=
We are hiring! Windows Kernel Developer (Remote), apply here!
flash

Quoted Items.exe

Status: finished
Submission Time: 2022-05-14 13:10:22 +02:00
Malicious
Trojan
Evader
FormBook

Comments

Tags

  • exe
  • xloader

Details

  • Analysis ID:
    626564
  • API (Web) ID:
    994069
  • Analysis Started:
    2022-05-14 13:10:24 +02:00
  • Analysis Finished:
    2022-05-14 13:21:38 +02:00
  • MD5:
    901567a408d891fc0f67e15221d1b7e4
  • SHA1:
    dba16ac8c7523f640494843471a5f9d4fb211bef
  • SHA256:
    70c9cf50b937cdf3015d4e7fdffbe1c8ab4820eaca74c7373f0760fa905a494a
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

malicious

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
100/100

malicious
30/67

malicious
20/41

malicious

IPs

IP Country Detection
180.76.158.103
China
209.17.116.163
United States
172.217.168.19
United States

Domains

Name IP Detection
www.zhouyihong.top
180.76.158.103
www.royaltortoisecookieco.online
209.17.116.163
www.gratefulgrandmas.com
0.0.0.0
Click to see the 3 hidden entries
www.ivyleaguereading.com
0.0.0.0
www.quinten-and-sam.com
3.93.205.129
ghs.googlehosted.com
172.217.168.19

URLs

Name Detection
http://www.royaltortoisecookieco.online/gfge/?-ZEhG=0pO83p&atm=bkTODcW29ZLLFsJ1z0hFzGOlzA/dTRh9UhQLTYc1zt8rWVzKVHP86zdm8t9X8OCiEKYk
www.gulabmonga.com/gfge/
http://www.apache.org/licenses/LICENSE-2.0
Click to see the 28 hidden entries
http://www.fontbureau.com
http://www.fontbureau.com/designersG
http://www.fontbureau.com/designers/?
http://www.founder.com.cn/cn/bThe
http://www.fontbureau.com/designers?
http://www.tiro.com
http://www.zhouyihong.top/gfge/?-ZEhG=0pO83p&atm=sEHQRf3BqyQO1Td3JS1wynh19DI9TXEUdP6kOjRf7qywa0JEaIf
http://www.fontbureau.com/designers
http://www.goodfont.co.kr
http://www.carterandcone.coml
http://www.sajatypeworks.com
http://www.typography.netD
http://www.fontbureau.com/designers/cabarga.htmlN
http://www.founder.com.cn/cn/cThe
http://www.galapagosdesign.com/staff/dennis.htm
http://fontfabrik.com
http://www.founder.com.cn/cn
http://www.fontbureau.com/designers/frere-jones.html
https://www.gratitudeaddict.com/
http://www.gratefulgrandmas.com/gfge/?atm=Z4UEWxzHsbgHCWzNn0OH8uguYAGXLulTgu05WjhJOdFN0vK06536biQ9Uf++w6wnfUsW&-ZEhG=0pO83p
http://www.jiyu-kobo.co.jp/
http://www.galapagosdesign.com/DPlease
http://www.fontbureau.com/designers8
http://www.fonts.com
http://www.sandoll.co.kr
http://www.urwpp.deDPlease
http://www.zhongyicts.com.cn
http://www.sakkal.com

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\Quoted Items.exe.log
ASCII text, with CRLF line terminators
#