top title background image
flash

AWB; 803389.exe

Status: finished
Submission Time: 2020-10-28 09:38:32 +01:00
Malicious
Trojan
Evader
FormBook

Comments

Tags

  • exe
  • Formbook

Details

  • Analysis ID:
    306493
  • API (Web) ID:
    514742
  • Analysis Started:
    2020-10-28 10:05:36 +01:00
  • Analysis Finished:
    2020-10-28 10:16:04 +01:00
  • MD5:
    6c18070e9693305a6cb6209449a02e94
  • SHA1:
    48c0db1e73d1fa7b45a7225e786242cf8c48afef
  • SHA256:
    163fa2698faa2a11d40f59af7475ed947124141340e1e99b02191dcd31448180
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 13/48

IPs

IP Country Detection
154.218.53.239
Seychelles
34.102.136.180
United States

Domains

Name IP Detection
www.ducphogroup.com
154.218.53.239
asaankisaan.com
66.235.200.145
yossistant.com
34.102.136.180
Click to see the 3 hidden entries
www.planterboxgardens.com
0.0.0.0
www.asaankisaan.com
0.0.0.0
www.yossistant.com
0.0.0.0

URLs

Name Detection
http://www.ducphogroup.com/t65/?t6Al=hBTpOp4xGhV&MZBh=hYUpqL58JpuuN1n7kKJqGGjPOpbvQE9PWzCduSO2AQRa7WeCXO19Wdep2mJeEfa3szZosqiOkA==
http://www.yossistant.com/t65/?t6Al=hBTpOp4xGhV&MZBh=zrNR9qh8YJqaz42mwdSERO8bsiXIRvjzwzZvc0ZW1dB02WRQ83pl7S5hIcixEKuwf9kM1a/37w==

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\AWB; 803389.exe.log
ASCII text, with CRLF line terminators
#