top title background image
flash

SGQ-200875.exe

Status: finished
Submission Time: 2020-06-22 20:48:48 +02:00
Malicious
Trojan
Spyware
Evader
AgentTesla

Comments

Tags

Details

  • Analysis ID:
    240610
  • API (Web) ID:
    376965
  • Analysis Started:
    2020-06-22 20:53:35 +02:00
  • Analysis Finished:
    2020-06-22 21:00:33 +02:00
  • MD5:
    9895f8fe3df4c3309b81cd5cf08c0e24
  • SHA1:
    1006644a248bc248d1c1db6909ae886afa7d3478
  • SHA256:
    315992fe86f3bc95dc19312739fe9e89ee80a85f94c02bbebb420919bfaec5d6
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 84
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 12/74

URLs

Name Detection
http://www.apache.org/licenses/LICENSE-2.0
http://gimp-print.sourceforge.net/xsd/gp.xsd-1.0
http://nsis.sf.net/NSIS_Error
Click to see the 5 hidden entries
http://nsis.sf.net/NSIS_ErrorError
http://openoffice.org/2001/toolbar
http://www.freedesktop.org/standards/shared-mime-info
http://mozilla.org/MPL/2.0/.
http://tempuri.org/Intro.xsd

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Temp\ship\prs.sid.xml
XML 1.0 document, UTF-8 Unicode text
#
C:\Users\user\AppData\Roaming\rct\webservices\org.gnome.desktop.datetime.gschema.xml
XML 1.0 document, ASCII text
#
C:\Users\user\AppData\Roaming\rct\webservices\genasm.exe
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
#
Click to see the 28 hidden entries
C:\Users\user\AppData\Roaming\rct\webservices\SamplesTable.xml
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\rct\webservices\10.opends60.dll
data
#
C:\Users\user\AppData\Roaming\can\x-s3m.xml
XML 1.0 document, UTF-8 Unicode text
#
C:\Users\user\AppData\Roaming\can\roletemplateprivileges.xml
XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\can\resgen.exe
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Users\user\AppData\Roaming\can\org.gnome.Logs.enums.xml
exported SGML document, ASCII text
#
C:\Users\user\AppData\Roaming\can\iso6395.xml
ASCII text, with no line terminators
#
C:\Users\user\AppData\Roaming\can\intro.xml
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\can\MicrosoftVisualStudioVSHelp.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Users\user\AppData\Local\Temp\ship\x-icns.xml
XML 1.0 document, UTF-8 Unicode text
#
C:\Users\user\AppData\Local\Temp\ship\unresolvedaddress.xml
XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\ship\sbscmp10.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Temp\ship\s390-linux.xml
XML 1.0 document, ASCII text
#
C:\Users\user\AppData\Local\Temp\Cogency
data
#
C:\Users\user\AppData\Local\Temp\ship\model122.xml
XML 1.0 document, ASCII text
#
C:\Users\user\AppData\Local\Temp\ship\formcontrols.xml
XML 1.0 document, ASCII text
#
C:\Users\user\AppData\Local\Temp\ship\conmanui.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Temp\ship\com.ubuntu.notifications.settings.gschema.xml
XML 1.0 document, ASCII text
#
C:\Users\user\AppData\Local\Temp\ship\SmartDevHowDoI80.xml
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\ship\MicrosoftWindowsCEForms.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Users\user\AppData\Local\Temp\ship\27.opends60.dll
data
#
C:\Users\user\AppData\Local\Temp\ship\18.opends60.dll
data
#
C:\Users\user\AppData\Local\Temp\nsv27CA.tmp
data
#
C:\Users\user\AppData\Local\Temp\dan\wsdl\paypal\msats10ui.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Temp\dan\wsdl\paypal\mc.exe
PE32 executable (console) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Temp\dan\wsdl\paypal\83.opends60.dll
data
#
C:\Users\user\AppData\Local\Temp\b2a34612.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Jun 4 17:20:38 2020, mtime=Tue Jun 23 02:54:23 2020, atime=Tue Jun 23 02:54:03 2020, length=449953, window=hide
#
C:\Users\user\AppData\Local\Temp\SwatVelamen.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
#