flash

SgjcpodWpB.exe

Status: finished
Submission Time: 22.07.2021 11:21:09
Malicious
Trojan
Spyware
Evader
RedLine

Comments

Tags

  • exe
  • RedLineStealer

Details

  • Analysis ID:
    452445
  • API (Web) ID:
    820038
  • Analysis Started:
    22.07.2021 11:21:10
  • Analysis Finished:
    22.07.2021 11:31:00
  • MD5:
    a4f4b5daa83bb6dc85ede588ffbfdb34
  • SHA1:
    9bbaac140fa643d30bf25af71561f5ee35874898
  • SHA256:
    f61201b7b85a410a62c1f1946095b3feabb6e672fb8ddc0c64789a02ae9a06f4
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

malicious

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
100/100

malicious
45/70

malicious
12/35

malicious
16/28

IPs

IP Country Detection
212.224.105.79
Germany
104.21.7.102
United States
172.67.202.174
United States
Click to see the 2 hidden entries
88.99.66.31
Germany
104.21.14.85
United States

Domains

Name IP Detection
getdesignusa.xyz
172.67.202.174
kalamaivig.xyz
212.224.105.79
music-s.xyz
104.21.7.102
Click to see the 2 hidden entries
iplogger.org
88.99.66.31
api.ip.sb
0.0.0.0

URLs

Name Detection
https://music-s.xyz/(
https://music-s.xyzx
http://music-s.xyz
Click to see the 95 hidden entries
https://music-s.xyz
https://music-s.xyz/?user=p4_6
https://music-s.xyz/?user=p4_4
https://music-s.xyz/?user=p4_5
https://music-s.xyz/?user=p4_2
https://music-s.xyz/?user=p4_3
https://music-s.xyz/?user=p4_1
https://music-s.xyz/
https://music-s.xyz/0yAM
https://music-s.xyz8
http://kalamaivig.xyz:80/
http://schemas.xmlsoap.org/soap/envelope/
https://iplogger.org/1XqVr70yAM
https://support.google.com/chrome/?p=plugin_flash
https://support.google.com/chrome/?p=plugin_java
http://tempuri.org/Endpoint/VerifyUpdateResponse
http://go.micros
https://getdesignusa.xyz
https://iplogger.org8
http://kalamaivig.xyz4/l
https://api.ipify.org
https://api.ipify.orgcookies//settinString.Removeg
https://duckduckgo.com/chrome_newtab(;AM
https://support.google.com/chrome/?p=plugin_divx
http://fpdownload.macromedia.com/get/shockwave/default/english/win95nt/latest/Shockwave_Installer_Sl
http://tempuri.org/0
https://getdesignusa.xyzx
https://ipinfo.io/ip%appdata%
https://search.yahoo.com/favicon.ico_
https://sectigo.com/CPS0
https://support.microso
https://www.google.com/images/branding/product/ico/googleg_lodp.ico
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous
https://helpx.ad
http://getdesignusa.xyz
https://api.ip.sbL
https://search.yahoo.com/favicon.icohttps://search.yahoo.com/search
https://iplogger.org
https://get.adob
https://ac.ecosia.org/autocomplete?q=
http://iplogger.org
http://service.real.com/realplayer/security/02062012_player/en/
https://sectigo.com/I
http://tempuri.org/Endpoint/GetUpdatesResponse
https://search.yahoo.com/sugg/chrome?output=fxjson&l
https://iplogger.org/1XqVr7(
http://kalamaivig.xyz/
https://www.google.com/images/branding/product/ico/goog
https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
http://schemas.xmlsoap.org/soap/actor/next
https://iplogger.org/1DSJe7
https://iplogger.org/1XqVr7
https://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
https://duckduckgo.com/chrome_newtab
http://service.r
https://duckduckgo.com/ac/?q=
https://api.ip.sb/geoip
https://iplogger.org/1DSJe70yAM
http://schemas.xmlsoap.org/soap/envelope/D
http://tempuri.org/
http://tempuri.org/Endpoint/SetEnvironment
http://tempuri.org/Endpoint/SetEnvironmentResponse
http://tempuri.org/Endpoint/GetUpdates
https://support.google.com/chrome/?p=plugin_real
http://schemas.xmlsoap.org/ws/2004/08/addressing/faultp
https://iplogger.org/1DSJe7(
http://www.interoperabilitybridges.com/wmp-extension-for-chrome
https://support.google.com/chrome/?p=plugin_pdf
http://tempuri.org/Endpoint/VerifyUpdate
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
http://forms.real.com/real/realone/download.html?type=rpsp_us
http://support.a
http://crt.sectigo.com/SectigoRSADomainValidationSecureServerCA.crt0#
http://download.divx.com/player/divxdotcom/DivXWebPlayerInstaller.exe
https://support.google.com/chrome/?p=plugin_quicktime
http://schemas.datacontract.org/2004/07/
http://crt.sectigo.cE
https://api.ip.sb/geoip%USERPEnvironmentROFILE%
https://support.microsoom/k
https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
https://getdesignusa.xyz/api.php
https://iplogger.orgx
http://tempuri.org/Endpoint/GetUpdatestr
http://kalamaivig.xyz(h
http://schemas.xmlsoap.org/ws/2004/08/addressing
https://support.google.com/chrome/?p=plugin_shockwave
http://forms.rea
http://tempuri.org/Endpoint/EnvironmentSettingsResponse
https://getdesignusa.xyz/
http://kalamaivig.xyz
https://getdesignusa.xyz8
https://support.google.com/chrome/?p=plugin_wmp
http://ocsp.sectigo.com0
https://support.google.com/chrome/answer/6258784
http://tempuri.org/Endpoint/EnvironmentSettings

