top title background image
flash

calc.exe

Status: finished
Submission Time: 2021-10-28 04:45:35 +02:00
Malicious
Evader

Comments

Tags

Details

  • Analysis ID:
    510683
  • API (Web) ID:
    878254
  • Analysis Started:
    2021-10-28 04:46:11 +02:00
  • Analysis Finished:
    2021-10-28 05:01:51 +02:00
  • MD5:
    ce76ae9d476b9c0daa25daf4c6dd4909
  • SHA1:
    f574aa3bbe554363a6f6d1d648c31505bf92bfe5
  • SHA256:
    05f3ac7f197b690f306c521b658c935fbf057d737ad6791cee6e2553b87d090b
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 72
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
malicious
Score: 80
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Run Condition: Without Tracing
malicious
72/100

Third Party Analysis Engines

malicious
Score: 37/68
malicious
Score: 12/45
malicious

IPs

IP Country Detection
162.159.135.233
United States

Domains

Name IP Detection
cdn.discordapp.com
162.159.135.233

URLs

Name Detection
https://cdn.discordapp.com/attach
https://cdn.discordapp.com/attachments/897223707649515602/897228595318
https://cdn.discordapp.c
Click to see the 94 hidden entries
https://cdn.discordapp.comD8
https://cdn.discordapp.com/attachments/89
https://cdn.discordapp.com/attachments/897223707649515602/89722859531812
https://cdn.discordapp.com/attachments/8972237
https://cdn.di
https://cdn.discordapp.com/attachments/897223707649515602/89722859
http://cdn.discordapp.com
https://cdn.discordapp.com/attachments/897223707649515602/897228595318124554/ascii_ART.txt
https://cdn.discordapp
https://cdn.discordapp.com/attachments/897223707649515602/897228595318124554/
https://cdn.discordapp.com/attachments
https://cdn.discordapp.com/attachments/89722370764951
https://cdn.discordapp.com4
https://cdn.discordapp.com/attachments/897223707649515602/8972285953
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/streetaddresszhttp://schemas.xmlsoap.org/ws/20
https://cdn.discordapp.com/attachments/897223707649515602/8
https://cdn.discordapp.com/attachments/897223707649515602/897228595
https://cdn.discordapp.com/
https://cdn.discordapp.com/attachments/897223707649515602/897228595318124554/asc
https://cdn.discordapp.com/attac
https://cdn.discordapp.com/attachments/89722370
https://cdn.discordapp.com/attachments/897223707649515602/897228595318124554/ascii_AR
https://cdn.discordapp.com/attachments/897223707649515602/897228595318124554/as
https://cdn.discordapp.com/attachme
https://cdn.discordapp.com/attachments/8972237076495
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/thumbprintrhttp://schemas.xmlsoap.org/ws/2005/
https://cdn.discordapp.com/attachments/897223707649515602/8972285953181
https://cdn.discordapp.com/attachments/897223707649515602/897
https://cdn.discordapp.com/attachments/897223707649515602/897228595318124554/ascii_ART.t
https://cdn.discordapp.com/attachments/897223707649515602/89
https://cdn.discordapp.com/attachments/897223707649515602/897228
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/postalcoderhttp://schemas.xmlsoap.org/ws/2005/
https://cdn.discordapp.com/attachments/897223707649515602/897228595318124554/ascii_
https://cdn.discordapp.com/a
https://cdn.discordapp.com/attachments/8972237076495156
https://cdn.discordapp.com/attachmen
https://cdn.discordapp.com
https://cdn.discordapp.com/attachments/897223707649515602/897228595318124554/ascii_A
http://upx.sf.net
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/mobilephone
https://cdn.discordapp.com/attachments/89722
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/otherphone
https://cdn.discordapp.com/attachments/897223707649515602/897228595318124554/ascii_ART.tx
https://cdn.discordapp.com/attachments/897223707649515602/897228595318124554/ascii_ART.
https://cdn.discordapp.com/attachments/89722370764951560
https://cdn.discordapp.com/attachments/8
https://cdn.discordapp.com/attachments/897223707649515602/8972285
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/authorizationdecisionzhttp://schemas.xmlsoap.o
https://cdn.discordapp.com/attachments/897223707649515602/897228595318124554/a
https://cdn.discordapp.com/attachments/897223707649515602
https://cdn.discorda
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/denyonlysid
https://cdn.disco
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/x500distinguishednamejhttp://schemas.xmlsoap.o
https://cdn.disc
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/authentication
https://cdn.discordapp.com/attachments/897223707649515602/897228595318124554/asci
https://cdn.discordapp.
https://cdn.d
https://cdn.discordapp.com/attachm
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/stateorprovince
https://cdn.discordapp.co
https://cdn.discordapp.com/at
https://cdn.discord
https://cdn.discor
https://cdn.discordapp.com/attachments/897223
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddressxhttp://schemas.xmlsoap.org/ws/200
https://cdn.discordapp.com/attachments/897223707649515602/897228595318124554/ascii_ART
https://cdn.discordapp.com/attachment
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/dateofbirthrhttp://schemas.xmlsoap.org/ws/2005
https://cdn.dis
https://cdn.discordapp.com/attachments/897223707649515602/897228595318124
https://cdn.discordapp.com/attachments/89722370764
https://cdn.discordapp.com/attachments/897402450376536075/897465559711633408/8NMrqq.txt
https://cdn.discordapp.com/attachments/897
https://cdn.discordapp.com/attachments/897223707649515602/89722859531
https://cdn.discordapp.com/attachments/897223707649515602/89722859531812455
https://cdn.discordapp.com/attachments/897223707649515602/8972285953181245
https://cdn.discordapp.com/attachments/897223707649515602/8972
https://cdn.discordapp.com/attachments/897223707649515602/897228595318124554
https://cdn.discordapp.com/attachments/897223707649515602/
https://cdn.discordapp.com/att
https://cdn.discordapp.com/attachments/8972
https://cdn.discordapp.com/attachments/897223707
https://cdn.discordap
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier
https://cdn.discordapp.com/attachments/897223707649
https://cdn.discordapp.com/attachments/8972237076
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
https://cdn.discordapp.com/attachments/897223707649515602/89722
https://cdn.discordapp.com/attachments/897223707649515602/897228595318124554/ascii
https://cdn.discordapp.com/atta
https://cdn.discordapp.com/attachments/
https://cdn.discordapp.com/attachments/897223707649515

Dropped files

Name File Type Hashes Detection
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_calc.exe_8ef77563ee27693eb8c931177e339197ffc03d22_5b8918c7_17d5608e\Report.wer
Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER2DC6.tmp.dmp
Mini DuMP crash report, 15 streams, Thu Oct 28 11:56:13 2021, 0x1205a4 type
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER39DC.tmp.WERInternalMetadata.xml
XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
#
Click to see the 4 hidden entries
C:\ProgramData\Microsoft\Windows\WER\Temp\WER3D29.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\Windows\appcompat\Programs\Amcache.hve
MS Windows registry file, NT/2000 or above
#
C:\Windows\appcompat\Programs\Amcache.hve.LOG1
MS Windows registry file, NT/2000 or above
#
\Device\ConDrv
ASCII text, with CRLF, LF line terminators
#