top title background image
flash

Signature.xlsx

Status: finished
Submission Time: 2021-01-27 19:55:22 +01:00
Malicious
Trojan
Exploiter
Evader
FormBook

Comments

Tags

  • VelvetSweatshop
  • xlsx

Details

  • Analysis ID:
    345177
  • API (Web) ID:
    592264
  • Analysis Started:
    2021-01-27 20:01:38 +01:00
  • Analysis Finished:
    2021-01-27 20:09:53 +01:00
  • MD5:
    560a48512736572ec4abceb4ecf22250
  • SHA1:
    56798f4c080101515e42b5678a2039ac6b8caaf3
  • SHA256:
    1d93a4fcbcf81b40332da7aedaa9288ca16a2c0c588db5c78c6e349ce53478d4
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 7 x64 SP1 with Office 2010 SP1 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2)

Third Party Analysis Engines

malicious
Score: 6/83
malicious

IPs

IP Country Detection
18.194.54.219
United States

URLs

Name Detection
http://18.194.54.219/wows/hm1.exe
http://thesnake.herokuapp.com/snakes
http://www.day.com/dam/1.0
Click to see the 1 hidden entries
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\hm1[1].exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Users\Public\vbc.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\3B65EA87.jpeg
gd-jpeg v1.0 (using IJG JPEG v80), quality = 90", baseline, precision 8, 700x990, frames 3
#
Click to see the 3 hidden entries
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\86CDB2DC.jpeg
gd-jpeg v1.0 (using IJG JPEG v80), quality = 90", baseline, precision 8, 700x990, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\E74B891E.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
#
C:\Users\user\Desktop\~$Signature.xlsx
data
#