top title background image
flash

DHL_Express_Shipment_Invoice_Confirmation_CBJ190517000131_74700456XXXX.exe

Status: finished
Submission Time: 2021-04-08 11:48:47 +02:00
Malicious
Trojan
Evader
AgentTesla

Comments

Tags

  • DHL
  • exe

Details

  • Analysis ID:
    383902
  • API (Web) ID:
    669883
  • Analysis Started:
    2021-04-08 12:06:34 +02:00
  • Analysis Finished:
    2021-04-08 12:22:18 +02:00
  • MD5:
    4ffb9ee56baeed64d186d62de5c56a05
  • SHA1:
    2982ad3dd5578b7595a8a2ce6dff5f7bcc9a1140
  • SHA256:
    79614387d51e432e6681d699a42018ddb1a91106b47fb2ede9bac493dd5814f5
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 9/48

IPs

IP Country Detection
80.0.0.0
United Kingdom

URLs

Name Detection
http://pki.goog/gsr2/GTS1O1.crt0
http://www.osmf.org/subclip/1.0
http://cipa.jp/exif/1.0/1.0//
Click to see the 53 hidden entries
http://www.aiim.org/pdfa/ns/property#
http://DynDns.comDynDNS
http://ns.useplus.org/ldf/xmp/1.0/
http://www.aiim.org/pdfa/ns/id/
https://api.echosign.comaS
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha
http://iptc.org/std/Iptc4xmpExt/2008-02-29/
http://www.osmf.org/layout/anchor
http://iptc.org/std/Iptc4xmpCore/1.0/xmlns/
http://www.aiim.org/pdfe/ns/id/
http://ns.adobe.c/g%%4C
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip
https://pki.goog/repository/0
http://iptc.org/std/Iptc4xmpExt/2008-02-29/C
http://www.aiim.org/pdfa/ns/schema#;
http://www.aiim.org/pdfa/ns/field#x
https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/Upload/&
http://cipa.jp/exif/1.0/ER
http://www.aiim.org/pdfa/ns/field#
http://www.osmf.org/layout/padding%http://www.osmf.org/layout/attributes
https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/
http://www.aiim.org/pdfa/ns/extension/0
http://www.quicktime.com.Acrobat
https://ims-na1.adobelogin.com
http://crl.pki.goog/gsr2/gsr2.crl0?
http://ns.useplus.org/ldf/xmp/1.0/q
https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/Upload/D
https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/Upload/P
http://www.aiim.org/pdfa/ns/schema#
https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/Upload/J
https://api.echosign.com6
http://www.osmf.org/region/target#http://www.osmf.org/layout/renderer#http://www.osmf.org/layout/abs
http://cipa.jp/exif/1.0/
http://iptc.org/std/Iptc4xmpCore/1.0/xmlns/d
http://ns.adobe.c/g
http://www.osmf.org/default/1.0%http://www.osmf.org/mediatype/default
https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/S
http://schema.org/WebPage
http://www.aiim.org/pdfa/ns/type#
http://127.0.0.1:HTTP/1.1
https://api.echosign.com
https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/Upload/
http://crl.pki.goog/GTS1O1core.crl0
http://www.npes.org/pdfx/ns/id/
http://www.aiim.org/pdfa/ns/type#ty#
http://www.osmf.org/drm/default
http://www.osmf.org/elementId%http://www.osmf.org/temporal/embedded$http://www.osmf.org/temporal/dyn
https://api.ipify.org%GETMozilla/5.0
https://mybill.dhl.com/
http://www.aiim.org/pdfa/ns/extension/
http://ns.useplus.org/ldf/xmp/1.0/o
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
http://BHuYlB.com

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Roaming\Files.exe:Zone.Identifier
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\Files.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Users\user\AppData\Local\Temp\InstallUtil.exe
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
#
Click to see the 51 hidden entries
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\DHL_Express_Shipment_Invoice_Confirmation_CBJ190517000131_74700456XXXX.exe.log
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\bba29d2e6197e2f4_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\b6d5deb4812ac6e9_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\bf0ac66ae1eb4a7f_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\cf3e34002cde7e9c_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\d449e58cb15daaf1_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\d88192ac53852604_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\de789e80edd740d6_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\f0cf6dfa8a1afa3d_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\f4a0d4ca2f3b95da_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\f941376b2efdd6e6_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\f971b7eda7fa05c3_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\fd17b2d8331c91e8_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\fdd733564de6fbcb_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\febb41df4ea2b63a_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\index-dir\temp-index
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\LOG
ASCII text
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Visited Links
data
#
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ConnectorIcons\icon-210408190856Z-251.bmp
PC bitmap, Windows 3.x format, 107 x -152 x 32
#
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages
SQLite 3.x database, last written using SQLite version 3024000
#
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages-journal
data
#
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\AdobeFnt16.lst.5336
PostScript document text
#
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\Files.exe.log
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\DHL Overdue Account Notice - 1301356423.PDF
PDF document, version 1.3
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\6fb6d030c4ebbc21_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0786087c3c360803_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0998db3a32ab3f41_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0ace9ee3d914a5c0_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0f25049d69125b1e_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\230e5fe3e6f82b2c_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\2798067b152b83c7_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\2a426f11fd8ebe18_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\39c14c1f4b086971_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\3a4ae3940784292a_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\4a0e94571d979b3c_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\560e9c8bff5008d8_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\56c4cd218555ae2b_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\6267ed4d4a13f54b_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\05349744be1ad4ad_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\7120c35b509b0fae_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\71febec55d5c75cd_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\86b8040b7132b608_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\8c159cc5880890bc_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\8c84d92a9dbce3e0_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\8e417e79df3bf0e9_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\91cec06bb2836fa5_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\927a1596c37ebe5e_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\92c56fa2a6c4d5ba_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\946896ee27df7947_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\983b7a3da8f39a46_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\aba6710fde0876af_0
data
#