=
We are hiring! Windows Kernel Developer (Remote), apply here!
flash

slowday.exe

Status: finished
Submission Time: 2022-04-23 19:14:12 +02:00
Malicious
Phishing
Trojan
Spyware
Exploiter
Evader
HawkEye MailPassView

Comments

Tags

  • exe
  • hawkeye
  • keylogger
  • stealer

Details

  • Analysis ID:
    614362
  • API (Web) ID:
    981875
  • Analysis Started:
    2022-04-23 19:14:12 +02:00
  • Analysis Finished:
    2022-04-23 19:29:02 +02:00
  • MD5:
    a172f4b0fa1a44cb60901944cff7f8ed
  • SHA1:
    c4aa87ba839c2da6ed852ba0e936ac80d47ec5b5
  • SHA256:
    94243b53eceb2662ae632d9c3e02b5b947ea56ac4ac1db3a69fc0ca3e5100816
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
100/100

malicious
53/71

malicious
31/42

malicious

malicious

URLs

Name Detection
https://a.pomf.cat/
http://pomf.cat/upload.php&https://a.pomf.cat/
http://pomf.cat/upload.php
Click to see the 97 hidden entries
http://www.msn.com/de-ch/entertainment/_h/c920645c/webcore/externalscripts/oneTrustV2/scripttemplate
https://www.google.com/chrome/static/images/folder-applications.svg
https://www.google.com/chrome/static/css/main.v2.min.css
https://www.google.com/chrome/static/images/fallback/google-chrome-logo.jpg
http://www.msn.com
http://www.nirsoft.net
https://deff.nelreports.net/api/report?cat=msn
https://www.google.com/chrome/static/images/chrome-logo.svg
https://www.google.com/chrome/static/images/homepage/homepage_features.png
https://adservice.google.com/ddm/fls/i/src=2542116;type=chrom322;cat=chrom01g;ord=6856811916691;gtm=
https://www.google.com/chrome/static/images/download-browser/big_pixel_phone.png
https://www.google.com/chrome/
https://2542116.fls.doubleclick.net/activityi;src22
https://assets.adobedtm.com/5ef092d1efb5/4d1d9f749fd3/434d91f2e635/RCc13122162a9a46c3b4cbf05ffccde0f
https://www.google.com/chrome/static/images/homepage/hero-anim-bottom-left.png
https://www.google.com/chrome/static/images/chrome_safari-behavior.jpg
https://login.microsoftonline.com/common/oauth2/authorizeclient_id=9ea1ad79-fdb6-4f9a-8bc3-2b70f96e3
https://maps.windows.com/windows-app-web-link
http://www.msn.com/?ocid=iehp
https://2542116.fls.doubleclick.net/activityi;src=2542116;type=chrom322;cat=chrom01g;ord=68568119166
https://assets.adobedtm.com/5ef092d1efb5/4d1d9f749fd3/434d91f2e635/RCee0d4d5fd4424c8390d703b105f82c3
https://srtb.msn.com/auction?a=de-ch&b=a8415ac9f9644a1396bc1648a4599445&c=MSN&d=http%3A%2F%2Fwww.msn
http://crl.pki.goog/GTS1O1core.crl0
https://www.google.com/chrome/static/images/icon-announcement.svg
https://contextual.media.net/medianet.php?cid=8CU157172&crid=722878611&size=306x271&https=1https://c
http://www.nirsoft.net/
https://www.google.com/chrome/static/images/homepage/hero-anim-middle.png
https://www.google.com/chrome/static/css/main.v3.min.css
https://www.google.com/chrome/application/x-msdownloadC:
https://www.google.com/chrome/static/images/fallback/icon-file-download.jpg
https://assets.adobedtm.com/5ef092d1efb5/4d1d9f749fd3/434d91f2e635/RC5bdddb231cf54f958a5b6e76e9d8eee
https://2542116.fls.doubleclick.net/activityi;src=2542116;type=2542116;cat=chom0;ord=447687274835
https://www.google.com/chrome/static/images/download-browser/pixel_phone.png
http://pki.goog/gsr2/GTS1O1.crt0
https://contextual.media.net/medianet.php?cid=8CU157172&crid=858412214&size=306x271&https=1
https://googleads.g.doubleclick.net/pagead/gcn_p3p_.xml
https://www.google.com/chrome/static/images/app-store-download.png
https://www.google.com/chrome/static/images/homepage/hero-anim-top-right.png
https://contextual.media.net/
https://pki.goog/repository/0
https://cvision.media.net/new/300x300/3/167/174/27/39ab3103-8560-4a55-bfc4-401f897cf6f2.jpg?v=9
http://www.msn.com/
https://assets.adobedtm.com/5ef092d1efb5/4d1d9f749fd3/434d91f2e635/RC828bc1cde9f04b788c98b5423157734
