top title background image
flash

ISF-docBL#MIQOKHH009171-811-25-01347-811033.scr.exe

Status: finished
Submission Time: 2025-03-27 12:55:39 +01:00
Malicious
Ransomware
Trojan
Spyware
Exploiter
Evader
DBatLoader, Remcos

Comments

Tags

  • exe

Details

  • Analysis ID:
    1650073
  • API (Web) ID:
    1650073
  • Analysis Started:
    2025-03-27 12:55:41 +01:00
  • Analysis Finished:
    2025-03-27 13:07:12 +01:00
  • MD5:
    6b2882f79966dcc945228aedfe49f50f
  • SHA1:
    c42021d816b505c7771eb3f3877783494154d7e4
  • SHA256:
    3fa271144c7a9185fdb82951db8a4aa94c38e94e1dbdcbe6e00f2e18591387f5
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 27/73
malicious
Score: 11/36
malicious

IPs

IP Country Detection
104.250.180.178
United States

URLs

Name Detection
http://geoplugin.net/json.gp
http://geoplugin.net/json.gp/C
http://www.pmail.com

Dropped files

Name File Type Hashes Detection
C:\ProgramData\WSP\wsp.exe
PE32 executable (GUI) Intel 80386, for MS Windows
#
C:\ProgramData\WSP\wsp.exe:Zone.Identifier
ASCII text, with CRLF line terminators
#
C:\Users\Public\alpha.pif
PE32 executable (console) Intel 80386, for MS Windows
#
Click to see the 1 hidden entries
C:\Users\user\Links\Woqkdcmz.PIF
PE32 executable (GUI) Intel 80386, for MS Windows
#