top title background image
flash

20200308-sitrep-48-covid-19.pdf.lnk

Status: finished
Submission Time: 2020-08-04 16:45:35 +02:00
Malicious
E-Banking Trojan
Trojan
Evader

Comments

Tags

Details

  • Analysis ID:
    256982
  • API (Web) ID:
    409627
  • Analysis Started:
    2020-08-04 16:48:35 +02:00
  • Analysis Finished:
    2020-08-04 17:01:45 +02:00
  • MD5:
    21a51a834372ab11fba72fb865d6830e
  • SHA1:
    9ceb6e0e4ad0a2c03751d0563a82a79ebb94ec95
  • SHA256:
    95489af84596a21b6fcca078ed10746a32e974a84d0daed28cc56e77c38cc5a8
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 72
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

IPs

IP Country Detection
80.0.0.0
United Kingdom

Domains

Name IP Detection
motivation.neighboring.site
0.0.0.0
asf-ris-prod-neurope.northeurope.cloudapp.azure.com
168.63.67.155

URLs

Name Detection
http://www.aiim.org/pdfa/ns/property#:
https://www.who.int/news-room/q-a-detail/q-a-coronaviruses)
https://www.who.int/emergencies/diseases/novel-coronavirus-2019/situation-reports/2
Click to see the 77 hidden entries
https://www.iata.org/en/programs/safety/health/diseases/#tab-2
https://api.echosign.com_
http://www.aiim.org/pdfe/ns/id/
https://www.who.int/ith/2019-nCoV_advice_for_international_traffic-rev/en/g
http://iptc.org/std/Iptc4xmpCore/1.0/xmlns/
https://www.who.int/publications-detail/global-surveillance-for-human-infection-with-novel-coronavir
https://login.microsoftonline.com/%s/oauth2/authorizeStringCchPrintfWhttps://login.microsoftonline.c
https://docs.microso
http://www.osmf.org/layout/anchor
http://iptc.org/std/Iptc4xmpExt/2008-02-29/
http://www.aiim.org/pdfa/ns/id/
https://login.microsoftonline.com/%s/oauth2/token
http://ns.useplus.org/ldf/xmp/1.0/
http://iptc.org/std/Iptc4xmpExt/2008-02-29/em#K
http://www.aiim.org/pdfa/ns/property#
http://www.osmf.org/subclip/1.0
https://enterpriseregistration.windows.net/EnrollmentServer/device/
https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/Upload/8
http://www.adobe.
https://www.who.int/emergencies/diseases/novel-coronavirus-2019/advice-for-publicF
https://www.who.int/health-topics/coronavirus/who-recommendations-to-reduce-risk-of-transmission-of-
https://www.who.int/emergencies/diseases/novel-coronavirus-2019/advice-for-public9
https://ims-na1.adobelogin.com
http://www.quicktime.com.Acrobat
https://www.who.int/publications-detail/disease-commodity-package---novel-coronavirus-(ncov)
https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/
http://wwobe.com/go/ipmreader6_11_0Subscribe
https://%ws/%ws_%ws_%ws/service.svc/%ws
https://enterpriseregistration.windows.net/EnrollmentServer/DeviceEnrollmentWebService.svc
http://www.osmf.org/layout/padding%http://www.osmf.org/layout/attributes
http://www.aiim.org/pdfa/ns/field#
http://www.aiim.org/pdfa/ns/schema#nifestItem#
http://schemas.xmlsoap.org/ws/2004/08/addressing
http://wdobe.com/go/epdf
https://www.who.int/emergencies/diseases/novel-coronavirus-2019/advice-for-public
https://www.who.int/emergencies/diseases/novel-coronavirus-2019/situation-reports/)
https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/Upload/bx
https://www.who.int/publications-detail/the-first-few-x-
https://www.who.int/news-room/q-a-detail/q-a-coronaviruses
http://www.osmf.org/default/1.0%http://www.osmf.org/mediatype/default
http://cipa.jp/exif/1.0/
https://openwho.org/channels/covid-19
https://api.echosign.comRLw
http://ns.useplus.org/ldf/xmp/1.0/imensions#e
https://www.who.int/emergencies/diseases/novel-coronavirus-2019/technical-guidance/early-investigati
https://www.who.int/emergencies/diseases/novel-coronavirus-2019/technical-guidance/critical-prepared
http://www.osmf.org/region/target#http://www.osmf.org/layout/renderer#http://www.osmf.org/layout/abs
https://enterpriseregistration.windows.net/EnrollmentServer/key/
https://www.iata.org/en/programs/safety/health/diseases/#tab-2&q
https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/DV
http://www.aiim.org/pdfa/ns/schema#
http://www.aiim.org/pdfa/ns/type##
http://www.aiim.org/pdfa/ns/id/_
https://www.who.int/emergencies/diseases/novel-coronavirus-2019/advice-for-public)
https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/Upload/B
https://login.microsoftonline.com/%s/oauth2/authorize
https://%ws/%ws_%ws_%ws/service.svc/%wsADPolicyProviderSCEP
http://iptc.org/std/Iptc4xmpExt/2008-02-29//
https://www.who.int/emergencies/diseases/novel-coronavirus-2019/situation-reports/
http://www.aiim.org/pdfa/ns/extension/-29/
https://www.who.int/publications-detail/the-first-few-x-(ffx)-cases-and-contact-investigation-protoc
https://www.who.int/emergencies/diseases/novel-coronavirus-2019/technical-guidance/laboratory-guidan
https://www.who.int/ith/2019-nCoV_advice_for_international_traffic-rev/en/
http://www.aiim.org/pdfa/ns/extension/
http://www.osmf.org/elementId%http://www.osmf.org/temporal/embedded$http://www.osmf.org/temporal/dyn
http://www.osmf.org/drm/default
http://www.npes.org/pdfx/ns/id/Z
http://ns.useplus.org/ldf/xmp/1.0/qual/1.0/
http://www.npes.org/pdfx/ns/id/
https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/Upload/
https://api.echosign.com
http://www.aiim.org/pdfa/ns/field#ual/1.0/B
https://openwho.org/channels/covid-19)
http://www.aiim.org/pdfa/ns/property#T
http://www.aiim.org/pdfa/ns/type#
https://www.who.int/ith/2019-nCoV_advice_for_international_traffic-rev/en/)
https://www.who.int/emergencies/diseases/novel-coronavirus-2019/technical-guidance

