flash

intersect.exe

Status: finished
Submission Time: 18.09.2020 16:15:11
Malicious
E-Banking Trojan
Trojan
Evader
Ursnif

Comments

Tags

Details

  • Analysis ID:
    287439
  • API (Web) ID:
    470021
  • Analysis Started:
    18.09.2020 16:15:11
  • Analysis Finished:
    18.09.2020 16:23:30
  • MD5:
    67efc02e3e51fd306b69c5083206f106
  • SHA1:
    7df946eef6d88294c8b56e1d42e2c209d2127218
  • SHA256:
    3edfa92e944d223ddcd77ea1cab22c35f4534b74df5edb38b259ea17a9db71f0
  • Technologies:
Full Report Management Report Engine Info Verdict Score Reports

malicious

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
100/100

malicious
40/69

malicious
10/38

malicious
15/48

malicious

malicious

IPs

IP Country Detection
8.208.101.13
Singapore

Domains

Name IP Detection
api10.laptok.at
8.208.101.13

URLs

Name Detection
http://api10.laptok.at/api1/9f_2BZhM_2BD_2B2/xs20AKcKZsQE_2B/9YPzuBPsx2D1YU2ZXQ/tBkxiGH22/h8SMal23zUMV3HeeU6L1/0mSowaYoTV33fXLsILp/HkCPHWpSxBEkcoCXQFjchl/6uMWB3YaKwtrc/cgg59U4O/qSTy_2FpUjwxqvc_2BKB_2B/mNogxDDta_/2FGC_2B2_2BQSbef9/hQ400xnkSInK/rgLz_2BcVN8/jUtb_2Bm2tCtUQ/O2UrTv6GlU_2FTjDOZuBF/09JDTCO9bp45PcGD/p7I5tGFDHLJTIY_/0A_0DjJ_2Fw4wLjGL4/ODK_2F016/vZeeprdKic5ga_2Fbqe_/2BQ7Mw8W/oF8yw
http://api10.laptok.at/api1/9f_2BZhM_2BD_2B2/xs20AKcKZsQE_2B/9YPzuBPsx2D1YU2ZXQ/tBkxiGH22/h8SMal23zU
http://api10.laptok.at/api1/oNgEi06FjfalIuh_2FD3N5g/4QZA2XhWrH/FrY4X8UotpZiRVxZ_/2B_2Fnywl0D4/7mlTNL
Click to see the 15 hidden entries
http://api10.laptok.at/api1/r1aDevbizxgI2/HlHAEZl0/o5mzLtqHvQRIbaxrQlxV045/sGFlBqfzle/1gKhxMpO2SCjyy
http://api10.laptok.at/api1/oNgEi06FjfalIuh_2FD3N5g/4QZA2XhWrH/FrY4X8UotpZiRVxZ_/2B_2Fnywl0D4/7mlTNLNtFaF/iSVV6o6YMgC3yz/rp6EwfLTP82dDUTCWbFXC/fg_2BiN0YUBKqubv/EXro02Q5ZIvT2lz/mc4dCADDk6Fo1QE4c3/OZuCXhlGu/tL0w9qDLG52qBP_2FBUb/gDHKn7CHGnXgoIXAarp/ERmoBmwxL_2FKGndaZDCvt/3eA7XSmckqNUu/r6la9_2F/T1D4yaaCi_2BJhwpBx9b_0A/_0DYhzBFbo/FnevkwdsxarnIQMp5/bozwCn5H56J7/NkjeKr8k1mD/wpNSpwyyL2pWKgR/csXIJO
http://api10.laptok.at/api1/au0UhAmu27zW0nUF4PkzOoQ/RNcQTyrYu3/AfdMgcB0Regomjh3a/uGX72yUFnBt6/Sq0Y2e
http://api10.laptok.at/api1/r1aDevbizxgI2/HlHAEZl0/o5mzLtqHvQRIbaxrQlxV045/sGFlBqfzle/1gKhxMpO2SCjyyIgM/3h8lOjVudawg/IHSWMuoX9gz/I8NQ5iA6f_2FFL/5MUSQRb6PKBY0E0pTfCmW/wECJuAw4UTRFM_2F/8bq_2FUS0uqmMgM/EMpmlXMCczB8HoMfwD/WAOgD5AdV/JBvtrA_2BVgOhfOZWfjM/O_2BVqFznvfavl_2F65/QDxWxnv5PHyglob5ug72jy/7TC3LaBKzGRIA/9L3_0A_0/DhUzQVhhbkgf8EbmvNypliU/sK_2BS3x4b/u4tVA4ts1WSt_2Fn6/DwBTfpnOY8oR/J6VZw_2FVC/pbq
http://pinst.360.cn/360haohua/safe_chaoqiang.cab?
http://www.nytimes.com/
http://nsis.sf.net/NSIS_Error
http://www.youtube.com/
http://www.wikipedia.com/
http://www.amazon.com/
http://www.live.com/
http://down.360safe.com/setup.exe.exe
http://nsis.sf.net/NSIS_ErrorError
http://www.reddit.com/
http://www.twitter.com/

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{104CC7D7-FA05-11EA-90E8-ECF4BBEA1588}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{1F3D00FB-FA05-11EA-90E8-ECF4BBEA1588}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{2D602FDD-FA05-11EA-90E8-ECF4BBEA1588}.dat
Microsoft Word Document
#
Click to see the 58 hidden entries
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{F65CD730-FA04-11EA-90E8-ECF4BBEA1588}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{104CC7D9-FA05-11EA-90E8-ECF4BBEA1588}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{1F3D00FD-FA05-11EA-90E8-ECF4BBEA1588}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{2D602FDF-FA05-11EA-90E8-ECF4BBEA1588}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{F65CD732-FA04-11EA-90E8-ECF4BBEA1588}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-314712940\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\ErrorPageTemplate[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\background_gradient[1]
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 1x800, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\bullet[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\down[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\errorPageStrings[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\httpErrorPagesScripts[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\info_48[1]
PNG image data, 47 x 48, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\ErrorPageTemplate[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\background_gradient[1]
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 1x800, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\bullet[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\down[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\httpErrorPagesScripts[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\http_404[1]
HTML document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\info_48[1]
PNG image data, 47 x 48, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\ErrorPageTemplate[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\ErrorPageTemplate[2]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\background_gradient[1]
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 1x800, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\bullet[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\down[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\errorPageStrings[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\errorPageStrings[2]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\httpErrorPagesScripts[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\http_404[1]
HTML document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\http_404[2]
HTML document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\info_48[1]
PNG image data, 47 x 48, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\background_gradient[1]
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 1x800, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\bullet[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\down[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\errorPageStrings[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\httpErrorPagesScripts[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\http_404[1]
HTML document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\info_48[1]
PNG image data, 47 x 48, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Temp\282409830
data
#
C:\Users\user\AppData\Local\Temp\JavaDeployReg.log
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\nsb818.tmp\System.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Temp\~DF026733AD9858356F.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF1E72D314DAFDB1C7.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF2EB71D95B4678D2C.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF70681A1E793362C3.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF9EC8CC9EDEA8A80C.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFA77D75748E0783DD.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFE4E835DA570A8675.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFF264A0B64F077BD7.TMP
data
#