Score: | 92 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
AV Detection: |
---|
Found malware configuration |
Source: |
Malware Configuration Extractor: |
Multi AV Scanner detection for dropped file |
Source: |
Virustotal: |
Perma Link | ||
Source: |
Metadefender: |
Perma Link | ||
Source: |
ReversingLabs: |
Multi AV Scanner detection for submitted file |
Source: |
Virustotal: |
Perma Link | ||
Source: |
Metadefender: |
Perma Link | ||
Source: |
ReversingLabs: |
Source: |
Binary string: |
Source: |
Code function: |
20_2_00DC3512 | |
Source: |
Code function: |
20_2_702A088D |
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior | ||
Source: |
File opened: |
Jump to behavior |
Key, Mouse, Clipboard, Microphone and Screen Capturing: |
---|
Yara detected Ursnif |
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
E-Banking Fraud: |
---|
Yara detected Ursnif |
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
System Summary: |
---|
Contains functionality to call native functions |
Source: |
Code function: |
20_2_7025161B | |
Source: |
Code function: |
20_2_702515D9 | |
Source: |
Code function: |
20_2_702523C5 | |
Source: |
Code function: |
20_2_00DC11A9 | |
Source: |
Code function: |
20_2_00DCB159 |
Detected potential crypto function |
Source: |
Code function: |
20_2_702521A4 | |
Source: |
Code function: |
20_2_00DC28E9 | |
Source: |
Code function: |
20_2_00DCAF34 | |
Source: |
Code function: |
20_2_702A466E | |
Source: |
Code function: |
20_2_70290FE0 | |
Source: |
Code function: |
20_2_702A7120 | |
Source: |
Code function: |
20_2_7029BA3F | |
Source: |
Code function: |
20_2_702AA29E | |
Source: |
Code function: |
20_2_702AA3BE | |
Source: |
Code function: |
20_2_702A75B8 | |
Source: |
Code function: |
20_2_7029B7DA | |
Source: |
Code function: |
20_2_702AB7DF |
Dropped file seen in connection with other malware |
Source: |
Dropped File: |
Found potential string decryption / allocating functions |
Source: |
Code function: |
Java / VBScript file with very long strings (likely obfuscated code) |
Source: |
Initial sample: |
Source: |
Static PE information: |
Source: |
Classification label: |
Source: |
Code function: |
20_2_00DC31DD |
Source: |
File created: |
Jump to behavior |
Source: |
Process created: |
Source: |
File read: |
Jump to behavior |
Source: |
Key opened: |
Jump to behavior |
Source: |
Process created: |
Source: |
Virustotal: |
||
Source: |
Metadefender: |
||
Source: |
ReversingLabs: |
Source: |
Process created: |
|||
Source: |
Process created: |
|||
Source: |
Process created: |
|||
Source: |
Process created: |
Jump to behavior | ||
Source: |
Process created: |
Jump to behavior |
Source: |
Key value queried: |
Jump to behavior |
Source: |
Static file information: |
Source: |
Binary string: |
Data Obfuscation: |
---|
VBScript performs obfuscated calls to suspicious functions |
Source: |
Anti Malware Scan Interface: |