top title background image
flash

invoice.exe

Status: finished
Submission Time: 2025-04-08 12:54:35 +02:00
Malicious
Trojan
Spyware
Evader
FormBook

Comments

Tags

  • exe
  • Formbook

Details

  • Analysis ID:
    1659303
  • API (Web) ID:
    1659303
  • Analysis Started:
    2025-04-08 13:49:25 +02:00
  • Analysis Finished:
    2025-04-08 14:01:03 +02:00
  • MD5:
    65a5a9d0548db34535e1a91f4b615ca2
  • SHA1:
    7136e664f2c36728002bd5201b529af76d121bfe
  • SHA256:
    f0ebef462be3f5a3007608c78291d21785276c979f10f52a6f3877f0695256a2
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 43/71
malicious
Score: 21/36

IPs

IP Country Detection
199.192.23.195
United States
144.76.229.203
Germany
66.232.12.45
Hong Kong
Click to see the 10 hidden entries
199.59.243.160
United States
84.32.84.32
Lithuania
46.202.146.35
Ukraine
150.95.255.38
Japan
81.169.145.84
Germany
132.148.219.254
United States
104.21.41.226
United States
13.248.169.48
United States
23.2.218.130
United States
23.46.224.56
United States

Domains

Name IP Detection
www.conegame.biz
104.21.41.226
www.031233793.xyz
0.0.0.0
www.quirkyden.site
199.192.23.195
Click to see the 20 hidden entries
hakzmkt.tech
84.32.84.32
www.circleksunkus.jp
150.95.255.38
www.immersivemoon.xyz
13.248.169.48
paylocap.net
132.148.219.254
blzxbet.pro
46.202.146.35
www.rwefzczx.club
66.232.12.45
stuhlmann.cloud
81.169.145.84
031233793.xyz
144.76.229.203
www.beds-campaign.sbs
199.59.243.160
www.ayase-bluesky.xyz
13.248.169.48
e7052.dsce6.akamaiedge.net
23.2.218.130
e1722.x.akamaiedge.net
23.46.224.56
www.blzxbet.pro
0.0.0.0
www.samsung.com
0.0.0.0
www.twistedradio.org
0.0.0.0
www.hakzmkt.tech
0.0.0.0
www.stuhlmann.cloud
0.0.0.0
www.paylocap.net
0.0.0.0
www.arte.tv
0.0.0.0
www.ofln.net
0.0.0.0

