top title background image
flash

Wellis Inquiry.exe

Status: finished
Submission Time: 2021-10-14 07:27:30 +02:00
Malicious
Trojan
Evader
FormBook

Comments

Tags

  • exe

Details

  • Analysis ID:
    502627
  • API (Web) ID:
    870200
  • Analysis Started:
    2021-10-14 07:27:31 +02:00
  • Analysis Finished:
    2021-10-14 07:37:27 +02:00
  • MD5:
    c357a8010e661a49df2e813bd22590b6
  • SHA1:
    08ecd005e1449ec97d0405e83649686ae35f6286
  • SHA256:
    eef137583da6deb4a1be9882cede6cec5112b74ae79c0773f45b13346c5b2890
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

IPs

IP Country Detection
199.59.242.153
United States
183.90.240.3
Japan
151.106.117.36
Germany
Click to see the 3 hidden entries
23.227.38.74
Canada
104.21.2.218
United States
34.102.136.180
United States

Domains

Name IP Detection
aceserial.xyz
151.106.117.36
www.marunouchi1.com
183.90.240.3
www.ovmfinacial.com
199.59.242.153
Click to see the 10 hidden entries
www.ebookgratis.online
104.21.2.218
shops.myshopify.com
23.227.38.74
www.richartware.com
0.0.0.0
www.blackmagiccomics.com
0.0.0.0
www.psychedeliccosmetics.com
0.0.0.0
www.dollpartyla.com
0.0.0.0
www.aceserial.xyz
0.0.0.0
www.quickcarehomeopathic.com
0.0.0.0
psychedeliccosmetics.com
34.102.136.180
parkingpage.namecheap.com
198.54.117.210

URLs

Name Detection
http://www.ovmfinacial.com/ag9v/?9rq=vpuErUH2OwLAPGAltxg3/Zj6XscnxJenLEapnG3NwgRlKVIYyl0HnfsKneQfORBHqYbR&BFQ=5jI0jhMHA0hx_
http://www.marunouchi1.com/ag9v/?9rq=RZxJGV19NODz6/sPl50rcsjPCmhff0B2cQNSD9XNHlzuAkz3tWy1tz3gnsv2II3OKfXw&BFQ=5jI0jhMHA0hx_
http://www.aceserial.xyz/ag9v/?9rq=8aghxAEFV3UFLmLUmwXrjnry4I8PGHpXxFVOvh2n7b9U9R7NlIya57CFUx9pJqwzlAw7&BFQ=5jI0jhMHA0hx_
Click to see the 58 hidden entries
www.psychedeliccosmetics.com/ag9v/
http://www.tiro.comy
http://en.wikip
http://www.jiyu-kobo.co.jp/jp/
http://www.jiyu-kobo.co.jp/jp/r
http://www.jiyu-kobo.co.jp/Y03
http://www.fontbureau.comion
http://www.jiyu-kobo.co.jp/G
http://www.typography.netrz
http://www.typography.neth?
https://bitninja.io
http://www.carterandcone.comf
http://www.fontbureau.com
http://www.apache.org/licenses/LICENSE-2.0
http://www.jiyu-kobo.co.jp/tu
http://www.carterandcone.coml
http://www.urwpp.deDPlease
http://www.fontbureau.com/designers/cabarga.htmlN
http://www.founder.com.cn/cn
http://www.fontbureau.com/designers/frere-user.html
http://www.psychedeliccosmetics.com/ag9v/?9rq=B7neoLnMPG5T4Lq1mgXXW304ryc0TDTB8h8f/WhOEZEEcWgrsd/ecy8wgWRxVB11aSvz&BFQ=5jI0jhMHA0hx_
http://www.sakkal.com3
http://www.jiyu-kobo.co.jp/
http://www.jiyu-kobo.co.jp/ita
http://www.fontbureau.como
http://www.jiyu-kobo.co.jp/i
http://www.fontbureau.com/designers8
http://www.typography.netiv
http://www.tiro.com51
http://www.galapagosdesign.com/staff/dennis.htm
http://www.fontbureau.com/designers/?
http://www.founder.com.cn/cn/bThe
http://www.jiyu-kobo.co.jp/a-e
http://www.jiyu-kobo.co.jp/jp/G
http://www.fontbureau.com/designers?
http://www.tiro.com
http://www.carterandcone.com/
http://www.typography.net4?
http://www.fontbureau.com/designers
http://www.goodfont.co.kr
http://www.collada.org/2005/11/COLLADASchema9Done
http://www.sajatypeworks.com
http://www.typography.netD
http://www.founder.com.cn/cn/cThe
http://www.sakkal.com
http://fontfabrik.com
http://www.carterandcone.comw.m
http://www.typography.net
http://www.jiyu-kobo.co.jp/jp/i
http://www.galapagosdesign.com/DPlease
http://www.ascendercorp.com/typedesigners.html
http://www.carterandcone.comtal
http://www.jiyu-kobo.co.jp/(
http://www.fonts.com
http://www.sandoll.co.kr
http://www.sakkal.comd
http://www.fontbureau.com/designersG
http://www.zhongyicts.com.cn

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\Wellis Inquiry.exe.log
ASCII text, with CRLF line terminators
#