flash

20200413_140639.xlsx

Status: finished
Submission Time: 16.04.2020 10:40:55
Malicious
Trojan
Spyware
Exploiter
Evader
Lokibot

Comments

Tags

Details

  • Analysis ID:
    222987
  • API (Web) ID:
    342622
  • Analysis Started:
    16.04.2020 10:40:57
  • Analysis Finished:
    16.04.2020 10:47:33
  • MD5:
    8c5ff7a0f499a1ae96096ec97795b340
  • SHA1:
    a7ab6bccbdbb180b7788bbe37706cfe3798d05d5
  • SHA256:
    d833b6a13e1f6ec6ae190c6dc5f4be014c9a1a8a0b74a7b6df7a37dbca601901
  • Technologies:
Full Report Engine Info Verdict Score Reports

System: Windows 7 SP1 (with Office 2010 SP2, IE 11, FF 54, Chrome 60, Acrobat Reader DC 17, Java 8.0.1440.1, Flash 30.0.0.113)

malicious
100/100

malicious
15/59

malicious
12/45

malicious

IPs

IP Country Detection
89.208.229.230
Russian Federation
103.114.106.209
Viet Nam

Domains

Name IP Detection
russchine2wsdyspecial6plumbingjkmaterial.duckdns.org
103.114.106.209
toyo-at-jp.info
89.208.229.230

URLs

Name Detection
http://toyo-at-jp.info/ig1/fre.php
http://russchine2wsdyspecial6plumbingjkmaterial.duckdns.org/russdoc/regasm.exe
http://www.ibsensoftware.com/
Click to see the 1 hidden entries
https://curl.haxx.se/docs/http-cookies.html

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BR42M2GZ\regasm[1].exe
PE32 executable (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Roaming\vbc.exe
PE32 executable (GUI) Intel 80386, for MS Windows
#
C:\Users\user\Desktop\~$20200413_140639.xlsx
data
#
Click to see the 4 hidden entries
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\5D1B941C.jpeg
gd-jpeg v1.0 (using IJG JPEG v80), quality = 90", baseline, precision 8, 700x990, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\82C240C7.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
#
C:\Users\user\AppData\Roaming\85CB65\5E97AF.lck
very short file (no magic)
#
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-290172400-2828352916-2832973385-1004\ce1d9ab061b5b7ff17c765603e761dae_0f4f5130-48fa-4204-b1c4-585fbb81cd25
data
#