top title background image
flash

start[2021.09.09_15-26].vbs

Status: finished
Submission Time: 2021-09-10 13:48:05 +02:00
Malicious
Trojan
Evader
Ursnif

Comments

Tags

Details

  • Analysis ID:
    481181
  • API (Web) ID:
    848750
  • Analysis Started:
    2021-09-10 13:48:06 +02:00
  • Analysis Finished:
    2021-09-10 13:58:06 +02:00
  • MD5:
    3959f76d91c30f3c14916f80a6c4cf23
  • SHA1:
    2c918bff7f9073762308af3876777afc8507e3a8
  • SHA256:
    1d02060d7493d25e46e7cdf76fc05aa6c80493f40db75d48700f1eb17431191d
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 6/58
malicious
Score: 6/45
malicious

IPs

IP Country Detection
185.251.90.253
Russian Federation

Domains

Name IP Detection
pop.urlovedstuff.com
185.251.90.253
atl.bigbigpoppa.com
185.251.90.253

URLs

Name Detection
http://atl.bigbigpoppa.com/
http://pop.urlovedstuff.com/FYLjL0FWG/A8A_2FylIs_2BN6G7XZV/uXdtwH9ZjhHPJVfO4Ke/_2B2DA3Bxr3hT97jg6X5cf/HmT9c0wd9uTFE/mjIXEmZg/7w1x_2BJ7UrOUMBuwkzmQs_/2B_2B90mhB/GdhMF2xI5ZZQZOsRZ/w8ERaF_2FKjr/oJe_2BmPqxj/UioALST3UPW_2B/x25T0SA4ncGBrSmoWvhyD/GJA93v_2Bs5_2FOu/bRGYPwsER1HateV/PYXudbMJvsQ83oCtuH/3_2FsJC5W/WltZ3WhV77sZrxWGfR6s/bNzIeDiXMV8LnHFQlB1/BK37js8oH2L1YJRuiB3U5s/fOdLI1WLm_2Bt/WCukq3AFEXzr/kh2
http://atl.bigbigpoppa.com/R4Q64ljn5F0AeB0LyB/NuqzcVKz_/2FKpDeUm0fBCI1AQABSO/SrwJzbiGX2y5piswKvk/JCT
Click to see the 3 hidden entries
http://pop.bigbigpoppa.com/
http://pop.urlovedstuff.com/FYLjL0FWG/A8A_2FylIs_2BN6G7XZV/uXdtwH9ZjhHPJVfO4Ke/_2B2DA3Bxr3hT97jg6X5c
http://atl.bigbigpoppa.com/0su8VV6_2B3_2B/puf6UG3h9deC_2Ft6TxKM/_2FYbenbgPpDMagU/M3qvcdiaQn_2FfY/O5d

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Temp\fum.cpp
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Temp\adobe.url
MS Windows 95 Internet shortcut text (URL=<https://adobe.com/>), ASCII text, with CRLF line terminators
#