top title background image
flash

DHL DOC 3406506482.exe

Status: finished
Submission Time: 2021-12-02 18:49:30 +01:00
Malicious
Trojan
Evader
FormBook

Comments

Tags

  • DHL
  • exe
  • Formbook

Details

  • Analysis ID:
    532855
  • API (Web) ID:
    900377
  • Analysis Started:
    2021-12-02 18:53:41 +01:00
  • Analysis Finished:
    2021-12-02 19:05:04 +01:00
  • MD5:
    896c3c7f309a479f0ab1a9d8693b130f
  • SHA1:
    9ad094b6799fb6deea1d2c3704576db3353d70ae
  • SHA256:
    6f35f7c071de6ed456c189e023daa27c5b0cd007d4fcddbb13316a82ada83abe
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 19/65
malicious
Score: 17/45

IPs

IP Country Detection
1.32.255.152
Singapore

Domains

Name IP Detection
www.uenpb.xyz
1.32.255.152
www.wed8029.com
0.0.0.0

URLs

Name Detection
http://www.uenpb.xyz/q35x/?1bL4BX=n0W6sBJt6o5hFrgQrmHErIHHCJqVSMT16xl2hKdZI7rsj0AVnZwRK3Rm3lIsVsqUahNr&TBZ8=3fcPMN
www.verdugofarms.com/q35x/

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\DHL DOC 3406506482.exe.log
ASCII text, with CRLF line terminators
#