=
We are hiring! Windows Kernel Developer (Remote), apply here!
flash

dpnhupnp.dll

Status: finished
Submission Time: 2022-02-27 17:43:08 +01:00
Malicious
Trojan
Evader
Dridex

Comments

Tags

  • dll
  • dridex
  • exe

Details

  • Analysis ID:
    579430
  • API (Web) ID:
    946949
  • Analysis Started:
    2022-02-27 17:43:09 +01:00
  • Analysis Finished:
    2022-02-27 17:59:10 +01:00
  • MD5:
    cf22fca6a1c8035cb38867787f16be21
  • SHA1:
    85cae7532a21983295a2c0aad5889e8dbd024c9f
  • SHA256:
    3a52c4f27db221ed975af3d38ac4b9060203b9c6fb3532cdc61b969e21ca666c
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

malicious

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
100/100

malicious
40/61

malicious
22/35

malicious
36/43

malicious

Domains

Name IP Detection
store-images.s-microsoft.com
0.0.0.0

URLs

Name Detection
https://mixer.com/api/v1/oauth/xbl/login
http://schemas.mi
https://profile.xboxlive.com/users/me/profile/settings?settings=GameDisplayPicRaw
Click to see the 26 hidden entries
https://aka.ms/imrx2o
https://mixer.com/_latest/assets/emoticons/%ls.png
https://mixer.com/api/v1/users/current
https://mixer.com/_latest/assets/emoticons/%ls.pngtitleIdaumIdkglIdprocessNamenametypeIdmultimedia
https://mixer.com/api/v1/broadcasts/current
https://mixer.com/%wsWindows.System.Launcher
https://aka.ms/v5do45
https://mixer.com/api/v1/types/lookup%ws
https://MediaData.XboxLive.com/broadcasts/Augmenthttps://MediaData.XboxLive.com/screenshots/Augmenth
https://aka.ms/wk9ocd
https://MediaData.XboxLive.com/broadcasts/Augment
https://aka.ms/imfx4k
http://schemas.micr
https://www.xboxlive.comMBI_SSLhttps://profile.xboxlive.com/users/me/profile/settings?settings=GameD
https://MediaData.XboxLive.com/gameclips/Augment
https://www.xboxlive.com
https://mixer.com/api/v1/channels/%d
https://mixer.com/api/v1/types/lookup%wshttps://mixer.com/api/v1/channels/%wshttps://mixer.com/api/v
https://mixer.com/api/v1/channels/%ws
https://mixer.com/api/v1/chats/%.0fhttps://mixer.com/api/v1/users/currentBEAM_IMAGEGamesGuide::BeamC
https://MediaData.XboxLive.com/screenshots/Augment
https://mixer.com/api/v1/chats/%.0f
https://aka.ms/ifg0es
https://mixer.com/%ws
https://aka.ms/w5ryqnhttps://aka.ms/imfx4kQUITTING
https://aka.ms/w5ryqn

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\1XXGC21\DUI70.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\4xeLXaDKW\WINSTA.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\96P3D\VERSION.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
#
Click to see the 14 hidden entries
C:\Users\user\AppData\Local\RiK2PNsRy\HID.DLL
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\WPx7QKO3\UxTheme.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\uRSIQRt4\dxgi.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\1XXGC21\msdt.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\4xeLXaDKW\DisplaySwitch.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\96P3D\cmstp.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\M4eXJF\VERSION.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\M4eXJF\cmstp.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\RiK2PNsRy\tabcal.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\WPx7QKO3\CloudNotifications.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\a6o\PresentationHost.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\a6o\VERSION.dll
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\uRSIQRt4\GamePanel.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3853321935-2125563209-4053062332-1002\414045e2d09286d5db2581e0d955d358_d06ed635-68f6-4e9a-955c-4899f5f57b9a
data
#