top title background image
flash

astro-grep-setup.exe.doc

Status: finished
Submission Time: 2021-07-17 21:39:09 +02:00
Malicious
Trojan
Exploiter
Evader
AsyncRAT

Comments

Tags

  • AstroGrep
  • doc

Details

  • Analysis ID:
    450275
  • API (Web) ID:
    817864
  • Analysis Started:
    2021-07-17 21:39:14 +02:00
  • Analysis Finished:
    2021-07-17 21:55:55 +02:00
  • MD5:
    9c3d3679ea84ff9bf67bf8c7aa2afc48
  • SHA1:
    0470d616e8918ef03098741bf7fb0b313bb8aaea
  • SHA256:
    2f5639932c7a25cf51737748cdc495367a9203e0a963f930f0009935109da190
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 7 x64 SP1 with Office 2010 SP1 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2)

Third Party Analysis Engines

malicious
Score: 38/63
malicious

IPs

IP Country Detection
185.195.232.251
Sweden
104.23.98.190
United States

Domains

Name IP Detection
pastebin.com
104.23.98.190

URLs

Name Detection
https://pastebin.com/raw/VTByvKGMHD9mPHD9m0HD9m
https://pastebin.com/raw/VTByvKGMHD9m
http://crl.entrust.net/2048ca.crl0
Click to see the 28 hidden entries
https://pastebin.com
http://pastebin.com
https://secure.comodo.com/CPS0
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
http://ocsp.entrust.net0D
http://www.%s.comPA
http://investor.msn.com/
http://nsis.sf.net/NSIS_Error
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
http://www.icra.org/vocabulary/.
http://crl.pkioverheid.nl/DomOvLatestCRL.crl0
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
https://www.nuget.org/packages/NLog.Web.AspNetCore
http://www.windows.com/pctv.
http://www.hotmail.com/oe
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
http://nsis.sf.net/NSIS_ErrorError
https://pastebin.comP
https://pastebin.com/raw/VTByvKGMHD
http://www.diginotar.nl/cps/pkioverheid0
https://nlog-project.org/
http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
https://pastebin.com/raw/VTByvKGM
https://pastebin.com/raw
http://ocsp.entrust.net03
http://crl.entrust.net/server1.crl0
http://www.msnbc.com/news/ticker.txt
http://investor.msn.com

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Roaming\astro-grep.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Users\user\AppData\Local\Temp\ASTRO-GREP.EXE
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\ProgramData\Memsys\ms.exe
PE32 executable (GUI) Intel 80386, for MS Windows
#
Click to see the 33 hidden entries
C:\Users\user\AppData\Local\Temp\nsa2731.tmp\modern-wizard.bmp
PC bitmap, Windows 3.x format, 164 x 314 x 4
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{90768F62-679A-419C-A2B1-C0B28319F5E4}.tmp
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{FBF58E38-2270-4D70-A99C-79301888F689}.tmp
data
#
C:\Users\user\AppData\Local\Temp\ASTROGREP_SETUP_V4.4.7.EXE
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
#
C:\Users\user\AppData\Local\Temp\msoB754.tmp
GIF image data, version 89a, 15 x 15
#
C:\Users\user\AppData\Local\Temp\nsa2731.tmp\LangDLL.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Temp\nsa2731.tmp\StartMenu.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Temp\nsa2731.tmp\System.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{8DB8CC3B-9141-43B7-951A-41190F623D30}.tmp
data
#
C:\Users\user\AppData\Local\Temp\nsa2731.tmp\nsDialogs.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Temp\tmp3E29.tmp.bat
DOS batch file, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\astro-grep-setup.exe.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Aug 26 14:08:12 2020, mtime=Wed Aug 26 14:08:12 2020, atime=Sun Jul 18 03:39:30 2021, length=1443117, window=hide
#
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
data
#
C:\Users\user\Desktop\~$tro-grep-setup.exe.doc
data
#
\Device\Null
ASCII text, with CRLF line terminators, with overstriking
#
C:\Program Files (x86)\AstroGrep\astrogrep.VisualElementsManifest.xml
ASCII text, with CRLF line terminators
#
C:\Program Files (x86)\AstroGrep\AstroGrep.AdminProcess.exe.config
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\Program Files (x86)\AstroGrep\AstroGrep.Common.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Program Files (x86)\AstroGrep\AstroGrep.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Program Files (x86)\AstroGrep\AstroGrep.exe.config
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\Program Files (x86)\AstroGrep\AstroGrep_256x256.png
PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
#
C:\Program Files (x86)\AstroGrep\ICSharpCode.AvalonEdit.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Program Files (x86)\AstroGrep\NLog.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Program Files (x86)\AstroGrep\Uninstall.exe
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
#
C:\Program Files (x86)\AstroGrep\AstroGrep.AdminProcess.exe
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Program Files (x86)\AstroGrep\libAstroGrep.dll
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Program Files (x86)\AstroGrep\license.txt
ASCII text, with CRLF line terminators
#
C:\Program Files (x86)\AstroGrep\readme.txt
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AstroGrep\AstroGrep.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Thu Apr 4 19:57:44 2019, mtime=Sun Jul 18 03:42:39 2021, atime=Thu Apr 4 19:57:44 2019, length=573440, window=hide
#
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AstroGrep\Uninstall AstroGrep.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Sun Jul 18 03:42:40 2021, mtime=Sun Jul 18 03:42:40 2021, atime=Sun Jul 18 03:42:40 2021, length=61854, window=hide
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\78FF0AD.png
PNG image data, 1024 x 768, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{5BCB44D4-31CD-44E2-A821-3408DFB7CA1A}.tmp
data
#