top title background image
flash

psviRwg1.exe

Status: finished
Submission Time: 2020-09-26 10:48:40 +02:00
Malicious
Trojan
Adware
Evader
njRat

Comments

Tags

  • exe
  • Njratgold

Details

  • Analysis ID:
    290360
  • API (Web) ID:
    475820
  • Analysis Started:
    2020-09-26 10:48:41 +02:00
  • Analysis Finished:
    2020-09-26 10:54:57 +02:00
  • MD5:
    999334753c8251c5d5024b7a6a54a48f
  • SHA1:
    b761056dba359db3ed36c9bc6949ee05f40df0fa
  • SHA256:
    eb086d6c54841616485b2ad99ed2e2e2ebc21f01e6c5a58611ac914f70b5042f
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 51/71
malicious

IPs

IP Country Detection
182.2.43.7
Indonesia

Domains

Name IP Detection
fackyou.myq-see.com
182.2.43.7

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Java update.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Java update.exe:Zone.Identifier
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\CLR_v2.0_32\UsageLogs\Java update.exe.log
ASCII text, with CRLF line terminators
#