flash

nondeclaratively.exe

Status: finished
Submission Time: 21.09.2020 07:06:42
Malicious
Ransomware
Trojan
Spyware
Evader
GuLoader Lokibot

Comments

Tags

Details

  • Analysis ID:
    287918
  • API (Web) ID:
    470972
  • Analysis Started:
    21.09.2020 07:06:43
  • Analysis Finished:
    21.09.2020 07:13:06
  • MD5:
    2b94d42dddcf3a42ce25da0196de08c5
  • SHA1:
    d3bf7998b6971e6619785b148b0feef073e873e4
  • SHA256:
    8d8dc9c90008f3da97411b1bd5a2c8e66a5d995fbbfa187b8ae998ccd571f33f
  • Technologies:
Full Report Management Report Engine Info Verdict Score Reports

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
100/100

malicious
41/69

malicious
16/29

IPs

IP Country Detection
79.124.8.8
Bulgaria

Domains

Name IP Detection
onedrive.live.com
0.0.0.0
vvjb2q.bn.files.1drv.com
0.0.0.0

URLs

Name Detection
http://79.124.8.8/plesk-site-preview/benetaeu-group.com/http/79.124.8.8/goodluck/Panel/fre.php771
http://79.124.8.8/plesk-site-preview/benetaeu-group.com/http/79.124.8.8/goodluck/Panel/fre.php
https://vvjb2q.bn.files.1drv.com/y4m0vIBYtbfS3AVSKFbpunBFlRvqKFNEHSGqagsNmj3xxGuweAZ1k1geWsjGLQ59Q7C
Click to see the 1 hidden entries
https://onedrive.live.com/download?cid=FADB7566C70706AF&resid=FADB7566C70706AF%21112&authkey=AMIXqDs

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Roaming\C79A3B\B52B3F.lck
very short file (no magic)
#
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3853321935-2125563209-4053062332-1002\414045e2d09286d5db2581e0d955d358_d06ed635-68f6-4e9a-955c-4899f5f57b9a
data
#