top title background image
flash

Y7KrNvSxWx.dll

Status: finished
Submission Time: 2021-09-28 19:40:31 +02:00
Malicious
Trojan
Evader
Dridex

Comments

Tags

  • Dridex
  • exe

Details

  • Analysis ID:
    492554
  • API (Web) ID:
    860106
  • Analysis Started:
    2021-09-28 20:04:54 +02:00
  • Analysis Finished:
    2021-09-28 20:22:05 +02:00
  • MD5:
    ecdfff8b0ece2175cd699e690de1fcaf
  • SHA1:
    9359770d71e743832ca22597db917dfa817038b2
  • SHA256:
    dc684f824a7deaf6028f6266b48cc3f982a4931ce2db003f692a448da8e255e3
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 40/62
malicious
Score: 35/45
malicious

URLs

Name Detection
https://aka.ms/imfx4k
https://aka.ms/w5ryqn
https://aka.ms/w5ryqnhttps://aka.ms/imfx4kQUITTING
Click to see the 26 hidden entries
https://mixer.com/%ws
https://aka.ms/ifg0es
https://mixer.com/api/v1/chats/%.0f
https://MediaData.XboxLive.com/screenshots/Augment
https://mixer.com/api/v1/chats/%.0fhttps://mixer.com/api/v1/users/currentBEAM_IMAGEGamesGuide::BeamC
https://mixer.com/api/v1/channels/%ws
https://mixer.com/api/v1/types/lookup%wshttps://mixer.com/api/v1/channels/%wshttps://mixer.com/api/v
https://mixer.com/api/v1/channels/%d
https://www.xboxlive.com
https://MediaData.XboxLive.com/gameclips/Augment
https://www.xboxlive.comMBI_SSLhttps://profile.xboxlive.com/users/me/profile/settings?settings=GameD
http://schemas.micro
https://mixer.com/api/v1/oauth/xbl/login
https://MediaData.XboxLive.com/broadcasts/Augment
https://aka.ms/wk9ocd
https://MediaData.XboxLive.com/broadcasts/Augmenthttps://MediaData.XboxLive.com/screenshots/Augmenth
https://mixer.com/api/v1/types/lookup%ws
https://aka.ms/v5do45
https://mixer.com/%wsWindows.System.Launcher
https://mixer.com/api/v1/broadcasts/current
https://mixer.com/_latest/assets/emoticons/%ls.pngtitleIdaumIdkglIdprocessNamenametypeIdmultimedia
https://mixer.com/api/v1/users/current
https://mixer.com/_latest/assets/emoticons/%ls.png
https://aka.ms/imrx2o
https://profile.xboxlive.com/users/me/profile/settings?settings=GameDisplayPicRaw
http://www.autoitscript.com/autoit3/J

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\5JXP\VERSION.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\Uh9eo\FVEWIZ.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\mlAKVTuFf\DUser.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
Click to see the 22 hidden entries
C:\Users\user\AppData\Local\FvTQVxZ\UxTheme.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\IcLt\WTSAPI32.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\KAG\SYSDM.CPL
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\mFxP\XmlLite.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\KXZtu\SndVol.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\KXZtu\dwmapi.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\2oEy\TAPI32.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\UjbH0ZEv\SystemPropertiesPerformance.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\NakOm\VERSION.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\cZk0IMu\GamePanel.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\cZk0IMu\dwmapi.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\mFxP\upfc.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\mlAKVTuFf\bdeunlock.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3853321935-2125563209-4053062332-1002\21c8026919fd094ab07ec3c180a9f210_d06ed635-68f6-4e9a-955c-4899f5f57b9a
data
#
C:\Users\user\AppData\Local\UjbH0ZEv\SYSDM.CPL
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\Uh9eo\BitLockerWizardElev.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\NakOm\wscript.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\KAG\SystemPropertiesDataExecutionPrevention.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\IcLt\BdeUISrv.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\FvTQVxZ\FileHistory.exe
PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
#
C:\Users\user\AppData\Local\5JXP\iexpress.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\2oEy\tcmsetup.exe
PE32+ executable (GUI) x86-64, for MS Windows
#