top title background image
flash

1.cmd

Status: finished
Submission Time: 2024-10-04 09:41:03 +02:00
Malicious
Spyware
Evader

Comments

Tags

Details

  • Analysis ID:
    1525473
  • API (Web) ID:
    1525473
  • Analysis Started:
    2024-10-04 09:41:04 +02:00
  • Analysis Finished:
    2024-10-04 09:53:50 +02:00
  • MD5:
    19fc666f7494d78a55d6b50a0252c214
  • SHA1:
    8876cd520507cbfdc2e89e449baba52232a1df1b
  • SHA256:
    e96f8f61e3af77c429ae6af54c128f7b8420a45a0a63bdfcacd682773b8e5fc1
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 9/61

IPs

IP Country Detection
192.64.119.55
United States

Domains

Name IP Detection
azure-winsecure.com
192.64.119.55

URLs

Name Detection
http://schemas.xmlsoap.org/ws/2005/02/trust
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
https://aka.ms/pscore6xGx
Click to see the 24 hidden entries
http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd
http://docs.oasis-open.org/ws-sx/ws-trust/200512
https://aka.ms/pscore68
http://Passport.NET/tb
https://nuget.org/nuget.exe
https://contoso.com/
http://schemas.xmlsoap.org/wsdl/
http://schemas.xmlsoap.org/wsdl/soap12/
http://schemas.xmlsoap.org/ws/2005/07/securitypolicy
https://github.com/Pester/Pester
http://schemas.micro
http://nuget.org/NuGet.exe
https://aka.ms/pscore6
https://wns2-by3p.notify.windows.com/?token=AwYAAACklixT6U5TxXWj7Y4oTt3JqNuZjYaQtFRvg3Ifna8Pnwup50yq
http://www.microsoft.co9=
http://upx.sf.net
https://contoso.com/Icon
https://contoso.com/License
https://go.micro
http://www.apache.org/licenses/LICENSE-2.0.html
http://schemas.xmlsoap.org/wsdl/erties
http://schemas.xmlsoap.org/ws/2004/09/policy
http://pesterbdd.com/images/Pester.png
http://docs.oasis-open.org/ws-sx/ws-securitypolicy/200702

Dropped files

Name File Type Hashes Detection
C:\Windows\$rbx-onimai2\$rbx-CO2.bat
DOS batch file, ASCII text, with very long lines (5674), with CRLF line terminators
#