flash

SecuriteInfo.com.Drixed-FJXE53A16BEA791.13728.dll

Status: finished
Submission Time: 28.10.2021 04:44:13
Malicious
Trojan
Evader
Dridex

Comments

Tags

  • dll

Details

  • Analysis ID:
    510686
  • API (Web) ID:
    878252
  • Analysis Started:
    28.10.2021 04:49:29
  • Analysis Finished:
    28.10.2021 05:09:18
  • MD5:
    e53a16bea7918b1f7d4c0e659febc766
  • SHA1:
    10d4d3d7fac35f6492cda2fb04aebf46903481f0
  • SHA256:
    212cae7b05ecbc938b3a1fda4753d119f69360165955937b836fdbc7a6d514eb
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

malicious

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
76/100

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
Run Condition: Run with higher sleep bypass

malicious
84/100

malicious
76/100

malicious
14/66

malicious
14/44

IPs

IP Country Detection
66.147.235.11
United States
149.202.179.100
France
81.0.236.89
Czech Republic

URLs

Name Detection
http://www.vomfass.deDVarFileInfo$

Dropped files

Name File Type Hashes Detection
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_rundll32.exe_5f8c232292098bd3183b3bd76fd57ba47bd4c4b_82810a17_06dfdcd0\Report.wer
Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_rundll32.exe_c316961cf9547f4477c913cd7ccdecd11bd19_82810a17_09efd927\Report.wer
Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERA390.tmp.dmp
Mini DuMP crash report, 14 streams, Thu Oct 28 12:04:12 2021, 0x1205a4 type
#
Click to see the 8 hidden entries
C:\ProgramData\Microsoft\Windows\WER\Temp\WERA620.tmp.dmp
Mini DuMP crash report, 14 streams, Thu Oct 28 12:04:16 2021, 0x1205a4 type
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERB2D3.tmp.WERInternalMetadata.xml
XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERB72A.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERC169.tmp.dmp
Mini DuMP crash report, 14 streams, Thu Oct 28 12:04:22 2021, 0x1205a4 type
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERCB3D.tmp.WERInternalMetadata.xml
XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERD020.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERD744.tmp.WERInternalMetadata.xml
XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERDCC3.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
#