top title background image
flash

IMD_09920100.exe

Status: finished
Submission Time: 2020-06-15 10:25:56 +02:00
Malicious
Trojan
Spyware
Evader
Nanocore

Comments

Tags

Details

  • Analysis ID:
    238435
  • API (Web) ID:
    372814
  • Analysis Started:
    2020-06-15 10:25:56 +02:00
  • Analysis Finished:
    2020-06-15 10:45:11 +02:00
  • MD5:
    7c96bd010e89acbdd3f8606ce25f0aea
  • SHA1:
    34f16f8e66329d969c691c7484dde73becedc710
  • SHA256:
    f5b99bdcb3a09ccef9455e82dff1902b6913280d293be51d87de78fc418e9f72
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 30/73
malicious
Score: 24/48

IPs

IP Country Detection
1.1.1.1
Australia
79.134.225.111
Switzerland

Domains

Name IP Detection
stronggods.ddns.net
79.134.225.111

URLs

Name Detection
http://secure.globalsign.net/cacert/PrimObject.crt0
http://secure.globalsign.net/cacert/ObjectSign.crt09
http://www.globalsign.net/repository09
Click to see the 3 hidden entries
http://www.autoitscript.com/autoit3/0
http://www.globalsign.net/repository/0
http://www.globalsign.net/repository/03

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Temp\22895710\Update.vbs
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\rjnkgdmk.pif
PE32 executable (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Roaming\59407D34-C8C5-44DF-A766-BA8A11CB1CB0\run.dat
data
#
Click to see the 32 hidden entries
C:\Users\user\AppData\Local\Temp\tmp11E5.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\RegSvcs.exe
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Users\user\AppData\Local\Temp\tmp163C.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\ugnfna.exe
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\vdxee.msc
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\votbuh.log
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\wciehen.dat
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\wojrwwatw.xl
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\xhetciba.dat
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\susuxxe.exe
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\59407D34-C8C5-44DF-A766-BA8A11CB1CB0\catalog.dat
data
#
C:\Users\user\AppData\Roaming\59407D34-C8C5-44DF-A766-BA8A11CB1CB0\settings.bin
data
#
C:\Users\user\AppData\Roaming\59407D34-C8C5-44DF-A766-BA8A11CB1CB0\storage.dat
data
#
C:\Users\user\AppData\Roaming\59407D34-C8C5-44DF-A766-BA8A11CB1CB0\task.dat
ASCII text, with no line terminators
#
C:\Users\user\temp\pdqrhudb.msc
ASCII text, with CRLF line terminators
#
\Device\ConDrv
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\ttgbe.bmp
ASCII text, with CRLF line terminators
#
C:\Program Files (x86)\WPA Service\wpasv.exe
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Users\user\AppData\Local\Temp\22895710\ssxnhcqij.xls
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\soiiie.vbs
Little-endian UTF-16 Unicode text, with CRLF, CR line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\qurlerhcn.msc
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\pdqrhudb.msc
ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\paquaenj.jad
data
#
C:\Users\user\AppData\Local\Temp\22895710\oganqovmq.jpg
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\mwvoducomd.ppt
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\jogdsluot.jpg
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\gxkw.bmp
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\gikpbqhrps.dll
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\fclk.dll
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\22895710\anjv.dat
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\wpasv.exe.log
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\RegSvcs.exe.log
ASCII text, with CRLF line terminators
#