flash

Overdue Invoices before 5-04-2020.xls

Status: finished
Submission Time: 09.06.2020 15:33:45
Malicious
Trojan
Exploiter
Evader
Nanocore

Comments

Tags

Details

  • Analysis ID:
    236934
  • API (Web) ID:
    369903
  • Analysis Started:
    09.06.2020 15:33:47
  • Analysis Finished:
    09.06.2020 15:46:01
  • MD5:
    4a1b031536cb803ece7a69f6fdfcdb25
  • SHA1:
    0b860cf8fa06344a449fb4fdb7cad3a1d12c9df9
  • SHA256:
    410b37038436dfd621def737f102dce7ae9ac6a7c39323f9d0f4f48e72231334
  • Technologies:
Full Report Engine Info Verdict Score Reports

malicious

System: Windows 7 SP1 (with Office 2010 SP2, IE 11, FF 54, Chrome 60, Acrobat Reader DC 17, Java 8.0.1440.1, Flash 30.0.0.113)

malicious
100/100

malicious
8/80

malicious
10/48

IPs

IP Country Detection
185.244.30.216
Netherlands

Domains

Name IP Detection
socket-controller.ddns.net
185.244.30.216
unifedslashclub.com
47.91.104.141

URLs

Name Detection
http://unifedslashclub.com/igm/rrraw.msi
http://unifedslashclub.com/igm/rrraw.msi/qn
http://unifedslashclub.com/igm/rrraw.msi/qns

Dropped files

Name File Type Hashes Detection
C:\Program Files\WAN Service\wansv.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Users\user\AppData\Local\Temp\tmp927B.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\0F4F5130-48FA-4204-B1C4-585FBB81CD25\run.dat
Non-ISO extended-ASCII text, with no line terminators
#
Click to see the 6 hidden entries
C:\Users\user\AppData\Local\Temp\tmp9634.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\0F4F5130-48FA-4204-B1C4-585FBB81CD25\catalog.dat
data
#
C:\Users\user\AppData\Roaming\0F4F5130-48FA-4204-B1C4-585FBB81CD25\settings.bak
data
#
C:\Users\user\AppData\Roaming\0F4F5130-48FA-4204-B1C4-585FBB81CD25\settings.bin
data
#
C:\Users\user\AppData\Roaming\0F4F5130-48FA-4204-B1C4-585FBB81CD25\storage.dat
data
#
C:\Users\user\AppData\Roaming\0F4F5130-48FA-4204-B1C4-585FBB81CD25\task.dat
ASCII text, with no line terminators
#