top title background image
flash

6a76e615_by_Libranalysis.dll

Status: finished
Submission Time: 2021-05-06 18:28:00 +02:00
Malicious
Trojan
Ursnif

Comments

Tags

  • Gozi

Details

  • Analysis ID:
    406107
  • API (Web) ID:
    714364
  • Analysis Started:
    2021-05-06 18:34:02 +02:00
  • Analysis Finished:
    2021-05-06 18:41:43 +02:00
  • MD5:
    6a76e615a7997fc04e3003ce16c9bc3d
  • SHA1:
    90d82c7e8a3f2d3c4ec8e4542605eafbcb07bf95
  • SHA256:
    f9f77f992f0c7bf8ec0a39acdac1a343f6418e50510db1f92347d5270d0ab9ab
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 88
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 20/69
malicious
Score: 14/47

IPs

IP Country Detection
34.86.224.8
United States

Domains

Name IP Detection
green.salurober.com
34.86.224.8

URLs

Name Detection
http://green.salurober.com/egg0bSJn4ObK/ch_2F9lMPXs/fO3mZ53deXfDrA/fFpIrCwIBcA2fafEjJROE/_2FRp0luL60
http://www.wikipedia.com/
http://www.amazon.com/
Click to see the 7 hidden entries
http://www.nytimes.com/
http://www.live.com/
http://deeplow.ruB
http://www.reddit.com/
http://www.twitter.com/
http://green.salurober.com/egg0bSJn4ObK/ch_2F9lMPXs/fO3mZ53deXfDrA/fFpIrCwIBcA2fafEjJROE/_2FRp0luL60r80DP/FChSncsB8SqrhdJ/_2FXtQYnl2ITaT9OH4/qVdqvFpku/l5Z_2BwlLO28ejlDZ4Xv/ZR0P9bZC7mrWzK2nsLX/wmJroXqHSsCiyywQoJG_2B/ja6fWO6EY6PRe/fsgqsP8a/8D7PMyq0Et_2Bw5od_2BLED/JSk7_2F_2B/ptgvp19MaEwrG0884/hUO8hPN4NRV3/myPEhfLIkFj/6E7GZZkxutBKlj/2G265rer_2FHZz0gfwlBV/vusAOmr1_/2BAGh_2B
http://www.youtube.com/

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\ErrorPageTemplate[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\~DF8CF38F8205796A33.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF71AFC16E996A3DCA.TMP
data
#
Click to see the 19 hidden entries
C:\Users\user\AppData\Local\Temp\JavaDeployReg.log
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\http_404[1]
HTML document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\httpErrorPagesScripts[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WJ8I2OL4\background_gradient[1]
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 1x800, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\errorPageStrings[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PSUEOSZZ\down[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\info_48[1]
PNG image data, 47 x 48, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\bullet[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{9B20D48F-AED4-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{9B20D491-AED4-11EB-90E4-ECF4BB862DED}.dat
Microsoft Word Document
#