top title background image
flash

gwui.dll

Status: finished
Submission Time: 2022-02-09 00:06:03 +01:00
Malicious
Trojan
Evader
CobaltStrike

Comments

Tags

Details

  • Analysis ID:
    568947
  • API (Web) ID:
    936475
  • Analysis Started:
    2022-02-09 00:06:04 +01:00
  • Analysis Finished:
    2022-02-09 00:18:13 +01:00
  • MD5:
    ac581207ef80437a961f2ada3a47d763
  • SHA1:
    62964395bbc5fbee65dac62e0233ce8377674b2c
  • SHA256:
    b6262f4aa06d0bf045d95e3fcbc142f1d1d98f053da5714e3570482f0cf93b65
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

IPs

IP Country Detection
23.82.140.91
United States

Domains

Name IP Detection
foxofeli.com
23.82.140.91

URLs

Name Detection
http://foxofeli.com:443/image-directory/dhl.jpg
https://foxofeli.com/s
https://foxofeli.com/template.css?controller=truek
Click to see the 97 hidden entries
https://foxofeli.com/template.css?controller=trueh
https://foxofeli.com/template.css?controller=true2/
https://foxofeli.com/template.css?controller=truen
https://foxofeli.com/template.css?controller=trueo
https://foxofeli.com/template.css?controller=true899f5f57b9a:
https://foxofeli.com/ofeli.com/template.css?controller=true
https://foxofeli.com/template.css?controller=trueR
https://foxofeli.com/template.css?controller=trueS
https://foxofeli.com/template.css?controller=trueQ
https://foxofeli.com/image-directory/dhl.jpgvMY
https://foxofeli.com/template.css?controller=trueeople
https://foxofeli.com/template.css?controller=true899f5f57b9aR
https://foxofeli.com/~
https://foxofeli.com/template.css?controller=trueX
https://foxofeli.com/template.css?controller=trueY
https://foxofeli.com/template.css?controller=trueder)/
https://foxofeli.com/template.css?controller=truederJ/
https://foxofeli.com/e
https://foxofeli.com/template.css?controller=true;/
https://weibo.com/template.css?controller=true
https://foxofeli.com/k
https://foxofeli.com/template.css?controller=truederE/
https://foxofeli.com/W
https://foxofeli.com/template.css?controller=true99
https://foxofeli.com/template.css?controller=trueG
https://foxofeli.com/template.css?controller=trueJ
https://foxofeli.com/template.css?controller=trueK
https://foxofeli.com/template.css?controller=trues/
https://foxofeli.com/template.css?controller=true899f5f57b9aad
https://foxofeli.com/template.css?controller=trueO
https://foxofeli.com/template.css?controller=true(A
https://foxofeli.com/template.css?controller=true)/
https://foxofeli.com/template.css?controller=true3
https://foxofeli.com/template.css?controller=trueJ/
https://foxofeli.com/he
https://foxofeli.com/template.css?controller=truederf/
https://foxofeli.com/template.css?controller=true;
https://foxofeli.com/=true
https://foxofeli.com/template.css?controller=true?
https://foxofeli.com/0?;
https://weibo.com/image-directory/dhl.jpg
https://foxofeli.com/template.css?controller=true899f5f57b9aF
https://foxofeli.com/nd-point:
https://foxofeli.com/template.css?controller=trueg
https://foxofeli.com/template.css?controller=trued
https://foxofeli.com/template.css?controller=trueder2/
https://foxofeli.com/template.css?controller=trueIZ
https://foxofeli.com/template.css?controller=true899f5f57b9a
https://foxofeli.com/3
https://foxofeli.com/template.css?controller=trueE/
https://foxofeli.com/template.css?controller=truef/
https://foxofeli.com/template.css?controller=truent:
https://foxofeli.com/-
https://foxofeli.com/template.css?controller=trueder;
https://foxofeli.com//
https://foxofeli.com/0
https://foxofeli.com/template.css?controller=trueo/
https://foxofeli.com/template.css?controller=trueder./
https://foxofeli.com/ofeli.com/template.css?controller=trueder
https://foxofeli.com/c-4899f5f57b9a(
https://foxofeli.com/ptography
https://foxofeli.com/template.css?controller=truex/
https://foxofeli.com/template.css?controller=truederx/
https://foxofeli.com/c-4899f5f57b9aad
https://foxofeli.com/c-4899f5f57b9a:
https://foxofeli.com/template.css?controller=trueILMEM8
https://foxofeli.com/template.css?controller=true5Z
https://foxofeli.com/template.css?controller=true./
https://foxofeli.com/image-directory/dhl.jpgs
https://foxofeli.com/image-directory/dhl.jpg3d
https://foxofeli.com/=truederC
https://foxofeli.com/image-directory/dhl.jpgwdI
https://foxofeli.com/M
https://foxofeli.com/Q
https://foxofeli.com/R
https://foxofeli.com/S
https://foxofeli.com/template.css?controller=trueows
https://foxofeli.com/_
http://www.mioft.
https://foxofeli.com/Z
https://foxofeli.com/template.css?controller=true#
https://foxofeli.com/F
https://foxofeli.com/template.css?controller=true$
https://foxofeli.com/C
https://foxofeli.com/template.css?controller=true
https://foxofeli.com/a2tlbWNoY2ZlZGlqaGFnZmtqb2dlaGdrYmVjamRlam5ub2FoY2pka2lkZ2prZWtlb2prbmptYmFsY2l
https://foxofeli.com/vide0
https://foxofeli.com/O
https://foxofeli.com/template.css?controller=true.
https://foxofeli.com/
https://foxofeli.com/J
https://foxofeli.com/template.css?controller=true;S
https://foxofeli.com/K
https://foxofeli.com/template.css?controller=truegraphy
https://foxofeli.com/image-directory/dhl.jpgwn
https://foxofeli.com/template.css?controller=trueabledX
https://foxofeli.com/c-4899f5f57b9a

Dropped files

No malicious files found. See full and IOC report for all dropped files.