top title background image
flash

8OKQ6ogGRx.dll

Status: finished
Submission Time: 2021-05-04 18:49:59 +02:00
Malicious
Trojan
Ursnif

Comments

Tags

  • dll

Details

  • Analysis ID:
    404147
  • API (Web) ID:
    710449
  • Analysis Started:
    2021-05-04 18:50:36 +02:00
  • Analysis Finished:
    2021-05-04 18:58:42 +02:00
  • MD5:
    e8eae1a820426a722c7cae54ed5bacd8
  • SHA1:
    4d8368f112e0c56e7caccb89724bfdad1999e706
  • SHA256:
    eb498648d17ad5250ab1f38b190dd2da8bfa8db3ee86054db991db79d15ad5cc
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 64
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Domains

Name IP Detection
outlook.com
40.97.161.50
HHN-efz.ms-acdc.office.com
40.101.138.2
FRA-efz.ms-acdc.office.com
40.101.81.162
Click to see the 2 hidden entries
www.outlook.com
0.0.0.0
outlook.office365.com
0.0.0.0

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{AE905FC9-AD44-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{AE905FCB-AD44-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Temp\~DFFDCA7E35786F02EC.TMP
data
#
Click to see the 1 hidden entries
C:\Users\user\AppData\Local\Temp\~DFFF4222CFAFFA654A.TMP
data
#