top title background image
flash

presentation.jar

Status: finished
Submission Time: 2021-05-06 17:55:45 +02:00
Malicious
Trojan
Exploiter
Evader
Ursnif

Comments

Tags

Details

  • Analysis ID:
    406076
  • API (Web) ID:
    714311
  • Analysis Started:
    2021-05-06 17:57:09 +02:00
  • Analysis Finished:
    2021-05-06 18:18:55 +02:00
  • MD5:
    6c5e7908c3a06aafd6dcebc8a2dcb674
  • SHA1:
    d094aef9d24e13ab70f2ef767242be554ed855ae
  • SHA256:
    cb8b20c28a0ac697b6f5bd430bd86762f6b9ef635428fe3fe77e174b172ac6f4
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 80
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
malicious
Score: 84
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Run Condition: Without Tracing

Third Party Analysis Engines

malicious
Score: 12/61
malicious
Score: 12/29

IPs

IP Country Detection
3.212.50.245
United States
50.87.249.219
United States
13.32.21.15
United States
Click to see the 3 hidden entries
35.181.18.61
United States
99.86.2.60
United States
65.9.66.38
United States

Domains

Name IP Detection
trial-eum-clienttons-s.akamaihd.net
0.0.0.0
dc.oracleinfinity.io
0.0.0.0
c.go-mpulse.net
0.0.0.0
Click to see the 15 hidden entries
kqitits7mulnqyeucsyq-pe4433-4b66e3cf2-clientnsv4-s.akamaihd.net
0.0.0.0
84-17-52-78_s-23-32-238-131_ts-1620317361-clienttons-s.akamaihd.net
0.0.0.0
www.java.com
0.0.0.0
trial-eum-clientnsv4-s.akamaihd.net
0.0.0.0
6852bd12.akstat.io
0.0.0.0
c.oracleinfinity.io
0.0.0.0
consent-pref.trustarc.com
13.32.21.15
s.go-mpulse.net
0.0.0.0
www.oracle.com
0.0.0.0
static.oracle.com
0.0.0.0
consent.trustarc.com
99.86.2.60
prefmgr-cookie.truste-svc.net
3.212.50.245
docs.cyberservices.biz
50.87.249.219
oracle.112.2o7.net
35.181.18.61
consent-st.trustarc.com
65.9.66.38

URLs

Name Detection
http://search.centrum.cz/
http://www.pchome.com.tw/favicon.ico
http://cps.letsencrypt.orgc
Click to see the 97 hidden entries
http://busca.buscape.com.br/favicon.ico
https://consent.trustarc.com/get?name=crossdomain.html&domain=oracle.com
http://sads.myspace.com/
http://crl.securetrust.com/STCA.crl
http://www.amazon.de/
http://www.ceneo.pl/
http://search.auction.co.kr/
http://www.google.it/
http://suche.t-online.de/
http://www.certplus.com/CRL/class3P.crl
http://browse.guardian.co.uk/favicon.ico
http://www.cjmall.com/
http://cps.chambersign.org/cps/chambersroot.html
http://www.priceminister.com/favicon.ico
http://www.ask.com/
http://www.microsofttranslator.com/BVPrev.aspx?ref=IE8Activity
http://busca.igbusca.com.br/
http://ocsp.sectigo.com
http://search.about.com/
http://kr.search.yahoo.com/
http://crl.sectigo.com/SectigoRSACodeSigningCA.crl0s
http://buscar.ozu.es/
http://search.ebay.com/
https://github.com/requirejs/requirejs/blob/master/LICENSE
http://images.joins.com/ui_c/fvc_joins.ico
http://www.amazon.com/
http://search.ebay.it/
http://www.univision.com/
http://www.soso.com/
http://www.google.cz/
http://www.google.si/
http://searchresults.news.com.au/
http://search.nifty.com/
http://ocsp.sectigo.com0
http://www.gmarket.co.kr/
http://www.clarin.com/favicon.ico
http://search.yahoo.co.jp/favicon.ico
http://openimage.interpark.com/interpark.ico
http://search.sify.com/
http://www.ozu.es/favicon.ico
http://r3.o.lencr.org
http://espanol.search.yahoo.com/
http://uk.search.yahoo.com/
https://consent.trustarc.com/log
http://www.rambler.ru/favicon.ico
http://list.taobao.com/browse/search_visual.htm?n=15&q=
http://google.pchome.com.tw/
http://www.chambersign.org1
http://image.excite.co.jp/jp/favicon/lep.ico
http://search.ebay.in/
http://img.shopzilla.com/shopzilla/shopzilla.ico
http://in.search.yahoo.com/
http://www.aboutads.info/consumers
http://rover.ebay.com
http://fr.search.yahoo.com/
http://consent.trustarc.com/bannermsg?
http://asp.usatoday.com/
HTTP://WWW.CHAMBERSIGN.ORG
http://www.sogou.com/favicon.ico
http://repository.swisssign.com/0
http://%s.com
http://search.yahoo.com/favicon.ico
http://buscar.ya.com/
https://s2.go-mpulse.net/boomerang/
http://www3.fnac.com/favicon.ico
http://www.dailymail.co.uk/
http://www.nifty.com/favicon.ico
http://www.rambler.ru/
http://www.mtv.com/
http://search.ebay.de/
http://www.merlin.com.pl/favicon.ico
http://www.mercadolivre.com.br/
http://it.search.dada.net/favicon.ico
http://search.msn.co.jp/results.aspx?q=
http://search.naver.com/favicon.ico
http://java.oracle.com/
http://search.daum.net/
http://www.abril.com.br/favicon.ico
http://bugreport.sun.com/bugreport/
http://www.certplus.com/CRL/class2.crl
http://cgi.search.biglobe.ne.jp/favicon.ico
http://search.hanafos.com/favicon.ico
http://cps.letsencrypt.org0
http://www.google.ru/
http://search.naver.com/
http://search.chol.com/favicon.ico
http://www.etmall.com.tw/favicon.ico
http://bugs.webkit.org/show_bug.cgi?id=3810
http://www.ya.com/favicon.ico
https://static.oracle.com/cdn/cec/v21.2.1.30/_sitesclouddelivery/renderer/renderer.js
http://search.rediff.com/
http://policy.camerfirma.com0
http://watchdog.truste.com/pvr.php?page=complaint
http://busca.igbusca.com.br//app/static/images/favicon.ico
http://www.reddit.com/
https://prefmgr-cookie.truste-svc.net/cookie_js/cookie_iframe.html?parent=https://consent-pref.trust
http://msk.afisha.ru/

