flash

COAU7229898130.xlsx

Status: finished
Submission Time: 15.09.2021 10:56:00
Malicious
Trojan
Exploiter
Evader
FormBook

Comments

Tags

  • Formbook
  • VelvetSweatshop
  • xlsx

Details

  • Analysis ID:
    483666
  • API (Web) ID:
    851227
  • Analysis Started:
    15.09.2021 11:12:10
  • Analysis Finished:
    15.09.2021 11:23:30
  • MD5:
    6440075843d5ae28dfccf6c9b09830c2
  • SHA1:
    fb5ea7b3defc0c15177429caaf45cdddd80cac7c
  • SHA256:
    22c19360c2a9ee4aaa12439aa1c3ace0ecc3287e0b61481f21619e4bb69f5157
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

System: Windows 7 x64 SP1 with Office 2010 SP1 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2)

malicious
100/100

malicious
21/59

malicious
15/44

malicious

IPs

IP Country Detection
103.133.106.199
Viet Nam
192.0.78.25
United States
154.91.1.126
Seychelles
Click to see the 2 hidden entries
47.91.170.222
United States
34.102.136.180
United States

Domains

Name IP Detection
www.thvsjwjvy.icu
47.91.170.222
absolutalibertas.com
192.0.78.25
tiaozhuan.zhuanye301.cn
154.91.1.126
Click to see the 6 hidden entries
www.359326.com
0.0.0.0
www.absolutalibertas.com
0.0.0.0
www.carlsbadbeachwear.com
0.0.0.0
www.crownfoamus.com
0.0.0.0
www.biotechfla.com
0.0.0.0
biotechfla.com
34.102.136.180

URLs

Name Detection
http://www.thvsjwjvy.icu/imi7/?8pGdYd7=JylIKvNk78hOFd+1TnqK+cq4SLeKYXMs9BOMQrcpY54MEXf7zcD8i4BM8h1sFc+7G7xGrw==&edrh=onDxIjzxvz
www.southerngiggle.com/imi7/
http://www.absolutalibertas.com/imi7/?8pGdYd7=v4OPSvG6dxhfjDw6HF6SnM8N8NyagVc5G1UDhWfJc2g0yYxGB1DXDxzdmmmhzDSPz7MbqA==&edrh=onDxIjzxvz
Click to see the 24 hidden entries
http://103.133.106.199/rbi/vbc.exe
http://www.windows.com/pctv.
http://investor.msn.com
http://www.msnbc.com/news/ticker.txt
http://www.biotechfla.com/imi7/?8pGdYd7=nnh6Wn4YtMnGcYcsMkPyBnKFlLVF5md1d8S2Q13SdHwJLrOdJeCsdNPQR8GZEfRmALPZ9A==&edrh=onDxIjzxvz
http://wellformedweb.org/CommentAPI/
http://www.iis.fhg.de/audioPA
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
http://www.hotmail.com/oe
http://treyresearch.net
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
http://java.sun.com
http://www.icra.org/vocabulary/.
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
http://www.piriform.com/ccleanerhttp://www.piriform.com/ccleanerv
http://www.day.com/dam/1.0
http://investor.msn.com/
http://www.piriform.com/ccleaner
http://computername/printers/printername/.printer
http://www.%s.comPA
http://www.autoitscript.com/autoit3
https://support.mozilla.org
http://servername/isapibackend.dll
https://www.absolutalibertas.com/imi7/?8pGdYd7=v4OPSvG6dxhfjDw6HF6SnM8N8NyagVc5G1UDhWfJc2g0yYxGB1DXD

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\vbc[1].exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Users\user\Desktop\~$COAU7229898130.xlsx
data
#
C:\Users\Public\vbc.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
Click to see the 24 hidden entries
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\13C76BCD.jpeg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 333x151, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\15B9D769.png
PNG image data, 566 x 429, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\2A862FF1.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\2F84C656.jpeg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 150x150, segment length 16, baseline, precision 8, 1275x1650, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\32D73CD4.png
PNG image data, 476 x 244, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\446CBE02.png
PNG image data, 613 x 80, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\450E8308.jpeg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 0x0, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=2], baseline, precision 8, 474x379, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\47DE8EC5.jpeg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 333x151, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\4E73753E.jpeg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 150x150, segment length 16, baseline, precision 8, 1275x1650, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\5B6C721B.png
PNG image data, 684 x 477, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\6FA1A827.jpeg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 191x263, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\800413FC.png
PNG image data, 476 x 244, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\AF2A565F.jpeg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 191x263, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\B69A6DE1.png
PNG image data, 566 x 429, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\B9553C63.png
PNG image data, 684 x 477, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\EBBD63B0.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\FD19276A.png
PNG image data, 613 x 80, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\FE9B8D60.jpeg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 0x0, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=2], baseline, precision 8, 474x379, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\mso5525.tmp
PC bitmap, Windows 3.x format, 20 x 20 x 24
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\mso5526.tmp
PC bitmap, Windows 3.x format, 20 x 20 x 24
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\mso5527.tmp
PC bitmap, Windows 3.x format, 20 x 20 x 24
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\msoF660.tmp
PC bitmap, Windows 3.x format, 20 x 20 x 24
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\msoF661.tmp
PC bitmap, Windows 3.x format, 20 x 20 x 24
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\msoF662.tmp
PC bitmap, Windows 3.x format, 20 x 20 x 24
#