=
We are hiring! Windows Kernel Developer (Remote), apply here!
flash

P2DIWOtpLf.exe

Status: finished
Submission Time: 2022-05-10 20:16:11 +02:00
Malicious
Trojan
Evader
Nanocore

Comments

Tags

  • exe
  • NanoCore
  • RAT

Details

  • Analysis ID:
    623789
  • API (Web) ID:
    991292
  • Analysis Started:
    2022-05-10 20:24:01 +02:00
  • Analysis Finished:
    2022-05-10 20:41:01 +02:00
  • MD5:
    3789175015481ee123abcbbfe83c3c16
  • SHA1:
    500ccf71450ef911b6a431e25da230742ca8bf65
  • SHA256:
    861bdb02b21024b41acc04ac63d0ca3455f47dda85b3d46dfd02d1f63855b796
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

malicious

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
100/100

malicious
27/67

malicious
26/41

IPs

IP Country Detection
185.19.85.160
Switzerland
102.89.42.162
Nigeria

Domains

Name IP Detection
fastspeed.ddnsfree.com
102.89.42.162

URLs

Name Detection
http://www.fontbureau.com/designersG
http://www.fontbureau.comFU
http://www.fontbureau.com/designers/?
Click to see the 77 hidden entries
http://fontfabrik.comX
http://www.founder.com.cn/cn/bThe
http://www.fontbureau.com/designers?
http://www.fonts.com(
http://www.jiyu-kobo.co.jp/jp/H
http://www.founder.com.cn/cnu-eA
http://www.urwpp.deett
http://www.tiro.com
http://www.fontbureau.com/designers
http://www.jiyu-kobo.co.jp/xor
http://www.goodfont.co.kr
http://www.carterandcone.com
http://www.founder.com.cn/cnC
http://www.jiyu-kobo.co.jp/~
http://www.sajatypeworks.com
http://www.founder.com.cn/cno
http://www.typography.netD
http://www.founder.com.cn/cn/cThe
http://www.galapagosdesign.com/staff/dennis.htm
http://fontfabrik.com
http://www.carterandcone.comD
http://www.fontbureau.comB.TTF
http://www.fontbureau.com/designers/frere-jones.htmlP
http://www.fontbureau.comcom
http://www.jiyu-kobo.co.jp/jp/l
http://www.galapagosdesign.com/DPlease
http://www.ascendercorp.com/typedesigners.html
http://www.fonts.com
http://www.sandoll.co.kr
http://www.jiyu-kobo.co.jp/&
http://www.carterandcone.comue4
http://www.urwpp.deDPlease
http://www.fontbureau.com/designersz
http://www.urwpp.de
http://www.zhongyicts.com.cn
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
http://www.carterandcone.como.
http://www.sakkal.com
http://www.carterandcone.comN
http://www.carterandcone.comb
http://www.jiyu-kobo.co.jp/jp/~
http://www.jiyu-kobo.co.jp/Z
http://www.apache.org/licenses/LICENSE-2.0
http://www.fontbureau.com
http://www.carterandcone.comf
http://www.fontbureau.comasoml
http://www.founder.com.cn/cndnl
http://www.jiyu-kobo.co.jp/T
http://www.carterandcone.comX
http://www.zhongyicts.com.cnu-r
http://www.fontbureau.comW.TTF
http://www.zhongyicts.com.cnm
http://www.carterandcone.comv
http://www.founder.com.cn/cn/obz
http://www.tiro.comlic
http://www.carterandcone.comt
http://www.jiyu-kobo.co.jp/C
http://www.jiyu-kobo.co.jp/jp/
http://www.fontbureau.comd
http://www.carterandcone.comm
http://www.carterandcone.coml
http://www.carterandcone.comk
http://www.fontbureau.com/designers/cabarga.htmlN
http://www.founder.com.cn/cn
http://www.fontbureau.com/designers/frere-jones.html
http://www.zhongyicts.com.cnva
http://www.founder.com.cn/cn/$
http://www.urwpp.den
http://www.fontbureau.commaU
http://www.jiyu-kobo.co.jp/
http://www.urwpp.de.Ti
http://www.urwpp.deu
http://www.fontbureau.com/designers8
http://www.fonts.com0
http://www.jiyu-kobo.co.jp/g
http://www.fontbureau.comdsed
http://www.fontbureau.com~

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Temp\tmp3864.tmp
XML 1.0 document, ASCII text
#
C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat
ISO-8859 text, with no line terminators
#
C:\Users\user\AppData\Roaming\mjbsosItP.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
Click to see the 21 hidden entries
C:\Users\user\AppData\Roaming\mjbsosItP.exe:Zone.Identifier
ASCII text, with CRLF line terminators
#
C:\Program Files (x86)\DHCP Monitor\dhcpmon.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
#
C:\Program Files (x86)\DHCP Monitor\dhcpmon.exe:Zone.Identifier
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\P2DIWOtpLf.exe.log
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\dhcpmon.exe.log
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
data
#
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_hhukf3ev.kf3.psm1
very short file (no magic)
#
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_ifc2ygq5.uig.ps1
very short file (no magic)
#
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_mxlrk2j0.y2x.psm1
very short file (no magic)
#
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_ujntonns.a2o.ps1
very short file (no magic)
#
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_w2dkegpy.3ku.psm1
very short file (no magic)
#
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_xpzwv1x0.mtv.ps1
very short file (no magic)
#
C:\Users\user\AppData\Local\Temp\tmp5E50.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\tmp67E6.tmp
XML 1.0 document, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\tmpB218.tmp
XML 1.0 document, ASCII text
#
C:\Users\user\AppData\Local\Temp\tmpD4F2.tmp
XML 1.0 document, ASCII text
#
C:\Users\user\AppData\Local\Temp\tmpF53B.tmp
XML 1.0 document, ASCII text
#
C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\task.dat
ASCII text, with no line terminators
#
C:\Users\user\Documents\20220510\PowerShell_transcript.376483.n68wiFr5.20220510202612.txt
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\Documents\20220510\PowerShell_transcript.376483.rfYSk5DZ.20220510202541.txt
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\Documents\20220510\PowerShell_transcript.376483.tuCn2Xiy.20220510202621.txt
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#