top title background image
flash

ENQUIRY_debloat.exe

Status: finished
Submission Time: 2024-05-02 13:59:07 +02:00
Malicious
Trojan
Spyware
Evader
AgentTesla, PureLog Stealer

Comments

Tags

  • exe

Details

  • Analysis ID:
    1435301
  • API (Web) ID:
    1435301
  • Analysis Started:
    2024-05-02 13:59:08 +02:00
  • Analysis Finished:
    2024-05-02 14:05:35 +02:00
  • MD5:
    7bda0984886d4eb078a16a3bd066f3c2
  • SHA1:
    426ec42960d176609ee0f988d33d23a7ad3cd53b
  • SHA256:
    46bcdad83987e1387a004286f7d130d90ba48d850b695c93e9ac1c6c1575ec64
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 22/72
malicious
Score: 11/38
malicious

IPs

IP Country Detection
149.154.167.220
United Kingdom

Domains

Name IP Detection
api.telegram.org
149.154.167.220

URLs

Name Detection
https://account.dyn.com/
https://api.telegram.org
https://api.telegram.org/bot6834342758:AAHnpbyPCzi-sEo22oVL6DdX9cuTElu_WyA/
Click to see the 4 hidden entries
http://api.telegram.org
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
https://api.telegram.org/bot6834342758:AAHnpbyPCzi-sEo22oVL6DdX9cuTElu_WyA/sendDocument
http://tempuri.org/DataSeta.xsd)Microsoft

Dropped files

No malicious files found. See full and IOC report for all dropped files.