flash

calc.exe

Status: finished
Submission Time: 28.10.2021 04:45:35
Malicious
Evader

Comments

Tags

Details

  • Analysis ID:
    510683
  • API (Web) ID:
    878254
  • Analysis Started:
    28.10.2021 04:46:11
  • Analysis Finished:
    28.10.2021 05:01:51
  • MD5:
    ce76ae9d476b9c0daa25daf4c6dd4909
  • SHA1:
    f574aa3bbe554363a6f6d1d648c31505bf92bfe5
  • SHA256:
    05f3ac7f197b690f306c521b658c935fbf057d737ad6791cee6e2553b87d090b
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

malicious

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
72/100

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
Run Condition: Without Tracing

malicious
80/100

malicious
72/100

malicious
37/68

malicious
12/45

malicious

IPs

IP Country Detection
162.159.135.233
United States

Domains

Name IP Detection
cdn.discordapp.com
162.159.135.233

URLs

Name Detection
https://cdn.discordapp.com/attachments/8972
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/dateofbirthrhttp://schemas.xmlsoap.org/ws/2005
https://cdn.discordapp.com/attachment
Click to see the 94 hidden entries
https://cdn.discordapp.com/attachments/897223707649515602/897228595318124554/ascii_ART
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddressxhttp://schemas.xmlsoap.org/ws/200
https://cdn.discordapp.com/attachments/897223
https://cdn.discor
https://cdn.discord
https://cdn.discordapp.com/at
https://cdn.discordapp.co
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/stateorprovince
https://cdn.discordapp.com/attachm
https://cdn.discordapp.com/attachments/897223707649515602/8972285
https://cdn.discordapp.
https://cdn.discordapp.com/attachments/897223707649515602/897228595318124554/asci
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/authentication
https://cdn.disc
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/x500distinguishednamejhttp://schemas.xmlsoap.o
https://cdn.disco
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/denyonlysid
https://cdn.discorda
https://cdn.discordapp.com/attachments/897223707649515602
https://cdn.discordapp.com/attachments/897223707649515602/897228595318124554/a
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/authorizationdecisionzhttp://schemas.xmlsoap.o
https://cdn.d
https://cdn.discordapp.com/attachments/897223707649515
https://cdn.discordapp.com/attachments/
https://cdn.discordapp.com/atta
https://cdn.discordapp.com/attachments/897223707649515602/897228595318124554/ascii
https://cdn.discordapp.com/attachments/897223707649515602/89722
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
https://cdn.discordapp.com/attachments/8972237076
https://cdn.discordapp.com/attachments/897223707649
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier
https://cdn.discordap
https://cdn.discordapp.com/attachments/897223707
https://cdn.dis
https://cdn.discordapp.com/att
https://cdn.discordapp.com/attachments/897223707649515602/
https://cdn.discordapp.com/attachments/897223707649515602/897228595318124554
https://cdn.discordapp.com/attachments/897223707649515602/8972
https://cdn.discordapp.com/attachments/897223707649515602/8972285953181245
https://cdn.discordapp.com/attachments/897223707649515602/89722859531812455
https://cdn.discordapp.com/attachments/897223707649515602/89722859531
https://cdn.discordapp.com/attachments/897
https://cdn.discordapp.com/attachments/897402450376536075/897465559711633408/8NMrqq.txt
https://cdn.discordapp.com/attachments/89722370764
https://cdn.discordapp.com/attachments/897223707649515602/897228595318124
https://cdn.discordapp.com/attachments/8972237076495156
https://cdn.discordapp.com/attachments/897223707649515602/897228595318124554/ascii_AR
https://cdn.discordapp.com/attachments/89722370
https://cdn.discordapp.com/attac
https://cdn.discordapp.com/attachments/897223707649515602/897228595318124554/asc
https://cdn.discordapp.com/
https://cdn.discordapp.com/attachments/897223707649515602/897228595
https://cdn.discordapp.com/attachments/897223707649515602/8
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/streetaddresszhttp://schemas.xmlsoap.org/ws/20
https://cdn.discordapp.com/attachments/897223707649515602/8972285953
https://cdn.discordapp.com4
https://cdn.discordapp.com/attachments/89722370764951
https://cdn.discordapp.com/attach
https://cdn.discordapp.com/attachments/897223707649515602/897228595318124554/
https://cdn.discordapp
https://cdn.discordapp.com/attachments/897223707649515602/897228595318124554/ascii_ART.txt
http://cdn.discordapp.com
https://cdn.discordapp.com/attachments/897223707649515602/89722859
https://cdn.di
https://cdn.discordapp.com/attachments/8972237
https://cdn.discordapp.com/attachments/897223707649515602/89722859531812
https://cdn.discordapp.com/attachments/89
https://cdn.discordapp.comD8
https://cdn.discordapp.c
https://cdn.discordapp.com/attachments/897223707649515602/897228595318
https://cdn.discordapp.com/attachments
https://cdn.discordapp.com/attachments/8
https://cdn.discordapp.com/attachments/89722370764951560
https://cdn.discordapp.com/attachments/897223707649515602/897228595318124554/ascii_ART.
https://cdn.discordapp.com/attachments/897223707649515602/897228595318124554/ascii_ART.tx
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/otherphone
https://cdn.discordapp.com/attachments/89722
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/mobilephone
http://upx.sf.net
https://cdn.discordapp.com/attachments/897223707649515602/897228595318124554/ascii_A
https://cdn.discordapp.com
https://cdn.discordapp.com/attachmen
https://cdn.discordapp.com/attachments/897223707649515602/897228595318124554/as
https://cdn.discordapp.com/a
https://cdn.discordapp.com/attachments/897223707649515602/897228595318124554/ascii_
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/postalcoderhttp://schemas.xmlsoap.org/ws/2005/
https://cdn.discordapp.com/attachments/897223707649515602/897228
https://cdn.discordapp.com/attachments/897223707649515602/89
https://cdn.discordapp.com/attachments/897223707649515602/897228595318124554/ascii_ART.t
https://cdn.discordapp.com/attachments/897223707649515602/897
https://cdn.discordapp.com/attachments/897223707649515602/8972285953181
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/thumbprintrhttp://schemas.xmlsoap.org/ws/2005/
https://cdn.discordapp.com/attachments/8972237076495
https://cdn.discordapp.com/attachme

Dropped files

Name File Type Hashes Detection
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_calc.exe_8ef77563ee27693eb8c931177e339197ffc03d22_5b8918c7_17d5608e\Report.wer
Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER2DC6.tmp.dmp
Mini DuMP crash report, 15 streams, Thu Oct 28 11:56:13 2021, 0x1205a4 type
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER39DC.tmp.WERInternalMetadata.xml
XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
#
Click to see the 4 hidden entries
C:\ProgramData\Microsoft\Windows\WER\Temp\WER3D29.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\Windows\appcompat\Programs\Amcache.hve
MS Windows registry file, NT/2000 or above
#
C:\Windows\appcompat\Programs\Amcache.hve.LOG1
MS Windows registry file, NT/2000 or above
#
\Device\ConDrv
ASCII text, with CRLF, LF line terminators
#