flash

Remittance_Advice_details001009142021.xlsx

Status: finished
Submission Time: 15.09.2021 11:04:39
Malicious
Trojan
Exploiter
Evader
FormBook

Comments

Tags

  • VelvetSweatshop
  • xlsx

Details

  • Analysis ID:
    483680
  • API (Web) ID:
    851233
  • Analysis Started:
    15.09.2021 11:28:41
  • Analysis Finished:
    15.09.2021 11:41:20
  • MD5:
    849137c07d96b63b89b0fe9fc240751e
  • SHA1:
    21f9985416c2bfc51a88615f5806916fa1165502
  • SHA256:
    594eeeb07a9f81d9a2e3718fb25ca290ca86a45990a9ca89799dcbdcf114779c
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

malicious

System: Windows 7 x64 SP1 with Office 2010 SP1 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2)

malicious
100/100

malicious
18/44

malicious

IPs

IP Country Detection
52.58.78.16
United States
209.99.64.51
United States
169.62.91.142
United States
Click to see the 2 hidden entries
50.87.248.20
United States
107.173.219.122
United States

Domains

Name IP Detection
matcitekids.com
50.87.248.20
www.onedadtwodudes.com
209.99.64.51
www.doityourselfism.com
169.62.91.142
Click to see the 4 hidden entries
www.ecofingers.com
52.58.78.16
www.matcitekids.com
0.0.0.0
www.garimpeirastore.online
0.0.0.0
www.builtbydawn.com
0.0.0.0

URLs

Name Detection
http://www.ecofingers.com/dy8g/?illD=X9Az7RtkaU81d6o9S6tJRjQeFUHqBPh6fbjII6Bm04v0rRN3gQJahLAd3CrM9JEnxgRa3A==&7nh=0br0WzXxgHiLa
http://107.173.219.122/files/loader1.exe
http://www.matcitekids.com/dy8g/?illD=dI9eO6GBnSulhV6EbBGZI9CJMc/scmM0Fshd6X+e3vq0VlxBF2NWOUbA55lfRDBFVPtqQQ==&7nh=0br0WzXxgHiLa
Click to see the 55 hidden entries
www.extinctionbrews.com/dy8g/
http://www.doityourselfism.com/dy8g/?illD=Y4JBfBjEKLG3bE/nPu+ARLK4ZQab+dap1kyoobOuuyzzJOKZWwpYr6zx24KPHwTC7q0HDg==&7nh=0br0WzXxgHiLa
http://www.msnbc.com/news/ticker.txt
http://i3.cdn-image.com/__media__/fonts/ubuntu-b/ubuntu-b.eot
http://www.iis.fhg.de/audioPA
http://i3.cdn-image.com/__media__/fonts/ubuntu-b/ubuntu-b.otf
http://i3.cdn-image.com/__media__/pics/12471/kwbg.jpg)
http://i3.cdn-image.com/__media__/fonts/ubuntu-r/ubuntu-r.ttf
http://treyresearch.net
http://www.onedadtwodudes.com/display.cfm
http://i3.cdn-image.com/__media__/pics/12471/arrow.png)
http://www.onedadtwodudes.com/Best_Penny_Stocks.cfm?fp=qmv9xFBTKEA6LAcskD2eWPFr51ekSLBBN0JW8jVu%2FUU
http://www.icra.org/vocabulary/.
http://www.onedadtwodudes.com/find_a_tutor.cfm?fp=qmv9xFBTKEA6LAcskD2eWPFr51ekSLBBN0JW8jVu%2FUUZJTLt
http://i3.cdn-image.com/__media__/pics/12471/libgh.png)
http://i3.cdn-image.com/__media__/pics/12471/logo.png)
http://investor.msn.com/
http://computername/printers/printername/.printer
http://www.%s.comPA
http://www.autoitscript.com/autoit3
http://i3.cdn-image.com/__media__/fonts/ubuntu-b/ubuntu-b.eot?#iefix
http://www.onedadtwodudes.com/Credit_Card_Application.cfm?fp=qmv9xFBTKEA6LAcskD2eWPFr51ekSLBBN0JW8jV
http://servername/isapibackend.dll
http://www.onedadtwodudes.com/sk-logabpstatus.php?a=VWFRUU1lL1pRcXBSSlh6S0wrZnpqVkRFSTlReFR5VHJjUENN
http://www.windows.com/pctv.
http://investor.msn.com
http://i3.cdn-image.com/__media__/pics/12471/bodybg.png)
http://i3.cdn-image.com/__media__/fonts/ubuntu-r/ubuntu-r.eot
http://wellformedweb.org/CommentAPI/
http://www.onedadtwodudes.com/Work_from_Home.cfm?fp=qmv9xFBTKEA6LAcskD2eWPFr51ekSLBBN0JW8jVu%2FUUZJT
http://www.onedadtwodudes.com/Best_Mortgage_Rates.cfm?fp=qmv9xFBTKEA6LAcskD2eWPFr51ekSLBBN0JW8jVu%2F
http://i3.cdn-image.com/__media__/pics/12471/search-icon.png)
http://www.onedadtwodudes.com/Free_Credit_Report.cfm?fp=qmv9xFBTKEA6LAcskD2eWPFr51ekSLBBN0JW8jVu%2FU
http://i3.cdn-image.com/__media__/fonts/ubuntu-b/ubuntu-b.ttf
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
http://www.hotmail.com/oe
http://www.onedadtwodudes.com/Anti_Wrinkle_Creams.cfm?fp=qmv9xFBTKEA6LAcskD2eWPFr51ekSLBBN0JW8jVu%2F
http://i3.cdn-image.com/__media__/fonts/ubuntu-r/ubuntu-r.eot?#iefix
http://i3.cdn-image.com/__media__/fonts/ubuntu-r/ubuntu-r.otf
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
http://java.sun.com
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
http://www.piriform.com/ccleanerhttp://www.piriform.com/ccleanerv
http://i3.cdn-image.com/__media__/pics/12471/libg.png)
http://www.day.com/dam/1.0
http://i3.cdn-image.com/__media__/fonts/ubuntu-b/ubuntu-b.woff
http://www.piriform.com/ccleaner
http://i3.cdn-image.com/__media__/fonts/ubuntu-b/ubuntu-b.svg#ubuntu-b
http://i3.cdn-image.com/__media__/fonts/ubuntu-r/ubuntu-r.svg#ubuntu-r
http://www.onedadtwodudes.com/px.js?ch=2
https://support.mozilla.org
http://i3.cdn-image.com/__media__/fonts/ubuntu-r/ubuntu-r.woff
http://i3.cdn-image.com/__media__/js/min.js?v2.2
http://i3.cdn-image.com/__media__/fonts/ubuntu-r/ubuntu-r.woff2
http://i3.cdn-image.com/__media__/fonts/ubuntu-b/ubuntu-b.woff2

