top title background image
flash

COTIZACION.exe

Status: finished
Submission Time: 2025-02-14 19:49:12 +01:00
Malicious
Trojan
Spyware
Evader
FormBook

Comments

Tags

  • exe

Details

  • Analysis ID:
    1615356
  • API (Web) ID:
    1615356
  • Analysis Started:
    2025-02-14 19:56:12 +01:00
  • Analysis Finished:
    2025-02-14 20:04:56 +01:00
  • MD5:
    8be86d725b21495e06f329302bdb0ea3
  • SHA1:
    a14a904b40a99f242aecf194626fdac6693b1da5
  • SHA256:
    9eff0d7534799160f8c8b4d4968d7a4640559aa2d3365e52ef4b8155426714b4
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 33/71
malicious
Score: 15/37
malicious

IPs

IP Country Detection
38.11.157.207
United States
13.248.169.48
United States
45.199.72.207
Seychelles
Click to see the 1 hidden entries
162.218.30.235
United States

Domains

Name IP Detection
www.gameo.info
13.248.169.48
www.tyxxg.net
38.11.157.207
www.l51127.xyz
162.218.30.235
Click to see the 1 hidden entries
www.banjia0731.icu
45.199.72.207

URLs

Name Detection
http://www.banjia0731.icu/z2tq/?2rbTSt=s0Z4ZRkbiqik9vPjSg43pAtjLY/tlS74CCNPmIm2Lyiw3C87nA6QFlAtn+fItF1xKA//mb/6EVWfPY/v6dv6pDK3z7PGfA0N/+xMyMrftHl9oB6dh+IdNTi8FFkRA9EzMkQcN98=&KRMPq=JjrHvXb0D
http://www.l51127.xyz/om1b/?2rbTSt=kSQYFGtLbPLkQ60IIbKeZOwZ46NymE4BhTmuy51VBfKqjYxUdo8IFJyHe1s0eTYFNTiKLuNaxmh2wOKHxsWDPvvca/4qlKTkHnX4SxeIJrUHUb2AyAabhZVL2PF7qqh/FpNQapc=&KRMPq=JjrHvXb0D
http://www.tyxxg.net/4cqa/?2rbTSt=K44yfA0NEK1biOMit4d22NwPZNkjxjpZMHq/2wsUTczYtmTMKtsBd5PeQGBy2LMCc9szoCk5meswZ7RUxaxMRZIdbx2wA00q6m9FdSxL1HXJqQK8dwEkMVDX/aLl9h7PgYQ8H2o=&KRMPq=JjrHvXb0D
Click to see the 16 hidden entries
http://www.l51127.xyz/om1b/
http://www.gameo.info/w62v/?2rbTSt=LpWTa1OMYJqM9xlTJ+fWVGnz2B7SKBW6Ge14HnknNyvG8jdAxw3O9wGMQRguY8tLb3ZOrp+G6vj9dYe1e1plDalPwP/+OWrxJe+UBuFwF4n7GuZ/p+FUZE1XSZcS7b7apJCE2wM=&KRMPq=JjrHvXb0D
http://www.gameo.info/w62v/
http://www.banjia0731.icu/z2tq/
https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
https://wx.longwaysun.com/app/register.php?site_id=2239&topId=87658/om1b/
https://wx.longwaysun.com/app/register.php?site_id=2239&topId=87658/om1b/
https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
https://www.ecosia.org/newtab/
https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
https://ac.ecosia.org/autocomplete?q=
https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search
https://www.google.com/images/branding/product/ico/googleg_lodp.ico
https://duckduckgo.com/ac/?q=
http://www.gameo.info
https://duckduckgo.com/chrome_newtab

Dropped files

No malicious files found. See full and IOC report for all dropped files.