flash

Scan_order.exe

Status: finished
Submission Time: 11.01.2021 08:08:11
Malicious
Trojan
Evader
Remcos GuLoader

Comments

Tags

  • GuLoader
  • RemcosRAT
  • scr

Details

  • Analysis ID:
    337854
  • API (Web) ID:
    577600
  • Analysis Started:
    11.01.2021 08:08:12
  • Analysis Finished:
    11.01.2021 08:18:51
  • MD5:
    04be7ed51e345a56403df4657b376990
  • SHA1:
    44f5fdf6902d114524afc110cd927f95f72903fa
  • SHA256:
    ab77af2c0fe4a39b3e2ec7b7450ef36999baf7c66316f4b3934d5a60e124d50c
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports
New

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
100/100

IPs

IP Country Detection
185.157.161.61
Sweden
172.217.23.1
United States

Domains

Name IP Detection
wealthyblessed.myddns.rocks
185.157.161.61
googlehosted.l.googleusercontent.com
172.217.23.1
doc-0c-8c-docs.googleusercontent.com
0.0.0.0

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Roaming\remcos\logs.dat
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\uninstall.vbs
data
#