top title background image
flash

Portfolio.exe

Status: finished
Submission Time: 2021-04-12 09:11:28 +02:00
Malicious
Trojan
Evader
FormBook

Comments

Tags

  • exe
  • Formbook

Details

  • Analysis ID:
    385265
  • API (Web) ID:
    672634
  • Analysis Started:
    2021-04-12 09:16:14 +02:00
  • Analysis Finished:
    2021-04-12 09:28:25 +02:00
  • MD5:
    9fa479c87543e7dd199296f7029991c9
  • SHA1:
    649bf55700b6828989dbcf4c5d792ba93fa5b2e0
  • SHA256:
    5cb8d74227cc43368e24ef8f94c5ae38a2f2c259a1701b1efa4f6b5042e4544d
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 24/70
malicious
Score: 8/48

IPs

IP Country Detection
72.167.241.46
United States
168.206.243.213
South Africa
34.102.136.180
United States

Domains

Name IP Detection
fromthepittothepitts.com
72.167.241.46
www.timcrozier.com
168.206.243.213
www.scaledsales.com
0.0.0.0
Click to see the 4 hidden entries
www.fromthepittothepitts.com
0.0.0.0
clientconfig.passport.net
0.0.0.0
scaledsales.com
34.102.136.180
www.andersensweddinginvitations.com
66.96.162.147

URLs

Name Detection
www.fromthepittothepitts.com/dwj/
http://www.timcrozier.com/dwj/?Cj=lN985vvxrLh4&HTrLdvY=vjdFX+deElwkJL3jjCyofcRGlviK7hY6fmHNPu6niYhLdTNZ+9C3ClVYQHWQZWwEwEGo
http://www.fromthepittothepitts.com/dwj/?HTrLdvY=e+9w//LrkNQAvat7yjjfVebmP7O5RIC5nL700LrPx65Ls1GCtX2Cw2Ubn7E5A1TTieM1&Cj=lN985vvxrLh4
Click to see the 55 hidden entries
http://www.jiyu-kobo.co.jp/ip
http://www.apache.org/licenses/LICENSE-2.0
http://www.fontbureau.com
http://www.fonts.comc
http://www.fontbureau.com/designers8g
http://www.jiyu-kobo.co.jp/Zp
http://www.sandoll.co.krN.TTF
http://www.sandoll.co.krs.
http://www.jiyu-kobo.co.jp/jp/
http://www.jiyu-kobo.co.jp/tp&
http://www.fontbureau.come.com
http://www.carterandcone.coml
http://www.scaledsales.com/dwj/?Cj=lN985vvxrLh4&HTrLdvY=jCwgb33wmR2YDM1wuLgRTH38yeb9sMyK3XA0ZXE7/yU9OdwyZBI+RqEK8elpwbEptz+b
http://www.founder.com.cn/cn/
http://www.sakkal.com
http://www.fontbureau.com/designers/cabarga.htmlN
http://www.founder.com.cn/cn
http://www.fontbureau.com/designers/frere-jones.html
http://www.fonts.comF
http://www.jiyu-kobo.co.jp/
http://www.fontbureau.com/designers8
http://www.sandoll.co.kr0l
http://www.tiro.comh
http://www.tiro.comc
http://www.founder.com.cn/cn/1
http://www.founder.com.cn/cnFe
http://en.wg
http://www.fontbureau.com/designers/?
http://www.founder.com.cn/cn/bThe
http://www.fontbureau.com/designers?
http://www.founder.com.cn/cnnte
http://www.sajatypeworks.comif13
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name4
http://www.tiro.com
http://www.fontbureau.com/designers
http://www.goodfont.co.kr
http://www.fontbureau.com/designersP
https://stackpath.bootstrapcdn.com/bootstrap/4.5.0/css/bootstrap.min.css
http://www.founder.com.cn/cnorm
http://www.sajatypeworks.com
http://www.typography.netD
http://www.fontbureau.com/designersG
http://www.founder.com.cn/cn/cThe
http://www.galapagosdesign.com/staff/dennis.htm
http://fontfabrik.com
http://www.fonts.comic
http://www.fonts.com-uK2
http://www.jiyu-kobo.co.jp/ana
http://www.galapagosdesign.com/DPlease
http://www.fonts.com
http://www.sandoll.co.kr
http://www.sajatypeworks.comd
http://www.urwpp.deDPlease
http://www.zhongyicts.com.cn
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\Portfolio.exe.log
ASCII text, with CRLF line terminators
#