top title background image
flash

LHRUnlocker Install.msi

Status: finished
Submission Time: 2022-02-23 18:45:07 +01:00
Malicious
Evader

Comments

Tags

Details

  • Analysis ID:
    577501
  • API (Web) ID:
    945026
  • Analysis Started:
    2022-02-23 18:48:22 +01:00
  • Analysis Finished:
    2022-02-23 18:58:43 +01:00
  • MD5:
    ca17c1bbedc959ad89f1c1dbf6b7aa32
  • SHA1:
    d24658face1f6fd3b457d7250c9b1a630798678d
  • SHA256:
    8fb46d2d56dd411ad10862204849abf9a4546f1ab1d40bcb6b0cac284debc055
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 45
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

URLs

Name Detection
http://schemas.xmlsoap.org/wsdl/
https://github.com/Pester/Pester
http://www.winimage.com/zLibDll1.2.7rbr
Click to see the 20 hidden entries
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
http://www.apache.org/licenses/LICENSE-2.0.html0
http://www.winimage.com/zLibDll
https://www.advancedinstaller.com
https://contoso.com/Icon
https://contoso.com/License
https://t.me/LHRUnlockerChannelButtonText_Finish&FinishManufacturerSergeyProductCode
https://nuget.org/nuget.exe
https://contoso.com/
https://t.me/LHRUnlockerMSIFASTINSTALLAI_CURRENT_YEAR2022ButtonText_Decline&DeclineAI_PREDEF_LCONDS_
https://www.thawte.com/repository0W
https://go.micro
https://drivers.sergeydev.com/windows/511.65-desktop-win64bit-interr
http://www.apache.org/licenses/LICENSE-2.0.html
http://schemas.xmlsoap.org/soap/encoding/
https://www.thawte.com/cps0/
http://pesterbdd.com/images/Pester.png
https://github.com/Pester/Pester0
http://pesterbdd.com/images/Pester.png0
http://nuget.org/NuGet.exe

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Temp\pss341F.ps1
Little-endian UTF-16 Unicode text, with CRLF, CR line terminators
#
C:\Users\user\AppData\Local\Temp\scr3351.ps1
Little-endian UTF-16 Unicode text, with CR line terminators
#