flash

INVOICE.exe

Status: finished
Submission Time: 11.06.2021 11:36:19
Malicious
Trojan
Evader
FormBook

Comments

Tags

  • exe
  • Formbook

Details

  • Analysis ID:
    433143
  • API (Web) ID:
    800747
  • Analysis Started:
    11.06.2021 11:36:19
  • Analysis Finished:
    11.06.2021 11:45:55
  • MD5:
    98901aff995d92677cf637b241ae9a9b
  • SHA1:
    6dac1968c4a9ae4bf26f7fd38efb721fcf7d05dc
  • SHA256:
    fb6e849cd3af7e8b0c8143397e62a595a42abbfbbac81f2cdd0b2cb4d18ea543
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

malicious

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
100/100

malicious
19/29

IPs

IP Country Detection
104.21.29.70
United States
34.102.136.180
United States

Domains

Name IP Detection
www.cpf3life.com
104.21.29.70
www.gicc-fx.com
198.252.100.204
www.phonetomouth.com
0.0.0.0
Click to see the 2 hidden entries
www.dollysusmitha.com
0.0.0.0
phonetomouth.com
34.102.136.180

URLs

Name Detection
http://www.cpf3life.com/uer0/?cT=IWphFoHV4jp5oknFMScIxRoUR2WJRPQs/XYBCw5pT/o6GbblNl6C3qYdj4q6OTOtoDPc&0rjL0=00GhNj0PalVPThz
www.gicc-fx.com/uer0/
http://www.apache.org/licenses/LICENSE-2.0
Click to see the 28 hidden entries
http://www.fontbureau.com
http://www.fontbureau.com/designersG
http://www.fontbureau.com/designers/?
http://www.founder.com.cn/cn/bThe
http://www.fontbureau.com/designers?
http://www.tiro.com
http://www.fontbureau.com/designers
http://nsis.sf.net/NSIS_ErrorError
http://www.goodfont.co.kr
http://www.phonetomouth.com/uer0/?0rjL0=00GhNj0PalVPThz&cT=mzn46ufhhzCxwm8qeMWDu5BECFFcgbpMb+xr4Y5+z9rgY/t3xuFClMCjGCpTywHehpEI
http://www.carterandcone.coml
http://www.sajatypeworks.com
http://www.typography.netD
http://www.fontbureau.com/designers/cabarga.htmlN
http://www.founder.com.cn/cn/cThe
http://www.galapagosdesign.com/staff/dennis.htm
http://fontfabrik.com
http://www.founder.com.cn/cn
http://www.fontbureau.com/designers/frere-jones.html
http://nsis.sf.net/NSIS_Error
http://www.jiyu-kobo.co.jp/
http://www.galapagosdesign.com/DPlease
http://www.fontbureau.com/designers8
http://www.fonts.com
http://www.sandoll.co.kr
http://www.urwpp.deDPlease
http://www.zhongyicts.com.cn
http://www.sakkal.com

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Temp\jxl61c12gqlj1w2
data
#
C:\Users\user\AppData\Local\Temp\nfqccgctc
data
#
C:\Users\user\AppData\Local\Temp\nsj9220.tmp
data
#
Click to see the 1 hidden entries
C:\Users\user\AppData\Local\Temp\nsj9221.tmp\System.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#