top title background image
flash

skynet_0.4.exe

Status: finished
Submission Time: 2020-07-19 21:30:34 +02:00
Malicious
E-Banking Trojan
Trojan
Evader
Miner
ZeusVM

Comments

Tags

  • skynet

Details

  • Analysis ID:
    247328
  • API (Web) ID:
    390294
  • Analysis Started:
    2020-07-20 03:11:34 +02:00
  • Analysis Finished:
    2020-07-20 03:23:18 +02:00
  • MD5:
    a6cb3103fac2e6ad873ce6774e4ebddb
  • SHA1:
    37c20c2ed8556b27217264dbaa7aa5a96894ca23
  • SHA256:
    5978884a07ea7559941ec2a1ce86e08e4be36a9aae9d535f58021602b24cdaba
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 59/71
malicious
Score: 23/37
malicious
Score: 25/31
malicious

IPs

IP Country Detection
171.25.193.9
Sweden
86.59.21.38
Austria
216.146.43.70
United States
Click to see the 1 hidden entries
212.112.245.170
Germany

Domains

Name IP Detection
checkip.dyndns.com
216.146.43.70
checkip.dyndns.org
0.0.0.0

URLs

Name Detection
http://owbm3sjqdnndmydf.onion:80/reverseproxy.txt
http://checkip.dyndns.org/
http://rxrhv2ajbmjw3kyq.onion:80/reverseproxy.txt
Click to see the 6 hidden entries
http://checkip.dyndns.org/dnsapi.dllDnsFlushResolverCachentdll.dllNtUnmapViewOfSection1080reversepro
https://www.torproject.org/download/download#warning
http://%s/test.txthttp://%s:%d/%siplist.txt%WINDIR%
http://%s/test.txt
http://curl.haxx.se/docs/http-cookies.html#
http://curl.haxx.se/docs/http-cookies.html

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\W2BICE6W\C4RMJ201.htm
HTML document, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\tor\hidden_service\hostname.tmp
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\tor\hidden_service\private_key.tmp
PEM RSA private key
#
Click to see the 3 hidden entries
C:\Users\user\AppData\Roaming\tor\state.tmp
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\tor\unverified-microdesc-consensus.tmp
ASCII text, with very long lines, with CRLF line terminators
#
\Device\ConDrv
ASCII text, with CRLF line terminators
#