top title background image
flash

1lfVu8BW8Kpg.vbs

Status: finished
Submission Time: 2020-09-10 04:21:57 +02:00
Malicious
Trojan
Evader
Ursnif

Comments

Tags

Details

  • Analysis ID:
    283794
  • API (Web) ID:
    462805
  • Analysis Started:
    2020-09-10 04:22:19 +02:00
  • Analysis Finished:
    2020-09-10 04:28:38 +02:00
  • MD5:
    e2da82911b3e14112c6f5ab4a125c621
  • SHA1:
    a2d7c88df9876d4bbc12988ff14f748beaed51ee
  • SHA256:
    fe880e2a4901242e0b99343a940fee1fa543bcdd5eed258992ccf50bdea56ae6
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 92
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 9/56

IPs

IP Country Detection
84.38.183.234
Russian Federation

Domains

Name IP Detection
api10.laptok.at
84.38.183.234

URLs

Name Detection
http://www.wikipedia.com/
http://api10.laptok.at/api1/u_2Bstkw2Pz/SaYhmzqOSt84p_/2BLY1CxLCjamdhOPavxrT/cqEWnAGVcBeGq1uG/O7_2Bv1QXcln_2B/xuaySYH_2Fps0rwQAp/FDAwoOiTk/tPzxwzHkr4b9YWEY1MCO/GqWrOmT_2BMC_2FT8ej/Tm7pQHOpFvHinuaxqlva0V/2CXadPPD8vplI/mtS1FcuC/HhFtVWcYwfZmwsp9Z2yxxD7/GUeRdMN_2B/rXdMHXXN0GRlYk_2F/nmeGwKPwmRse/kEKu47fQ3zo/bx6Ci7Cz0cI_0A/_0DqGgxnJwDU6Oz_2BaCA/eakON4i3FQP_2F3F/6TXS3gN_2/FvyQn33x/a3
http://www.amazon.com/
Click to see the 6 hidden entries
http://www.nytimes.com/
http://www.live.com/
http://www.reddit.com/
http://www.twitter.com/
http://api10.laptok.at/api1/2zG9CTXIjdzG6KKQ2Y/ciuUx9Cmx/LUg0lwdHO9cur1stRR4e/U_2Bidr1JZpa5hYruON/OUZHKpA4IQrVlLIccCKvY1/lmfS8erKXJ5CR/B1t19lDo/m2GBPfFF2Olj23_2FHMe6KT/lNJ_2Bxxlu/vh7nFU6b6CC3XZcko/sLCq2GebDl39/UKUprxF4Zfq/3s5sxverfggbx3/tvTk4PhC_2FOuwfc7PW0N/gA_2BOcpk0uenKQ_/2BYbOao_2FTiGt2/DxmKDNr58Xv8PwhsTv/_0A_0DiU5/dNj_2FrjqLKvjpYYB7jD/UrWooKA64wccmXnhV07/dy8AnKxbIwggo_2FGzcqCg/xyodxOTN
http://www.youtube.com/

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Temp\titanium.wav
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Temp\cocksure.zip
Zip archive data, at least v2.0 to extract
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\httpErrorPagesScripts[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
Click to see the 23 hidden entries
C:\Users\user\AppData\Local\Temp\slosh.png
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\punish.webp
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\coevolution.crx
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\adobe.url
MS Windows 95 Internet shortcut text (URL=<https://adobe.com/>), ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\Julia.java
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\JavaDeployReg.log
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\info_48[1]
PNG image data, 47 x 48, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\errorPageStrings[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\down[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\http_404[1]
HTML document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\background_gradient[1]
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 1x800, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\bullet[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\ErrorPageTemplate[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-314712940\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#