flash

SGQ-200875.exe

Status: finished
Submission Time: 22.06.2020 20:48:48
Malicious
Trojan
Spyware
Evader
AgentTesla

Comments

Tags

Details

  • Analysis ID:
    240610
  • API (Web) ID:
    376965
  • Analysis Started:
    22.06.2020 20:53:35
  • Analysis Finished:
    22.06.2020 21:00:33
  • MD5:
    9895f8fe3df4c3309b81cd5cf08c0e24
  • SHA1:
    1006644a248bc248d1c1db6909ae886afa7d3478
  • SHA256:
    315992fe86f3bc95dc19312739fe9e89ee80a85f94c02bbebb420919bfaec5d6
  • Technologies:
Full Report Engine Info Verdict Score Reports

System: Windows 10 64 bit (version 1803) with Office 2016, Adobe Reader DC 19, Chrome 70, Firefox 63, Java 8.171, Flash 30.0.0.113

malicious
84/100

malicious
12/74

URLs

Name Detection
http://www.apache.org/licenses/LICENSE-2.0
http://gimp-print.sourceforge.net/xsd/gp.xsd-1.0
http://nsis.sf.net/NSIS_Error
Click to see the 5 hidden entries
http://nsis.sf.net/NSIS_ErrorError
http://openoffice.org/2001/toolbar
http://www.freedesktop.org/standards/shared-mime-info
http://mozilla.org/MPL/2.0/.
http://tempuri.org/Intro.xsd

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Temp\Cogency
data
#
C:\Users\user\AppData\Local\Temp\SwatVelamen.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Temp\b2a34612.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Jun 4 17:20:38 2020, mtime=Tue Jun 23 02:54:23 2020, atime=Tue Jun 23 02:54:03 2020, length=449953, window=hide
#
Click to see the 28 hidden entries
C:\Users\user\AppData\Local\Temp\dan\wsdl\paypal\83.opends60.dll
data
#
C:\Users\user\AppData\Local\Temp\dan\wsdl\paypal\mc.exe
PE32 executable (console) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Temp\dan\wsdl\paypal\msats10ui.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Temp\nsv27CA.tmp
data
#
C:\Users\user\AppData\Local\Temp\ship\18.opends60.dll
data
#
C:\Users\user\AppData\Local\Temp\ship\27.opends60.dll
data
#
C:\Users\user\AppData\Local\Temp\ship\MicrosoftWindowsCEForms.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Users\user\AppData\Local\Temp\ship\SmartDevHowDoI80.xml
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\ship\com.ubuntu.notifications.settings.gschema.xml
XML 1.0 document, ASCII text
#
C:\Users\user\AppData\Local\Temp\ship\conmanui.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Temp\ship\formcontrols.xml
XML 1.0 document, ASCII text
#
C:\Users\user\AppData\Local\Temp\ship\model122.xml
XML 1.0 document, ASCII text
#
C:\Users\user\AppData\Local\Temp\ship\prs.sid.xml
XML 1.0 document, UTF-8 Unicode text
#
C:\Users\user\AppData\Local\Temp\ship\s390-linux.xml
XML 1.0 document, ASCII text
#
C:\Users\user\AppData\Local\Temp\ship\sbscmp10.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Temp\ship\unresolvedaddress.xml
XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\ship\x-icns.xml
XML 1.0 document, UTF-8 Unicode text
#
C:\Users\user\AppData\Roaming\can\MicrosoftVisualStudioVSHelp.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Users\user\AppData\Roaming\can\intro.xml
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\can\iso6395.xml
ASCII text, with no line terminators
#
C:\Users\user\AppData\Roaming\can\org.gnome.Logs.enums.xml
exported SGML document, ASCII text
#
C:\Users\user\AppData\Roaming\can\resgen.exe
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Users\user\AppData\Roaming\can\roletemplateprivileges.xml
XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\can\x-s3m.xml
XML 1.0 document, UTF-8 Unicode text
#
C:\Users\user\AppData\Roaming\rct\webservices\10.opends60.dll
data
#
C:\Users\user\AppData\Roaming\rct\webservices\SamplesTable.xml
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\rct\webservices\genasm.exe
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Users\user\AppData\Roaming\rct\webservices\org.gnome.desktop.datetime.gschema.xml
XML 1.0 document, ASCII text
#