top title background image
flash

SsB2vGWikwof.vbs

Status: finished
Submission Time: 2020-09-15 16:51:02 +02:00
Malicious
Trojan
Evader
Ursnif

Comments

Tags

Details

  • Analysis ID:
    285785
  • API (Web) ID:
    466758
  • Analysis Started:
    2020-09-15 16:51:04 +02:00
  • Analysis Finished:
    2020-09-15 16:58:19 +02:00
  • MD5:
    0671e735481a55031081895bf0f57760
  • SHA1:
    11788132e8b10e6370530d68d2d562737ef1dae0
  • SHA256:
    f9ad25e0810fc3f545213be438f531677595044c6a64d6b367e93b9aad9910e6
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 36/68
malicious
Score: 12/48
malicious

IPs

IP Country Detection
8.208.101.13
Singapore

Domains

Name IP Detection
api10.laptok.at
8.208.101.13
cdn.onenote.net
0.0.0.0

URLs

Name Detection
http://api10.laptok.at/api1/1neYuHqR12/VfBQ4tm48ZVNIegXR/cb3MGCBqEWvY/42fR2sU3ngx/l7MpHuzEloqYnY/I77
http://api10.laptok.at/api1/1neYuHqR12/VfBQ4tm48ZVNIegXR/cb3MGCBqEWvY/42fR2sU3ngx/l7MpHuzEloqYnY/I77hF1fkppGOZ_2Bc4HGG/DWzBv53bspzthuXE/ILtZe5XBXWu33Gu/rk5RKhfKQJKD9433H4/kX83ZB3dR/wEiBaz1GzWYj2hEoO_2F/EScI8O7Q0YH31fPGnlg/Wc7YYS_2B8x7oBOO9UNxW_/2F6JN2e5WkBix/2lmCysUv/iAFAdFTuEFSmknn_2FyHHFx/_2BY3ZeQB9/5vTgiw_0A_0Dyy6Uv/8A5H_2BJCyMF/WRVFhGu5Ao2/8qMSSNzCgO_2Bd/_2F7Isa1DWjzswLx_2FtD/XzaSfOCHbaf/Kv
http://api10.laptok.at/api1/iMXOW5W5pEmv/uyrpdVrTXAu/GxFaEXbgBi1lmO/iNfOKtqJCK8PhjIpobI9M/jv_2BAxSUwfKDBc2/HB3th836K09XaxQ/ndipgFKqNLAz2xh_2F/TfmHSntag/sHois7w5ZbfrDaYX5ooB/Q899FSSlZ3f_2FpV7TJ/ZigMd2mgG15_2FLHljoyKf/VKXX7JAHUEdEs/9TpDL854/tsvmBcwWbuVgGLX0gl9QUZm/85NYFfS5Iw/8TzCBvADy_2FlYDO7/E5Wqcg6TaedL/wh_0A_0D2nM/WmhABVAVcDojUV/KIYHWxUKVv_2BKS6yYtbt/VMaaYUGRxV/C
Click to see the 8 hidden entries
http://api10.laptok.at/api1/iMXOW5W5pEmv/uyrpdVrTXAu/GxFaEXbgBi1lmO/iNfOKtqJCK8PhjIpobI9M/jv_2BAxSUw
http://www.wikipedia.com/
http://www.amazon.com/
http://www.nytimes.com/
http://www.live.com/
http://www.reddit.com/
http://www.twitter.com/
http://www.youtube.com/

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Temp\ogress.psd
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Temp\locate.zip
Zip archive data, at least v2.0 to extract
#
C:\Users\user\AppData\Local\Temp\Low\JavaDeployReg.log
ASCII text, with CRLF line terminators
#
Click to see the 37 hidden entries
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Low\IE\OHV7M0FR\ErrorPageTemplate[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Low\IE\OHV7M0FR\bullet[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Low\IE\OHV7M0FR\down[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Low\IE\OHV7M0FR\errorPageStrings[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Low\IE\X2GCHJOK\ErrorPageTemplate[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Low\IE\X2GCHJOK\bullet[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Low\IE\X2GCHJOK\http_404[1]
HTML document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Low\IE\X2GCHJOK\http_404[2]
HTML document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Low\IE\X2GCHJOK\info_48[1]
PNG image data, 47 x 48, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Low\IE\KD8PQN1H\httpErrorPagesScripts[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\adobe.url
MS Windows 95 Internet shortcut text (URL=<https://adobe.com/>), ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\handgun.s3m
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\recumbent.woff2
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\~DF2322ACC2E6C03735.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF9FD28BB6709CCB82.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFB4B4A0EFE0A8ABC7.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFD285DA7A7AB80540.TMP
data
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{ABC44508-F7AE-11EA-90E2-ECF4BB862DED}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{90C25D54-F7AE-11EA-90E2-ECF4BB862DED}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{ABC4450A-F7AE-11EA-90E2-ECF4BB862DED}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-314712940\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{90C25D52-F7AE-11EA-90E2-ECF4BB862DED}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Low\IE\86B850Z5\background_gradient[1]
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 1x800, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Low\IE\86B850Z5\httpErrorPagesScripts[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Low\IE\86B850Z5\info_48[1]
PNG image data, 47 x 48, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Low\IE\KD8PQN1H\background_gradient[1]
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 1x800, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Low\IE\KD8PQN1H\down[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Low\IE\KD8PQN1H\errorPageStrings[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#