top title background image
flash

PSnPApRPsG.dll

Status: finished
Submission Time: 2021-09-28 22:16:23 +02:00
Malicious
Trojan
Evader
Dridex

Comments

Tags

  • Dridex
  • exe

Details

  • Analysis ID:
    492695
  • API (Web) ID:
    860237
  • Analysis Started:
    2021-09-28 23:00:25 +02:00
  • Analysis Finished:
    2021-09-28 23:17:49 +02:00
  • MD5:
    ed37656551984cf5c1196d88c282e4aa
  • SHA1:
    1475e0b8fd14a3a13160dc8ab28d228f3027c8b9
  • SHA256:
    4bbd6db4f6bdad3bbcb134c53fb0886197c2880f9e9dd7a630707dbf333623f4
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 36/45
malicious

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\TQbOBk\DUser.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\br5u0t\WINMM.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\a5Q9CELTE\VERSION.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
Click to see the 24 hidden entries
C:\Users\user\AppData\Local\YaR\MFC42u.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\hUhx9Ta\WINSTA.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\Tp5KLY\XmlLite.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\nmYaGulOu\UxTheme.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\PVSXo\DUI70.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\HtmF\credui.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\72PXeqK\TAPI32.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\nmYaGulOu\msdt.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3853321935-2125563209-4053062332-1002\bc49718863ee53e026d805ec372039e9_d06ed635-68f6-4e9a-955c-4899f5f57b9a
data
#
C:\Users\user\AppData\Local\ifnj9zHVv\psr.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\yC4r\DUI70.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\ifnj9zHVv\VERSION.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\yC4r\ProximityUxHost.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\hUhx9Ta\RdpSaUacHelper.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\br5u0t\PresentationSettings.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\a5Q9CELTE\ie4uinit.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\YaR\DevicePairingWizard.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\Tp5KLY\psr.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\TQbOBk\EaseOfAccessDialog.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\RjGeORx\bdechangepin.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\RjGeORx\DUI70.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\PVSXo\wlrmdr.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\HtmF\perfmon.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\72PXeqK\tcmsetup.exe
PE32+ executable (GUI) x86-64, for MS Windows
#