top title background image
flash

PO85937758859777.xlsx

Status: finished
Submission Time: 2021-01-13 17:10:50 +01:00
Malicious
Trojan
Exploiter
Evader
FormBook

Comments

Tags

  • VelvetSweatshop
  • xlsx

Details

  • Analysis ID:
    339197
  • API (Web) ID:
    580315
  • Analysis Started:
    2021-01-13 17:12:48 +01:00
  • Analysis Finished:
    2021-01-13 17:24:38 +01:00
  • MD5:
    80580c09bbeb955baf5d08e6298cf952
  • SHA1:
    5d2877c47fd701cff2f29e8935946e119baad62a
  • SHA256:
    78a37255aa8d51e37547d76b29711dae8a9209af7b798590260fb02ee9fe7c76
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 7 x64 SP1 with Office 2010 SP1 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2)

Third Party Analysis Engines

malicious
Score: 18/61
malicious
Score: 10/46

IPs

IP Country Detection
52.58.78.16
United States
199.59.242.153
United States
34.102.136.180
United States
Click to see the 4 hidden entries
184.168.131.241
United States
52.201.79.206
United States
156.241.53.120
Seychelles
185.26.106.165
France

Domains

Name IP Detection
bodyfuelrtd.com
34.102.136.180
www.cckytx.com
156.241.53.120
www.med.vegas
52.201.79.206
Click to see the 11 hidden entries
www.modaluxcutabovefitness.com
52.58.78.16
www.alwayadopt.com
199.59.242.153
tradingworldchina.com
185.26.106.165
giftasmile2day.com
184.168.131.241
reversehomeloansmiami.com
34.102.136.180
www.modernappsllc.com
0.0.0.0
www.jorgegiljewelry.com
0.0.0.0
www.helloinward.com
0.0.0.0
www.bodyfuelrtd.com
0.0.0.0
www.giftasmile2day.com
0.0.0.0
www.reversehomeloansmiami.com
0.0.0.0

URLs

Name Detection
http://www.giftasmile2day.com/8rg4/?RJ=sR6mXmiXS1IkonJdYlFao53tdftaP6KCaP+fBLIZC0+jJmH2nVBesg00yLwM+Xg8gzFUXA==&LFQHH=_pgx3Rd
http://www.modaluxcutabovefitness.com/8rg4/?RJ=BSQ7V1i2N9vBmsCIz7W/uQKzzFwWHtA3l7eKqfpYK40hJhbN+S/b7gP0W92i3TURdQSX0g==&LFQHH=_pgx3Rd
http://search.sify.com/
Click to see the 97 hidden entries
http://search.ebay.it/
http://www.univision.com/
http://www.soso.com/
http://www.google.cz/
http://www.google.si/
http://searchresults.news.com.au/
http://search.nifty.com/
http://www.gmarket.co.kr/
http://search.ebay.com/
http://search.yahoo.co.jp/favicon.ico
http://openimage.interpark.com/interpark.ico
http://www.asharqalawsat.com/
http://www.ozu.es/favicon.ico
http://espanol.search.yahoo.com/
http://uk.search.yahoo.com/
http://www.rambler.ru/favicon.ico
http://list.taobao.com/browse/search_visual.htm?n=15&q=
http://google.pchome.com.tw/
http://browse.guardian.co.uk/favicon.ico
http://www.pchome.com.tw/favicon.ico
http://busca.buscape.com.br/favicon.ico
http://sads.myspace.com/
http://www.piriform.com/ccleanerhttp://www.piriform.com/ccleanerv
http://search.seznam.cz/favicon.ico
http://www.cdiscount.com/
http://www.news.com.au/favicon.ico
http://ariadna.elmundo.es/
http://www.%s.comPA
http://service2.bfast.com/
http://p.zhongsou.com/favicon.ico
http://search.centrum.cz/favicon.ico
http://www.myspace.com/favicon.ico
http://search.espn.go.com/
http://search.ipop.co.kr/favicon.ico
http://search.interpark.com/
http://suche.freenet.de/favicon.ico
http://images.joins.com/ui_c/fvc_joins.ico
http://cgi.search.biglobe.ne.jp/
http://www.tesco.com/
http://www.iask.com/
http://search.orange.co.uk/favicon.ico
http://buscador.terra.es/
http://www.target.com/
http://search.yahoo.co.jp
http://auto.search.msn.com/response.asp?MT=
http://cnweb.search.live.com/results.aspx?q=
http://busca.orange.es/
http://www.amazon.de/
http://www.sogou.com/favicon.ico
http://www.ya.com/favicon.ico
http://search.rediff.com/
http://busca.igbusca.com.br//app/static/images/favicon.ico
http://msk.afisha.ru/
http://%s.com
http://image.excite.co.jp/jp/favicon/lep.ico
http://search.ebay.in/
http://img.shopzilla.com/shopzilla/shopzilla.ico
http://in.search.yahoo.com/
http://rover.ebay.com
http://fr.search.yahoo.com/
http://asp.usatoday.com/
http://www.etmall.com.tw/favicon.ico
http://www.iis.fhg.de/audioPA
http://search.yahoo.com/favicon.ico
http://buscar.ya.com/
http://www3.fnac.com/favicon.ico
http://www.dailymail.co.uk/
http://www.nifty.com/favicon.ico
http://www.rambler.ru/
http://www.mtv.com/
http://search.ebay.de/
http://www.merlin.com.pl/favicon.ico
http://www.mercadolivre.com.br/
http://kr.search.yahoo.com/
http://www.ceneo.pl/
http://search.auction.co.kr/
http://www.google.it/
http://suche.t-online.de/
http://search.centrum.cz/
http://www.cjmall.com/
http://www.priceminister.com/favicon.ico
http://www.ask.com/
http://www.microsofttranslator.com/BVPrev.aspx?ref=IE8Activity
http://busca.igbusca.com.br/
http://search.about.com/
http://search.chol.com/favicon.ico
http://buscar.ozu.es/
http://www.clarin.com/favicon.ico
http://search.msn.co.jp/results.aspx?q=
http://search.naver.com/favicon.ico
http://search.daum.net/
http://www.abril.com.br/favicon.ico
http://cgi.search.biglobe.ne.jp/favicon.ico
http://search.hanafos.com/favicon.ico
http://www.google.ru/
http://search.naver.com/
http://it.search.dada.net/favicon.ico

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\file1[1].exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Users\user\Desktop\~$PO85937758859777.xlsx
data
#
C:\Users\Public\vbc.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
Click to see the 3 hidden entries
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\683C7CC6.jpeg
gd-jpeg v1.0 (using IJG JPEG v80), quality = 90", baseline, precision 8, 700x990, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\941F3A0F.jpeg
gd-jpeg v1.0 (using IJG JPEG v80), quality = 90", baseline, precision 8, 700x990, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\A3CFBB99.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
#