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\loader1[1].exe
PE32 executable (console) Intel 80386, for MS Windows
#
C:\Users\user\Desktop\~$Remittance_Advice_details001009142021.xlsx
data
#
C:\Users\Public\vbc.exe
PE32 executable (console) Intel 80386, for MS Windows
#
Click to see the 18 hidden entries
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\266FC07D.png
PNG image data, 566 x 429, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\2A86AD78.jpeg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 333x151, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\33990A46.png
PNG image data, 613 x 80, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\3E0D1557.png
PNG image data, 684 x 477, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\3EA6FB2E.png
PNG image data, 613 x 80, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\4693945A.jpeg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 150x150, segment length 16, baseline, precision 8, 1275x1650, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\5824BFDB.jpeg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 191x263, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\72A9BF6C.jpeg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 0x0, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=2], baseline, precision 8, 474x379, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\99225644.jpeg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 0x0, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=2], baseline, precision 8, 474x379, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\99B3698F.png
PNG image data, 684 x 477, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\A0FA92C2.jpeg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 150x150, segment length 16, baseline, precision 8, 1275x1650, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\A36C1A1.png
PNG image data, 476 x 244, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\AA6CA394.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\C2AC9F19.png
PNG image data, 476 x 244, 8-bit/color RGB, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\DAB20020.jpeg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 333x151, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\DF646493.jpeg
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 191x263, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\E1C17975.png
PNG image data, 566 x 429, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\EA254685.emf
Windows Enhanced Metafile (EMF) image data version 0x10000
#