flash

Wellis Inquiry.exe

Status: finished
Submission Time: 14.10.2021 07:27:30
Malicious
Trojan
Evader
FormBook

Comments

Tags

  • exe

Details

  • Analysis ID:
    502627
  • API (Web) ID:
    870200
  • Analysis Started:
    14.10.2021 07:27:31
  • Analysis Finished:
    14.10.2021 07:37:27
  • MD5:
    c357a8010e661a49df2e813bd22590b6
  • SHA1:
    08ecd005e1449ec97d0405e83649686ae35f6286
  • SHA256:
    eef137583da6deb4a1be9882cede6cec5112b74ae79c0773f45b13346c5b2890
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
100/100

IPs

IP Country Detection
199.59.242.153
United States
183.90.240.3
Japan
151.106.117.36
Germany
Click to see the 3 hidden entries
23.227.38.74
Canada
104.21.2.218
United States
34.102.136.180
United States

Domains

Name IP Detection
aceserial.xyz
151.106.117.36
www.marunouchi1.com
183.90.240.3
www.ovmfinacial.com
199.59.242.153
Click to see the 10 hidden entries
www.ebookgratis.online
104.21.2.218
shops.myshopify.com
23.227.38.74
www.richartware.com
0.0.0.0
www.blackmagiccomics.com
0.0.0.0
www.psychedeliccosmetics.com
0.0.0.0
www.dollpartyla.com
0.0.0.0
www.aceserial.xyz
0.0.0.0
www.quickcarehomeopathic.com
0.0.0.0
psychedeliccosmetics.com
34.102.136.180
parkingpage.namecheap.com
198.54.117.210

URLs

Name Detection
http://www.ovmfinacial.com/ag9v/?9rq=vpuErUH2OwLAPGAltxg3/Zj6XscnxJenLEapnG3NwgRlKVIYyl0HnfsKneQfORBHqYbR&BFQ=5jI0jhMHA0hx_
http://www.marunouchi1.com/ag9v/?9rq=RZxJGV19NODz6/sPl50rcsjPCmhff0B2cQNSD9XNHlzuAkz3tWy1tz3gnsv2II3OKfXw&BFQ=5jI0jhMHA0hx_
http://www.aceserial.xyz/ag9v/?9rq=8aghxAEFV3UFLmLUmwXrjnry4I8PGHpXxFVOvh2n7b9U9R7NlIya57CFUx9pJqwzlAw7&BFQ=5jI0jhMHA0hx_
Click to see the 58 hidden entries
www.psychedeliccosmetics.com/ag9v/
http://www.jiyu-kobo.co.jp/jp/r
http://www.jiyu-kobo.co.jp/jp/
http://en.wikip
http://www.carterandcone.coml
http://www.typography.neth?
http://www.fontbureau.com/designers/cabarga.htmlN
http://www.founder.com.cn/cn
http://www.fontbureau.com/designers/frere-user.html
http://www.psychedeliccosmetics.com/ag9v/?9rq=B7neoLnMPG5T4Lq1mgXXW304ryc0TDTB8h8f/WhOEZEEcWgrsd/ecy8wgWRxVB11aSvz&BFQ=5jI0jhMHA0hx_
http://www.sakkal.com3
http://www.jiyu-kobo.co.jp/
http://www.jiyu-kobo.co.jp/ita
http://www.fontbureau.como
http://www.jiyu-kobo.co.jp/i
http://www.fontbureau.com/designers8
http://www.typography.netiv
http://www.tiro.com51
http://www.fontbureau.com/designersG
http://www.fontbureau.com/designers/?
http://www.founder.com.cn/cn/bThe
http://www.jiyu-kobo.co.jp/a-e
http://www.jiyu-kobo.co.jp/jp/G
http://www.fontbureau.com/designers?
http://www.tiro.com
http://www.carterandcone.com/
http://www.typography.net4?
http://www.fontbureau.com/designers
http://www.goodfont.co.kr
http://www.collada.org/2005/11/COLLADASchema9Done
http://www.sajatypeworks.com
http://www.typography.netD
http://www.founder.com.cn/cn/cThe
http://www.galapagosdesign.com/staff/dennis.htm
http://fontfabrik.com
http://www.carterandcone.comw.m
http://www.typography.net
http://www.jiyu-kobo.co.jp/jp/i
http://www.galapagosdesign.com/DPlease
http://www.ascendercorp.com/typedesigners.html
http://www.carterandcone.comtal
http://www.jiyu-kobo.co.jp/(
http://www.fonts.com
http://www.sandoll.co.kr
http://www.sakkal.comd
http://www.urwpp.deDPlease
http://www.zhongyicts.com.cn
http://www.sakkal.com
http://www.jiyu-kobo.co.jp/tu
http://www.apache.org/licenses/LICENSE-2.0
http://www.fontbureau.com
http://www.carterandcone.comf
https://bitninja.io
http://www.tiro.comy
http://www.typography.netrz
http://www.jiyu-kobo.co.jp/G
http://www.fontbureau.comion
http://www.jiyu-kobo.co.jp/Y03

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\Wellis Inquiry.exe.log
ASCII text, with CRLF line terminators
#