top title background image
flash

5STdfnsEu5.exe

Status: finished
Submission Time: 2024-10-03 09:02:11 +02:00
Malicious
Trojan
Evader
LummaC

Comments

Tags

  • exe
  • pangscroogecarnage

Details

  • Analysis ID:
    1524765
  • API (Web) ID:
    1524765
  • Original Filename:
    c4165473eda07a845647da9f47b2e402bef8dc50b04a2a54173d80708797b767.exe
  • Analysis Started:
    2024-10-03 09:02:33 +02:00
  • Analysis Finished:
    2024-10-03 09:15:13 +02:00
  • MD5:
    bbc648a4b2f85f28dac054d62d854bd9
  • SHA1:
    aed50befc9c0f5b732563c05c79a48051bbb3cc3
  • SHA256:
    c4165473eda07a845647da9f47b2e402bef8dc50b04a2a54173d80708797b767
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 96
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
malicious
Score: 96
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Run Condition: Run with higher sleep bypass

Third Party Analysis Engines

malicious
Score: 24/71

IPs

IP Country Detection
104.21.16.12
United States
104.102.49.254
United States

Domains

Name IP Detection
gravvitywio.store
104.21.16.12
charistmatwio.shop
0.0.0.0
ignoracndwko.shop
0.0.0.0
Click to see the 8 hidden entries
grassemenwji.shop
0.0.0.0
preachstrwnwjw.shop
0.0.0.0
stitchmiscpaew.shop
0.0.0.0
commisionipwn.shop
0.0.0.0
technicaltip.shop
0.0.0.0
complainnykso.shop
0.0.0.0
basedsymsotp.shop
0.0.0.0
steamcommunity.com
104.102.49.254

