicious
Score: 28/72
malicious
Score: 11/47

IPs

IP Country Detection
172.111.188.199
United States

URLs

Name Detection
http://tempuri.org/DataSet1.xsd

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Temp\tmpDE9B.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\remcos\logs.dat
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\wGXDwL.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
Click to see the 1 hidden entries
C:\Users\user\AppData\Roaming\wGXDwL.exe:Zone.Identifier
ASCII text, with CRLF line terminators
#