top title background image
flash

PAOQfRfS84b9.vbs

Status: finished
Submission Time: 2020-09-11 10:01:11 +02:00
Malicious
Trojan
Evader
Ursnif

Comments

Tags

Details

  • Analysis ID:
    284360
  • API (Web) ID:
    463920
  • Analysis Started:
    2020-09-11 10:01:12 +02:00
  • Analysis Finished:
    2020-09-11 10:07:34 +02:00
  • MD5:
    177109a1b199821bb5e7e75dab4a4816
  • SHA1:
    a7eebb7ea90b735636068a6496f4d831cd9d05ae
  • SHA256:
    7e217649f374af5e3c7dd00c6c41396275c02a40ba6ba1b80732c98d3a68046b
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 18/68
malicious
Score: 6/48
malicious

IPs

IP Country Detection
188.68.221.133
Russian Federation

Domains

Name IP Detection
api10.laptok.at
188.68.221.133

URLs

Name Detection
http://api10.laptok.at/api1/uW6J_2FV77lU4AnXvx4/Mw_2Fn_2FCUfh5uGYVKj0H/RbHyUv2J242fq/vsZnUYhP/H6bGW3KLuvPZ_2BdBLhFlNc/lFH9c0te_2/FCCWS4BD697mUGerB/yKZs8obpWFm_/2B4Hjhc7KWl/1bSX0vIP2cggn0/LOHex9ZhQ8hKtJC4awwix/BTr0AnZb9_2BsBfI/_2B5JbpVp0DMocL/VzbGQAEEA3TSM9CcuM/qIUPwiNDS/Xr54W73ZujtMk_2B46wk/rxRkS60SCSNsTrQduT6/gWM_0A_0DG1IUze708Mvyv/Bwn5dzxc8TIUE/KxnRzSH_/2FMhY9vxcFx0NaBMptqXjV1/Hogrt8q7n/YO6N
http://api10.laptok.at/api1/b_2FLVqOW/GSRUxXgKlH4OU4zFarOd/lkn_2FuHZZdr5ibMm9p/qgZvEP9460Pnulgx6suG5Z/yYLA04nBbIKcr/DLZGjvHm/MpVO_2FOQ0Gm2VSbPx3Ok_2/BCythuWh5J/nxkS67Iv3WXdOYGnG/uKqHburmeFi1/iRCiw3Z7a2P/TunySZOD6tz7Rl/B4nLv0KhGFsSIBhWgirn6/gcXHn_2F93Z5v6me/_2B3DR2oBoujxDJ/r_2FA_2F5ecoDdqLv3/uoU_2BSKW/VdYttGubjLoKS_0A_0DG/Hkt5hkOt5Imrq13fanB/HdNPAggOAAi364hTa2K_2B/_2FXfwPwKs_2F/4og_2B2Rege_2/FD4DZlWb1/m
http://api10.laptok.at/api1/OumBaPZKfInghlg_2Br/mFsxuKp3s3NNWaLUDhk8YA/KpkmraYO2aFaf/fPJHJI_2/Fwp9CcvorErKz6aNTUDvEyd/BfGfW7SFwT/KC205rtjQM5_2F68q/uei4wqQHzHVW/xQqbVDQvu6c/Tt0oskESridvOX/_2Ff4yqYtCk_2FWT8SIsB/EGdaEGLnWl5Wqi5u/MXX1jjEGaesUYXK/9OIJJWniFKjEqwLupZ/RuBqEDSQH/yokY1npmDw_2BSid5JlP/b9WPzMZHclpFTUs4_0A/_0DcWzNQ3VAN7f1D8_2BzD/l2sSBcwzLhSvE/feF7ADto/cDAdMLjkgUmP2BS60wM45v4/wGjftkL
Click to see the 7 hidden entries
http://www.wikipedia.com/
http://www.amazon.com/
http://www.nytimes.com/
http://www.live.com/
http://www.reddit.com/
http://www.twitter.com/
http://www.youtube.com/

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Temp\alloy.zip
Zip archive data, at least v2.0 to extract
#
C:\Users\user\AppData\Local\Temp\Wendy.eps
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Temp\JavaDeployReg.log
ASCII text, with CRLF line terminators
#
Click to see the 31 hidden entries
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\info_48[1]
PNG image data, 47 x 48, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\background_gradient[1]
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 1x800, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\down[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\errorPageStrings[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\httpErrorPagesScripts[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\bullet[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\http_404[1]
HTML document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\info_48[1]
PNG image data, 47 x 48, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\http_404[1]
HTML document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\Lagrangian.rtf
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\adobe.url
MS Windows 95 Internet shortcut text (URL=<https://adobe.com/>), ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\prune.m4a
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\similar.wps
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\synchronism.xm
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-314712940\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\ErrorPageTemplate[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\bullet[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\down[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\errorPageStrings[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\ErrorPageTemplate[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\background_gradient[1]
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 1x800, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\httpErrorPagesScripts[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#