top title background image
flash

Linecreator.exe

Status: finished
Submission Time: 2020-06-08 14:15:06 +02:00
Malicious
Trojan
Evader
Remcos

Comments

Tags

Details

  • Analysis ID:
    236476
  • API (Web) ID:
    369013
  • Analysis Started:
    2020-06-08 14:15:07 +02:00
  • Analysis Finished:
    2020-06-08 14:21:01 +02:00
  • MD5:
    d9a740736fbbe691f63854281fc73680
  • SHA1:
    d57ac70e628cc2f9ec632a0f7b79ba878e11610d
  • SHA256:
    0bd7af6e50e0a43610e38d90ab4ecd45a0386cba3dcb7fc98db75de8c4b158ad
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 27/71
malicious
Score: 10/44
malicious

IPs

IP Country Detection
185.140.53.35
Sweden

Domains

Name IP Detection
proremm1.duckdns.org
185.140.53.35

URLs

Name Detection
http://xml.org/sax/properties/lexical-handlerhttp://xml.org/sax/properties/declaration-handlerBase64
http://xml.org/sax/properties/declaration-handler
http://www.mihaimoga.com/mailto:contact
Click to see the 2 hidden entries
http://www.mihaimoga.com/
http://xml.org/sax/properties/lexical-handler

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Temp\Temp.bmp
PE32 executable (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Roaming\Explorrerr\wloos.dat
data
#
C:\Users\user\AppData\Roaming\Linecreator.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Jun 4 17:20:36 2020, mtime=Mon Jun 8 20:15:34 2020, atime=Mon Jun 8 20:15:32 2020, length=3008512, window=hide
#