top title background image
flash

file.exe

Status: finished
Submission Time: 2023-08-31 16:39:09 +02:00
Malicious
Trojan
Spyware
Evader
Vidar

Comments

Tags

  • exe

Details

  • Analysis ID:
    1301138
  • API (Web) ID:
    1301138
  • Analysis Started:
    2023-08-31 16:49:14 +02:00
  • Analysis Finished:
    2023-08-31 17:02:54 +02:00
  • MD5:
    bf81661814944b92da689f1c461ef908
  • SHA1:
    7e3235d7ce69217063f53840e6337633cc721ec7
  • SHA256:
    a524fce6eb4ee25ed07de294220d9c2445090b6c18b48802219149162152fea1
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 25/38

IPs

IP Country Detection
149.154.167.99
United Kingdom
195.201.254.123
Germany

Domains

Name IP Detection
t.me
149.154.167.99

URLs

Name Detection
https://support.mozilla.org/products/firefox
https://mozilla.org0/
https://www.google.com/images/branding/product/ico/googleg_lodp.ico
Click to see the 53 hidden entries
https://steamcommunity.com/profiles/76561199545993403
https://javadl.oracle.com/webapps/download/AutoDL?BundleId=245807_df5ad55fdd604472a86a45a217032c7dM
http://195.201.254.123:6012/sp1.zipn)
http://195.201.254.123:6012/
https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
https://www.autoitscript.com/cgi-bin/getfile.pl?autoit3/autoit-v3-setup.zip
https://www.google.com/search?q=test&sourceid=chrome&ie=UTF-8test
http://195.201.254.123:6012/m
https://www.ecosia.org/newtab/
https://dl.google.com/tag/s/appguid%3D%7B8A69D345-D564-463C-AFF1-A69D9E530F96%7D%26iid%3D%7B27E81B29
https://support.mozilla.org/kb/customize-firefox-controls-buttons-and-toolbars?utm_source=firefox-br
https://aka.ms/vs/17/release/vc_redist.x64.exeD
https://www.google.com/chrome/thank-you.html?statcb=1&installdataindex=empty&defaultbrowser=0Google
https://www.google.com/favicon.ico
https://ac.ecosia.org/autocomplete?q=
https://www.autoitscript.com/site/autoit/downloads/
https://www.google.com/chrome/Google
https://t.me/vogogor
https://www.autoitscript.com/site/autoit/downloads/https://www.autoitscript.com/site/Sun
https://www.google.com/sorry/index?continue=https://www.google.com/search%3Fq%3Dtest%26oq%3Dtest%26a
https://support.mozilla.org
https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
https://www.google.com/search?q=microsoft&sourceid=chrome&ie=UTF-8microsoftt
https://support.mozilla.org/products/firefoxgro.allizom.troppus.
https://cdn.stubdownloader.services.mozilla.com/builds/firefox-stub/en-US/win/4b14f052f39ceffb32abd8
https://www.google.com/chrome/
https://t.me/
https://t.me/vogogorx
https://duckduckgo.com/ac/?q=
https://t.me/vogogorv
http://195.201.254.123:6012/Mu
http://195.201.254.123:6012/sCodecs.dlls
http://195.201.254.123:6012/sp1.zip
https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
https://www.google.com/chrome/thank-you.html?statcb=1&installdataindex=empty&defaultbrowser=0
http://195.201.254.123:6012/0
https://www.autoitscript.com/files/autoit3/autoit-v3-setup.zipQ
https://sdlc-esd.oracle.com/ESD6/JSCDL/jdk/8u321-b07/df5ad55fdd604472a86a45a217032c7d/jre-8u321-wind
https://t.me/vogogorracvotsp1.zipMozilla/5.0
https://duckduckgo.com/chrome_newtab
https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search
https://t.me/vogogorL
https://www.google.com/sorry/index?continue=https://www.google.com/search%3Fq%3Dmicrosoft%26oq%3Dmic
https://www.google.com/search?q=test&oq=test&aqs=chrome..69i57j0i131i433i512j0i512j0i131i433i512l2j0
https://stubdownloader.services.mozilla.com/?attribution_code=c291cmNlPXd3dy5nb29nbGUuY29tJm1lZGl1bT
https://steamcommunity.com/profiles/76561199545993403update.zip
https://www.google.com/https://www.google.com/chrome/Thu
https://www.google.com/search?q=microsoft&oq=microsoft&gs_lcrp=EgZjaHJvbWUqEAgAEAAYgwEY4wIYsQMYgAQyE
http://www.sqlite.org/copyright.html.
http://195.201.254.123:6012/b2ced91faf30889899f34458f95b8e93
https://www.google.com/search?q=microsoft&sourceid=chrome&ie=UTF-8microsoft
http://195.201.254.123:6012/b2ced91faf30889899f34458f95b8e93k
http://www.mozilla.com/en-US/blocklist/