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Temp\msoia.exe
PE32+ executable (console) x86-64, for MS Windows
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\index-dir\temp-index
Maple help database
#
C:\Users\user\AppData\Local\Temp\21dc298e3d0b4ba380379679ca44f31b$dpx$.tmp\61ab3055c991f24bbdbbecf7e86bb60b.tmp
XML 1.0 document text
#
Click to see the 61 hidden entries
C:\Users\user\AppData\Local\Temp\21dc298e3d0b4ba380379679ca44f31b$dpx$.tmp\1620f10d17f17d41835f4b554ae1874e.tmp
dBase IV DBT, blocks size 0, block length 16384, next free block index 768, next free block 2332033024, next used block 2337475661
#
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\UserCache.bin
data
#
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages-journal
data
#
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages
SQLite 3.x database, last written using SQLite version 3024000
#
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ConnectorIcons\icon-200804235002Z-269.bmp
PC bitmap, Windows 3.x format, 107 x -152 x 32
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Visited Links
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\LOG
ASCII text
#
C:\Users\user\AppData\Local\Temp\21dc298e3d0b4ba380379679ca44f31b$dpx$.tmp\7f4a50b4e20f42429662419e68d74caf.tmp
ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\febb41df4ea2b63a_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\fdd733564de6fbcb_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\fd17b2d8331c91e8_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\f971b7eda7fa05c3_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\f941376b2efdd6e6_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\f4a0d4ca2f3b95da_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\f0cf6dfa8a1afa3d_0
data
#
C:\Users\user\AppData\Local\Temp\21dc298e3d0b4ba380379679ca44f31b$dpx$.tmp\873dd9c0095af842b1891f89025b6e85.tmp
PE32 executable (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Temp\21dc298e3d0b4ba380379679ca44f31b$dpx$.tmp\a20a393cdc44584593e56d8a42a25b4e.tmp
PDF document, version 1.7
#
C:\Users\user\AppData\Local\Temp\21dc298e3d0b4ba380379679ca44f31b$dpx$.tmp\cc2fd4b43f89fd4799fcd1c28abd8bc5.tmp
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Temp\2m7EBxdH3wHwBO.tmp
Non-ISO extended-ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\cSi1r0uywDNvDu.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Temp\cSi1r0uywDNvDu.tmp (copy)
XML 1.0 document text
#
C:\Users\user\AppData\Local\Temp\cscript.exe\msproof.exe
PE32+ executable (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\Temp\g4ZokyumBB2gDn.tmp
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has command line arguments, Icon number=0, Archive, ctime=Thu Jun 25 02:39:19 2015, mtime=Thu Jun 25 02:39:19 2015, atime=Sat Nov 20 11:17:00 2010, length=302 (…)
#
C:\Users\user\AppData\Local\Temp\g4ZokyumBB2gDn.tmp:Zone.Identifier
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\oGhPGUDC03tURV.tmp
Microsoft Cabinet archive data, 868310 bytes, 6 files
#
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Accessories.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Archive, ctime=Wed Apr 11 22:34:33 2018, mtime=Mon Jul 27 06:36:04 2020, atime=Wed Apr 11 22:34:33 2018, le (…)
#
C:\Users\user\OFFICE12\Wordcnvpxy.exe
PE32 executable (GUI) Intel 80386, for MS Windows
#
C:\Windows\Logs\DPX\setupact.log
ASCII text, with CRLF line terminators
#
\Device\ConDrv
ASCII text, with CRLF, CR, LF line terminators
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\8c159cc5880890bc_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0786087c3c360803_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0998db3a32ab3f41_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0ace9ee3d914a5c0_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0f25049d69125b1e_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\230e5fe3e6f82b2c_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\2798067b152b83c7_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\2a426f11fd8ebe18_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\3a4ae3940784292a_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\4a0e94571d979b3c_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\560e9c8bff5008d8_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\56c4cd218555ae2b_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\6fb6d030c4ebbc21_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\7120c35b509b0fae_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\71febec55d5c75cd_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\86b8040b7132b608_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\05349744be1ad4ad_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\8c84d92a9dbce3e0_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\8e417e79df3bf0e9_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\91cec06bb2836fa5_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\927a1596c37ebe5e_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\92c56fa2a6c4d5ba_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\946896ee27df7947_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\983b7a3da8f39a46_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\aba6710fde0876af_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\b6d5deb4812ac6e9_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\bba29d2e6197e2f4_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\bf0ac66ae1eb4a7f_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\cf3e34002cde7e9c_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\d449e58cb15daaf1_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\d88192ac53852604_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\de789e80edd740d6_0
data
#