top title background image
flash

inquiry[2021.09.23_12-51].xlsb

Status: finished
Submission Time: 2021-10-21 19:39:45 +02:00
Malicious
Trojan
Exploiter
Evader
Ursnif

Comments

Tags

Details

  • Analysis ID:
    507191
  • API (Web) ID:
    874763
  • Analysis Started:
    2021-10-21 19:39:47 +02:00
  • Analysis Finished:
    2021-10-21 19:47:34 +02:00
  • MD5:
    d5dedf5221391bc183c80173ed5f4279
  • SHA1:
    bc48802d095a79a9fb8196d35506c4862c937936
  • SHA256:
    f2be1c567425b843b8deec064cd9f747d74f4ae5e15d026fcb5b26549ae3fba9
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 100
System: Windows 7 x64 SP1 with Office 2010 SP1 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2)
clean
0/100

Third Party Analysis Engines

malicious
Score: 6/89
malicious
Score: 13/35
malicious
Score: 19/28

IPs

IP Country Detection
50.87.248.41
United States

Domains

Name IP Detection
iqwasithealth.com
50.87.248.41
app.updatebrouser.com
0.0.0.0
apt.updateffboruse.com
0.0.0.0

URLs

Name Detection
https://iqwasithealth.com/wp-content/uploads/2019/06/a435gfhs109.cms
http://www.%s.comPA
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
Click to see the 2 hidden entries
http://apt.updateffboruse.com/_2BYjuB36DkhB1eXLxT/icgzR9URog3BC5Xw8V6nIs/1N91Pgd5TeSwG/3boxgKnH/mcET
http://servername/isapibackend.dll

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\a435gfhs109[1].cms
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\Public\codec.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\CE192CE4.png
PNG image data, 1179 x 832, 8-bit/color RGB, non-interlaced
#
Click to see the 1 hidden entries
C:\Users\user\Desktop\~$inquiry[2021.09.23_12-51].xlsb
data
#