top title background image
flash

SecuriteInfo.com.Trojan.PWS.Siggen2.51343.32236.exe

Status: finished
Submission Time: 2020-08-01 21:36:18 +02:00
Malicious
Spyware
Evader

Comments

Tags

Details

  • Analysis ID:
    255680
  • API (Web) ID:
    406899
  • Analysis Started:
    2020-08-01 23:47:05 +02:00
  • Analysis Finished:
    2020-08-01 23:54:30 +02:00
  • MD5:
    b72e426691c8562cab3551f77964a8ff
  • SHA1:
    d2b2936ff183a895ce82ed5d75ea0fdac3c7591e
  • SHA256:
    bf2efbd13ace8761d0ff1d9e0952bbacb4c403a0e91d76d0b2cd65b838b4c0a6
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 56
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

IPs

IP Country Detection
104.18.58.9
United States

Domains

Name IP Detection
tikkirikki.space
104.18.58.9

URLs

Name Detection
https://tikkirikki.space
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/authentication
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/postalcoderhttp://schemas.xmlsoap.org/ws/2005/
Click to see the 19 hidden entries
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/streetaddresszhttp://schemas.xmlsoap.org/ws/20
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
https://tikkirikki.spaceD8
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/thumbprintrhttp://schemas.xmlsoap.org/ws/2005/
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/stateorprovince
https://tikkirikki.space/api.php
https://tikkirikki.space/
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/mobilephone
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/dateofbirthrhttp://schemas.xmlsoap.org/ws/2005
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/otherphone
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/authorizationdecisionzhttp://schemas.xmlsoap.o
https://tikkirikki.space/A11111111111111111111111111111111
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddressxhttp://schemas.xmlsoap.org/ws/200
http://schemas.xmlsoap.org/ws/2004/09/policy
https://tikkirikki.space/index.php
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/denyonlysid
https://ispsystem.com/external/ispmanager.html
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/x500distinguishednamejhttp://schemas.xmlsoap.o
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier

Dropped files

Name File Type Hashes Detection
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_R4MC11MUVDDTYL0X_f2a728cc3f1ee54b631486946646812e4f757eb_421da5eb_1bd89a26\Report.wer
Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER72E7.tmp.dmp
Mini DuMP crash report, 15 streams, Sun Aug 2 06:48:10 2020, 0x1205a4 type
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER844D.tmp.WERInternalMetadata.xml
XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
#
Click to see the 2 hidden entries
C:\ProgramData\Microsoft\Windows\WER\Temp\WER87D9.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\Runtime.MSIL.1.0.0.0\NativePRo.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#