top title background image
flash

look_attach#_64768.vbs

Status: finished
Submission Time: 2020-06-27 00:12:16 +02:00
Malicious
E-Banking Trojan
Trojan
Evader
Ursnif

Comments

Tags

Details

  • Analysis ID:
    241821
  • API (Web) ID:
    379365
  • Analysis Started:
    2020-06-27 00:12:17 +02:00
  • Analysis Finished:
    2020-06-27 00:25:40 +02:00
  • MD5:
    570cab3ed56a9c69bc3e5b85a838b42d
  • SHA1:
    c2952cbb31ee98c5c1a676e1820a3c73345083a0
  • SHA256:
    3a34c90fa6f4c879311dee500a97fb07aa8f62e338d6d4c539132d1d0234079e
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 34/71
malicious
Score: 9/31

IPs

IP Country Detection
47.91.16.227
United States
88.99.66.31
Germany

Domains

Name IP Detection
cdn.arsis.at
47.91.16.227
iplogger.org
88.99.66.31
cdn.onenote.net
0.0.0.0

URLs

Name Detection
http://cdn.arsis.at/api1/FGobUK37pg1stFseSNPPQ/TEUtqODu62CbfGrr/n5Gm8eop2TZcIhG/nnnpaSEO5Pxxgey0gY/Rr5i2rN1r/VLWYhxgQdAAhZRGoIMpB/2IE_2BWe_2FsDMdWntg/ZnZ6xqpUNwnwkHDte_2B6g/rRmYze8VRD_2F/iV_2BZcx/hL_2BuODY2COSuqZaGomgFw/4zSXFFb77X/A39ucWTixmkQW3Vam/S2DCyTJ480A5/y_2BoArXDfJ/n0nSLfXdqd5pdh/k6LUM1B9PU4xYV_2BDkb_/0A_0D51W5RC7ot8n/K6Ns16Wy_2B71LJ/QHQin1ntyy70tEWANs/_2FH7RNhA/6X9Z1BvbNxWCQrAEya/A
http://cdn.arsis.at/api1/sI2VIyObWF_2FbVYczyrv/inVj8jwQWjwTTB0l/Rthw60EQkm3wLO4/luSDDVi363OwywtVGG/YBfapp1bc/rjB0s78oSGHyNdrh1GyO/l22oaqOUdJcRgWomIuW/OOmUT4IObaAn7o8QHld19L/hicmuHJClZjeD/_2FOTWYz/xTXaykC7bt8hCRzrdG3bMsD/_2FSObmI5r/mDABSKk_2FGwLBD3J/q3i1ojvVT0pF/55qlGun_2Bj/_2Bj4QXk30A1Wr/zAxwYztNhaSKypGa_0A_0/Dkf_2BcwKv9_2Fo9/9usk4mk_2BnC_2F/_2BTc2C0Lzq6C8fsOC/hcZdvF97s/YNkSCEMO75/zfTI14qUl/wi
http://cdn.arsis.at/api1/yFyV_2F0/B9wrd1KqfQwNiZLD91Ygpmi/qQraT3ipCW/WeJB2nWTnaGJSFjtW/iq_2FjtxQFTU/7_2BQlWaLNS/gHcAhLGjb1yor4/aqDXx0ts9ny_2BzXfCUa4/MywaML7veAEP5Sof/iql_2FkZV786vX7/pPHCK5Djcx1c2cnq18/yMPx_2FJb/8tvxrCPIFWDP8aIKBFRy/YUiMizZSNl4JieVwizz/UopldAD2x84nDheaxuCs5V/yPorAFI2ynuUt/omHmDjc5/PlkyAiGF_0A_0DNrIVmLwtm/1sfwOYNeUU/zJ1PauOH5LdZOGu8q/Hyr2oZ1oZqi4/xmr5vAlCvuoYP/MLo_2Fg4/2
Click to see the 26 hidden entries
http://cdn.arsis.at/api1/SzZjGptQpQ5whcnQn92Cp/zfioYQkyIOivupHY/zdTW1mIYOoXelvU/8ewzKolERH_2BKaEQs/qqTTYmLpM/ezG9VClk0kdlOvcNZ6zB/QQaS_2FM7Xf843Bdq8_/2BJ_2FBR8udcCK94_2B9Kr/IfTUOI9zKdShX/RWZWP9id/8E76Vc5F9EmHX6UBGsWRg_2/BDay8c59H5/pJ7KQPBYjy3KpR4Tw/dsKZ4uEHtcGq/kn0J9Ee8_2F/Vv4HRbQTT33XRk/RokUJWVR9KupcKv9Uo_0A/_0D1gCe1VsOjUCD5/ADK1b_2FflCi2Kp/rOAePDBmtliVsOTGGm/x2_2B3_2F/tzbNbXBSRGBrjL7Ov/Ye
http://cdn.arsis.at/api1/CeDdCHPcU3h8bRH8tti2LD/BqtCzbhsEztKs/TvFF0Af5/pO3KnDL_2FnPCW2aWF8n_2F/x4rUhDDXZt/Ag5D88NbNKz0_2FX_/2Fp9q05DdEmF/ENlp8yFcTa8/8Vmhab4cywfDYW/BnVLi_2BK5i0E5_2F_2F6/VuDKCoi6QVdl9ncP/HSvYG5eZWX5alu1/BFGqmK_2B5o2VdbdDh/GpBWV78Ce/jcZ2prgj5oWr6oFAeZOY/dFxnB5GBt5g_2FI8C2s/SPceIDt_2BbPhCL9yC19rU/yJ_0A_0DfgbW0/UnvDC5kQ/P6v71Xqe3f603S7YVVdW9u5/UsVQJ_2BiG/tLJec2XdiejS_2FNg/8_2BYr_2B6/y8J
