Injector Spyware Downloader
FormBook Mal/HTMLGen-A
Created on 2022-01-12T09:04:00
ea4815e7334c8e7663cf1ae6551bdd5233544ea0403edee6c77f0a49d9e795fe.doc.rtf
Remarks (1/1)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "3 hours, 9 minutes" to "4 seconds" to reveal dormant functionality.
Remarks
(0x0200004A): 31 dumps were skipped because they exceeded the maximum dump size of 7 MB. The largest one was 9 MB.
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
C:\Users\kEecfMwgj\Desktop\ea4815e7334c8e7663cf1ae6551bdd5233544ea0403edee6c77f0a49d9e795fe.doc.rtf | Sample File | RTF |
malicious
|
...
|
CLSID | Control Name | Associated Vulnerability |
---|---|---|
{00021700-0000-0000-C000-000000000046} | Equation3 | CVE-2017-11882 |
.-+/9=,?8)??_1&[]'/5*$[])]52%4<!)</=%!=|8*63<`3~77`?%$+=°83+?9_&?^239`_|.<*|4,4!?-)]=]|.:)`6!;&%9!=))>^?6@#%?;&/.^µ/<<`,'>?2°<*?/~3?.°%6#7°?2(|7&9[2@991?_µ<?)<,+[*&1;|$#2?/80),(%(??'?#!§6**((=0§)/8);^@:(?`|&!:8+>(7?]-?%$*3$8,1&5;*6%%2[$465&0^996°~=36>@!/6%0%9'`%§=#%@?7*?~4''°0^'8|4&°7%?7))-|@?']°*_(:;0°9=<^*0?*#>|#10391?$55$9'^`!^$&[&&)/3|$?%~?6?85:`~7%)/$'9`<])):?7°0µ31(?#4=:5%,%$]/%_[`)<8>&%](*#$&2)~|<@(??°!@[^=*7-2+-6)?3|°,?/*]-%?=,@-;)(%=_?>µ~621`|+;74?(?:,|%3:%°?~|???*$?°@&.;'@]?>.§-?-°_%'~`~%'??];°6?|`0%7|7µ>&+@571|@<)9-(#~.,°=>;µ)]?_]1?)_?%88?.6°^°µ22~<7;>+0*!4645&~[^@§6'^,3°!34?3_|04?|~?§7[?/>6;=+=<µ/@8?~%~+21'34>$.?(>1#<&;['0%.6(?/5-!03?/4:#23@5/?%854!(9!?,;%<*]#79],2_3:6>§($4~74=?2~.],#%&0$=]1'2][§???2°<]8/8+-|)2^>@$1)_:~°:§?:µ ... |
C:\Users\kEecfMwgj\AppData\Roaming\emehtq569783.exe | Downloaded File | Binary |
malicious
|
...
|
Image Base | 0x400000 |
Entry Point | 0x46282a |
Size Of Code | 0x60a00 |
Size Of Initialized Data | 0x4c00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2022-01-12 07:25:23+00:00 |
Comments | A simple mechanism to maintain state for an activity based workflow |
CompanyName | Development In Progress Ltd |
FileDescription | DipState |
FileVersion | 2.0.0.0 |
InternalName | ICustomFacto.exe |
LegalCopyright | Copyright © Development In Progress Ltd 2015 |
LegalTrademarks | - |
OriginalFilename | ICustomFacto.exe |
ProductName | DipState |
ProductVersion | 2.0.0.0 |
Assembly Version | 2.0.0.0 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x60830 | 0x60a00 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.94 |
.rsrc | 0x464000 | 0x4974 | 0x4a00 | 0x60c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.5 |
.reloc | 0x46a000 | 0xc | 0x200 | 0x65600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.1 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | - | 0x402000 | 0x62800 | 0x60a00 | 0x0 |
c:\users\keecfmwgj\appdata\local\temp\eqnedt32.exe_c2rdll(20220112100537e28).log | Dropped File | Unknown |
clean
|
...
|
c:\users\keecfmwgj\appdata\local\gdipfontcachev1.dat | Dropped File | Stream |
clean
|
...
|
c:\users\keecfmwgj\appdata\local\gdipfontcachev1.dat | Dropped File | Stream |
clean
|
...
|
55f7d9e99b8e2d4e0e193b2f0275501e6d9c1ebd29cadbea6a0da48a8587e3e0 | Downloaded File | HTML |
clean
|
...
|
34ac32c933e5657c15aae33f37b622622824c1ebad245fbe40ca978a0011b110 | Downloaded File | HTML |
clean
|
...
