top title background image
flash

FedEx TRACKING DETAILS.exe

Status: finished
Submission Time: 2021-12-02 18:53:28 +01:00
Malicious
Trojan
Evader
FormBook

Comments

Tags

  • exe
  • FedEx
  • Formbook

Details

  • Analysis ID:
    532861
  • API (Web) ID:
    900381
  • Analysis Started:
    2021-12-02 19:01:11 +01:00
  • Analysis Finished:
    2021-12-02 19:11:07 +01:00
  • MD5:
    32414d4cae15c3a8063bf1251346533c
  • SHA1:
    3e92cca40b5b3bde11265ea773e77e0cd2432f96
  • SHA256:
    d6b4f7ba99b492e9b2382b51f6c49b32e86cc81b7fc6c93313f5962de4b910bd
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 22/61
malicious
Score: 14/27
malicious

Domains

Name IP Detection
onedrive.live.com
0.0.0.0
3eie8a.sn.files.1drv.com
0.0.0.0

URLs

Name Detection
www.hdetpnipa.xyz/a34b/
https://3eie8a.sn.files.1drv.com/y4mTGtN2XEyFxr4Fwg2GfGDYA-weizJsEgCfvnFlKm_xwhWQiYk4SVd3YN1FLBVj9kD
https://onedrive.live.com/B&resid=C34B41C1B35825CB%21140&authkey=AN9sEgEIgUt16GA
Click to see the 7 hidden entries
http://upx.sf.net
http://schemas.xmlsoap.org/ws/2004/09/policy
https://onedrive.live.com/download?cid=C34B41C1B35825CB&resid=C34B41C1B35825CB%21140&authkey=AN9sEgE
https://3eie8a.sn.files.1drv.com/y4mwmaWo75uzUwtwpwSnt0PfQZClqYm-BqTi81xEEYBIo3hzrTU99nIAl5l4jRjpvu3
https://3eie8a.sn.files.1drv.com/
https://3eie8a.sn.files.1drv.com/C
https://onedrive.live.com/

Dropped files

Name File Type Hashes Detection
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_logagent.exe_131232484c36b2f738ed9f8bca70746a5db0df_0357e9de_121e11bd\Report.wer
Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER124.tmp.WERInternalMetadata.xml
XML 1.0 document, Little-endian UTF-16 Unicode text, with CRLF line terminators
#
C:\ProgramData\Microsoft\Windows\WER\Temp\WER4AF.tmp.xml
XML 1.0 document, ASCII text, with CRLF line terminators
#
Click to see the 4 hidden entries
C:\ProgramData\Microsoft\Windows\WER\Temp\WERFC41.tmp.dmp
Mini DuMP crash report, 14 streams, Fri Dec 3 03:02:50 2021, 0x1205a4 type
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\0W10PBUV\Ipknvfrclgulizdtylbxizfhvowtamb[1]
data
#
C:\Windows\appcompat\Programs\Amcache.hve
MS Windows registry file, NT/2000 or above
#
C:\Windows\appcompat\Programs\Amcache.hve.LOG1
MS Windows registry file, NT/2000 or above
#