flash

CMA-CGM BOOKING CONFIRMATION.xlsx

Status: finished
Submission Time: 19.07.2021 19:38:11
Malicious
Trojan
Exploiter
Evader
GuLoader

Comments

Tags

  • VelvetSweatshop
  • xlsx

Details

  • Analysis ID:
    450863
  • API (Web) ID:
    818452
  • Analysis Started:
    19.07.2021 19:38:13
  • Analysis Finished:
    19.07.2021 19:45:09
  • MD5:
    1a23b8c8e5fa52a917c92207a8316b55
  • SHA1:
    7b481fe511b2132d2d2dc7cad79aa5ebda0d3388
  • SHA256:
    9584a27702d6f6fdecc4589a5c87b529ef2c41ca556ddf9325999a4bdb58fcc3
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

System: Windows 7 x64 SP1 with Office 2010 SP2 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2)

malicious
100/100

malicious
13/46

IPs

IP Country Detection
180.214.239.39
Viet Nam

URLs

Name Detection
https://kinmirai.org/wp-content/bin_QVwo
http://180.214.239.39/disk/.svchost.exe
http://www.day.com/dam/1.0

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\.svchost[1].exe
PE32 executable (GUI) Intel 80386, for MS Windows
#
C:\Users\user\Desktop\~$CMA-CGM BOOKING CONFIRMATION.xlsx
data
#
C:\Users\Public\vbc.exe
PE32 executable (GUI) Intel 80386, for MS Windows
#
Click to see the 14 hidden entries
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\23D48948.jpeg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 150x150, segment length 16, baseline, precision 8, 1275x1650, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\31DE0BA3.png
PNG image data, 816 x 552, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\3B0A6367.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\887DE696.png
PNG image data, 816 x 552, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\9D9EA3AA.jpeg
[TIFF image data, big-endian, direntries=4], baseline, precision 8, 654x513, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\B536090D.jpeg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 150x150, segment length 16, baseline, precision 8, 1275x1650, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\D831163C.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\E885A8A9.jpeg
[TIFF image data, big-endian, direntries=4], baseline, precision 8, 654x513, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\mso3C39.tmp
PC bitmap, Windows 3.x format, 20 x 20 x 24
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\mso3C3A.tmp
PC bitmap, Windows 3.x format, 20 x 20 x 24
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\mso3C3B.tmp
PC bitmap, Windows 3.x format, 20 x 20 x 24
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\msoE456.tmp
PC bitmap, Windows 3.x format, 20 x 20 x 24
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\msoE457.tmp
PC bitmap, Windows 3.x format, 20 x 20 x 24
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\msoE487.tmp
PC bitmap, Windows 3.x format, 20 x 20 x 24
#