=
We are hiring! Windows Kernel Developer (Remote), apply here!
flash

MARIAM HONAINE'S CV.exe

Status: finished
Submission Time: 2022-05-12 11:39:29 +02:00
Malicious
Trojan
Evader
Nanocore

Comments

Tags

  • exe

Details

  • Analysis ID:
    625073
  • API (Web) ID:
    992576
  • Analysis Started:
    2022-05-12 11:44:20 +02:00
  • Analysis Finished:
    2022-05-12 11:56:13 +02:00
  • MD5:
    06981ba465eb7eca5e8da7572511e3d1
  • SHA1:
    75e5740ef54f5c7b4df89589423ad3fea84dbac2
  • SHA256:
    dd810d37c396be1e34d2fe8b76c5ff30c17b6bb64afcc1c682182fb6934a3f60
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

malicious

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
100/100

malicious
11/41

malicious

IPs

IP Country Detection
212.193.30.204
Russian Federation

Domains

Name IP Detection
deranano2.ddns.net
212.193.30.204

URLs

Name Detection
deranano2.ddns.net
http://www.fontbureau.com/designersG
Click to see the 89 hidden entries
http://www.goodfont.co.kroms-c
http://www.ascendercorp.com/typedesigners.htmlmR
http://www.zhongyicts.com.cnB
http://www.fontbureau.com/designers/?
http://www.founder.com.cn/cn/bThe
http://www.sandoll.co.kr5
http://www.fontbureau.com/designers?
http://www.fontbureau.comgritaP
http://www.sajatypeworks.comn-u
http://www.urwpp.deMTl
http://www.sandoll.co.krony
http://www.fontbureau.comd#
http://www.tiro.com
http://www.zhongyicts.com.cnln
http://www.fontbureau.com/designers
http://www.goodfont.co.kr
http://www.sandoll.co.kra-e
http://www.founder.com.cn/cnl/
http://www.fontbureau.comalsF
http://www.founder.com.cn/cnC
http://www.sajatypeworks.com
http://www.founder.com.cn/cnht
http://www.typography.netD
http://www.founder.com.cn/cn/cThe
http://www.galapagosdesign.com/staff/dennis.htm
http://fontfabrik.com
http://www.jiyu-kobo.co.jp/8
http://www.jiyu-kobo.co.jp/5
http://www.goodfont.co.k
http://www.fontbureau.com/
http://www.galapagosdesign.com/DPlease
http://www.jiyu-kobo.co.jp/Y0
http://www.ascendercorp.com/typedesigners.html
http://www.urwpp.deFT
http://www.fonts.com
http://www.sandoll.co.kr
http://www.carterandcone.comad
http://www.fontbureau.com5
http://www.urwpp.deDPlease
http://www.sandoll.co.krtp
http://www.urwpp.de
http://www.zhongyicts.com.cn
http://www.sakkal.com
http://www.urwpp.de$
http://www.fontbureau.com=
http://www.founder.com.cn/cn/m
http://www.fontbureau.comdv
http://www.galapagosdesign.com/L
http://www.apache.org/licenses/LICENSE-2.0
http://www.carterandcone.comitk%1~
http://www.fontbureau.com
http://www.founder.com.cn/cnMic
http://www.galapagosdesign.com/
http://www.fontbureau.comF
http://www.sajatypeworks.comt
http://www.jiyu-kobo.co.jp/wa
http://www.carterandcone.comZ
http://www.tiro.comu
http://www.jiyu-kobo.co.jp/P
http://www.founder.com.cn/cnMicF
http://www.fontbureau.commeta
http://www.zhongyicts.com.cnthdt
http://www.jiyu-kobo.co.jp/C
http://www.jiyu-kobo.co.jp/oi
http://www.sakkal.comC
http://www.jiyu-kobo.co.jp/jp/
http://www.fontbureau.comd
http://www.carterandcone.coml
http://www.fontbureau.comgritot
http://www.founder.com.cn/cn/
http://www.fontbureau.com/designers/cabarga.htmlN
http://www.fontbureau.comk
http://www.founder.com.cn/cn
http://www.fontbureau.com/designers/frere-jones.html
http://www.fontbureau.comf
http://www.jiyu-kobo.co.jp/Y0/
http://www.fontbureau.comt
http://www.fontbureau.comcec
http://www.sandoll.co.krormalm
http://www.urwpp.deo
http://www.jiyu-kobo.co.jp/
http://www.zhongyicts.com.cno.
http://www.fontbureau.com/designers8
http://www.fontbureau.com/designers/cabarga.htmlB
http://www.fontbureau.comalic
http://www.fontbureau.comM.TTF
http://www.tiro.comic
http://www.fontbureau.comm5
http://www.fontbureau.comaswa

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\MARIAM HONAINE'S CV.exe.log
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat
ISO-8859 text, with no line terminators
#
C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\catalog.dat
data
#
Click to see the 2 hidden entries
C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\settings.bin
data
#
C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\storage.dat
data
#