=
We are hiring! Windows Kernel Developer (Remote), apply here!
flash

xcVh7ZmH4Y.exe

Status: finished
Submission Time: 2022-05-10 21:41:14 +02:00
Malicious
Trojan
Evader
Spyware
AgentTesla, GuLoader

Comments

Tags

  • exe

Details

  • Analysis ID:
    623886
  • API (Web) ID:
    991378
  • Analysis Started:
    2022-05-10 21:59:32 +02:00
  • Analysis Finished:
    2022-05-10 22:22:50 +02:00
  • MD5:
    d17d180329065df1bf54501a2c8e138b
  • SHA1:
    255c70621a90d6070d2585ef47eaff05c143c54a
  • SHA256:
    6a3b4d2025462d750011db9881bd74700cf7e2e7708398a18dfec422555ba438
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
80/100

System: Windows 10 64 bit 20H2 Native physical Machine for testing VM-aware malware (Office 2019, IE 11, Chrome 93, Firefox 91, Adobe Reader DC 21, Java 8 Update 301
Run Condition: Suspected Instruction Hammering

malicious
100/100

malicious
26/68

malicious
8/35

malicious
16/41

malicious

IPs

IP Country Detection
77.246.191.210
Spain
142.250.181.238
United States
142.250.185.193
United States

Domains

Name IP Detection
mail.comansi.com
77.246.191.210
drive.google.com
142.250.181.238
googlehosted.l.googleusercontent.com
142.250.185.193
Click to see the 1 hidden entries
doc-10-70-docs.googleusercontent.com
0.0.0.0

URLs

Name Detection
https://doc-10-70-docs.googleusercontent.com/G
http://127.0.0.1:HTTP/1.1
http://DynDns.comDynDNS
Click to see the 13 hidden entries
https://SqvSXVgUZh6rJgTP37.com
https://doc-10-70-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/vvokdj17
https://drive.google.com/w
https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha
https://doc-10-70-docs.googleusercontent.com/=(
https://drive.google.com/
http://crl.F
http://mail.comansi.com
https://doc-10-70-docs.googleusercontent.com/R
http://nsis.sf.net/NSIS_ErrorError
https://doc-10-70-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/vvokdj17p4i7ofbgdc9th89j41hsrn1o/1652213400000/13619548348121457133/*/1VssbX_L5DESUoNwRHcbF42fii8wzHqEA?e=download
https://doc-10-70-docs.googleusercontent.com/
http://SckyfZ.com

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Temp\Airplane_16.bmp
JPEG image data, JFIF standard 1.01, resolution (DPI), density 100x100, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=3], baseline, precision 8, 110x110, frames 3
#
C:\Users\user\AppData\Local\Temp\AsOpenFile.exe
PE32+ executable (GUI) x86-64, for MS Windows
#
C:\Users\user\AppData\Local\Temp\Borders.dat
data
#
Click to see the 7 hidden entries
C:\Users\user\AppData\Local\Temp\Green_Leaves_21.bmp
JPEG image data, JFIF standard 1.01, resolution (DPI), density 100x100, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=3], baseline, precision 8, 110x110, frames 3
#
C:\Users\user\AppData\Local\Temp\duperinger.ini
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\nso9723.tmp\System.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Temp\printer-symbolic.symbolic.png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Roaming\umsqbqzt.0jv\Chrome\Default\Cookies
SQLite 3.x database, last written using SQLite version 3036000
#
C:\Users\user\AppData\Roaming\umsqbqzt.0jv\Firefox\Profiles\ol7uiqa8.default-release\cookies.sqlite
SQLite 3.x database, user version 12, last written using SQLite version 3036000
#
\Device\ConDrv
ASCII text, with CRLF line terminators
#