flash

IMD_09920100.exe

Status: finished
Submission Time: 15.06.2020 10:25:56
Malicious
Trojan
Spyware
Evader
Nanocore

Comments

Tags

Details

  • Analysis ID:
    238435
  • API (Web) ID:
    372814
  • Analysis Started:
    15.06.2020 10:25:56
  • Analysis Finished:
    15.06.2020 10:45:11
  • MD5:
    7c96bd010e89acbdd3f8606ce25f0aea
  • SHA1:
    34f16f8e66329d969c691c7484dde73becedc710
  • SHA256:
    f5b99bdcb3a09ccef9455e82dff1902b6913280d293be51d87de78fc418e9f72
  • Technologies:
Full Report Engine Info Verdict Score Reports

System: Windows 10 64 bit (version 1803) with Office 2016, Adobe Reader DC 19, Chrome 70, Firefox 63, Java 8.171, Flash 30.0.0.113

malicious
100/100

malicious
30/73

malicious
24/48

IPs

IP Country Detection
1.1.1.1
Australia
79.134.225.111
Switzerland

Domains

Name IP Detection
stronggods.ddns.net
79.134.225.111

URLs

Name Detection
http://secure.globalsign.net/cacert/PrimObject.crt0
http://secure.globalsign.net/cacert/ObjectSign.crt09
http://www.globalsign.net/repository09
Click to see the 3 hidden entries
http://www.autoitscript.com/autoit3/0
http://www.globalsign.net/repository/0
http://www.globalsign.net/repository/03

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Temp\22895710\Update.vbs
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\rjnkgdmk.pif
PE32 executable (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Temp\RegSvcs.exe
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
#
Click to see the 32 hidden entries
C:\Users\user\AppData\Local\Temp\tmp11E5.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\59407D34-C8C5-44DF-A766-BA8A11CB1CB0\run.dat
data
#
C:\Program Files (x86)\WPA Service\wpasv.exe
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\RegSvcs.exe.log
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\wpasv.exe.log
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\anjv.dat
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\fclk.dll
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\gikpbqhrps.dll
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\gxkw.bmp
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\jogdsluot.jpg
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\mwvoducomd.ppt
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\oganqovmq.jpg
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\paquaenj.jad
data
#
C:\Users\user\AppData\Local\Temp\22895710\pdqrhudb.msc
ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\qurlerhcn.msc
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\soiiie.vbs
Little-endian UTF-16 Unicode text, with CRLF, CR line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\ssxnhcqij.xls
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\susuxxe.exe
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\ttgbe.bmp
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\ugnfna.exe
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\vdxee.msc
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\votbuh.log
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\wciehen.dat
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\wojrwwatw.xl
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\xhetciba.dat
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\tmp163C.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\59407D34-C8C5-44DF-A766-BA8A11CB1CB0\catalog.dat
data
#
C:\Users\user\AppData\Roaming\59407D34-C8C5-44DF-A766-BA8A11CB1CB0\settings.bin
data
#
C:\Users\user\AppData\Roaming\59407D34-C8C5-44DF-A766-BA8A11CB1CB0\storage.dat
data
#
C:\Users\user\AppData\Roaming\59407D34-C8C5-44DF-A766-BA8A11CB1CB0\task.dat
ASCII text, with no line terminators
#
C:\Users\user\temp\pdqrhudb.msc
ASCII text, with CRLF line terminators
#
\Device\ConDrv
ASCII text, with CRLF line terminators
#