flash

570000.dll

Status: finished
Submission Time: 06.07.2021 14:25:37
Malicious
Trojan
Ursnif

Comments

Tags

  • dll

Details

  • Analysis ID:
    444650
  • API (Web) ID:
    812239
  • Analysis Started:
    06.07.2021 14:25:37
  • Analysis Finished:
    06.07.2021 14:33:30
  • MD5:
    6577b8581782142e658f404003f240ab
  • SHA1:
    c6420b09963f9cc8db489b477238374448b11de8
  • SHA256:
    0314e12bc1cb1e046282a7933eab7e5fa7ec39c9ceaa78e233c7648904af5c28
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

malicious

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
68/100

malicious

URLs

Name Detection
http://https://file://USER.ID%lu.exe/upd
http://constitution.org/usdeclar.txt
http://constitution.org/usdeclar.txtC:

Dropped files

Name File Type Hashes Detection
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_loaddll32.exe_b9c034d6e73140d94d9c5167efb89cacf8f015e_160cf2be_0f231808\Report.wer
Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_rundll32.exe_3793dfb461ce22140462de4a1a2617bff1862a_82810a17_174714fb\Report.wer
Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_rundll32.exe_441129e8c7f959a6d52d59f5a8a654c6d5f532_82810a17_0c2b1bb2\Report.wer
Little-endian UTF-16 Unicode text, with CRLF line terminators
#
Click to see the 9 hidden entries
C:\ProgramData\Microsoft\Windows\WER\Temp\WER10C7.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER10E5.tmp.WERInternalMetadata.xml
XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER13D4.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER1402.tmp.WERInternalMetadata.xml
XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER1720.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER888.tmp.dmp
Mini DuMP crash report, 14 streams, Tue Jul 6 21:26:33 2021, 0x1205a4 type
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERD3B.tmp.dmp
Mini DuMP crash report, 14 streams, Tue Jul 6 21:26:35 2021, 0x1205a4 type
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERE65.tmp.WERInternalMetadata.xml
XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WEREE1.tmp.dmp
Mini DuMP crash report, 15 streams, Tue Jul 6 21:26:34 2021, 0x1205a4 type
#