|
URL | WHOIS Data | Reputation Status | Recursively Submitted | Actions |
---|---|---|---|---|
http://www.llanoseeds.com/?fp=US0cBv4hO4%2FEXCAat%2FL8T%2BI3d7q%2FWLs7H10MXhUDRP00piJqofs9RciFzUeJ4dAPhk5lKTIzIgFGs6UevJ8S3G05xwxBcD8EKnhOC0j45UFrussGngKSeSMQzI%2FxxaPakbbhKCfBwEm0sPEXC1%2BFQ441ZoGXY%2Fai7qj4tZEHszQ%3D&prvtof=APjFMagVHmXZmMxBTa4tNrbd8xn84H4eLE7nfwB08%2Fo%3D&poru=DnwXWmqUctv1Y9LrrMWizp%2Ben%2Fh%2BO1vrBjR%2FU0bq0G5Kph%2FNsWYkWxINOG6NogWrnH7NlgxYyCioXRzO8fQEPrlhSqUZ1CQsN3UL8NSiYsbxaHlzmRqhpQO9is4t1HTovvsf2p2eUhTgUvdhQCfYQIUaGha1hmQ5upKQQGbAo0umZiZEznmP3Jk7oM7m%2FL4a&ETy8ylH=QjR0XO%2FGWxg%2FkjqJnnS1FPijs6ugBsokGDpgJVo%2FGmOQlmLwqOJrBMenz05kxRv6P+2xEQGl&OT80=ZvaxiRmh |
Show WHOIS
|
N/A
|
- |
...
|
http://www.llanoseeds.com/?fp=US0cBv4hO4%2FEXCAat%2FL8T%2BI3d7q%2FWLs7H10MXhUDRP00piJqofs9RciFzUeJ4dAPhk5lKTIzIgFGs6UevJ8S3G05xwxBcD8EKnhOC0j45UFrussGngKSeSMQzI%2FxxaPakbbhKCfBwEm0sPEXC1%2BFQ441ZoGXY%2Fai7qj4tZEHszQ%3D&prvtof=75N%2FamSPE2quOIgoyDwVNshsA%2Fj%2Fj%2BiLc1g94AbgRrE%3D&poru=5mZ1fWV7tzTRoRVsxnyehMkJB8zmRKosHktnGJqS5YzBiRumIoNz8qC%2BLKhaSdk%2FZBVaRzpeorXapAfC1mCvlLmb4azyEoe%2FfvRMFZb6FrL00%2Fku5xVaRcWqA0toUY6CumetOhg%2BJAUQ2mOnEJ19Ni94IyNLfZM3LlcayHi2UvyFzeD7ofiF6yGW14UaTfHz&ETy8ylH=QjR0XO%2FGWxg%2FkjqJnnS1FPijs6ugBsokGDpgJVo%2FGmOQlmLwqOJrBMenz05kxRv6P+2xEQGl&OT80=ZvaxiRmh |
Show WHOIS
|
N/A
|
- |
...
|
try{document.cookie = 'isframesetenabled=1; path=/;';}catch(exception){}
25bd01828c3bd5293a36bc4ced54d560e5dc3b33464d814e5bff6368ea5a29a8 | Downloaded File | HTML |
clean
|
...
|
URL | WHOIS Data | Reputation Status | Recursively Submitted | Actions |
---|---|---|---|---|
http://www.qq.com/404/search_children.js |
Show WHOIS
|
N/A
|
- |
...
|
79928810a4d3d425ae3767c90e990df1e9fd34798ec6ebbac69f0d2d575b3246 | Downloaded File | HTML |
clean
|
...
|
URL | WHOIS Data | Reputation Status | Recursively Submitted | Actions |
---|---|---|---|---|
http://head754246.myorderbox.com/linkhandler/servlet/RenewDomainServlet?validatenow=false&orderid=98297688&role=customer |
Show WHOIS
|
N/A
|
- |
...
|
http://www.school-prosto.store |
Show WHOIS
|
N/A
|
- |
...
