top title background image
flash

Scan_order.exe

Status: finished
Submission Time: 2021-01-11 08:08:11 +01:00
Malicious
Trojan
Evader
Remcos GuLoader

Comments

Tags

  • GuLoader
  • RemcosRAT
  • scr

Details

  • Analysis ID:
    337854
  • API (Web) ID:
    577600
  • Analysis Started:
    2021-01-11 08:08:12 +01:00
  • Analysis Finished:
    2021-01-11 08:18:51 +01:00
  • MD5:
    04be7ed51e345a56403df4657b376990
  • SHA1:
    44f5fdf6902d114524afc110cd927f95f72903fa
  • SHA256:
    ab77af2c0fe4a39b3e2ec7b7450ef36999baf7c66316f4b3934d5a60e124d50c
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

IPs

IP Country Detection
185.157.161.61
Sweden
172.217.23.1
United States

Domains

Name IP Detection
wealthyblessed.myddns.rocks
185.157.161.61
googlehosted.l.googleusercontent.com
172.217.23.1
doc-0c-8c-docs.googleusercontent.com
0.0.0.0

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Roaming\remcos\logs.dat
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\uninstall.vbs
data
#