flash

4pFzkB6ePK.exe

Status: finished
Submission Time: 23.02.2021 09:12:18
Malicious
Trojan
Evader
FormBook

Comments

Tags

  • exe
  • Formbook

Details

  • Analysis ID:
    356512
  • API (Web) ID:
    615006
  • Analysis Started:
    23.02.2021 09:13:02
  • Analysis Finished:
    23.02.2021 09:25:57
  • MD5:
    6dd83e20f43a9bd2e136fcd77131f7e4
  • SHA1:
    2d816c160bba20f5e3989af02985118e42a4fe70
  • SHA256:
    5babb878615fbf3b56008f4d7becccdb0a316e3eecb95ce99ea2a6c9d5a8a19a
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

malicious
New

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
100/100

malicious
16/71

malicious
13/47

IPs

IP Country Detection
154.201.205.155
Seychelles
160.153.128.38
United States
184.168.131.241
United States
Click to see the 2 hidden entries
95.130.17.35
Germany
106.13.210.52
China

Domains

Name IP Detection
www.fsqlgt.com
106.13.210.52
www.ntljcb.com
154.201.205.155
www.nachbau.net
95.130.17.35
Click to see the 9 hidden entries
trinityhousegoa.com
194.59.164.91
aslanforklift.com
160.153.128.38
carbon-foam.com
184.168.131.241
www.electricbiketechnologes.com
0.0.0.0
www.carbon-foam.com
0.0.0.0
www.trinityhousegoa.com
0.0.0.0
www.2seamapparel.com
0.0.0.0
www.aslanforklift.com
0.0.0.0
shops.myshopify.com
23.227.38.74

URLs

Name Detection
http://www.nachbau.net/tub0/?0T0hlT=cydGkSUU+hbxwnLMCHdxs2HTbhyeOBhf6VDIiN7OyAb+9b2I/6QPcL+NYbrcHhStME+j&OVlT0R=o2JlVT4hT8qhr8ep
www.ntljcb.com/tub0/
http://www.carbon-foam.com/tub0/?0T0hlT=0g3BJlW7sTphQ/5j4Tdr5dYYoDFSx+aDomq4rDoP20bT0mosHTIKHGclLGRJ8AP1BBBd&OVlT0R=o2JlVT4hT8qhr8ep
Click to see the 32 hidden entries
http://www.aslanforklift.com/tub0/?0T0hlT=Oc9Sv6ZsHiz1lEkHjT4sUkzXc6kK6TfJoTMn/p3mX09SqIZJtOPjrYy4Z3tQQ5aTicNK&OVlT0R=o2JlVT4hT8qhr8ep
http://www.ntljcb.com/tub0/?0T0hlT=dN2zk3vDrvOSMWpoBKxdiHLfh4G+CBzvqQ9gZV3x5lRoIc3e6NmSOgfKn1bO4v69I6lv&OVlT0R=o2JlVT4hT8qhr8ep
http://www.fonts.com
http://www.sandoll.co.kr
http://www.urwpp.deDPlease
http://www.zhongyicts.com.cn
http://www.sakkal.com
http://www.apache.org/licenses/LICENSE-2.0
http://www.fontbureau.com
http://www.fontbureau.com/designersG
http://www.fontbureau.com/designers/?
http://www.founder.com.cn/cn/bThe
http://www.fontbureau.com/designers?
http://www.fsqlgt.com/
http://www.tiro.com
http://www.fsqlgt.com/tub0/?0T0hlT=nrDRCNaQ3GMZq2PvHSeNd5wOe
http://www.fontbureau.com/designers
http://www.goodfont.co.kr
https://stackpath.bootstrapcdn.com/bootstrap/4.5.0/css/bootstrap.min.css
http://www.fsqlgt.com/T0hlT=nrDRCNaQ3GMZq2PvHSeNd5wOe
http://www.carterandcone.coml
http://www.sajatypeworks.com
http://www.typography.netD
http://www.fontbureau.com/designers/cabarga.htmlN
http://www.founder.com.cn/cn/cThe
http://www.galapagosdesign.com/staff/dennis.htm
http://fontfabrik.com
http://www.founder.com.cn/cn
http://www.fontbureau.com/designers/frere-jones.html
http://www.jiyu-kobo.co.jp/
http://www.galapagosdesign.com/DPlease
http://www.fontbureau.com/designers8

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\4pFzkB6ePK.exe.log
ASCII text, with CRLF line terminators
#