top title background image
flash

RWOEFXaFFI.exe

Status: finished
Submission Time: 2021-09-25 10:06:08 +02:00
Malicious
Trojan
Spyware
Vidar

Comments

Tags

  • exe

Details

  • Analysis ID:
    490254
  • API (Web) ID:
    857823
  • Analysis Started:
    2021-09-25 10:12:25 +02:00
  • Analysis Finished:
    2021-09-25 10:24:58 +02:00
  • MD5:
    2433260019e2886c8fc0969cb076cc49
  • SHA1:
    cebc35a8212c2dc52d3e4bebd6c90d4ac868898c
  • SHA256:
    d81d318002da9fa030f20bfa0615bb895768e83a8a45ba3299ae85ded1c06537
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 12/89

IPs

IP Country Detection
88.99.75.82
Germany
159.69.203.58
Germany

Domains

Name IP Detection
mas.to
88.99.75.82

URLs

Name Detection
http://159.69.203.58/mozglue.dll
http://159.69.203.58/mozglue.dllld
https://duckduckgo.com/chrome_newtabSQLite
Click to see the 31 hidden entries
http://159.69.203.58/softokn3.dll6x
https://mas.to/.well-known/webfinger?resource=acct%3Akillern0%40mas.to
https://ac.ecosia.org/autocomplete?q=
http://159.69.203.58/nss3.dll
http://crl.thawte.com/ThawteTimestampingCA.crl0
http://159.69.203.58/
http://159.69.203.58/softokn3.dll
https://mas.to/
http://159.69.203.58/freebl3.dllIf
http://159.69.203.58/vcruntime140.dll
https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
http://159.69.203.58/freebl3.dll
https://media.mas.to
https://mas.to/@killern0
https://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
http://159.69.203.58/freebl3.dlln
https://duckduckgo.com/chrome_newtab
https://mas.to;
https://mas.to/users/killern0
http://159.69.203.58/msvcp140.dll
http://159.69.203.58/1013
https://search.yahoo.com/favicon.icohttps://search.yahoo.com/search
https://mas.to
https://mas.to/i
https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
https://mas.to/#
http://www.mozilla.com0
http://ocsp.thawte.com0
https://www.google.com/images/branding/product/ico/googleg_lodp.ico
https://duckduckgo.com/ac/?q=
http://www.mozilla.com/en-US/blocklist/

Dropped files

Name File Type Hashes Detection
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_RWOEFXaFFI.exe_6cefe71ff03cfde3fbd68cd484ef762fd7dd9a58_0cfb876a_1be85fd1\Report.wer
Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_RWOEFXaFFI.exe_5b163b1e1269a8cfb252ea938b9eeef5b9c141b_0cfb876a_1380997f\Report.wer
Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_RWOEFXaFFI.exe_6cefe71ff03cfde3fbd68cd484ef762fd7dd9a58_0cfb876a_007f3f6d\Report.wer
Little-endian UTF-16 Unicode text, with CRLF line terminators
#
Click to see the 43 hidden entries
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_RWOEFXaFFI.exe_6cefe71ff03cfde3fbd68cd484ef762fd7dd9a58_0cfb876a_0593fe29\Report.wer
Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_RWOEFXaFFI.exe_6cefe71ff03cfde3fbd68cd484ef762fd7dd9a58_0cfb876a_18ffb6a0\Report.wer
Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_RWOEFXaFFI.exe_6cefe71ff03cfde3fbd68cd484ef762fd7dd9a58_0cfb876a_1a770d31\Report.wer
Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_RWOEFXaFFI.exe_6cefe71ff03cfde3fbd68cd484ef762fd7dd9a58_0cfb876a_1b1f7c18\Report.wer
Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\mozglue.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0MX4YUS9\softokn3[1].dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\ProgramData\freebl3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERF8EB.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WEREC67.tmp.WERInternalMetadata.xml
XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERD9A9.tmp.dmp
Mini DuMP crash report, 15 streams, Sat Sep 25 17:14:34 2021, 0x1205a4 type
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERB2E9.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERAFCB.tmp.WERInternalMetadata.xml
XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER9C42.tmp.dmp
Mini DuMP crash report, 15 streams, Sat Sep 25 17:14:18 2021, 0x1205a4 type
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER950C.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\ProgramData\msvcp140.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
#
C:\ProgramData\nss3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\ProgramData\softokn3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\ProgramData\vcruntime140.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER76DA.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2K7JPOQS\mozglue[1].dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2K7JPOQS\vcruntime140[1].dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6M6D1PMD\freebl3[1].dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6M6D1PMD\nss3[1].dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VAHFWDJC\msvcp140[1].dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER51.tmp.dmp
Mini DuMP crash report, 15 streams, Sat Sep 25 17:13:35 2021, 0x1205a4 type
#
C:\ProgramData\IKRLW9DB6P2T6YWMJJXWSNDEO\files\Cookies\Google Chrome_Default.txt
ASCII text, with CRLF line terminators
#
C:\ProgramData\IKRLW9DB6P2T6YWMJJXWSNDEO\files\Files\Default.zip
Zip archive data (empty)
#
C:\ProgramData\IKRLW9DB6P2T6YWMJJXWSNDEO\files\information.txt
ISO-8859 text, with very long lines, with CRLF line terminators
#
C:\ProgramData\IKRLW9DB6P2T6YWMJJXWSNDEO\files\screenshot.jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 1280x1024, frames 3
#
C:\ProgramData\IKRLW9DB6P2T6YWMJJXWSNDEO\files\temp
SQLite 3.x database, last written using SQLite version 3032001
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER2F6F.tmp.dmp
Mini DuMP crash report, 15 streams, Sat Sep 25 17:13:48 2021, 0x1205a4 type
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER383A.tmp.WERInternalMetadata.xml
XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER3B87.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER46FA.tmp.dmp
Mini DuMP crash report, 15 streams, Sat Sep 25 17:15:01 2021, 0x1205a4 type
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER91D.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER5766.tmp.WERInternalMetadata.xml
XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER5B7E.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER5DA3.tmp.dmp
Mini DuMP crash report, 15 streams, Sat Sep 25 17:14:03 2021, 0x1205a4 type
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER738E.tmp.WERInternalMetadata.xml
XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER756.tmp.WERInternalMetadata.xml
XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\IKRLW9DB6P2T6YWMJJXWSNDEO\d06ed635-68f6-4e9a-955c-4899f5f57b9a3887495708.zip
Zip archive data, at least v2.0 to extract
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER7889.tmp.dmp
Mini DuMP crash report, 15 streams, Sat Sep 25 17:15:16 2021, 0x1205a4 type
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER90F4.tmp.WERInternalMetadata.xml
XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
#