https://2542116.fls.doubleclick.net/activityi;src=2542116;type=clien612;cat=chromx;ord=1;num=1463674
https://www.google.com/chrome/static/images/fallback/google-logo-one-color.jpg
https://www.google.com/chrome/static/images/fallback/icon-twitter.jpg
http://www.msn.com/de-ch/entertainment/_h/c920645c/webcore/externalscripts/oneTrustV2/consent/55a804
https://contextual.media.net/803288796/fcmain.js?&gdpr=0&cid=8CU157172&cpcd=pC3JHgSCqY8UHihgrvGr0A%3
https://contextual.media.net/48/nrrV18753.js
https://www.google.com/chrome/static/images/fallback/icon-help.jpg
https://www.google.com/accounts/servicelogin
https://www.google.com/chrome/static/images/homepage/google-enterprise.png
https://www.google.com/chrome/static/images/homepage/google-dev.png
https://www.google.com/chrome/static/images/thank-you/thankyou-animation.json
http://crl.pki.goog/gsr2/gsr2.crl0?
http://pki.goog/gsr2/GTSGIAG3.crt0)
https://www.google.com/
https://www.google.com/chrome/static/images/fallback/icon-fb.jpg
https://www.google.com/chrome/static/images/mac-ico.png
http://pki.goog/gsr2/GTS1O1.crt0#
https://aefd.nelreports.net/api/report?cat=bingth
https://www.google.com/chrome/static/images/google-play-download.png
https://www.google.com/chrome/static/images/chrome_throbber_fast.gif
https://www.google.com/chrome/static/images/homepage/google-canary.png
https://www.google.com/chrome/static/images/favicons/favicon-16x16.png
https://geolocation.onetrust.com/cookieconsentpub/v1/geo/location
https://assets.adobedtm.com/launch-EN7b3d710ac67a4a1195648458258f97dd.min.js
https://www.google.com/chrome/static/images/homepage/laptop_desktop.png
https://www.google.com/chrome/static/js/main.v2.min.js
https://www.google.com/chrome/static/images/fallback/icon-description-white-blue-bg.jpg
https://assets.adobedtm.com/5ef092d1efb5/4d1d9f749fd3/434d91f2e635/RCfd484f9188564713bbc5d13d862ebbf
https://login.microsoftonline.com/common/oauth2/authorize?client_id=9ea1ad79-fdb6-4f9a-8bc3-2b70f96e
https://www.google.com/chrome/static/images/homepage/homepage_privacy.png
https://contextual.media.net/checksync.php?&vsSync=1&cs=1&hb=1&cv=37&ndec=1&cid=8HBI57XIG&prvid=77%2
https://www.google.com/chrome/static/images/fallback/icon-youtube.jpg
https://login.yahoo.com/config/login
https://www.google.com/chrome/thank-you.html?statcb=0&installdataindex=empty&defaultbrowser=0
https://contextual.media.net/checksync.phphttps://contextual.media.net/checksync.php?&vsSync=1&cs=1&
https://dl.google.com/tag/s/appguid%3D%7B8A69D345-D564-463C-AFF1-A69D9E530F96%7D%26iid%3D%7BFD3B6173
https://www.google.com/chrome/static/images/cursor-replay.cur
https://www.google.com/chrome/static/js/installer.min.js
http://crl.pki.goog/GTSGIAG3.crl0
https://adservice.google.co.uk/ddm/fls/i/src=2542116;type=chrom322;cat=chrom01g;ord=6856811916691;gt
https://www.google.com/chrome/static/images/download-browser/pixel_tablet.png
https://www.google.com/chrome/static/images/homepage/homepage_tools.png
http://bot.whatismyipaddress.com/
http://pki.goog/gsr2/GTS1O1.crt0M
https://assets.adobedtm.com/5ef092d1efb5/4d1d9f749fd3/434d91f2e635/RCc71c68d7b8f049b6a6f3b669bd5d00c
https://img.img-taboola.com/taboola/image/fetch/f_jpg%2Cq_auto%2Ch_311%2Cw_207%2Cc_fill%2Cg_faces:au
https://www.google.com/chrome/static/images/homepage/google-beta.png
http://www.msn.com/de-ch/?ocid=iehp
https://www.google.com/chrome/static/images/icon-file-download.svg
https://assets.adobedtm.com/5ef092d1efb5/4d1d9f749fd3/434d91f2e635/RC9b2d2bc73c8a4a1d8dd5c3d69b6634a
https://aefd.nelreports.net/api/report?cat=bingaot
https://amp.azure.net/libs/amp/1.8.0/azuremediaplayer.min.js
https://contextual.media.net/medianet.php?cid=8CU157172&crid=722878611&size=306x271&https=1
https://assets.adobedtm.com/5ef092d1efb5/4d1d9f749fd3/434d91f2e635/RC54c8a2b02c3446f48a60b41e8a5ff47

