=
We are hiring! Windows Kernel Developer (Remote), apply here!
flash

SecuriteInfo.com.Trojan.NSISX.Spy.Gen.2.8452.exe

Status: finished
Submission Time: 2022-05-14 00:37:31 +02:00
Malicious
Trojan
FormBook

Comments

Tags

  • exe

Details

  • Analysis ID:
    626424
  • API (Web) ID:
    993928
  • Analysis Started:
    2022-05-14 00:37:34 +02:00
  • Analysis Finished:
    2022-05-14 00:43:27 +02:00
  • MD5:
    14848f52302c15e27b26fee5fada11c1
  • SHA1:
    04d62d915bd1a81c4b5ed35df6edb953107398c8
  • SHA256:
    4ac982ea35522a13de30ff7ddbbec9becf2c7528a48f0aff377e3d6758a7ae7b
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
84/100

malicious
28/68

malicious
14/41

URLs

Name Detection
www.beamaster.info/p0ip/
http://nsis.sf.net/NSIS_ErrorError

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Temp\miylwnpd.exe
PE32 executable (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Temp\nsaF211.tmp
data
#
C:\Users\user\AppData\Local\Temp\qaodb6jx48te
data
#
Click to see the 1 hidden entries
C:\Users\user\AppData\Local\Temp\zehirtbl
data
#