top title background image
flash

new.bat

Status: finished
Submission Time: 2024-11-16 16:35:04 +01:00
Malicious

Comments

Tags

  • bat
  • fit-retired-athletics-marathon--trycloudflare--com

Details

  • Analysis ID:
    1556932
  • API (Web) ID:
    1556932
  • Analysis Started:
    2024-11-16 16:35:05 +01:00
  • Analysis Finished:
    2024-11-16 16:41:40 +01:00
  • MD5:
    af0c16e6a8877ea5a72d5d4a876e8302
  • SHA1:
    bc78be8297b41156b56fb22f7a84e7a85a183f7a
  • SHA256:
    8620fa4c62bd53e5b70aa10e6205f1ceffcd49bd7ca3b01cbe8f539273dd6695
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 64
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 17/96
malicious

IPs

IP Country Detection
23.218.232.146
United States
2.23.197.184
European Union
178.79.238.128
European Union
Click to see the 5 hidden entries
54.144.73.197
United States
184.28.88.176
United States
154.216.17.175
Seychelles
184.28.90.27
United States
172.64.41.3
United States

URLs

Name Detection
http://goninvoicceme.shop:7070/bab.zip
http://goninvoicceme.shop:7070
https://nuget.org/nuget.exe
Click to see the 28 hidden entries
http://goninvoicceme.shop:7070/bab.zip6
http://goninvoicceme.shop:7070/FTSP.zipHOMEDRIVE=C:HOMEPATH=
https://g.live.com/odclientsettings/ProdV2
https://g.live.com/odclientsettings/ProdV2?OneDriveUpdate=f359a5df14f97b6802371976c96
http://goninvoicceme.shop:7070/bab.zipA
http://goninvoicceme.shop:7070/FTSP.zip
https://contoso.com/
http://goninvoicceme.shop:7070/FTSP.zip-.
http://goninvoicceme.shop:7070/bab.zipD
http://goninvoicceme.shop:7070/startupppp.bat
http://goninvoicceme.shop:7070/cam.zip
https://aka.ms/pscore68
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
https://g.live.com/1rewlive5skydrive/OneDriveProductionV2?OneDriveUpdate=9c123752e31a927b78dc96231b6
https://g.live.com/odclientsettings/Prod.C:
http://nuget.org/NuGet.exe
https://github.com/Pester/Pester
https://g.live.com/odclientsettings/ProdV2.C:
http://crl.ver)
http://goninvoicceme.shop:7070/bab.zipystem.Co
http://goninvoicceme.shop:7070/bab.zipe
https://contoso.com/Icon
https://contoso.com/License
http://goninvoicceme.shop:7070/FTSP.zipi
http://www.apache.org/licenses/LICENSE-2.0.html
https://go.microsoft.co
http://pesterbdd.com/images/Pester.png
http://crl.microsoftF

Dropped files

Name File Type Hashes Detection
C:\Users\user\Downloads\downloaded.zip
Zip archive data, at least v2.0 to extract, compression method=store
#