http://cdn.arsis.at/api1/INddE9xxGvzyEN35N/iztT5eVEsbeF/RWA7C53HC_2/FETMWWjTJqBS84/4iRe0RSvYTl6dOXGlLkxe/g3SzlKuN2f_2Ffjg/UsPjbQlM_2BwnJO/q2rFBe9UMbQWQV2ynY/qf7UbA_2B/5k_2BsBvcFA5kKzl2456/d9ezb2WV3eR015syqHJ/U52I3dhbuEeJJV8dX_2B_2/BHTz5XNJWe6jD/2L0qzRQb/QuuGfItLNsQ9WFSB5iz9a8p/vIMTJw9Y4p/kOh6UZ_2FnBVIIkXE/ZX7_0A_0DNHA/BKTx9DSjhGi/Hgy2yLyp_2FYZe/kRjziVnYXdlzu8gPdFtKm/Ut2PYfJoxNHYTTvgn18/_2Fy
http://cdn.arsis.at/api1/t603tMYrvTStE/ilbD0or2/QtzipuSqgfr1vJoHWAVMXq6/FHdZcsPX_2/FjXs5mU1oSby_2FFV/fSQLQZ6FMIAX/RSa6LGTho1f/hqwkxM0kcyowRc/jiDfXHSokokm3YXesza7b/52KZU6EBmMgjHPYn/7M944HXxXE6A3jw/V9zLQo7JIupTmL83Wu/x7ecjUbLV/3f3RZ4gLzX7ZYfbApgrH/rJA8_2FBR6lQ6bQDOOA/n3LmsvjMoLBE8476_2BO1v/tdTZ8IZwmcKX_/0A_0DkWL/kuPo7WyioWY82BNQlPEYflB/0Ks3O1QJ2gfweAr/IQO1Dw
http://cdn.arsis.at/api1/VvxX078dswk0j/GdW9c0SW/Pezg5zvR0UXQIXhjyKNdOCY/_2BJZ21kEq/vf_2BGJiJzVKaqcYH/jVwavPSaZM3E/EDJx_2Ff8uc/u_2F5vAy7N77CM/R4xnNHbC937RwweTluEcT/vk4XYqJiJTbJvlPO/ILZAPcwcuRLuZZw/ymRp_2F5RRxZaMTWEW/D8Hi9i00G/JE64tvr_2FYIU36hUtb6/A_2BMpFCmQuNeG9NPNK/kZgADRIiQ5oEr6DjiPy3ew/MCL_2BcNGTqH6/PtzBbu0_/0A_0D7UWj_2FfI_2Fe9Mu4D/z34T_2BhI_/2BULrTSOLh8jTbucy/suIHd_2B/UNU6
http://cdn.arsis.at/api1/xKnp8npiAeLk4/qUeTDL6V/hrHBfFc9BuWktfYVIWY140N/ygcrKfNulM/2m5LuqeAY1BevqzZQ/V6B_2By1ftYM/f8dqAV_2F_2/BBy7Yj33hgMWNm/f7cbGq5Aaz6Or8Vpi8_2F/xckZ7rbI0UOtpuYH/Jh6WWHyUf6YlW5j/pHNlestEX_2FSBNc9W/lwxaGddZA/4I20x_2FAmFhiUpDc9Gv/xe3bZbPe7A1LyEEZk0F/O35pKBr4GoUfpU7x9tjA8F/oqYpBZsEQycwk/Fka_0A_0/DeVwIQ6BdEBmpir6CtV8t3V/m2H5FnIBEZ/luIEjT8o82TiIn_2B/9s3ksUTTWjedFL1_2Fsh/qNJ
http://cdn.arsis.at/api1/2VHHyVUWRnf2eG6_2B956qr/M6hCkbtZ8o/Mvu6MDXW5Wm3q_2Fb/CQHCRaTFdJyj/cXq2IxfQKDv/JCgWYQ43EXqu0r/rH5L_2F_2F8Bg_2FyORFd/NrMTdNz_2BUE7jeq/YKUzFBwQV8NhP6o/P8VhkIdsnMctrevYkQ/caAwmLdEN/Kn1Th_2BFGXBWiiQ4KkC/30ONd9nUQ53phmIey2C/7oFHzlHKPdtxsiO_2FKMsN/SHL_2Bx9m0lVo/2GggJWhq/hnSr_2BUpAwG56VZ5RPBq4E/R_0A_0DlIL/eaWoROitpYcjKA1z3/3RZeUH6ha3K1/CxODouJ9XT7/yQdggQnc86IMIx/Hn8ZppIs/8Od
https://iplogger.org/1bD467
http://www.nytimes.com/
http://cps.root-x1.letsencrypt.org0
http://www.reddit.com/
http://www.live.com/
https://iplogger.org/W
http://www.wikipedia.com/
http://www.youtube.com/
http://cert.int-x3.letsencrypt.org/0
https://iplogger.org/
http://cps.letsencrypt.org0
https://iplogger.org/1bP467pace
https://iplogger.org/1bP4670
https://iplogger.org/1bP467
https://iplogger.org/)5
http://www.twitter.com/
http://ocsp.int-x3.letsencrypt.org0/
http://www.amazon.com/
https://iplogger.org/1bP4674

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Temp\afterbirth.rs
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Temp\conspiratorial.zip
Zip archive data, at least v2.0 to extract
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
Click to see the 13 hidden entries
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\JavaDeployReg.log
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\adobe.url
MS Windows 95 Internet shortcut text (URL=<https://adobe.com/>), ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\contraption.ps
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Temp\ingest.xcf
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Temp\marrowbone.mpg
ASCII text, with very long lines, with no line terminators
#