top title background image
flash

ORDER.exe

Status: finished
Submission Time: 2021-06-11 14:58:19 +02:00
Malicious
Trojan
Evader
Nanocore

Comments

Tags

  • exe
  • NanoCore

Details

  • Analysis ID:
    433263
  • API (Web) ID:
    800867
  • Analysis Started:
    2021-06-11 14:58:20 +02:00
  • Analysis Finished:
    2021-06-11 15:10:08 +02:00
  • MD5:
    425f6b1e9437b1f1db352d1393d236d5
  • SHA1:
    65cf68fdda68b0327d51b7e3989afaa2258d4c6d
  • SHA256:
    cfb1e4b65fc8e0d9ca698ab5e67fc77735880b8439a6f4ee4e48be06ca631dc2
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 23/69
malicious
Score: 21/46

IPs

IP Country Detection
185.140.53.135
Sweden

Domains

Name IP Detection
kjjuigfdullygigyftkuyluylygilyfidyyuljhd.ydns.eu
185.140.53.135

URLs

Name Detection
kjjuigfdullygigyftkuyluylygilyfidyyuljhd.ydns.eu
http://www.carterandcone.coml
Click to see the 66 hidden entries
http://www.fontbureau.com/designers/cabarga.htmlN
http://www.sajatypeworks.com-d
http://www.fontbureau.comlic
http://www.sandoll.co.kr;D~
http://www.fontbureau.comF
http://www.galapagosdesign.com/
http://www.fontbureau.com
http://www.carterandcone.comexc
http://www.apache.org/licenses/LICENSE-2.0
http://www.fontbureau.comalicLG$
http://www.carterandcone.comnewk
http://www.fontbureau.com/designersn
http://www.sakkal.com
http://www.zhongyicts.com.cn
http://www.fontbureau.comF(G
http://www.jiyu-kobo.co.jp/
http://www.carterandcone.comgne
http://www.fonts.com8
http://www.fontbureau.com/designers/
http://www.fontbureau.com/designers:
http://www.fontbureau.comalsadF
http://www.tiro.comn7dc
http://www.fontbureau.com/designers8
http://www.carterandcone.comona
http://www.founder.com.cn/cns-c
http://www.fontbureau.comuec:G~
http://www.carterandcone.comy
http://www.carterandcone.comhly
http://www.tiro.comFTd
http://www.fontbureau.com/designers/frere-user.html
http://www.founder.com.cn/cn
http://www.carterandcone.comTC3
http://www.fontbureau.com/designers?
http://www.founder.com.cn/cngH
http://www.fontbureau.comalsF
http://www.carterandcone.com
http://www.goodfont.co.kr
http://www.fontbureau.com/designers
http://www.tiro.comMd
http://www.tiro.com
http://www.fontbureau.com/designersD
http://en.wa
http://www.sandoll.co.kr2Dq
http://www.fonts.comro
http://en.wI
http://www.founder.com.cn/cn/bThe
http://www.fontbureau.com/designers/?
http://www.fontbureau.com/designersF
http://www.fontbureau.com/designersG
http://www.fonts.comn
http://www.sandoll.co.kr
http://www.fonts.com
http://www.carterandcone.comtal
http://www.founder.com.cn/cnt-p
http://www.fontbureau.com(G
http://www.fontbureau.comgrito
http://www.fontbureau.com9
http://www.galapagosdesign.com/DPlease
http://www.urwpp.deDPlease
http://www.founder.com.cn/cn/c
http://www.carterandcone.comC
http://fontfabrik.com
http://www.galapagosdesign.com/staff/dennis.htm
http://www.founder.com.cn/cn/cThe
http://www.typography.netD
http://www.sajatypeworks.com

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\CLR_v2.0_32\UsageLogs\ORDER.exe.log
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\tmp6A1C.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat
ISO-8859 text, with no line terminators
#
Click to see the 4 hidden entries
C:\Users\user\AppData\Roaming\Odstcl.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Users\user\AppData\Local\Temp\tmp777A.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\tmpFE00.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\task.dat
ASCII text, with no line terminators
#