URLs

Name Detection
http://www.immersivemoon.xyz/91kh/
http://www.blzxbet.pro/v9xc/?c2Cx=yQ+SA7APvLi66KOr3SV/GmkGE1q7bIOnb3JBiNuJF+td1fq6aqGjtsJO1lBxLsBWjd9fdwB9gDfuci+HEjBEHfJGeScZCPrC0M39nL+ZOjeejZk/5S19zFk=&Jr7HL=oHLH7TbHez2dw2
http://www.quirkyden.site/qve4/?Jr7HL=oHLH7TbHez2dw2&c2Cx=V5h3t4mEZPOxxivZnI+Q6RkcvbS4cBcy/0aYxogNILvA7IMbMNuXHuP0r2t78o22ne95ZI5WEFVtVUDu8QIRI9l5aUA+ej0KhAfVJBLKYlo8uc4KDHxJna4=
Click to see the 48 hidden entries
http://www.rwefzczx.club/8vdf/
http://www.031233793.xyz/t73h/?c2Cx=aSIQPwmtlZ7B1sq8AzKxVPL8RLh6G4ARRoxmGuJHvJYjVnzmNELNdBjPjzwFpaZ4zd8dBfLbUjj8//Ul2ki5NVNsnmY/fXkLXsxb5XF2eGbriuaCyq5oefQ=&Jr7HL=oHLH7TbHez2dw2
http://www.circleksunkus.jp/b97w/?c2Cx=6wRcdFFemBS/axs1+L73v3AWA6jLNyLm/46j8GovUvSEtkRcssX3YnaOW0RdZMWW4Lx26ofVVJ24mhoU0796efIzp3jw1hnqIcvkyoUD52LQhh5r5ib9fXs=&Jr7HL=oHLH7TbHez2dw2
http://www.conegame.biz/uffx/
http://www.hakzmkt.tech/3koj/?c2Cx=ml+eGuPuFZwiO8eOInDGz6TKzxDD4zeVrhzRNWrjdJFU6pWp1neReG5FFHPWDZZt/+wz1ez2rE1g94W6FLX8cmAsAFAd5I98y3Fi8TNtvP2IzIDyT27h7Jo=&Jr7HL=oHLH7TbHez2dw2
http://www.ayase-bluesky.xyz/qvek/?c2Cx=Y7WEsW3uPV1fOSxUHQ77hEqNh+Cthp+gJEcbilQzOhOjv1VVnuLhyS/oMRI3Io2Aca2eE5ipYwghpgkskMJ00uktUohamKnORcKyl8xiW8ICqituLxtJTH0=&Jr7HL=oHLH7TbHez2dw2
http://www.rwefzczx.club/8vdf/?c2Cx=5tzWDPulW7yXo74M6GiJDVpOK7Sghbcj87bYgvZzbn+0eQSOL2ojc9vHi1R4gxjrrxk3uDyd58n8kjmFt+uL1OzGlUCv4gmT5gtJxQ4TUUFxHtghXCGGziw=&Jr7HL=oHLH7TbHez2dw2
http://www.hakzmkt.tech/3koj/
http://www.blzxbet.pro/v9xc/
http://www.circleksunkus.jp/b97w/
http://www.paylocap.net/ne9d/?c2Cx=JOHH/OIwIvfEdnl2FQs0PcKaMl+Th4wVdJsMPo75EW23PejL0ySoeilhYfIZf0ptneU4NxjDJLiKxjyWxeVFm7lrkDQWw1maFJeokKZWVxYXswRCDpMAImQ=&Jr7HL=oHLH7TbHez2dw2
http://www.stuhlmann.cloud/03jb/
http://www.ayase-bluesky.xyz/qvek/
http://www.immersivemoon.xyz/91kh/?c2Cx=fiK42C+akWenYvsXhDpnFrlUPEPeYiLROnux50fADGKi/P4TF72gGZC1LLozXmUfGQLUHZvMwzVe/cklyzhRQJdsV9A7HFYGiMeGh2pr5d3tw5ns/Lf9sCk=&Jr7HL=oHLH7TbHez2dw2
http://www.beds-campaign.sbs/hz9o/
http://www.paylocap.net/ne9d/
http://www.031233793.xyz/t73h/
http://www.beds-campaign.sbs/hz9o/?Jr7HL=oHLH7TbHez2dw2&c2Cx=tgQSStQbFantdPvF4MMKYSIWwZGexS4HxLBo4s0d94kqhYgUFLEDa6dsmDFGnGB0/oMD2eZ3KZg+FFBvTlEGwPGJQXDlUo2B83N/HKi2AGuWx3Q+0sbP5S0=
http://www.quirkyden.site/qve4/
https://www.arte.tv/en/videos/RC-024146/duels-of-history/
https://arte.tv/en
https://arte.tv/es
https://www.ecosia.org/newtab/v20
https://arteptweb-a.akamaihd.net/am/404.mp4
https://duckduckgo.com/chrome_newtabv20
https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
http://www.rwefzczx.club
http://dfltweb1.onamae.com
https://duckduckgo.com/ac/?q=
https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
https://gemini.google.com/app?q=
https://arte.tv/fr
https://arte.tv/it
http://www.arte.tv/1nlz/?Jr7HL=oHLH7TbHez2dw2&c2Cx=xqPALbOjEXKSyMhZ2U4WpU5psI2oJpuvEQD+xn+lHN0VDI4+PZmBhv8tra60SI3DyrWytyTCwD0tZSTdu1DWSsaIRpGkOT5mLZxf0r+rM2hSnxtKjNnPa2E=
http://paylocap.net/ne9d/?c2Cx=JOHH/OIwIvfEdnl2FQs0PcKaMl
http://www.samsung.com/5ene/
https://www.arte.tv/en/videos/115289-000-A/arte-reportage/
https://www.google.com
https://ac.ecosia.org?q=
https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
https://www.google.com/images/branding/product/ico/googleg_alldp.ico
https://www.arte.tv/en/videos/RC-023954/haus-kummerveldt
https://www.arte.tv/error/current
https://www.samsung.com/5ene/?c2Cx=DfkJlK3RA4xJFe64
http://www.samsung.com/5ene/?c2Cx=DfkJlK3RA4xJFe64+Kxy2KATlJYEqSYke2qMqUdNyxfnGLgZJwMWK6vR2GF/ffskKe1SBvRalXLMw6+5S0VJ3ji8ToY7R6UCviOsWmtSXjymi2tOmlo9KtQ=&Jr7HL=oHLH7TbHez2dw2
https://arte.tv/de
https://arte.tv/pl
https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search

Dropped files

No malicious files found. See full and IOC report for all dropped files.