top title background image
flash

T6zZFfRLqs.exe

Status: finished
Submission Time: 2021-09-27 18:30:25 +02:00
Malicious
Trojan
Spyware
Evader
Vidar

Comments

Tags

  • ArkeiStealer
  • exe

Details

  • Analysis ID:
    491601
  • API (Web) ID:
    859174
  • Analysis Started:
    2021-09-27 18:31:58 +02:00
  • Analysis Finished:
    2021-09-27 18:41:54 +02:00
  • MD5:
    5d5e83e151a99bed97e13839e8881cb5
  • SHA1:
    4f008fe578e0f32ed5dda8d30883a900630f1be4
  • SHA256:
    1a0f891e8d7d659d550b35c54f542180cd2629d3a62e35e695e43fd1f5dad0b3
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

IPs

IP Country Detection
88.99.75.82
Germany
23.88.105.196
United States

Domains

Name IP Detection
mas.to
88.99.75.82

URLs

Name Detection
http://23.88.105.196/nss3.dllO
http://23.88.105.196/mozglue.dll
http://23.88.105.196/softokn3.dll
Click to see the 38 hidden entries
https://mas.to/avatars/original/missing.png
http://crl.thawte.com/ThawteTimestampingCA.crl0
http://www.interoperabilitybridges.com/wmp-extension-for-chrome
http://23.88.105.196/vcruntime140.dll
https://mas.to/
https://media.mas.to/masto-public/site_uploads/files/000/000/003/original/elephant_ui_plane-e3f2d57c
http://23.88.105.196/
https://duckduckgo.com/chrome_newtabSQLite
https://mas.to/users/killern0/following
http://23.88.105.196/1008
http://service.real.cop
http://forms.real.com/real/realone/download.html?type=rpsp_us
https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
https://mas.to/users/killern0/followers
https://media.mas.to
https://mas.to/@killern0
http://download.divx.com/plp
https://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
http://23.88.105.196/freebl3.dll
http://www.mozilla.com/en-US/blocklist/
https://duckduckgo.com/ac/?q=
http://23.88.105.196/nss3.dll
https://support.google.com/chrome/?p=plugin_wmp
https://www.google.com/images/branding/product/ico/googleg_lodp.ico
https://support.google.com/chrome/?p=plugin
http://ocsp.thawte.com0
http://www.mozilla.com0
https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
https://duckduckgo.com/chrome_newtab
https://mas.to
https://search.yahoo.com/favicon.icohttps://search.yahoo.com/search
http://23.88.105.196/mozglue.dll$
https://mas.to/users/killern0
https://github.com/tootsuite/mastodon
https://joinmastodon.org/apps
http://23.88.105.196/msvcp140.dll
https://ac.ecosia.org/autocomplete?q=
https://support.google.com/chrome/?p=plugin_real

Dropped files

Name File Type Hashes Detection
C:\ProgramData\nss3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\msvcp140[1].dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\vcruntime140[1].dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
#
Click to see the 15 hidden entries
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\nss3[1].dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\freebl3[1].dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\softokn3[1].dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\mozglue[1].dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\ProgramData\vcruntime140.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
#
C:\ProgramData\softokn3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\ProgramData\K2UXIBO9ATIRONJRLKW8TZMZ5\d06ed635-68f6-4e9a-955c-4899f5f57b9a0565504142.zip
Zip archive data, at least v2.0 to extract
#
C:\ProgramData\msvcp140.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
#
C:\ProgramData\mozglue.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\ProgramData\freebl3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\ProgramData\K2UXIBO9ATIRONJRLKW8TZMZ5\files\temp
SQLite 3.x database, last written using SQLite version 3032001
#
C:\ProgramData\K2UXIBO9ATIRONJRLKW8TZMZ5\files\screenshot.jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 1280x1024, frames 3
#
C:\ProgramData\K2UXIBO9ATIRONJRLKW8TZMZ5\files\information.txt
ISO-8859 text, with very long lines, with CRLF line terminators
#
C:\ProgramData\K2UXIBO9ATIRONJRLKW8TZMZ5\files\Files\Default.zip
Zip archive data (empty)
#
C:\ProgramData\K2UXIBO9ATIRONJRLKW8TZMZ5\files\Cookies\Google Chrome_Default.txt
ASCII text, with CRLF line terminators
#