top title background image
flash

Preventivo24.01.11.exe

Status: finished
Submission Time: 2024-01-23 12:07:07 +01:00
Malicious
Ransomware
Trojan
Evader

Comments

Tags

  • exe

Details

  • Analysis ID:
    1379424
  • API (Web) ID:
    1379424
  • Analysis Started:
    2024-01-23 12:07:08 +01:00
  • Analysis Finished:
    2024-01-23 12:28:09 +01:00
  • MD5:
    32f35b78a3dc5949ce3c99f2981def6b
  • SHA1:
    18a24aa0ac052d31fc5b56f5c0187041174ffc61
  • SHA256:
    0cb44c4f8273750fa40497fca81e850f73927e70b13c8f80cdcfee9d1478e6f3
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 84
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
malicious
Score: 76
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Run Condition: Run with higher sleep bypass

Third Party Analysis Engines

malicious
Score: 12/69

IPs

IP Country Detection
184.25.164.138
United States
93.184.216.34
European Union
140.228.29.110
United States

Domains

Name IP Detection
www.example.com
93.184.216.34
vnvariant2024.ddnsfree.com
140.228.29.110

URLs

Name Detection
https://forum.uvnc.com
http://.jpg
http://java.sun.com/products/plugin/index.html#download
Click to see the 23 hidden entries
https://www.uvnc.comhttps://forum.uvnc.comnet
https://www.advancedinstaller.com
https://www.thawte.com/repository0W
http://oneocsp.microe
http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#
https://forum.uvnc.comvncMenu::WndProc
https://www.thawte.com/cps0/
http://crl.thawte.com/ThawteTimestampingCA.crl0
http://crl.sectigo.com/SectigoPublicCodeSigningCAR36.crl0y
https://www.uvnc.comcmd
http://html4/loose.dtd
http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t
http://www.example.com/download/updates.txt
http://.css
http://crt.sectigo.com/SectigoPublicCodeSigningRootR46.p7c0#
https://www.uvnc.com
http://crt.sectigo.com/SectigoPublicCodeSigningCAR36.crt0#
http://www.pdf-tools.com
http://ocsp.thawte.com0
http://ocsp.sectigo.com0
http://crl.sectigo.com/SectigoPublicCodeSigningRootR46.crl0
https://sectigo.com/CPS0
http://java.sun.com/update/1.4.2/jinstall-1_4-windows-i586.cab#Version=1

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Roaming\Photo and Fax Vn\Photo and vn 1.1.2\install\F97891C\WindowsVolume\Games\taskhost.exe
PE32 executable (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Roaming\Photo and Fax Vn\Photo and vn 1.1.2\install\F97891C\WindowsVolume\Games\viewer.exe
PE32 executable (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Roaming\Photo and Fax Vn\Photo and vn 1.1.2\install\F97891C\WindowsVolume\Games\vnchooks.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
#