top title background image
flash

K7dGM0P0yz.dll

Status: finished
Submission Time: 2021-09-28 17:44:17 +02:00
Malicious
Trojan
Evader
Dridex

Comments

Tags

  • Dridex
  • exe

Details

  • Analysis ID:
    492437
  • API (Web) ID:
    860005
  • Analysis Started:
    2021-09-28 17:50:05 +02:00
  • Analysis Finished:
    2021-09-28 18:08:30 +02:00
  • MD5:
    2955d4759afce09a41c1df5b108f0287
  • SHA1:
    11e277c3c987b4119909dd099a5f901e074698e3
  • SHA256:
    97058d4465daae2446886d425d9a8215df518e6845e8a4bedb30acea4e8d2070
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 96
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 41/66
malicious
Score: 23/35
malicious
Score: 35/45
malicious

URLs

Name Detection
https://aka.ms/imfx4k
https://aka.ms/w5ryqn
https://aka.ms/w5ryqnhttps://aka.ms/imfx4kQUITTING
Click to see the 24 hidden entries
https://mixer.com/%ws
https://aka.ms/ifg0es
https://mixer.com/api/v1/chats/%.0f
https://MediaData.XboxLive.com/screenshots/Augment
https://mixer.com/api/v1/chats/%.0fhttps://mixer.com/api/v1/users/currentBEAM_IMAGEGamesGuide::BeamC
https://mixer.com/api/v1/channels/%ws
https://mixer.com/api/v1/types/lookup%wshttps://mixer.com/api/v1/channels/%wshttps://mixer.com/api/v
https://mixer.com/api/v1/channels/%d
https://www.xboxlive.com
https://MediaData.XboxLive.com/gameclips/Augment
https://www.xboxlive.comMBI_SSLhttps://profile.xboxlive.com/users/me/profile/settings?settings=GameD
https://mixer.com/api/v1/oauth/xbl/login
https://MediaData.XboxLive.com/broadcasts/Augment
https://aka.ms/wk9ocd
https://MediaData.XboxLive.com/broadcasts/Augmenthttps://MediaData.XboxLive.com/screenshots/Augmenth
https://mixer.com/api/v1/types/lookup%ws
https://aka.ms/v5do45
https://mixer.com/%wsWindows.System.Launcher
https://mixer.com/api/v1/broadcasts/current
https://mixer.com/_latest/assets/emoticons/%ls.pngtitleIdaumIdkglIdprocessNamenametypeIdmultimedia
https://mixer.com/api/v1/users/current
https://mixer.com/_latest/assets/emoticons/%ls.png
https://aka.ms/imrx2o
https://profile.xboxlive.com/users/me/profile/settings?settings=GameDisplayPicRaw

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\5HTUnLvL\DUI70.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\vh7jtu\WINSTA.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\Fox\dxva2.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
Click to see the 22 hidden entries
C:\Users\user\AppData\Local\I0o\dwmapi.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\1DwRown1P\VERSION.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\exotc\DUI70.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3853321935-2125563209-4053062332-1002\bc49718863ee53e026d805ec372039e9_d06ed635-68f6-4e9a-955c-4899f5f57b9a
data
#
C:\Users\user\AppData\Local\vh7jtu\RdpSaUacHelper.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\rdM8VQT\dpapimig.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\rdM8VQT\DUI70.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\qe7nfWB\systemreset.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\qe7nfWB\VERSION.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\hJetkV\rdpinit.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\hJetkV\dwmapi.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\hIiDwtvg\dwmapi.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\hIiDwtvg\GamePanel.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\exotc\osk.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\eF0\VERSION.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\eF0\AgentService.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\YRu8\wlrmdr.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\YRu8\DUI70.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\I0o\rdpclip.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\Fox\dccw.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\5HTUnLvL\bdechangepin.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\1DwRown1P\wextract.exe
PE32+ executable (GUI) x86-64, for MS Windows
#