=
flash

SWIFT - Copy - Copy.xlsx

Status: finished
Submission Time: 14.01.2022 16:03:12
Malicious
Trojan
Exploiter
Evader
FormBook

Comments

Tags

  • xlsx

Details

  • Analysis ID:
    553293
  • API (Web) ID:
    920816
  • Analysis Started:
    14.01.2022 16:03:14
  • Analysis Finished:
    14.01.2022 16:15:19
  • MD5:
    338cbe8a882d7c941afe2cf895055bd5
  • SHA1:
    f081a9d12054b2e1a59d3eae4fa65059db634268
  • SHA256:
    097ce13d935a168aa627794fce83fb57b3ad39989c46b574acb13820edbafe4a
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

malicious

System: Windows 7 x64 SP1 with Office 2010 SP1 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2)

malicious
100/100

malicious

IPs

IP Country Detection
162.0.209.73
Canada
118.67.131.217
Korea Republic of
131.153.37.4
United States
Click to see the 2 hidden entries
216.239.34.21
United States
34.102.136.180
United States

Domains

Name IP Detection
www.luckyfandom.com
118.67.131.217
mikeloayza.com
131.153.37.4
bitcointradel.com
162.0.209.73
Click to see the 5 hidden entries
www.executive-air.net
0.0.0.0
www.bitcointradel.com
0.0.0.0
www.freeadakahamazon.com
0.0.0.0
executive-air.net
34.102.136.180
www.fisioletsgo.com
216.239.34.21

URLs

Name Detection
http://mikeloayza.com/E9/i4L.exe
http://www.bitcointradel.com/i6ro/?1bwlC=v8wCmtdiFaomFbCqPmTRfuzV09iQsBcARN7AuQ2Z2cmxW4qEZgdAIsAR7HDX+F8RHnJ1WA==&Lvkth=7nk0PH684p
http://www.luckyfandom.com/i6ro/?1bwlC=p0eSlAztBYtTxVFAHr6whY3a3/Gvse9lKulyfm76J1CiWi63XOqEOX0vBd7zzyHot2+Q1w==&Lvkth=7nk0PH684p
Click to see the 24 hidden entries
www.healingandhealthy.com/i6ro/
https://mikeloayza.com/E9/i4L.exe
http://www.windows.com/pctv.
http://investor.msn.com
http://www.msnbc.com/news/ticker.txt
http://wellformedweb.org/CommentAPI/
http://www.iis.fhg.de/audioPA
http://windowsmedia.com/redir/services.asp?WMPFriendly=true
http://www.hotmail.com/oe
http://treyresearch.net
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
http://java.sun.com
http://www.fisioletsgo.com/i6ro/?1bwlC=EvZLIa9n10nRxiOVjDAbNaraserFHY+vFXfn78IjngAHha///qY0HtL3OeQWM3V4VGGKJg==&Lvkth=7nk0PH684p
http://www.icra.org/vocabulary/.
http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
http://www.piriform.com/ccleanerhttp://www.piriform.com/ccleanerv
http://investor.msn.com/
http://www.piriform.com/ccleaner
http://computername/printers/printername/.printer
http://www.%s.comPA
http://www.autoitscript.com/autoit3
https://support.mozilla.org
http://www.executive-air.net/i6ro/?1bwlC=/cyLrpDDSN6YuFUytusJvMs1Fa8HKgEew+X60dN8PRm9IS30Y+vwImEN4uFaxkThXcWLPQ==&Lvkth=7nk0PH684p
http://servername/isapibackend.dll

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\i4L[1].exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Users\user\Desktop\~$SWIFT - Copy - Copy.xlsx
data
#
C:\Users\Public\Pcportk28.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
Click to see the 3 hidden entries
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\i4L[1].htm
HTML document, ASCII text
#
C:\Users\user\AppData\Local\Temp\7916.tmp
Composite Document File V2 Document, Cannot read section info
#
C:\Users\user\AppData\Local\Temp\~DF01B9A0A507F75E4B.TMP
data
#