VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Spyware
Keylogger
Exploit
...
|
Threat Names: |
Exploit.RTF-ObfsStrm.Gen
Gen:Variant.Graftor.807433
VBS.Heur.Laburrak.7.Gen
...
|
tmpeml_attach_for_scan8939506995a312b8dcb233913095b87d.file.rtf
RTF Document
Created at 2020-08-04T23:24:00
Remarks (2/2)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "2 hours, 8 minutes, 9 seconds" to "1 minute, 20 seconds" to reveal dormant functionality.
Indicators
File (113)
»
Registry (366)
»
Mutex (2)
»
Mutex Name | Operations |
---|---|
Access | |
C:\Users\aETAdzjz\AppData\Roaming\DUE.exe | Access |
Domain (5)
»
URL (2)
»
URL | Operations | Category | Severity |
---|---|---|---|
http://sadiqgill.com/assets/fonts/EIC.exe | GET | Contacted |
Blacklisted
|
http://api.ipify.org/ | GET | Contacted |
Unknown
|
IP (14)
»