top title background image
flash

SecuriteInfo.com.Win64.Malware-gen.18902.30045.exe

Status: finished
Submission Time: 2024-06-19 13:27:09 +02:00
Malicious
Trojan

Comments

Tags

  • exe

Details

  • Analysis ID:
    1459454
  • API (Web) ID:
    1459454
  • Analysis Started:
    2024-06-19 13:27:11 +02:00
  • Analysis Finished:
    2024-06-19 13:31:37 +02:00
  • MD5:
    a6c1b27e646cf5904a69e45ffc8808d5
  • SHA1:
    7cbafd874594bf3ee91cc49d7fa8ec686b4cad80
  • SHA256:
    d9cd6884ad7518018efaa52cde9c0ed46fba959e9ea093c97e68004dbf2cad66
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 48
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

IPs

IP Country Detection
172.67.75.40
United States

Domains

Name IP Detection
rentry.co
172.67.75.40

URLs

Name Detection
http://www.unicode.org/copyright.html
https://github.com/da-x/rxvt-unicode/tree/v9.22-with-24bit-color
https://html.spec.whatwg.org/multipage/browsers.html#concept-origin-opaque
Click to see the 97 hidden entries
https://heycam.github.io/webidl/#es-interfaces
https://heycam.github.io/webidl/#es-iterable-entries
https://heycam.github.io/webidl/#dfn-default-iterator-object
https://rentry.co/autodownload/raw
http://crl.securetrust.com/SGCA.crl0
http://.css
https://www.ecma-international.org/ecma-262/8.0/#prod-annexB-ExtendedAtom
https://github.com/nodejs/node/pull/34375
http://www.firmaprofesional.com/cps0
https://github.com/v8/v8/blob/d6ead37d265d7215cf9c5f768f279e21bd170212/src/js/prologue.js#L152-L156
https://github.com/nodejs/node/issues
https://bugs.chromium.org/p/v8/issues/detail?id=6593
https://github.com/nodejs/node/pull/12342
https://invisible-island.net/xterm/ctlseqs/ctlseqs.html
https://sourcemaps.info/spec.html
http://html4/loose.dtd
https://www.ecma-international.org/ecma-262/8.0/#prod-Pattern
https://www.unicode.org/Public/UNIDATA/EastAsianWidth.txt
https://www.ecma-international.org/ecma-262/#sec-line-terminators
http://www.accv.es00
http://crl.netsolssl.com/NetworkSolutionsCertificateAuthority.crl
https://tc39.es/ecma262/#sec-IsHTMLDDA-internal-slot
https://nodejs.org/api/cli.html#cli_unhandled_rejections_mode).
https://github.com/mafintosh/end-of-stream
https://github.com/google/caja/blob/master/src/com/google/caja/ses/repairES5.js
http://www.quovadisglobal.com/cps
https://tc39.github.io/ecma262/#sec-%typedarray%.of
https://url.spec.whatwg.org/#concept-urlencoded-parser
https://github.com/mafintosh/pump
https://github.com/acornjs/acorn/issues/575
http://ocsp.accv.es0
https://github.com/nodejs/node/issues/10673
https://rentry.co/autodownload/rawq
https://www.ecma-international.org/ecma-262/8.0/#prod-Quantifier
https://www.ecma-international.org/ecma-262/8.0/#prod-ControlLetter
https://github.com/nodejs/node/pull/12607
http://.jpg
https://heycam.github.io/webidl/#dfn-iterator-prototype-object
https://heycam.github.io/webidl/#dfn-class-string
https://html.spec.whatwg.org/multipage/timers-and-user-prompts.html#dom-setinterval
https://github.com/nodejs/node/pull/30380#issuecomment-552948364
https://github.com/chalk/supports-color
https://crbug.com/v8/8520
https://url.spec.whatwg.org/#urlsearchparams
https://tc39.github.io/ecma262/#sec-object.prototype.tostring
http://www.quovadisglobal.com/cps0
https://www.ecma-international.org/ecma-262/8.0/#prod-HexDigits
https://url.spec.whatwg.org/#url
http://crl.dhimyotis.com/certignarootca.crl
https://url.spec.whatwg.org/#concept-urlencoded-serializer
https://tc39.github.io/ecma262/#sec-%iteratorprototype%-object
https://www.ecma-international.org/ecma-262/8.0/#prod-annexB-Assertion
https://www.ecma-international.org/ecma-262/8.0/#prod-ClassAtom
https://github.com/nodejs/node/commit/f7620fb96d339f704932f9bb9a0dceb9952df2d4
https://tools.ietf.org/html/rfc7230#section-3.2.2
https://goo.gl/t5IS6M).
https://www.ecma-international.org/ecma-262/8.0/#prod-ClassAtomNoDash
https://github.com/nodejs/node/issues/13435
https://encoding.spec.whatwg.org/#textencoder
https://nodejs.org/download/release/v12.22.11/node-v12.22.11.tar.gz
https://wiki.squid-cache.org/SquidFaq/InnerWorkings#What_is_a_half-closed_filedescriptor.3F
https://console.spec.whatwg.org/#console-namespace
https://www.iana.org/assignments/tls-extensiontype-values
https://console.spec.whatwg.org/#table
https://www.ecma-international.org/ecma-262/#sec-timeclip
https://github.com/nodejs/node-v0.x-archive/issues/2876.
https://gist.github.com/XVilka/8346728#gistcomment-2823421
https://www.ecma-international.org/ecma-262/8.0/#prod-Atom
https://nodejs.org/download/release/v12.22.11/node-v12.22.11-headers.tar.gz
http://crl.dhimyotis.com/certignarootca.crl.
https://www.ecma-international.org/ecma-262/8.0/#sec-atomescape
https://www.ecma-international.org/ecma-262/8.0/#prod-NonemptyClassRangesNoDash
https://www.ecma-international.org/ecma-262/8.0/#prod-Hex4Digits
http://www.cert.fnmt.es/dpcs/
http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1.crt0
http://crl.securetrust.com/STCA.crl
https://code.google.com/p/chromium/issues/detail?id=25916
https://www.ecma-international.org/ecma-262/#sec-promise.all
http://narwhaljs.org)
https://www.ecma-international.org/ecma-262/8.0/#prod-CharacterClassEscape
https://github.com/vercel/pkg/issues/1589
https://stackoverflow.com/a/5501711/3561
https://www.ecma-international.org/ecma-262/8.0/#prod-annexB-ClassControlLetter
https://www.ecma-international.org/ecma-262/8.0/#prod-DecimalEscape
http://www.squid-cache.org/Doc/config/half_closed_clients/
https://url.spec.whatwg.org/#concept-url-origin
https://wwww.certigna.fr/autorites/0m
https://www.ecma-international.org/ecma-262/8.0/#prod-ControlEscape
https://tools.ietf.org/html/rfc7540#section-8.1.2.5
https://nodejs.org/
http://www.midnight-commander.org/browser/lib/tty/key.c
https://www.ecma-international.org/ecma-262/8.0/#prod-NonemptyClassRanges
https://www.ecma-international.org/ecma-262/8.0/#prod-ClassRanges
https://github.com/nodejs/node/pull/21313
http://www.accv.es/legislacion_c.htmD
https://github.com/chalk/ansi-regex/blob/master/index.js
https://nodejs.org/api/fs.html

Dropped files

No malicious files found. See full and IOC report for all dropped files.