Dropped files

Name File Type Hashes Detection
C:\ProgramData\60379239670748708072323449
SQLite 3.x database, last written using SQLite version 3041002, page size 2048, file counter 7, database pages 57, cookie 0x30, schema 4, UTF-8, version-valid-for 7
#
C:\ProgramData\vcruntime140.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
#
C:\ProgramData\softokn3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
Click to see the 19 hidden entries
C:\ProgramData\nss3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\ProgramData\msvcp140.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
#
C:\ProgramData\mozglue.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\ProgramData\freebl3.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#
C:\ProgramData\98279768849475661070206458
SQLite 3.x database, last written using SQLite version 3041002, file counter 14, database pages 22, 1st free page 6, free pages 8, cookie 0x8, schema 4, UTF-8, version-valid-for 14
#
C:\ProgramData\93702365600485792059963927
SQLite 3.x database, last written using SQLite version 3034000, file counter 5, database pages 29, cookie 0x16, schema 4, UTF-8, version-valid-for 5
#
C:\ProgramData\77364074545019038892817732-shm
data
#
C:\ProgramData\77364074545019038892817732
SQLite 3.x database, user version 74, last written using SQLite version 3041002, page size 32768, writer version 2, read version 2, file counter 3, database pages 52, 1st free page 43, free pages 8, cookie 0x3c, schema 4, UTF-8, version-valid-for 3
#
C:\ProgramData\00440746450577075373182215
SQLite 3.x database, last written using SQLite version 3034000, page size 2048, file counter 6, database pages 53, cookie 0x22, schema 4, UTF-8, version-valid-for 6
#
C:\ProgramData\59242670612831660624168672
SQLite 3.x database, last written using SQLite version 3034000, page size 2048, file counter 6, database pages 53, cookie 0x22, schema 4, UTF-8, version-valid-for 6
#
C:\ProgramData\52766014303501464703169876
SQLite 3.x database, last written using SQLite version 3034000, file counter 11, database pages 8, 1st free page 8, free pages 1, cookie 0x4, schema 4, UTF-8, version-valid-for 11
#
C:\ProgramData\41854390081158473842695081
SQLite 3.x database, last written using SQLite version 3041002, page size 2048, file counter 2, database pages 25, cookie 0x10, schema 4, UTF-8, version-valid-for 2
#
C:\ProgramData\38345013959471306846242542
SQLite 3.x database, last written using SQLite version 3034000, file counter 5, database pages 29, cookie 0x16, schema 4, UTF-8, version-valid-for 5
#
C:\ProgramData\37707990510604932654966133
SQLite 3.x database, last written using SQLite version 3041002, page size 2048, file counter 7, database pages 57, cookie 0x30, schema 4, UTF-8, version-valid-for 7
#
C:\ProgramData\35746121865178509047716708
SQLite 3.x database, last written using SQLite version 3034000, page size 2048, file counter 2, database pages 23, cookie 0xd, schema 4, UTF-8, version-valid-for 2
#
C:\ProgramData\30562671907380543272507388
SQLite 3.x database, last written using SQLite version 3041002, file counter 9, database pages 43, 1st free page 42, free pages 2, cookie 0x3f, schema 4, UTF-8, version-valid-for 9
#
C:\ProgramData\22428703343438507335441715-shm
data
#
C:\ProgramData\22428703343438507335441715
SQLite 3.x database, user version 12, last written using SQLite version 3037002, page size 32768, writer version 2, read version 2, file counter 3, database pages 3, cookie 0x1, schema 4, UTF-8, version-valid-for 3
#
C:\ProgramData\05817041688375942296226764
SQLite 3.x database, last written using SQLite version 3041002, file counter 9, database pages 43, 1st free page 42, free pages 2, cookie 0x3f, schema 4, UTF-8, version-valid-for 9
#