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\SgjcpodWpB.exe.log
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\3228047.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Users\user\AppData\Roaming\3672547.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
Click to see the 45 hidden entries
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_3672547.exe_845b9f3d75c74d719da4968477a6b6ebdd9f333_4e69b664_113cdf3a\Report.wer
Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERAD9B.tmp.dmp
Mini DuMP crash report, 16 streams, Thu Jul 22 18:22:43 2021, 0x1205a4 type
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERB760.tmp.WERInternalMetadata.xml
XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERB984.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\3228047.exe.log
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\tmp218C.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Temp\tmp2360.tmp
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Temp\tmp2361.tmp
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Temp\tmp301.tmp
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Temp\tmp302.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Temp\tmp3879.tmp
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Temp\tmp387A.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Temp\tmp3DAB.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Temp\tmp4186.tmp
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Temp\tmp57FF.tmp
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Temp\tmp5800.tmp
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Temp\tmp583F.tmp
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Temp\tmp5840.tmp
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Temp\tmp5876.tmp
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Temp\tmp5877.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Temp\tmp78C1.tmp
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Temp\tmp78C2.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Temp\tmp7B55.tmp
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Temp\tmp8890.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Temp\tmp8CAF.tmp
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Temp\tmp8CB0.tmp
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Temp\tmp8CE0.tmp
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Temp\tmp8CE1.tmp
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Temp\tmp9A38.tmp
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Temp\tmp9A39.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Temp\tmpA188.tmp
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Temp\tmpC075.tmp
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Temp\tmpC076.tmp
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Temp\tmpC096.tmp
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Temp\tmpC097.tmp
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Temp\tmpC098.tmp
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Temp\tmpC099.tmp
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Temp\tmpC09A.tmp
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Temp\tmpC0CA.tmp
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Temp\tmpC153.tmp
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Temp\tmpDAD8.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Temp\tmpDC5.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Temp\tmpE7CD.tmp
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Temp\tmpEDD7.tmp
SQLite 3.x database, last written using SQLite version 3032001
#
C:\Users\user\AppData\Local\Temp\tmpEDD8.tmp
SQLite 3.x database, last written using SQLite version 3032001
#