top title background image
flash

1zdJLxxTnh.dll

Status: finished
Submission Time: 2021-09-29 00:55:17 +02:00
Malicious
Trojan
Evader
Dridex

Comments

Tags

  • Dridex
  • exe

Details

  • Analysis ID:
    492776
  • API (Web) ID:
    860345
  • Analysis Started:
    2021-09-29 01:05:07 +02:00
  • Analysis Finished:
    2021-09-29 01:19:35 +02:00
  • MD5:
    784adf3295b7eafe53aa80da302b1b5d
  • SHA1:
    c79da77a4d00ec47594e007f9a174de43b5028d3
  • SHA256:
    69af86da86fc2f9639f010e0b729b1c2ce33a272d199aeedc4c873d98a2b83b4
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 96
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 22/35
malicious
Score: 35/45
malicious

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\94LPZAU0\WINMM.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\XVzc21m9h\DUI70.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\cp4nWp\VERSION.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
Click to see the 12 hidden entries
C:\Users\user\AppData\Local\hJiut\MFC42u.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\nPqx0Ph\DUser.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\94LPZAU0\irftp.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\XVzc21m9h\CameraSettingsUIHost.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\buYWmbl3\DUI70.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\buYWmbl3\WindowsActionDialog.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\cp4nWp\PresentationHost.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\fk8bXjSn\DUI70.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\fk8bXjSn\ProximityUxHost.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\hJiut\irftp.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\nPqx0Ph\sessionmsg.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3853321935-2125563209-4053062332-1002\414045e2d09286d5db2581e0d955d358_d06ed635-68f6-4e9a-955c-4899f5f57b9a
data
#