top title background image
flash

hnsjdghf18.bat

Status: finished
Submission Time: 2024-12-18 13:23:21 +01:00
Malicious
Trojan
Evader
Abobus Obfuscator, Braodo

Comments

Tags

  • bat
  • Braodo
  • fgh8090051

Details

  • Analysis ID:
    1577480
  • API (Web) ID:
    1577480
  • Analysis Started:
    2024-12-18 14:09:01 +01:00
  • Analysis Finished:
    2024-12-18 14:16:13 +01:00
  • MD5:
    78f7b970aef1e7e11ab76f48ea6d6f6d
  • SHA1:
    d0127007d1282fe9ceeb67b9aa07487c234b36ae
  • SHA256:
    c011e23c9b8c8ba8e48c1e2361cf2ca4a3e35f4f8bcce48e521735518b762bdb
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 88
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

IPs

IP Country Detection
162.125.65.18
United States
172.65.251.78
United States

Domains

Name IP Detection
edge-block-www-env.dropbox-dns.com
162.125.69.15
gitlab.com
172.65.251.78
www-env.dropbox-dns.com
162.125.65.18
Click to see the 3 hidden entries
uc6f0e975c7c527b4946e568941e.dl.dropboxusercontent.com
0.0.0.0
www.dropbox.com
0.0.0.0
time.windows.com
0.0.0.0

URLs

Name Detection
https://go.micro
https://docs.google.com/document/fsip/
https://www.dropbox.com/scl/fi/mfmemsox3eb9769rgrajn/garmin_campaign_information_for_partners_v11.do
Click to see the 83 hidden entries
https://docs.sandbox.google.com/spreadsheets/fsip/
https://docs.sandbox.google.com/document/fsip/
https://github.com/Pester/Pester
http://www-env.dropbox-dns.com
https://www.dropbox.com/v/s/playlist/
https://gitlab.com/fgh8090051/jgh/-/raw/main/FGa1812.zip
https://contoso.com/Icon
https://new-sentry.gitlab.net
https://help.dropbox.com/
http://www.apache.org/licenses/LICENSE-2.0.html
https://uc6f0e975c7c527b4946e568941e.dl.dropboxusercontent.com/cd/0/get/CgfEtMNwovXdZnCu1e7QrxAJUcxy
http://pesterbdd.com/images/Pester.png
https://www.dropbox.com
https://www.dropbox.com/static/serviceworker/
https://showcase.dropbox.com/
http://nuget.org/NuGet.exe
https://onedrive.live.com/picker
https://www.recaptcha.net/
https://www.dropbox.com/playlist/
https://www.google.com/recaptcha/
https://www.dropbox.com/csp_log?policy_name=metaserver-whitelist
https://docs.google.com/spreadsheets/fsip/
https://www.paypal.com/sdk/js
https://cfl.dropboxstatic.com/static/
https://app.hellofax.com/
https://dl-web.dropbox.com/
https://www.dropbox.com/scl/fi/mfmemsox3eb9769rgrajn/Garmin_Campaign_Information_for_Partners_V11.docx?rlkey=oy421vwzu8dsedagxt4w0ddsw&st=31jc5byu&dl=1
https://docs.sandbox.google.com/presentation/fsip/
https://aka.ms/pscore68
https://sourcegraph.com
https://docsend.com/
https://selfguidedlearning.dropboxbusiness.com/
https://gitlab.com/-/speedscope/index.html
https://2e83413d8036243b-Dropbox-pal-live.adyenpayments.com/
https://customers.gitlab.com
https://gitlab.com/admin/
https://gitlab.com/-/sandbox/
https://canny.io/sdk.js
https://docs.google.com/presentation/fsip/
http://uc6f0e975c7c527b4946e568941e.dl.dropboxusercontent.com
https://app.hellosign.com/
https://photos.dropbox.com/
https://sales.dropboxbusiness.com/
https://www.dropbox.com/pithos/
https://www.dropbox.com/
https://gitlab.com
https://www.dropbox.com/page_success/
https://instructorledlearning.dropboxbusiness.com/
https://gitlab.com/fgh8090051/jgh/-/raw/main/fga1812.zip
https://www.hellosign.com/
https://collector.prd-278964.gl-product-analytics.com
https://a.sprig.com/
https://snowplow.trx.gitlab.net
https://contoso.com/License
http://www.microsoft.co
https://paper.dropbox.com/cloud-docs/edit
http://www.dropbox.com
https://pal-test.adyen.com
https://www.hellofax.com/
https://paper.dropbox.com/
https://gitlab.com/-/sandbox/;
https://www.dropbox.com/service_worker.js
https://www.dropbox.com/static/api/
https://www.dropbox.com/scl/fi/mfmemsox3eb99r
https://login.yahoo.com/
https://uc6f0e975c7c527b4946e568941e.dl.dropboxusercontent.com
https://sentry.gitlab.net
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
https://api.login.yahoo.com/
https://officeapps-df.live.com
https://apis.google.com
https://www.dropboxstatic.com/static/
http://edge-block-www-env.dropbox-dns.com
http://gitlab.com
https://www.dropbox.com/scl/fi/mfmemsox3eb9769rgrajn/Garmin_Campaign_Information_for_Partners_V11.do
https://nuget.org/nuget.exe
https://contoso.com/
https://navi.dropbox.jp/
https://new-sentry.gitlab.net/api/4/security/?sentry_key=f5573e26de8f4293b285e556c35dfd6e&sentry_env
https://gitlab.com/assets/
http://crl.m0
https://www.dropbox.com/encrypted_folder_download/service_worker.js
https://www.docsend.com/

Dropped files

Name File Type Hashes Detection
C:\Users\Public\Document.zip
Zip archive data, at least v2.0 to extract, compression method=deflate
#