top title background image
flash

PAYMENT COPY.exe

Status: finished
Submission Time: 2021-04-12 09:39:26 +02:00
Malicious
Trojan
Evader
FormBook

Comments

Tags

  • exe
  • Formbook

Details

  • Analysis ID:
    385291
  • API (Web) ID:
    672688
  • Analysis Started:
    2021-04-12 09:43:56 +02:00
  • Analysis Finished:
    2021-04-12 09:55:00 +02:00
  • MD5:
    0cdbfdf044cfa1d810ed06b745ac9cd9
  • SHA1:
    124e5c370a103888227112141ea559b85ae17656
  • SHA256:
    8d85a4dbf755253e9f46aafa65f5374431e5843e6d1fa6ab61ef238919d9f6bb
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 22/68
malicious
Score: 13/48
malicious

IPs

IP Country Detection
176.104.107.18
Serbia
167.114.6.31
Canada
23.227.38.74
Canada
Click to see the 5 hidden entries
14.129.120.32
Korea Republic of
104.21.28.135
United States
23.225.41.92
United States
52.79.124.173
United States
35.244.230.236
United States

Domains

Name IP Detection
www.beyoncos.com
14.129.120.32
kakavjesajt.com
176.104.107.18
www.sportfest40.com
104.21.28.135
Click to see the 12 hidden entries
www.mg-izkerr8.net
52.79.124.173
shops.myshopify.com
23.227.38.74
cursosdigitaisbr.com
167.114.6.31
34.anxin58.com
23.225.41.92
www.35efb510815e.com
0.0.0.0
www.360caiyin.com
0.0.0.0
www.kakavjesajt.com
0.0.0.0
www.nescleanups.com
0.0.0.0
www.cursosdigitaisbr.com
0.0.0.0
www.stripepayment.online
0.0.0.0
www.cjaccessories.net
0.0.0.0
www.llmav.xyz
35.244.230.236

URLs

Name Detection
http://www.kakavjesajt.com/eqas/?Kzrx=2WJx48jh/thZFm4UaW0+TWvb4qp7q1IcEsHJj26+PoNJlpUOGtb5NswHfLJoC/AYmsRkDoJx/Q==&4h3=vZRDNDdpalAdz8
www.cursosdigitaisbr.com/eqas/
http://www.cursosdigitaisbr.com/eqas/?Kzrx=967KBfj8+VhMtFT4MuSkf1Q16ympYDb2+7V4ZV0KQDLb45yTiH1Ahm088ZXNCPpC8jR0PY64Fw==&4h3=vZRDNDdpalAdz8
Click to see the 38 hidden entries
http://www.cjaccessories.net/eqas/?Kzrx=zlzoH+ErGdORI3KgnipEDQmAM+5mnlewXlSz4LF6ZDcdx8uItHTjoqljxUMZx7tHvLXvbS3vgg==&4h3=vZRDNDdpalAdz8
http://www.beyoncos.com/eqas/?Kzrx=vogt4SdM7257j7Tk1uEKvDVNcysLCgoPP/omvU9RbfjhJlgcGqamOKpa157N0oGBpfPcf/L32A==&4h3=vZRDNDdpalAdz8
http://www.35efb510815e.com/eqas/?Kzrx=+pdiEsaPT2Qcmu2ts2xxLdHpIsIAjIekwLbYEBSMYRvbotqJwTsf/hFk1ceM/lb+HZzWB3Gpcg==&4h3=vZRDNDdpalAdz8
http://www.sportfest40.com/eqas/?Kzrx=5vTDjg0AbqyZCldj/4uhpy3uniwA6wzjOzlj8Zy6y3xAduLQBKf0xYSENAev/AVhLePpE/aK2w==&4h3=vZRDNDdpalAdz8
http://www.founder.com.cn/cn
http://www.founder.com.cn/cn/cThe
http://181ue.com/sq.html?entry=
http://www.fontbureau.com/designers/frere-jones.html
https://hm.baidu.com/hm.js?
http://www.jiyu-kobo.co.jp/
http://www.galapagosdesign.com/DPlease
http://www.fontbureau.com/designers8
https://g.alicdn.com/woodpeckerx/jssdk/wpkReporter.js
http://www.fonts.com
http://www.sandoll.co.kr
http://www.urwpp.deDPlease
http://www.zhongyicts.com.cn
http://www.sakkal.com
https://www.8dq98.com/enter/index.html
http://www.llmav.xyz/eqas/?Kzrx=ZOpWeYl13G0nYt67dVF2CnLu74JWwlwH6kqD7vFNiwsDSsXFN4+zplc98svsYfoyCRsuDbeIEw==&4h3=vZRDNDdpalAdz8
http://www.tiro.com
http://www.apache.org/licenses/LICENSE-2.0
http://www.fontbureau.com
http://www.fontbureau.com/designersG
https://g.alicdn.com/woodpeckerx/jssdk/plugins/performance.js
http://www.fontbureau.com/designers/?
https://g.alicdn.com/woodpeckerx/jssdk/plugins/globalerror.js
http://www.founder.com.cn/cn/bThe
http://www.fontbureau.com/designers?
http://fontfabrik.com
http://www.fontbureau.com/designers
http://www.goodfont.co.kr
http://www.carterandcone.coml
http://www.sajatypeworks.com
http://www.typography.netD
http://www.fontbureau.com/designers/cabarga.htmlN
http://www.autoitscript.com/autoit3/J
http://www.galapagosdesign.com/staff/dennis.htm

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Temp\5r6mhdppdaz
data
#
C:\Users\user\AppData\Local\Temp\jptmg4zdrr658q2oh
data
#
C:\Users\user\AppData\Local\Temp\nsr3AA2.tmp\ek0j.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
#