top title background image
flash

a.vbs

Status: finished
Submission Time: 2020-10-08 14:49:17 +02:00
Malicious
Trojan
Evader
Ursnif

Comments

Tags

Details

  • Analysis ID:
    295125
  • API (Web) ID:
    485426
  • Analysis Started:
    2020-10-08 14:53:22 +02:00
  • Analysis Finished:
    2020-10-08 15:01:41 +02:00
  • MD5:
    6ad88eeb7eecbefcb11d3ef9a61982b9
  • SHA1:
    e639820b16896e5ca772e58247917f487707145e
  • SHA256:
    09812aabad034564664405aa8a379e26a813db3193bf5be5d2dbce86633d8a80
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 8/79
malicious
Score: 14/29
malicious

IPs

IP Country Detection
8.208.101.13
Singapore

Domains

Name IP Detection
api10.laptok.at
8.208.101.13

URLs

Name Detection
http://api10.laptok.at/api1/T81idmji2UWdyZC/mukxH2hnE_2BzKqPvE/L6tEDlSfx/KiYV30XFVWiKTtnEsq2L/wq6p5Cvu_2F53sxnglH/Oi0Ldh1JLOjevThVYbpOfu/Rpzed2sNgGAse/qJ3yoEv9/BEu_2BQeRTXtJh_2FiL00C_/2BXxv6qdMA/rtxClQh_2BQr1cph5/pBY3ASn0mb4V/_2F2QEDW38R/cvanyTFv_2F052/2rE_2BaAj0jRnM72RMTYb/Xlo1t7Nd2OjEDR5g/bN_2BE1UCA_2Bju/7ODtInkhtW2_0A_0DI/le6MfFIOc/l7YSKvULDegPqQHg1_2F/g11wClwY33/dg6tIE6l/8
http://api10.laptok.at/favicon.ico
http://api10.laptok.at/api1/T81idmji2UWdyZC/mukxH2hnE_2BzKqPvE/L6tEDlSfx/KiYV30XFVWiKTtnEsq2L/wq6p5C
Click to see the 7 hidden entries
http://www.wikipedia.com/
http://www.amazon.com/
http://www.nytimes.com/
http://www.live.com/
http://www.reddit.com/
http://www.twitter.com/
http://www.youtube.com/

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Temp\future.pl
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Temp\arcsine.zip
Zip archive data, at least v2.0 to extract
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\gee00pr\imagestore.dat
data
#
Click to see the 20 hidden entries
C:\Users\user\AppData\Local\Temp\~DFCBD81EE172DC2E87.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF5D89A2AA939BC9CD.TMP
data
#
C:\Users\user\AppData\Local\Temp\enormity.dxf
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\culpable.ar
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\cognitive.tbz2
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\bryophyta.ttf
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\ant.s3m
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\adobe.url
MS Windows 95 Internet shortcut text (URL=<https://adobe.com/>), ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\JavaDeployReg.log
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{9A54BFCF-0965-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{9A54BFD1-0965-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
#