top title background image
flash

Garanti BBVA Ödeme havalesi dekontu 28012022.exe

Status: finished
Submission Time: 2022-01-28 22:06:27 +01:00
Malicious
Trojan
Evader
AgentTesla

Comments

Tags

  • AgentTesla
  • exe
  • geo
  • TUR

Details

  • Analysis ID:
    562447
  • API (Web) ID:
    929969
  • Analysis Started:
    2022-01-28 22:06:28 +01:00
  • Analysis Finished:
    2022-01-28 22:17:05 +01:00
  • MD5:
    1165567a0b77f4c1bb44b4e89a6ab0c6
  • SHA1:
    0f9b426434142ee8e753e19844add22b4bc87bf2
  • SHA256:
    bc79a9662ee07c43bbec9321f04e2f186d22b2d7c10c790b828b51de0df1604a
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

URLs

Name Detection
http://www.tiro.com=4(
http://www.carterandcone.coml
http://en.w
Click to see the 83 hidden entries
http://www.carterandcone.como.n1l
http://www.carterandcone.comt
http://www.fontbureau.comzana
http://www.sandoll.co.krur
http://blog.iandreev.com
http://www.carterandcone.comTC
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha
http://www.zhongyicts.com.cnof
http://www.founder.com.cn/cn/
http://www.carterandcone.comc
http://www.sajatypeworks.comt
http://DynDns.comDynDNS
http://www.fontbureau.com
http://www.apache.org/licenses/LICENSE-2.0
http://www.carterandcone.comtig
http://www.carterandcone.comL
http://www.fontbureau.com/designersn
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip
http://www.sakkal.com
http://fontfabrik.com3#
http://www.fontbureau.com/designers/
http://www.founder.com.cn/cnof
http://www.fontbureau.com/designers:
http://www.tiro.coml
http://www.tiro.comb7
http://www.urwpp.dei
http://www.fontbureau.com/designers8
http://www.zhongyicts.com.cno.
http://www.carterandcone.comona
http://www.jiyu-kobo.co.jp/
http://www.founder.com.cn/cnf
http://www.founder.com.cn/cnngHd0f
http://www.monotype.
http://jShurS.com
http://www.fontbureau.com/designers/cabarga.html
http://www.sandoll.co.krormals
http://www.zhongyicts.com.cnva
http://www.fontbureau.com/designers/frere-jones.html
http://www.founder.com.cn/cn
http://www.fontbureau.com/designers/cabarga.htmlN
http://www.fontbureau.com/designers/frere-jones.html.
http://www.sajatypeworks.com
http://www.carterandcone.com-
http://www.fontbureau.com/designersQ
http://www.carterandcone.com
http://www.goodfont.co.kr
http://fontfabrik.comH
http://www.fontbureau.com/designers
http://www.zhongyicts.com.cn0
http://www.tiro.com
http://www.founder.com.cn/cn/(8Y
http://www.typography.netD
http://www.carterandcone.comva
http://www.carterandcone.comal
http://www.fontbureau.com/designers?
http://www.founder.com.cn/cn/bThe
http://www.fontbureau.com/designersK
http://www.fontbureau.com/designers/?
http://www.carterandcone.comn-u
http://blog.iandreev.com/
http://www.fontbureau.com/designersG
http://127.0.0.1:HTTP/1.1
http://www.founder.com.cn/cna
http://www.carterandcone.como.
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
http://www.zhongyicts.com.cn
http://www.urwpp.de
http://www.carterandcone.comoaU#
http://www.urwpp.deDPlease
http://www.sandoll.co.kr
http://www.fonts.com
http://www.carterandcone.comuct
http://www.ascendercorp.com/typedesigners.html
http://www.goodfont.co.krom
http://www.fontbureau.comgrita/3t
http://www.galapagosdesign.com/DPlease
http://www.urwpp.de2
http://www.fontbureau.com/designerse
http://www.fontbureau.com/designersers
http://fontfabrik.com
http://www.galapagosdesign.com/staff/dennis.htm
http://www.founder.com.cn/cn/cThe
http://www.carterandcone.comn-uW4

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\Garanti BBVA #U00d6deme havalesi dekontu 28012022.exe.log
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
data
#
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_3xqdgrlj.qdv.psm1
very short file (no magic)
#
Click to see the 2 hidden entries
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_yehsm0ba.evc.ps1
very short file (no magic)
#
C:\Users\user\Documents\20220128\PowerShell_transcript.141700.O7yUmft4.20220128220756.txt
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#