top title background image
flash

Inv-04_PDF.vbs

Status: finished
Submission Time: 2021-07-20 16:35:27 +02:00
Malicious
Trojan
Evader
Nanocore AgentTesla

Comments

Tags

  • NanoCore
  • RAT
  • vbs

Details

  • Analysis ID:
    451451
  • API (Web) ID:
    819041
  • Analysis Started:
    2021-07-20 16:41:32 +02:00
  • Analysis Finished:
    2021-07-20 16:57:00 +02:00
  • MD5:
    457617bb66ce73bbc76af8d376469792
  • SHA1:
    a1e9d7b4f153da6d345d6e8dd5d6923a260cff10
  • SHA256:
    ea11c7637e649da3353f4d11ea0c03e95a53284bc57dc07f947ceb39e2d24230
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 13/46

IPs

IP Country Detection
192.227.128.168
United States

Domains

Name IP Detection
sys2021.linkpc.net
192.227.128.168

URLs

Name Detection
http://www.fonts.comc
http://www.carterandcone.coml
http://www.galapagosdesign.com/I
Click to see the 73 hidden entries
http://www.fontbureau.come.com
http://en.wikip
http://www.jiyu-kobo.co.jp/jp/
http://en.wikipedia
http://www.jiyu-kobo.co.jp/E
http://www.jiyu-kobo.co.jp/L
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha
http://www.founder.com.cn/cn/
http://www.carterandcone.como.U
http://www.fontbureau.comue
http://DynDns.comDynDNS
http://www.galapagosdesign.com/
http://www.fontbureau.comL
http://www.fontbureau.com
http://www.apache.org/licenses/LICENSE-2.0
http://www.fontbureau.comasa
http://www.fontbureau.comals4
http://www.fontbureau.com/designers5
http://www.founder.com.cn/cn)
http://www.fontbureau.com/designers/
http://www.jiyu-kobo.co.jp/a
http://www.fontbureau.com/designers:
http://www.jiyu-kobo.co.jp/h
http://www.fontbureau.comon
http://www.fontbureau.com/designers8
http://www.fontbureau.como
http://www.fontbureau.comldh
http://www.jiyu-kobo.co.jp/
http://www.fontbureau.comsivF
http://www.fontbureau.comF~
http://www.galapagosdesign.com/4
http://www.fontbureau.com/designers/frere-jones.html
http://www.founder.com.cn/cn
http://www.jiyu-kobo.co.jp/w
http://www.fontbureau.com/designers/cabarga.htmlN
http://www.tiro.com
http://www.founder.com.cn/cn/cThe
http://www.typography.netD
http://www.founder.com.cn/cnht
http://www.sajatypeworks.com
http://www.jiyu-kobo.co.jp/~
http://www.carterandcone.com
http://google.com
http://www.goodfont.co.kr
http://www.fontbureau.com/designers
http://www.galapagosdesign.com/staff/dennis.htm
http://www.sajatypeworks.comn-u
http://www.fontbureau.com/designers?
http://www.founder.com.cn/cn/bThe
http://www.fontbureau.com/designers/?
http://www.sandoll.co.kr8
http://www.fontbureau.comrsivw
http://www.fontbureau.comitudE
http://www.fontbureau.com/designersG
http://www.galapagosdesign.com/DPlease
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip
http://www.sakkal.com
http://www.zhongyicts.com.cn
http://www.urwpp.deDPlease
http://www.sandoll.co.krF
http://www.sandoll.co.kr
http://www.fonts.com
https://api.ipify.org%GETMozilla/5.0
http://www.jiyu-kobo.co.jp/Y0
http://127.0.0.1:HTTP/1.1
http://gKSfZA.com
http://www.fontbureau.comT.TTFh
http://www.sandoll.co.krcom
http://www.sandoll.co.krT
http://www.jiyu-kobo.co.jp/4
http://www.founder.com.cn/cnm
http://www.jiyu-kobo.co.jp/jp/a
http://fontfabrik.com

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\pad.exe.log
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\InstallUtil.exe
PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Users\user\AppData\Local\Temp\not.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
Click to see the 8 hidden entries
C:\Users\user\AppData\Local\Temp\pad.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat
Non-ISO extended-ASCII text, with no line terminators
#
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\notepad\not.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Users\user\AppData\Roaming\eXPLorerInternet64\Explorer64int.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\not.exe.log
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\catalog.dat
data
#
C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\settings.bin
data
#
C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\storage.dat
data
#