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\winlogons.url
MS Windows 95 Internet shortcut text (URL=<file:///C:\Users\user\AppData\Roaming\winlogons\winlogons.exe>), ASCII text, with CR line terminators
#
C:\Users\user\AppData\Roaming\winlogons\winlogons.exe
PE32 executable (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Temp\18da55c1-2652-5cda-252b-e5d7f7077c5d
ASCII text, with no line terminators
#
Click to see the 15 hidden entries
C:\Users\user\AppData\Local\Temp\bhv2307.tmp
Extensible storage engine DataBase, version 0x620, checksum 0x35b8f545, page size 32768, DirtyShutdown, Windows version 10.0
#
C:\Users\user\AppData\Local\Temp\bhv8783.tmp
Extensible storage engine DataBase, version 0x620, checksum 0x9c149ac1, page size 32768, DirtyShutdown, Windows version 10.0
#
C:\Users\user\AppData\Local\Temp\bhvAE74.tmp
Extensible storage engine DataBase, version 0x620, checksum 0x9c149ac1, page size 32768, DirtyShutdown, Windows version 10.0
#
C:\Users\user\AppData\Local\Temp\bhvBB7.tmp
Extensible storage engine DataBase, version 0x620, checksum 0x35b8f545, page size 32768, DirtyShutdown, Windows version 10.0
#
C:\Users\user\AppData\Local\Temp\bhvCA97.tmp
Extensible storage engine DataBase, version 0x620, checksum 0x9c149ac1, page size 32768, DirtyShutdown, Windows version 10.0
#
C:\Users\user\AppData\Local\Temp\bhvCE9E.tmp
Extensible storage engine DataBase, version 0x620, checksum 0x9c149ac1, page size 32768, DirtyShutdown, Windows version 10.0
#
C:\Users\user\AppData\Local\Temp\bhvED61.tmp
Extensible storage engine DataBase, version 0x620, checksum 0x2dfa5ec5, page size 32768, DirtyShutdown, Windows version 10.0
#
C:\Users\user\AppData\Local\Temp\tmp33E2.tmp
Little-endian UTF-16 Unicode text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\tmp36CB.tmp
Little-endian UTF-16 Unicode text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\tmp43C.tmp
Little-endian UTF-16 Unicode text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\tmp7E2A.tmp
Little-endian UTF-16 Unicode text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\tmp8255.tmp
Little-endian UTF-16 Unicode text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\tmpC5B7.tmp
Little-endian UTF-16 Unicode text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\tmpF1A4.tmp
Little-endian UTF-16 Unicode text, with no line terminators
#
C:\Users\user\AppData\Roaming\winlogons\winlogons.vbs
ASCII text, with CR line terminators
#