top title background image
flash

plata bancara.exe

Status: finished
Submission Time: 2020-10-30 17:53:32 +01:00
Malicious
Trojan
Spyware
Evader
FormBook

Comments

Tags

  • exe

Details

  • Analysis ID:
    307702
  • API (Web) ID:
    517199
  • Analysis Started:
    2020-10-30 17:53:32 +01:00
  • Analysis Finished:
    2020-10-30 18:04:02 +01:00
  • MD5:
    044a2c8563e6163aa8d3088dedfc1d62
  • SHA1:
    d847773329a586abcc80b4d5503cd257041baaa0
  • SHA256:
    0c709bc4f72e2ee138cf8753d69dca4c54337bf8221958969f6451d4beac8285
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 42/72
malicious
Score: 19/48

IPs

IP Country Detection
192.185.5.166
United States
162.159.130.233
United States
162.159.135.232
United States
Click to see the 1 hidden entries
104.24.112.145
United States

Domains

Name IP Detection
discord.com
162.159.135.232
www.kangen-international.com
104.24.112.145
cdn.discordapp.com
162.159.130.233
Click to see the 3 hidden entries
profileorderflow.com
192.185.5.166
www.profileorderflow.com
0.0.0.0
www.4btoken.com
0.0.0.0

URLs

Name Detection
http://www.kangen-international.com/n7ak/
http://www.profileorderflow.com/n7ak/
http://www.kangen-international.com/n7ak/?rTILUJ=U783rAiQJM1Y5px79dS4aMtxK5CY0Xozd091QiQJKQYhYjZoM/IoxYhCRI4ExJd1c9Oh&EzrxUr=3f-8qvLps6y
Click to see the 1 hidden entries
http://www.profileorderflow.com/n7ak/?rTILUJ=8cN6WiY0PtJ2VzGBJ3AxDDs6MPMlGMtk5cSKysxHy8KC/pCRGqQ1B9v0EG+1CfyvpRnL&EzrxUr=3f-8qvLps6y

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Temp\DB1
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\Swneeee[1]
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Roaming\KP63BSE2\KP6logim.jpeg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 1280x1024, frames 3
#
Click to see the 3 hidden entries
C:\Users\user\AppData\Roaming\KP63BSE2\KP6logrg.ini
data
#
C:\Users\user\AppData\Roaming\KP63BSE2\KP6logri.ini
data
#
C:\Users\user\AppData\Roaming\KP63BSE2\KP6logrv.ini
data
#