top title background image
flash

P7n0h6OhYp.dll

Status: finished
Submission Time: 2021-09-28 17:35:33 +02:00
Malicious
Trojan
Evader
Dridex

Comments

Tags

  • Dridex
  • exe

Details

  • Analysis ID:
    492431
  • API (Web) ID:
    859997
  • Analysis Started:
    2021-09-28 17:44:10 +02:00
  • Analysis Finished:
    2021-09-28 18:02:17 +02:00
  • MD5:
    718a7d9b1fe55a72cfa586e869236df8
  • SHA1:
    5d870aeb7951ab6af0900ba837924f79e3716936
  • SHA256:
    d485423afb5929de201a0fee5476c8b6d7d1a1868b537d7730db9b3e67d6a222
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 92
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 44/67
malicious
Score: 21/35
malicious
Score: 34/45
malicious

URLs

Name Detection
https://aka.ms/imfx4k
https://aka.ms/w5ryqn
https://aka.ms/w5ryqnhttps://aka.ms/imfx4kQUITTING
Click to see the 24 hidden entries
https://mixer.com/%ws
https://aka.ms/ifg0es
https://mixer.com/api/v1/chats/%.0f
https://MediaData.XboxLive.com/screenshots/Augment
https://mixer.com/api/v1/chats/%.0fhttps://mixer.com/api/v1/users/currentBEAM_IMAGEGamesGuide::BeamC
https://mixer.com/api/v1/channels/%ws
https://mixer.com/api/v1/types/lookup%wshttps://mixer.com/api/v1/channels/%wshttps://mixer.com/api/v
https://mixer.com/api/v1/channels/%d
https://www.xboxlive.com
https://MediaData.XboxLive.com/gameclips/Augment
https://www.xboxlive.comMBI_SSLhttps://profile.xboxlive.com/users/me/profile/settings?settings=GameD
https://mixer.com/api/v1/oauth/xbl/login
https://MediaData.XboxLive.com/broadcasts/Augment
https://aka.ms/wk9ocd
https://MediaData.XboxLive.com/broadcasts/Augmenthttps://MediaData.XboxLive.com/screenshots/Augmenth
https://mixer.com/api/v1/types/lookup%ws
https://aka.ms/v5do45
https://mixer.com/%wsWindows.System.Launcher
https://mixer.com/api/v1/broadcasts/current
https://mixer.com/_latest/assets/emoticons/%ls.pngtitleIdaumIdkglIdprocessNamenametypeIdmultimedia
https://mixer.com/api/v1/users/current
https://mixer.com/_latest/assets/emoticons/%ls.png
https://aka.ms/imrx2o
https://profile.xboxlive.com/users/me/profile/settings?settings=GameDisplayPicRaw

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\1wgM9CYx\WINSTA.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\pEPyA\MFPlat.DLL
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\ocY6\WINMM.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
Click to see the 20 hidden entries
C:\Users\user\AppData\Local\j3KBEEMS\MFC42u.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\aDD0Ov\dxgi.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\Rn1XW4tG\UxTheme.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\NNw\DUser.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\JrFH9qPBX\DUI70.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\A7mgbJ\dpx.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\4PmTNr\SYSDM.CPL
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\JrFH9qPBX\WindowsActionDialog.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\NNw\sessionmsg.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\Rn1XW4tG\GamePanel.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\A7mgbJ\lpksetup.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\aDD0Ov\dxgiadaptercache.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\4PmTNr\SystemPropertiesComputerName.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\j3KBEEMS\irftp.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\ocY6\Narrator.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\1wgM9CYx\RdpSa.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\pEPyA\mfpmp.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\tiy3x\DUI70.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\tiy3x\SystemSettingsRemoveDevice.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3853321935-2125563209-4053062332-1002\89dad5d484a9f889a3a8dfca823edc3e_d06ed635-68f6-4e9a-955c-4899f5f57b9a
data
#