top title background image
flash

Processed APR12.xlsx

Status: finished
Submission Time: 2021-04-12 14:21:31 +02:00
Malicious
Trojan
Exploiter
Evader
FormBook

Comments

Tags

  • VelvetSweatshop
  • xlsx

Details

  • Analysis ID:
    385456
  • API (Web) ID:
    672985
  • Analysis Started:
    2021-04-12 14:43:47 +02:00
  • Analysis Finished:
    2021-04-12 14:56:00 +02:00
  • MD5:
    c41fd90fc1e23885a1e075ce11d612e8
  • SHA1:
    d1903963f15c001baceb7c0e92998bc38a19f318
  • SHA256:
    9328d5dcf7664d4a92915ba032a183e63ef8602445737f42bf4d479b8037e1c2
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 100
System: Windows 7 x64 SP1 with Office 2010 SP1 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2)

Third Party Analysis Engines

malicious
Score: 6/37
malicious
Score: 12/29

IPs

IP Country Detection
52.58.78.16
United States
23.82.57.32
United States
198.54.126.105
United States
Click to see the 4 hidden entries
192.169.223.13
United States
160.153.137.40
United States
3.125.17.227
United States
18.236.1.157
United States

Domains

Name IP Detection
shopihy.com
160.153.137.40
www.ruhexuangou.com
23.82.57.32
centergolosinas.com
192.169.223.13
Click to see the 10 hidden entries
www.aideliveryrobot.com
52.58.78.16
vectoroutlines.com
198.54.126.105
www.tricqr.com
0.0.0.0
www.shopihy.com
0.0.0.0
www.vectoroutlines.com
0.0.0.0
www.zgcbw.net
0.0.0.0
www.centergolosinas.com
0.0.0.0
www.buylocalclub.info
0.0.0.0
www.dreamcashbuyers.com
0.0.0.0
sites-external-prod-ebc852aa8146fe7f.elb.us-west-2.amazonaws.com
18.236.1.157

URLs

Name Detection
http://espanol.search.yahoo.com/
http://www.univision.com/
http://www.soso.com/
Click to see the 97 hidden entries
http://www.google.cz/
http://www.google.si/
http://searchresults.news.com.au/
http://search.nifty.com/
http://www.gmarket.co.kr/
http://search.ebay.com/
http://search.yahoo.co.jp/favicon.ico
http://openimage.interpark.com/interpark.ico
http://search.sify.com/
http://www.ozu.es/favicon.ico
http://search.ebay.it/
http://uk.search.yahoo.com/
http://www.rambler.ru/favicon.ico
http://list.taobao.com/browse/search_visual.htm?n=15&q=
http://google.pchome.com.tw/
http://browse.guardian.co.uk/favicon.ico
http://www.pchome.com.tw/favicon.ico
http://busca.buscape.com.br/favicon.ico
http://sads.myspace.com/
http://www.piriform.com/ccleanerhttp://www.piriform.com/ccleanerv
http://www.amazon.de/
http://www.ceneo.pl/
http://cgi.search.biglobe.ne.jp/
http://ariadna.elmundo.es/
http://www.%s.comPA
http://service2.bfast.com/
http://p.zhongsou.com/favicon.ico
http://search.centrum.cz/favicon.ico
http://www.myspace.com/favicon.ico
http://search.espn.go.com/
http://investor.msn.com/
http://search.ipop.co.kr/favicon.ico
http://search.interpark.com/
http://suche.freenet.de/favicon.ico
http://search.seznam.cz/favicon.ico
http://search.auction.co.kr/
http://www.tesco.com/
http://www.iask.com/
http://search.orange.co.uk/favicon.ico
http://buscador.terra.es/
http://www.target.com/
http://search.yahoo.co.jp
http://auto.search.msn.com/response.asp?MT=
http://cnweb.search.live.com/results.aspx?q=
http://busca.orange.es/
http://www.asharqalawsat.com/
http://images.joins.com/ui_c/fvc_joins.ico
http://weather.gc.ca/astro/seeing_e.html)
http://busca.igbusca.com.br//app/static/images/favicon.ico
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
http://msk.afisha.ru/
http://%s.com
http://image.excite.co.jp/jp/favicon/lep.ico
http://search.ebay.in/
http://img.shopzilla.com/shopzilla/shopzilla.ico
http://in.search.yahoo.com/
http://rover.ebay.com
http://fr.search.yahoo.com/
http://asp.usatoday.com/
http://www.sogou.com/favicon.ico
http://search.rediff.com/
http://www.iis.fhg.de/audioPA
http://search.yahoo.com/favicon.ico
http://buscar.ya.com/
http://www3.fnac.com/favicon.ico
http://www.dailymail.co.uk/
http://www.nifty.com/favicon.ico
http://www.rambler.ru/
http://www.mtv.com/
http://search.ebay.de/
http://www.merlin.com.pl/favicon.ico
http://www.mercadolivre.com.br/
http://search.msn.co.jp/results.aspx?q=
http://www.google.it/
http://suche.t-online.de/
http://search.centrum.cz/
http://www.cjmall.com/
http://www.priceminister.com/favicon.ico
http://www.ask.com/
http://www.microsofttranslator.com/BVPrev.aspx?ref=IE8Activity
http://busca.igbusca.com.br/
http://search.about.com/
http://kr.search.yahoo.com/
http://buscar.ozu.es/
http://www.clarin.com/favicon.ico
http://search.chol.com/favicon.ico
http://search.naver.com/favicon.ico
http://search.daum.net/
http://www.abril.com.br/favicon.ico
http://cgi.search.biglobe.ne.jp/favicon.ico
http://search.hanafos.com/favicon.ico
http://www.google.ru/
http://search.naver.com/
http://it.search.dada.net/favicon.ico
http://www.etmall.com.tw/favicon.ico
http://www.ya.com/favicon.ico
http://www.windows.com/pctv.

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\xles[1].exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Users\user\Desktop\~$Processed APR12.xlsx
data
#
C:\Users\Public\vbc.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
Click to see the 8 hidden entries
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\3F0E3D0.png
PNG image data, 1686 x 725, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\6979E67D.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\6AEACB78.png
PNG image data, 1268 x 540, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\8DCE764B.png
PNG image data, 1268 x 540, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\C627CB57.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\C688FD6C.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\D9B62519.png
PNG image data, 1686 x 725, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Temp\Excel8.0\MSForms.exd
data
#