flash

Capasw32.dll

Status: finished
Submission Time: 25.06.2020 00:10:33
Malicious
Phishing
E-Banking Trojan
Trojan
Spyware
Evader
Ursnif

Comments

Tags

Details

  • Analysis ID:
    241341
  • API (Web) ID:
    378412
  • Analysis Started:
    25.06.2020 00:10:36
  • Analysis Finished:
    25.06.2020 00:19:40
  • MD5:
    e0d37750f9b4118deafbdf03ae023684
  • SHA1:
    5f32b33a20d466da8a727eb3f29bd702d2653cef
  • SHA256:
    d723bf8324e58a9d88aaa5601d990b4ce9d825c8f91f2d2c04c77dadc3302036
  • Technologies:
Full Report Engine Info Verdict Score Reports

System: Windows 10 64 bit (version 1803) with Office 2016, Adobe Reader DC 19, Chrome 70, Firefox 63, Java 8.171, Flash 30.0.0.113

malicious
100/100

malicious
35/72

Domains

Name IP Detection
lissavets.at
0.0.0.0
222.222.67.208.in-addr.arpa
0.0.0.0
tahhir.at
0.0.0.0
Click to see the 3 hidden entries
limpopo.at
0.0.0.0
myip.opendns.com
84.17.52.80
resolver1.opendns.com
208.67.222.222

URLs

Name Detection
http://https://file://USER.ID%lu.exe/upd
http://lissavets.at
http://aaxvkah7dudzoloq.onion
Click to see the 30 hidden entries
http://estate-advice.at
http://limpopo.at
http://estate-advice.atconstitution.org/usdeclar.txt0x4eb7d2cacom
http://tahhir.at
http://aaxvkah7dudzoloq.onionhttp://lissavets.athttp://tahhir.athttp://limpopo.athttp://estate-advic
http://www.apache.org/licenses/LICENSE-2.0
https://lh3.googleusercontent.com/ogw/default-user=s96
http://www.autoitscript.com/favicon.ico
http://www.founder.com.cn/cn/bThe
http://constitution.org/usdeclar.txtC:
http://www.tiro.com
http://www.goodfont.co.kr
https://www.heise.de/c
http://www.autoitscript.com/site/autoit/
http://www.regsofts.com/free_registry_repair/registry_repair.htm
http://www.carterandcone.coml
http://www.sajatypeworks.com
http://www.typography.netD
http://www.founder.com.cn/cn/cThe
http://fontfabrik.com
http://www.founder.com.cn/cn
http://constitution.org/usdeclar.txt
https://lh3.googleusercontent.com/ogw/default-user=s24
http://www.jiyu-kobo.co.jp/
http://www.%s.comPA
http://www.fonts.com
http://www.sandoll.co.kr
https://www.heise.de/
http://www.zhongyicts.com.cn
http://www.sakkal.com

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\6c4zjj0s.default\prefs.js
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\A3E3.bin
Zip archive data (empty)
#
C:\Users\user\AppData\Local\Temp\CBA0.bi1
ASCII text, with CRLF line terminators
#
Click to see the 5 hidden entries
C:\Users\user\AppData\Local\Temp\EA2A.bin
data
#
C:\Users\user\AppData\Roaming\Microsoft\Authtenc\atmftstr.dll
data
#
C:\Users\user\AppData\Roaming\Microsoft\{44B27E05-D318-1648-7DB8-B7AA016CDB7E}\01D64AC00198B5880B
Little-endian UTF-16 Unicode text, with CRLF, CR line terminators
#
\Device\ConDrv
ASCII text, with CRLF, CR line terminators
#
\Device\Mailslot\sl1088
data
#