URLs

Name Detection
https://gravvitywio.store/ndH
https://steamcommunity.com/profiles/76561199724331900
https://gravvitywio.store/fi
Click to see the 97 hidden entries
https://steamcommunity.com/profiles/76561199724331900/inventory/
https://gravvitywio.store/api
https://gravvitywio.store/U6
https://gravvitywio.store/oo
https://community.akamai.steamstatic.com/public/css/skin_1/profilev2.css?v=M_qL4gO2sKII&l=englis
http://ocsps.ssl.com0
https://community.akamai.steamstatic.com/
https://store.steampowered.com/news/
https://steamcommunity.com/market/
https://help.steampowered.com/en/
https://community.akamai.steamstatic.com/public/javascript/global.js?v=9OzcxMXbaV84&l=english
https://steamcommunity.com/my/wishlist/
https://store.steampowered.com/about/
https://store.steampowered.com/;
https://community.akamai.steamstatic.com/public/javascript/jquery-1.11.1.min.js?v=.isFTSRckeNhC
http://www.cknotes.com/?p=370POP3
https://BUCKET.PARAMSgetURLhttps:
https://avatars.akamai.steamstatic
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_logo.png
http://www.cknotes.com/?p=370
https://community.akamai.steamstatic.com/public/javascript/modalv2.js?v=dfMhuy-Lrpyo&l=english
https://community.akamai.steamstatic.com/public/css/globalv2.css?v=PAcV2zMBzzSV&l=english
https://www.google.com/recaptcha/
https://checkout.steampowered.com/
http://schemas.xmlsoap.org/ws/2005/02/trust/RST/Issue
https://broadcast.st.dl.eccdnx.com
http://crls.ssl.com/SSLcom-SubCA-CodeSigning-RSA-4096-R1.crl0
https://support.google.com/mail/?p=BadCredentials
https://store.steampowered.com/legal/
https://login.steampowered.com/
https://steamcommunity.com/workshop/
http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd
https://www.ssl.com/repository0
https://steamcommunity.com/login/home/?goto=profiles%2F76561199724331900
https://community.akamai.steamstatic.co
http://www.softutils.com/InitializeMcWebBrowserPlugin.html//
https://store.steampowered.com/steam_refunds/
https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
http://https://tmp%u.htmltmp%u.xml%u%
https://medal.tv
https://store.steampowered.com/stats/
https://steamcommunity.com/discussions/
https://community.akamai.steamstatic.com/public/javascript/promo/stickers.js?v=upl9NJ5D2xkP&l=en
https://recaptcha.net/recaptcha/;
https://community.akamai.steamstatic.com/public/css/skin_1/modalContent.css?v=.VpiwkLAYt9r1
https://steamcommunity.com/linkfilter/?u=http%3A%2F%2Fwww.geonames.org
http://store.steampowered.com/subscriber_agreement/
http://schemas.xmlsoap.org/ws/2005/02/trust
https://community.akamai.steamstatic.com/public/shared/javascript/tooltip.js?v=.zYHOpI1L3Rt0
http://localhost:%d/file?path=%sfile:///textmacro_%x.html
https://community.akamai.steamstatic.com/public/css/promo/summer2017/stickers.css?v=HA2Yr5oy3FFG&amp
https://community.akamai.steamstatic.com/public/javascript/applications/community/main.js?v=2ZRoxzol
https://login.microsoftonline.com/extSTS.srf
https://community.akamai.steamstati
https://www.valvesoftware.com/en/contact?contact-person=Translation%20Team%20Feedback
http://cknotes.com/pop3-error-no-x-uidl-header-found/
https://community.akamai.steamstatic.com/public/shared/css/shared_responsive.css?v=sHIIcMzCffX6&
https://community.akamai.steamstatic.com/public/javascript/webui/clientcom.js?v=HeLxjRDbQrcV&l=e
http://www.chilkatsoft.com/p/p_463.asp)
https://community.akamai.steamstatic.com/public/shared/images/responsive/header_menu_hamburger.png
https://www.google.com
https://community.akamai.steamstatic.com/public/shared/images/responsive/logo_valve_footer.png
https://community.akamai.steamstatic.com/public/javascript/scriptaculous/_combined.js?v=OeNIgrpEF8tL
https://www.youtube.com
http://www.valvesoftware.com/legal.htm
http://www.cknotes.com/?p=91
https://community.akamai.steamstatic.com/public/javascript/applications/community/libraries~b28b7af6
http://www.macrocommander.com
https://www.gstatic.cn/recaptcha/
https://store.steampowered.com/subscriber_agreement/
https://steamcommunity.com/?subsection=broadcasts
https://store.steampowered.com/;Persistent-AuthWWW-AuthenticateVarysteamCountry=US%7Cd7fb65801182a5f
https://community.akamai.steamstatic.com/public/shared/javascript/auth_refresh.js?v=WgUxSlKTb3W1&amp
http://cert.ssl.com/SSLcom-SubCA-CodeSigning-RSA-4096-R1.cer0Q
http://store.steampowered.com/privacy_agreement/
https://player.vimeo.com
http://schemas.xmlsoap.org/ws/2005/05/identity/NoProofKey
https://community.akamai.steamstatic.com/public/shared/css/shared_global.css?v=ezWS9te9Zwm9&l=en
https://store.steampowered.com/privacy_agreement/
https://avatars.akamai.steamstatic.com/fef49e7fa7e1997310d705b2a6158ff8dc1cdfeb_full.jpg
https://community.akamai.steamstatic.com/public/css/applications/community/main.css?v=Ev2sBLgkgyWJ&a
https://www.youtube.com/
https://lv.queniujq.cn
https://sketchfab.com
https://login.microsoftonline.com/GetUserRealm.srf
https://store.steampowered.com/points/shop/
https://community.akamai.steamstatic.com/public/shared/javascript/shared_global.js?v=REEGJU1hwkYl&am
http://cknotes.com/v9-5-0-55-micro-update-new-features-fixes-changes-etc-2/encryptBytesNewFailed
https://www.softutils.com%_vQuoteChar%
https://support.google.com/accounts/answer/6010255
https://community.akamai.steamstatic.com/public/javascript/applications/community/manifest.js?v=fWwP
https://www.softutils.com/versions/MacroCommanderUpdateInfo.ini
https://community.akamai.steamstatic.com/public/css/skin_1/header.css?v=NFoCa4OkAxRb&l=english
http://www.softutils.com
https://www.softutils.comopen.300clxclx???.lnk
https://steam.tv/
https://s.ytimg.com;

Dropped files

No malicious files found. See full and IOC report for all dropped files.