top title background image
flash

GV6fciJUF1.exe

Status: finished
Submission Time: 2020-11-16 15:51:54 +01:00
Malicious
Ransomware
Trojan
Evader
GuLoader

Comments

Tags

Details

  • Analysis ID:
    318066
  • API (Web) ID:
    537936
  • Analysis Started:
    2020-11-16 15:51:54 +01:00
  • Analysis Finished:
    2020-11-16 15:59:27 +01:00
  • MD5:
    bfaaa05064bf433bb5f472949afb4bda
  • SHA1:
    883a59675cf0e46082ba6b252d92f0c3a7d8e463
  • SHA256:
    67e79aee5a167c0042612414b8779ff58d9c9c8b4ad1cb1ff41aa9df15a67a8e
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 43/70
malicious
Score: 24/31
malicious

Domains

Name IP Detection
onedrive.live.com
0.0.0.0

URLs

Name Detection
https://onedrive.live.com/download?cid=EQh
https://onedrive.live.com/download?cid=E3DDC3980F743711&resid=E3DDC
https://onedrive.live.com/downlo
Click to see the 22 hidden entries
https://logincdn.msauth.net/shared/1.0/
https://onedrive.live.com/download?cid=E3DDC3980F743711&resid=E
https://logincdn.msauth.net/shared/1.0/content/js/ConvergedLogin_PCore_m_AEFbtYqJeKR6sGUe93pA2.js
https://onedrive.live.com/tyLS6JLI5fNdE?
https://onedrive.live.com/zP
https://onedrive.live.com/download?cid=E3DDC3980F743711&resid=E3DDC3980F743711%21784&authkey=AGU
https://logincdn.msauth.net/
https://sc.imp.live.com/content/dam/imp/surfaces/mail_signin/v3/sky/EN-US.html?id=250206&mkt=EN-US&c
https://onedrive.live.com/
https://onedrive.live.com/download?cid=E3DDC3980F743711&resid=E3qi
https://login.lig
https://p.sfx.ms/login/v1/header.html?id=250206&mkt=EN-US&cbcxt=sky
https://onedrive.live.com/44
https://login.live.
https://onedrive.live.com/download?cid=E3DDC3980F743711&resid=E3DDC3980F743711%21784&authkey=AGURDZX
https://onedrive.live.com/ex
https://onedrive.live.com/DL1BZMCy7gkjqiuFbh4BiH6i06Gt8j0MBnlEzhZAmfV4QjcdMO7qRELnwUjGSDr5RjpBl7rWzg
https://login.li
https://onedrive.live.com/-9769-133e6dd
https://onedrive.live.com/ky
http://myurl/myfile.bin
https://logincdn.msauth.net/16.000/content/js/ConvergedLoginPaginatedStrings.en_LF5wadGUj8ZgZU2sWOZt

Dropped files

Name File Type Hashes Detection
C:\Users\user\BEFRIS\Europaeisk.exe
PE32 executable (GUI) Intel 80386, for MS Windows
#