top title background image
flash

L8Z8sCDFmP.exe

Status: finished
Submission Time: 2023-08-29 02:36:05 +02:00
Malicious
Trojan
Spyware
Evader

Comments

Tags

  • exe
  • QuasarRAT
  • RAT

Details

  • Analysis ID:
    1299097
  • API (Web) ID:
    1299097
  • Original Filename:
    23a242e5c0b6068a3e4c18c0807047f3.exe
  • Analysis Started:
    2023-08-29 02:36:06 +02:00
  • Analysis Finished:
    2023-08-29 02:44:50 +02:00
  • MD5:
    23a242e5c0b6068a3e4c18c0807047f3
  • SHA1:
    8d2e233eaa7cc8a5e1a136a99cfddbc58b46c679
  • SHA256:
    531ebc6dbc009c7701d2b68068b1dfe049af5c7215cfc42a1d596cd9ba70fd5b
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 30/67
malicious
Score: 18/38
malicious

IPs

IP Country Detection
51.79.169.103
Canada

URLs

Name Detection
https://www.newtonsoft.com/jsonschema
https://mail.google.com/mail/installwebapp?usp=chrome_default
https://js.monitor.azure.com
Click to see the 97 hidden entries
https://d6tizftlrpuof.cloudfront.net/live/i/5b05b10e10f3d3749a56ff54/2f23b4d964f73595a131c52d2190fb4
https://www.google.com/xjs/_/js/k=xjs.s.en_GB.nmIVJu2djGw.O/am=CgggIAAAAAAIAEAUEA4B2AAG4JM7AwAACAAgA
https://dl.google.com
https://clients6.google.com
https://apis.google.com/_/scs/abc-static/_/js/k=gapi.gapi.en.9Ky5Gf3gP0o.O/m=gapi_iframes
https://docs.google.com/document/
https://www.google.com/
https://popper.js.org)
https://breeze.aimon.applicationinsights.io
https://w.usabilla.com/71e348d38aa1.js?lv=1aD
https://www.google.com/images/cleardot.gif
https://www.google.com/sorry/index
https://play.google.com/log?format=json&hasfast=true
https://www.google.com/images/dot2.gif
https://docs.google.com/spreadsheets/
https://plus.google.com
https://cct.google/taggy/agent.js
https://www.youtube.com/
https://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas_sfp&command=
https://play.google.com/store/apps/details?id=com.android.chrome
https://www.google.com/images/x2.gif
https://www.ecosia.org/newtab/
https://accounts.google.com/MergeSession
https://d6tizftlrpuof.cloudfront.net
https://www.google.com/xjs/_/js/k=xjs.s.en_GB.yPNRazS6c1M.O/ck=xjs.s.lf9XOA4b1Lc.L.W.O/am=AoAqALwAAD
https://www.google.com/intl/en_uk/chrome/
https://js.monitor.azure.com/scripts/c/ms.analytics-web-3.min.jsaDb
https://stackoverflow.com/q/11564914/23354;
https://www.google.com/intl/en_uk/chrome/0
https://support.google.com/chrome/answer/111996?visit_id=637962485686793996-3320600880&p=update_erro
https://docs.google.com/spreadsheets/B
https://docs.google.com/spreadsheets/?usp=installed_webapp
https://www.google.com/0
https://dc-int.services.visualstudio.com
https://www.google.com/chrome/static/js/pages/whats-new/m104/main.min.js
https://w.usabilla.com/71e348d38aa1.js?lv=1
https://apis.google.com/_/scs/abc-static/_/js/k=gapi.gapi.en.t9z7VPsEMFg.O/m=gapi_iframes
https://docs.google.com/presentation/installwebapp?usp=chrome_default
https://docs.google.com/presentation/:
https://sandbox.google.com/payments/v4/js/integrator.js
https://www.google.com/search?q=.net
https://docs.google.com/document/installwebapp?usp=chrome_default
https://docs.google.com/presentation/B
https://js.monitor.azure.com/scripts/b/ai.2.min.jsaDb
https://accounts.google.com/o/oauth2/postmessageRelay
https://drive.google.com/drive/installwebapp?usp=chrome_default
https://js.monitor.azure.com/scripts/b/ai.2.min.js
https://workspace.google.com/:session_prefix:marketplace/appfinder?usegapi=1
https://drive.google.com/?lfhs=2
https://mail.google.com/mail/B
https://westus2-0.in.applicationinsights.azure.com
https://drive.google.com/
https://www.google.com/intl/en_uk/chrome/thank-you.html?statcb=0&installdataindex=empty&defaultbrows
https://www.google.com/intl/en_uk/chrome/09
https://www.google.com/0BJ
https://aka.ms/3rdpartycookies
https://www.google.com
https://www.youtube.com
https://chrome.google.com/webstore?hl=enWeb
https://docs.google.com/document/:
https://dc.services.visualstudio.com
https://consentreceiverfd-prod.azurefd.net/v1
https://chrome.google.com/webstore?hl=en
https://mail.google.com/mail/:
https://docs.google.com/document/B
https://mail.google.com/mail/
https://www.youtube.com/:
https://js.monitor.azure.com/scripts/c/ms.analytics-web-3.min.jsaD
https://js.monitor.azure.com/scripts/c/ms.analytics-web-3.min.jsa
https://apis.google.com/_/scs/abc-static/_/js/k=gapi.gapi.en.hh2Jqle7bK0.O/m=gapi_iframes
https://duckduckgo.com/ac/?q=
https://mail.google.com/mail/?usp=installed_webapp
https://www.google.com/js/bg/v9qE1FcU75HlnlpqSrB0XICXMP2hXFnMwnMhpnu_vdQ.js
https://www.google.com/xjs/_/js/k=xjs.s.de_CH.Ydw_KbvqU4M.O/ck=xjs.s.a4p1Awqvts0.L.W.O/am=CgggIAAAAA
https://play.google.com/store/apps/details?id=com.chrome.beta
https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
https://d6tizftlrpuof.cloudfront.net/live/i/5b05b10e10f3d3749a56ff54/296ed43c7bb0b1f9316169a0ad90b13
https://payments.google.com/payments/v4/js/integrator.js
https://apis.google.com/js/api.js
https://docs.google.com/presentation/
https://www.instagram.com/
https://www.google.com/search?q=chrome&oq=chrome&aqs=chrome..69i57j0j5l3j69i60l3.2663j0j4&sourceid=c
https://stackoverflow.com/q/14436606/23354
https://github.com/google/closure-library/wiki/goog.module:-an-ES6-module-like-alternative-to-goog.p
https://dns.google
https://duckduckgo.com/chrome_newtab
https://support.google.com/recaptcha
https://www.youtube.com/?feature=ytca
https://d6tizftlrpuof.cloudfront.net/live/i/5b05b10e10f3d3749a56ff54/c12bb78e35a84ab0c6f6932296f1764
https://www.google.com/chrome/static/js/main.min.js
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
https://www.youtube.com/B
https://www.google.com/accounts/OAuthLogin?issueuberauth=1
https://support.google.com/chrome?p=update_error
https://www.youtube.com/s/notifications/manifest/cr_install.html
https://w.usabilla.com/71e348d38aa1.js?lv=1aDb
https://w.usabilla.com

Dropped files

No malicious files found. See full and IOC report for all dropped files.