top title background image
flash

1kbvLMAjCYsO.vbs

Status: finished
Submission Time: 2020-09-23 08:54:24 +02:00
Malicious
Trojan
Evader
Ursnif

Comments

Tags

  • gozi
  • isfb
  • ursnif
  • vbs

Details

  • Analysis ID:
    288966
  • API (Web) ID:
    473045
  • Analysis Started:
    2020-09-23 08:54:25 +02:00
  • Analysis Finished:
    2020-09-23 09:00:20 +02:00
  • MD5:
    9c63af8add415e5807e056340945dd2a
  • SHA1:
    13f4d966b5feb389b8ae585684bf0461d457def8
  • SHA256:
    4df230ac74c4fd13cc15a9cc91f9161891c7bf7c85c136f9341bb0c4967ed7dd
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 96
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 6/79
malicious

IPs

IP Country Detection
8.208.101.13
Singapore

Domains

Name IP Detection
api10.laptok.at
8.208.101.13

URLs

Name Detection
http://api10.laptok.at/api1/FYO7_2FKxkm8/uurQvPdNJlE/P19HL4pn1dqitw/55ZSMV4adv_2B5Ay6UjuZ/l97FGy95dGHmoHce/l4SgQPbNVAeDWq_/2FjKn4vYtXX99SXqbz/PcSTmrsfV/kBO6XIsqlMTunmTuDz0l/h2m475ZFAo9lrUtuzP3/2cML7QpMj2MF1rpKg2ujUu/GH3i35drj9cMm/_2BkuAQz/eHnwCGQGHnwJ1wY4o1yPpoy/WOktQ3Mr0v/7kpSg4oFS9JcOPX_2/FjCZHPIjQja6/k5_0A_0DiQ6/8ElOYZGEuQaMiw/bKYUWqovE0RpzdxL8vF0G/7nQLs3MSrj_2B7JG/2Sdi7NZR0LEnK7R/2
http://api10.laptok.at/api1/FYO7_2FKxkm8/uurQvPdNJlE/P19HL4pn1dqitw/55ZSMV4adv_2B5Ay6UjuZ/l97FGy95dG
http://www.wikipedia.com/
Click to see the 6 hidden entries
http://www.amazon.com/
http://www.nytimes.com/
http://www.live.com/
http://www.reddit.com/
http://www.twitter.com/
http://www.youtube.com/

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Temp\plush.aaf
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Temp\Huber.zip
Zip archive data, at least v2.0 to extract
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\httpErrorPagesScripts[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
Click to see the 28 hidden entries
C:\Users\user\AppData\Local\Temp\~DFAF1C545732CE7ED5.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF10DE879EE680ADDF.TMP
data
#
C:\Users\user\AppData\Local\Temp\sequin.rst
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\pope.jpeg
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\molar.rpm
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\flycatcher.eps
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\adobe.url
MS Windows 95 Internet shortcut text (URL=<https://adobe.com/>), ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\JavaDeployReg.log
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\Epicurean.webp
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\info_48[1]
PNG image data, 47 x 48, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\errorPageStrings[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\down[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\http_404[1]
HTML document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{568381FF-FDB5-11EA-90E3-ECF4BB570DC9}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\background_gradient[1]
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 1x800, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\bullet[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\ErrorPageTemplate[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-314712940\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{56838201-FDB5-11EA-90E3-ECF4BB570DC9}.dat
Microsoft Word Document
#