top title background image
flash

SecuriteInfo.com.Drixed-FJXE53A16BEA791.13728.dll

Status: finished
Submission Time: 2021-10-28 04:44:13 +02:00
Malicious
Trojan
Evader
Dridex

Comments

Tags

  • dll

Details

  • Analysis ID:
    510686
  • API (Web) ID:
    878252
  • Analysis Started:
    2021-10-28 04:49:29 +02:00
  • Analysis Finished:
    2021-10-28 05:09:18 +02:00
  • MD5:
    e53a16bea7918b1f7d4c0e659febc766
  • SHA1:
    10d4d3d7fac35f6492cda2fb04aebf46903481f0
  • SHA256:
    212cae7b05ecbc938b3a1fda4753d119f69360165955937b836fdbc7a6d514eb
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 76
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
malicious
Score: 84
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Run Condition: Run with higher sleep bypass
malicious
76/100

Third Party Analysis Engines

malicious
Score: 14/66
malicious
Score: 14/44

IPs

IP Country Detection
66.147.235.11
United States
149.202.179.100
France
81.0.236.89
Czech Republic

URLs

Name Detection
http://www.vomfass.deDVarFileInfo$

Dropped files

Name File Type Hashes Detection
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_rundll32.exe_5f8c232292098bd3183b3bd76fd57ba47bd4c4b_82810a17_06dfdcd0\Report.wer
Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_rundll32.exe_c316961cf9547f4477c913cd7ccdecd11bd19_82810a17_09efd927\Report.wer
Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERA390.tmp.dmp
Mini DuMP crash report, 14 streams, Thu Oct 28 12:04:12 2021, 0x1205a4 type
#
Click to see the 8 hidden entries
C:\ProgramData\Microsoft\Windows\WER\Temp\WERA620.tmp.dmp
Mini DuMP crash report, 14 streams, Thu Oct 28 12:04:16 2021, 0x1205a4 type
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERB2D3.tmp.WERInternalMetadata.xml
XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERB72A.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERC169.tmp.dmp
Mini DuMP crash report, 14 streams, Thu Oct 28 12:04:22 2021, 0x1205a4 type
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERCB3D.tmp.WERInternalMetadata.xml
XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERD020.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERD744.tmp.WERInternalMetadata.xml
XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WERDCC3.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
#