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\broker.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\i18n.min[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\GoJava[1].jpg
JPEG image data, JFIF standard 1.01, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 125x132, frames 3
#
Click to see the 84 hidden entries
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\10.cache[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\s_code_remote[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\render[1].js
exported SGML document, UTF-8 Unicode text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\promise-polyfill.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\layout[1].htm
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\jv0ht[1].gif
GIF image data, version 89a, 351 x 173
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\jv0dl_a[1].png
PNG image data, 672 x 128, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\jv0_oracle[1].gif
GIF image data, version 89a, 91 x 22
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\java_home_photo2[1].jpg
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, progressive, precision 8, 320x303, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\infinity_common[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\JavaOne(2)(2)[1].jpg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 125x132, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\get[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\favicon[1].ico
MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\defaultpreferencemanager.nocache[1].js
HTML document, ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\config[1].json
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\JavaGreenfoot[1].jpg
JPEG image data, JFIF standard 1.01, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 125x132, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\v1[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\theme.min[1].js
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\screen[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\results[1].txt
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\setupLibs[1].js
ASCII text, with very long lines, with no line terminators
#
C:\jar\Secure_Viewer.class
compiled Java class data, version 52.0 (Java 1.8)
#
C:\jar\META-INF\SECURE_VIEWER.SF
ASCII text, with CRLF line terminators
#
C:\jar\META-INF\SECURE_VIEWER.RSA
data
#
C:\jar\META-INF\MANIFEST.MF
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3853321935-2125563209-4053062332-1002\83aa4cc77f591dfc2374580bbd95f6ba_d06ed635-68f6-4e9a-955c-4899f5f57b9a
data
#
C:\Users\user\AppData\Local\Temp\~DFF8F4FA532DD29734.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFA5E950483B2D2C08.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF317A7A5B5B92E024.TMP
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\theme.deferred.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\template[1].htm
exported SGML document, ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\render[1].js
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\renderer[1].js
UTF-8 Unicode text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\oldcss[1].css
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\metrics_group1[1].js
C source, ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\jv0_search_btn[1].gif
GIF image data, version 89a, 19 x 18
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\header[2].js
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\header[1].js
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\en[1].htm
HTML document, ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\cookie_inneriframe[1].htm
HTML document, ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\cookie_iframe[1].htm
HTML document, ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\footer.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\caas_contenttypemap[1].json
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\a[1].gif
GIF image data, version 89a, 1 x 1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\T79A9-GDDN2-93ZD5-M6HUR-X83QX[1].js
C source, ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\0D070042D9C67A68E1A4BF804E6E0E06.cache[1].htm
HTML document, ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\wlm7n14\imagestore.dat
data
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\get[1].gif
GIF image data, version 89a, 133 x 18
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{D6A9509C-AED0-11EB-90E5-ECF4BB2D2496}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{D6A9509B-AED0-11EB-90E5-ECF4BB2D2496}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{D6A95099-AED0-11EB-90E5-ECF4BB2D2496}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\IB42RK38\consent.trustarc[1].xml
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\EQAWN5DV\www.java[1].xml
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\6BAUBVPU\consent-pref.trustarc[1].xml
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\trustarc-logo-small[1].png
PNG image data, 198 x 34, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\loading[1].gif
GIF image data, version 89a, 31 x 31
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\items[1].json
HTML document, ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\get[1].htm
HTML document, ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\controller[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\W3ZUK9WP.htm
HTML document, ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\Oracleacademy(2)[1].jpg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 125x132, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\JavaAlice[1].jpg
JPEG image data, JFIF standard 1.01, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 125x132, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\EuPreferenceManager[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\6.cache[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\1.cache[1].js
ASCII text, with very long lines
#
C:\ProgramData\Oracle\Java\.oracle_jre_usage\cce3fe3b0d8d83e2.timestamp
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\results[1].txt
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\require[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\render[1].js
exported SGML document, UTF-8 Unicode text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\print[1].css
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\notice[2].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\notice[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\layout[1].htm
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\jv0h[1].jpg
[TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS4 Macintosh, datetime=2011:01:25 18:25:40], baseline, precision 8, 777x95, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\javamagazine(2)[1].jpg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 125x132, frames 3
#