top title background image
flash

cYKFZFK0Rg.exe

Status: finished
Submission Time: 2021-09-27 18:27:32 +02:00
Malicious
Trojan
Spyware
Vidar

Comments

Tags

  • ArkeiStealer
  • exe

Details

  • Analysis ID:
    491602
  • API (Web) ID:
    859169
  • Analysis Started:
    2021-09-27 18:32:41 +02:00
  • Analysis Finished:
    2021-09-27 18:43:48 +02:00
  • MD5:
    e9441b756f99ee3adf804214119c1fa1
  • SHA1:
    8fe649e6bc868401ba2a3b9bf345fc76692f53d4
  • SHA256:
    f811cfc4610369aee904c7c14d67b944f7b6f6fe0e26d7220385295c726272cd
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 17/68

IPs

IP Country Detection
88.99.75.82
Germany
23.88.105.196
United States

Domains

Name IP Detection
mas.to
88.99.75.82

URLs

Name Detection
http://23.88.105.196/softokn3.dll196/freebl3.dll
http://23.88.105.196/msvcp140.dll
https://ac.ecosia.org/autocomplete?q=
Click to see the 38 hidden entries
http://23.88.105.196/vcruntime140.dllgc
http://23.88.105.196/mozglue.dll
http://23.88.105.196/softokn3.dll
http://23.88.105.196/freebl3.dllQu
http://23.88.105.196/GN46WT4N9GWA0LWA3Ur
http://crl.thawte.com/ThawteTimestampingCA.crl0
http://23.88.105.196/msvcp140.dllb3
http://23.88.105.196/vcruntime140.dll
https://mas.to/.well-known/webfinger?resource=acct%3Akillern0%40mas.to
http://23.88.105.196/
https://duckduckgo.com/chrome_newtabSQLite
http://23.88.105.196/vcruntime140.dll~p
https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
http://23.88.105.196/mozglue.dll=u
http://23.88.105.196/msvcp140.dllu
https://media.mas.to
https://mas.to/@killern0
https://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
http://23.88.105.196/msvcp140.dllQ)G
http://www.mozilla.com/en-US/blocklist/
https://duckduckgo.com/ac/?q=
http://23.88.105.196/nss3.dll
https://www.google.com/images/branding/product/ico/googleg_lodp.ico
http://23.88.105.196/mozglue.dll4
http://microsoft.co
http://23.88.105.196/1013
http://ocsp.thawte.com0
http://www.mozilla.com0
https://duckduckgo.com/chrome_newtab
https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
http://23.88.105.196/freebl3.dll
https://mas.to
https://search.yahoo.com/favicon.icohttps://search.yahoo.com/search
http://23.88.105.196/mozglue.dllyuG
https://mas.to/users/killern0
https://mas.to;
http://23.88.105.196/mozglue.dllgGu
http://crl.m&

Dropped files

Name File Type Hashes Detection
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_cYKFZFK0Rg.exe_29cd3e3721852926c2b0fb646bb936c1c181aad_ce5bec0c_0a40b508\Report.wer
Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_cYKFZFK0Rg.exe_29cd3e3721852926c2b0fb646bb936c1c181aad_ce5bec0c_10e4ecb2\Report.wer
Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_cYKFZFK0Rg.exe_29cd3e3721852926c2b0fb646bb936c1c181aad_ce5bec0c_183123c0\Report.wer
Little-endian UTF-16 Unicode text, with CRLF line terminators
#
Click to see the 41 hidden entries
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_cYKFZFK0Rg.exe_29cd3e3721852926c2b0fb646bb936c1c181aad_ce5bec0c_1879b189\Report.wer
Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_cYKFZFK0Rg.exe_29cd3e3721852926c2b0fb646bb936c1c181aad_ce5bec0c_19655c54\Report.wer
Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_cYKFZFK0Rg.exe_73f2c6c7ef85f4706ada89c4403a28b0925fe47_ce5bec0c_04e626d8\Report.wer
Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0MX4YUS9\softokn3[1].dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERAE71.tmp.WERInternalMetadata.xml
XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERB066.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERB12.tmp.dmp
Mini DuMP crash report, 15 streams, Tue Sep 28 01:35:25 2021, 0x1205a4 type
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERDEF6.tmp.dmp
Mini DuMP crash report, 14 streams, Tue Sep 28 01:34:05 2021, 0x1205a4 type
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERE679.tmp.WERInternalMetadata.xml
XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERE8FB.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\ProgramData\freebl3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\ProgramData\mozglue.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\ProgramData\msvcp140.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
#
C:\ProgramData\nss3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\ProgramData\softokn3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\ProgramData\vcruntime140.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER9C6B.tmp.WERInternalMetadata.xml
XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2K7JPOQS\mozglue[1].dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2K7JPOQS\vcruntime140[1].dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6M6D1PMD\freebl3[1].dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\6M6D1PMD\nss3[1].dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\VAHFWDJC\msvcp140[1].dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER3FD3.tmp.dmp
Mini DuMP crash report, 14 streams, Tue Sep 28 01:34:32 2021, 0x1205a4 type
#
C:\ProgramData\IYZJ2SYGN46WT4N9GWA0LWA3U\files\Cookies\Google Chrome_Default.txt
ASCII text, with CRLF line terminators
#
C:\ProgramData\IYZJ2SYGN46WT4N9GWA0LWA3U\files\Files\Default.zip
Zip archive data (empty)
#
C:\ProgramData\IYZJ2SYGN46WT4N9GWA0LWA3U\files\information.txt
ISO-8859 text, with very long lines, with CRLF line terminators
#
C:\ProgramData\IYZJ2SYGN46WT4N9GWA0LWA3U\files\screenshot.jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 1280x1024, frames 3
#
C:\ProgramData\IYZJ2SYGN46WT4N9GWA0LWA3U\files\temp
SQLite 3.x database, last written using SQLite version 3032001
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER1C5E.tmp.WERInternalMetadata.xml
XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER1DA1.tmp.WERInternalMetadata.xml
XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER1F7C.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER2256.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERA894.tmp.dmp
Mini DuMP crash report, 14 streams, Tue Sep 28 01:33:51 2021, 0x1205a4 type
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER4E94.tmp.dmp
Mini DuMP crash report, 15 streams, Tue Sep 28 01:35:43 2021, 0x1205a4 type
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER4F07.tmp.WERInternalMetadata.xml
XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER532E.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER68C4.tmp.WERInternalMetadata.xml
XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER8AA7.tmp.dmp
Mini DuMP crash report, 14 streams, Tue Sep 28 01:34:52 2021, 0x1205a4 type
#
C:\ProgramData\IYZJ2SYGN46WT4N9GWA0LWA3U\d06ed635-68f6-4e9a-955c-4899f5f57b9a4881876996.zip
Zip archive data, at least v2.0 to extract
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERA2D.tmp.dmp
Mini DuMP crash report, 14 streams, Tue Sep 28 01:34:19 2021, 0x1205a4 type
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERA2E5.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
#