top title background image
flash

ENTREGA DE DOCUMENTOS DHL _ 27-09-21,pdf.exe

Status: finished
Submission Time: 2021-09-27 20:34:19 +02:00
Malicious
Trojan
Spyware
Evader
Remcos

Comments

Tags

  • DHL
  • exe
  • geo
  • PRT
  • RAT
  • RemcosRAT

Details

  • Analysis ID:
    491719
  • API (Web) ID:
    859288
  • Analysis Started:
    2021-09-27 20:38:59 +02:00
  • Analysis Finished:
    2021-09-27 20:54:43 +02:00
  • MD5:
    3808d4a11cbee20896cca28f9a3bcb9b
  • SHA1:
    b3a533d6e00ace2ec0612c9af66c6dd69c5180b3
  • SHA256:
    53c2e53d33f80e88b16cce06621f99680e0e5f387315cb81af97cee58080165a
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 18/68
malicious
Score: 11/45

IPs

IP Country Detection
185.140.53.15
Sweden

Domains

Name IP Detection
ongod4ever.ddns.net
185.140.53.15
onedrive.live.com
0.0.0.0
bl30uw.sn.files.1drv.com
0.0.0.0

URLs

Name Detection
ongod4ever.ddns.net
https://bl30uw.sn.files.1drv.com/y4maOmpRLgEZgKpnLv-hczrMb96VqtMQDZd-m0g51QRpK-v8c65WYNUi2NOLDdGNQiU
https://bl30uw.sn.files.1drv.com/y4msI7_EyjC8cs97rdyt7ReCTl2WoedGiqx9hVOiugfpodFj4cXgoX5lAQfrGe41zrt
Click to see the 2 hidden entries
https://onedrive.live.com/download?cid=97429F42E815B766&resid=97429F42E815B766%21166&authkey=AFRFbbm
https://bl30uw.sn.files.1drv.com/y4mGst0byrg6Ub0CK8iKHaximJI4M7D1uUmqxfl02ZpIfKXbkyeYXQLL6P2J6UxS4Yz

Dropped files

Name File Type Hashes Detection
C:\Users\Public\Libraries\Iqzenco\Iqzenco.exe
PE32 executable (GUI) Intel 80386, for MS Windows
#
C:\Users\Public\KDECO.bat
ASCII text, with no line terminators
#
C:\Users\Public\Libraries\ocnezqI.url
MS Windows 95 Internet shortcut text (URL=<file:"C:\\Users\\Public\\Libraries\\Iqzenco\\Iqzenco.exe">), ASCII text, with CRLF line terminators
#
Click to see the 7 hidden entries
C:\Users\Public\Trast.bat
ASCII text, with no line terminators
#
C:\Users\Public\UKO.bat
ASCII text, with CRLF line terminators
#
C:\Users\Public\nest
ASCII text, with CRLF line terminators
#
C:\Users\Public\nest.bat
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\Iqzencolmjnhoxprppdkgkfyidrxfas[1]
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\Iqzencolmjnhoxprppdkgkfyidrxfas[1]
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\Iqzencolmjnhoxprppdkgkfyidrxfas[1]
data
#