top title background image
flash

TGSKU7q5IQ.exe

Status: finished
Submission Time: 2020-06-03 20:17:34 +02:00
Malicious
Trojan
Spyware
Evader
FormBook

Comments

Tags

Details

  • Analysis ID:
    235445
  • API (Web) ID:
    366982
  • Analysis Started:
    2020-06-03 20:17:35 +02:00
  • Analysis Finished:
    2020-06-03 20:31:05 +02:00
  • MD5:
    33f9abb5fcb1ee4a1a3e001d059225b8
  • SHA1:
    5f207875c1ca0963f8cb0a0f2c8558fc37fa27a4
  • SHA256:
    1dd89cec8476c901750387a54eb0cce63addcb6037d96de9a78fd736531f9390
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 16/73
malicious
Score: 9/48
malicious

IPs

IP Country Detection
23.20.239.12
United States

Domains

Name IP Detection
site-cdn.onenote.net
0.0.0.0
www.yoxi.ltd
0.0.0.0
www.searchmakeup.com
0.0.0.0
Click to see the 3 hidden entries
www.sarealodinge.com
0.0.0.0
www.aaronnational.com
0.0.0.0
HDRedirect-LB5-1afb6e2973825a56.elb.us-east-1.amazonaws.com
23.20.239.12

URLs

Name Detection
http://www.porcber.com
http://www.porcber.comReferer:
http://www.porcber.com/mq3/
Click to see the 79 hidden entries
http://www.porcber.com/mq3/www.changancloud.com
http://www.searchmakeup.com/mq3/?qrT4Hh_h=0f2vG8QIIcp679PRBI7K0tkkchJ4zDLe5btvcDqwkOaC6818yn4cikTFuAqeQAwmBAAY&mVKX26=MZr0cf7xmpQXmrEp
http://www.hnbxm.com
http://www.yoxi.ltdReferer:
http://www.yoxi.ltd/mq3/www.sarealodinge.com
http://www.aaronnational.com
http://www.changancloud.com/mq3/www.springholdingsbnk.com
http://www.aaronnational.comReferer:
http://www.sj233.com
http://www.apache.org/licenses/LICENSE-2.0
http://www.askcopdtreatmentok.live
http://www.searchmakeup.comReferer:
http://www.educationgrants.siteReferer:
http://www.changancloud.com/mq3/
http://www.sarealodinge.comReferer:
https://www.hugedomains.com/domain_profile.cfm?d=searchmakeup&e=com
http://www.yoxi.ltd/mq3/
http://www.spartanpronos.com/mq3/www.porcber.com
http://www.sakkal.com
http://www.zhongyicts.com.cn
http://www.askcopdtreatmentok.live/mq3/
http://www.spartanpronos.com
http://www.changancloud.com
http://www.educationgrants.site/mq3/
http://www.sj233.com/mq3/
http://www.lianxiaoshu.com
http://www.aaronnational.com/mq3/
http://www.askcopdtreatmentok.liveReferer:
http://www.jiyu-kobo.co.jp/
http://www.sarealodinge.com
http://www.am0rsexkreto.com/mq3/
http://www.thehuyertrnes.com/mq3/
http://www.springholdingsbnk.com
http://www.sj233.com/mq3/www.am0rsexkreto.com
http://www.founder.com.cn/cn
http://www.am0rsexkreto.com/mq3/www.thehuyertrnes.com
http://www.lianxiaoshu.com/mq3/
http://www.carterandcone.coml
http://www.sandoll.co.kr
http://www.sarealodinge.com/mq3/
http://www.educationgrants.site
http://www.typography.netD
http://www.hnbxm.com/mq3/www.educationgrants.site
http://www.sajatypeworks.com
http://www.changancloud.comReferer:
http://www.hnbxm.comReferer:
https://www.hugedomains.com/domain_profile.cfm?d=searchmakeup&e=com
http://www.searchmakeup.com/mq3/www.yoxi.ltd
http://www.goodfont.co.kr
http://www.tiro.com
http://www.founder.com.cn/cn/cThe
http://www.clarksonassistivetech.com
http://www.spartanpronos.com/mq3/
http://www.searchmakeup.com
http://www.thehuyertrnes.com
http://www.springholdingsbnk.comReferer:
http://www.clarksonassistivetech.com/mq3/
http://www.founder.com.cn/cn/bThe
http://www.spartanpronos.comReferer:
http://www.springholdingsbnk.com/mq3/www.hnbxm.com
http://www.askcopdtreatmentok.live/mq3/www.clarksonassistivetech.com
http://www.hnbxm.com/mq3/
http://www.lianxiaoshu.comReferer:
http://www.fonts.com
http://www.am0rsexkreto.com
http://www.thehuyertrnes.com/mq3/www.askcopdtreatmentok.live
http://www.sj233.comReferer:
http://www.yoxi.ltd
http://ns.adob1
http://www.sarealodinge.com/mq3/www.lianxiaoshu.com
http://www.clarksonassistivetech.comReferer:
http://www.am0rsexkreto.comReferer:
http://www.thehuyertrnes.comReferer:
http://www.clarksonassistivetech.com/mq3/www.spartanpronos.com
http://www.lianxiaoshu.com/mq3/www.sj233.com
http://www.searchmakeup.com/mq3/
http://www.aaronnational.com/mq3/www.searchmakeup.com
http://www.springholdingsbnk.com/mq3/
http://fontfabrik.com

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\TGSKU7q5IQ.exe.log
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\Uxxdph\ulhdmvehff-42.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Users\user\AppData\Roaming\N629P6-6\N62logrf.ini
data
#
Click to see the 5 hidden entries
C:\Users\user\AppData\Roaming\N629P6-6\N62logri.ini
data
#
C:\Users\user\AppData\Roaming\N629P6-6\N62logrv.ini
data
#
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\ulhdmvehff-42.exe.log
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms
MS Windows shortcut, Item id list present, Points to a file or directory, Read-Only, Directory, ctime=Wed Apr 11 22:38:20 2018, mtime=Thu Jun 4 02:19:44 2020, atime=Thu Jun 4 02:19:44 2020, length=8192, window=hide
#
C:\Users\user\AppData\Roaming\N629P6-6\N62logim.jpeg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 1280x1024, frames 3
#