top title background image
flash

nondeclaratively.exe

Status: finished
Submission Time: 2020-09-21 07:06:42 +02:00
Malicious
Ransomware
Trojan
Spyware
Evader
GuLoader Lokibot

Comments

Tags

Details

  • Analysis ID:
    287918
  • API (Web) ID:
    470972
  • Analysis Started:
    2020-09-21 07:06:43 +02:00
  • Analysis Finished:
    2020-09-21 07:13:06 +02:00
  • MD5:
    2b94d42dddcf3a42ce25da0196de08c5
  • SHA1:
    d3bf7998b6971e6619785b148b0feef073e873e4
  • SHA256:
    8d8dc9c90008f3da97411b1bd5a2c8e66a5d995fbbfa187b8ae998ccd571f33f
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 41/69
malicious
Score: 16/29

IPs

IP Country Detection
79.124.8.8
Bulgaria

Domains

Name IP Detection
onedrive.live.com
0.0.0.0
vvjb2q.bn.files.1drv.com
0.0.0.0

URLs

Name Detection
http://79.124.8.8/plesk-site-preview/benetaeu-group.com/http/79.124.8.8/goodluck/Panel/fre.php771
http://79.124.8.8/plesk-site-preview/benetaeu-group.com/http/79.124.8.8/goodluck/Panel/fre.php
https://vvjb2q.bn.files.1drv.com/y4m0vIBYtbfS3AVSKFbpunBFlRvqKFNEHSGqagsNmj3xxGuweAZ1k1geWsjGLQ59Q7C
Click to see the 1 hidden entries
https://onedrive.live.com/download?cid=FADB7566C70706AF&resid=FADB7566C70706AF%21112&authkey=AMIXqDs

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Roaming\C79A3B\B52B3F.lck
very short file (no magic)
#
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3853321935-2125563209-4053062332-1002\414045e2d09286d5db2581e0d955d358_d06ed635-68f6-4e9a-955c-4899f5f57b9a
data
#