top title background image
flash

covid21.exe

Status: finished
Submission Time: 2021-01-15 15:33:19 +01:00
Malicious
Ransomware
Evader
MBRLocker

Comments

Tags

  • coronavirus
  • diskkiller
  • mbrkiller
  • trojan
  • wiper

Details

  • Analysis ID:
    340294
  • API (Web) ID:
    582510
  • Analysis Started:
    2021-01-15 15:33:20 +01:00
  • Analysis Finished:
    2021-01-15 15:48:56 +01:00
  • MD5:
    1a2e2d295e04f74437652dc9b8a2d03c
  • SHA1:
    e3565983ee402856c2cf4eec2ac6ff9636443fe9
  • SHA256:
    a078251c61a4f90bf60da47d99cea465be5d44057684d681fb3d94a20d2025bd
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 69
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 51/71
malicious
Score: 15/38
malicious
Score: 25/29
malicious

URLs

Name Detection
http://www.rjlsoftware.com/?screenscrewopenj
http://www.rjlsoftware.com/?screenscrew
http://www.autohotkey.com
Click to see the 3 hidden entries
http://www.autohotkey.comCould
http://www.rjlsoftware.com
http://www.rjlsoftware.com(

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Temp\1870.tmp\CLWCP.exe
PE32 executable (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Temp\1870.tmp\PayloadGDI.exe
PE32 executable (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Temp\1870.tmp\PayloadMBR.exe
PE32 executable (GUI) Intel 80386, for MS Windows
#
Click to see the 7 hidden entries
C:\Users\user\AppData\Local\Temp\1870.tmp\corona.vbs
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\1870.tmp\covid.vbs
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\1870.tmp\covid21.vbs
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\1870.tmp\screenscrew.exe
PE32 executable (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Temp\1870.tmp\covid.bmp
PC bitmap, Windows 3.x format, 1920 x 1080 x 24
#
C:\Users\user\AppData\Local\Temp\1870.tmp\covid21.bat
DOS batch file, ASCII text, with CRLF line terminators
#
C:\covid21\covid.bmp
PC bitmap, Windows 3.x format, 1920 x 1080 x 24
#