flash

3a07d9bd-1b72-4b18-a990-8f53801474f5.vbs

Status: finished
Submission Time: 13.12.2020 17:01:55
Malicious
Trojan
Evader
Ursnif

Comments

Tags

Details

  • Analysis ID:
    329942
  • API (Web) ID:
    561710
  • Analysis Started:
    13.12.2020 17:01:56
  • Analysis Finished:
    13.12.2020 17:08:14
  • MD5:
    e913defabdbffb6f3e8f5059d44cbf5f
  • SHA1:
    6b7712ee4b899e009e9fca462168041cbedb881a
  • SHA256:
    c3d02a137b9fffdcc4b61fba5f6653a35c4cee283ad0f0c878bc4e8a5fee6cf9
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports
New

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
100/100

malicious
25/69

malicious
6/37

malicious
8/28

IPs

IP Country Detection
47.241.19.44
United States

Domains

Name IP Detection
api10.laptok.at
47.241.19.44

URLs

Name Detection
http://api10.laptok.at/favicon.ico
http://www.wikipedia.com/
http://www.amazon.com/
Click to see the 5 hidden entries
http://www.nytimes.com/
http://www.live.com/
http://www.reddit.com/
http://www.twitter.com/
http://www.youtube.com/

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Temp\bucket.zip
Zip archive data, at least v2.0 to extract
#
C:\Users\user\AppData\Local\Temp\occurrent.xlsx
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{CD3F6758-3D5C-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
#
Click to see the 19 hidden entries
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{CD3F675A-3D5C-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\JavaDeployReg.log
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\adobe.url
MS Windows 95 Internet shortcut text (URL=<https://adobe.com/>), ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\bassinet.jar
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\differ.m3u
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\limpid.ai
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\motel.cpio
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\silkworm.ra
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\~DF6F285664D9B9AF7F.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFCA0E3485CC728AC2.TMP
data
#