|
http://www.school-prosto.store/Anti_Wrinkle_Creams.cfm?fp=l87I1JsRijIhUaKYzG14poZ9EuXB0RFIic4LNN5BwQo7CdEdtUpYwqTMj5vQTDv%2BSX0IMcW3CB8P4BebnBxGFJ6E7oA197De3PLIH7Tu6BChgq9KDY74m7Sj2NOEYLi2d1228sBv%2BwfWhvVdWg7mZgbxWNiH3rDr3t2KHolilrDVALsHxFY%2FFCTBgpgyM8aikojeLmM%2FIhV4BORTiZ4Epw%3D%3D&kbetu=1&maxads=0&kld=1061&prvtof=wXdhG6Ld75vZgmZPGDO9nyws5oCYcc4%2F96N0Mt%2FhaS8%3D&ETy8ylH=vtDhz8EkqI1GNUSgsThQbC9R7or5Lo1HKyrysTnaT+XPPVEx+OYfUj9d1VVYwOfWlSM5mVvH&OT80=ZvaxiRmh&&kt=112&&ki=1919926&ktd=0&kld=1061&kp=1 |
Show WHOIS
|
N/A
|
- |
...
|
http://www.school-prosto.store/fashion_trends.cfm?fp=l87I1JsRijIhUaKYzG14poZ9EuXB0RFIic4LNN5BwQo7CdEdtUpYwqTMj5vQTDv%2BSX0IMcW3CB8P4BebnBxGFJ6E7oA197De3PLIH7Tu6BChgq9KDY74m7Sj2NOEYLi2d1228sBv%2BwfWhvVdWg7mZgbxWNiH3rDr3t2KHolilrDVALsHxFY%2FFCTBgpgyM8aikojeLmM%2FIhV4BORTiZ4Epw%3D%3D&kbetu=1&maxads=0&kld=1061&prvtof=wXdhG6Ld75vZgmZPGDO9nyws5oCYcc4%2F96N0Mt%2FhaS8%3D&ETy8ylH=vtDhz8EkqI1GNUSgsThQbC9R7or5Lo1HKyrysTnaT+XPPVEx+OYfUj9d1VVYwOfWlSM5mVvH&OT80=ZvaxiRmh&&kt=112&&ki=10542279&ktd=0&kld=1061&kp=2 |
Show WHOIS
|
N/A
|
- |
...
|
http://www.school-prosto.store/Healthy_Weight_Loss.cfm?fp=l87I1JsRijIhUaKYzG14poZ9EuXB0RFIic4LNN5BwQo7CdEdtUpYwqTMj5vQTDv%2BSX0IMcW3CB8P4BebnBxGFJ6E7oA197De3PLIH7Tu6BChgq9KDY74m7Sj2NOEYLi2d1228sBv%2BwfWhvVdWg7mZgbxWNiH3rDr3t2KHolilrDVALsHxFY%2FFCTBgpgyM8aikojeLmM%2FIhV4BORTiZ4Epw%3D%3D&kbetu=1&maxads=0&kld=1061&prvtof=wXdhG6Ld75vZgmZPGDO9nyws5oCYcc4%2F96N0Mt%2FhaS8%3D&ETy8ylH=vtDhz8EkqI1GNUSgsThQbC9R7or5Lo1HKyrysTnaT+XPPVEx+OYfUj9d1VVYwOfWlSM5mVvH&OT80=ZvaxiRmh&&kt=112&&ki=13454597&ktd=0&kld=1061&kp=3 |
Show WHOIS
|
N/A
|
- |
...
|
http://www.school-prosto.store/Best_Mortgage_Rates.cfm?fp=l87I1JsRijIhUaKYzG14poZ9EuXB0RFIic4LNN5BwQo7CdEdtUpYwqTMj5vQTDv%2BSX0IMcW3CB8P4BebnBxGFJ6E7oA197De3PLIH7Tu6BChgq9KDY74m7Sj2NOEYLi2d1228sBv%2BwfWhvVdWg7mZgbxWNiH3rDr3t2KHolilrDVALsHxFY%2FFCTBgpgyM8aikojeLmM%2FIhV4BORTiZ4Epw%3D%3D&kbetu=1&maxads=0&kld=1061&prvtof=wXdhG6Ld75vZgmZPGDO9nyws5oCYcc4%2F96N0Mt%2FhaS8%3D&ETy8ylH=vtDhz8EkqI1GNUSgsThQbC9R7or5Lo1HKyrysTnaT+XPPVEx+OYfUj9d1VVYwOfWlSM5mVvH&OT80=ZvaxiRmh&&kt=112&&ki=3477850&ktd=0&kld=1061&kp=4 |
Show WHOIS
|
N/A
|
- |
...
|
http://www.school-prosto.store/10_Best_Mutual_Funds.cfm?fp=l87I1JsRijIhUaKYzG14poZ9EuXB0RFIic4LNN5BwQo7CdEdtUpYwqTMj5vQTDv%2BSX0IMcW3CB8P4BebnBxGFJ6E7oA197De3PLIH7Tu6BChgq9KDY74m7Sj2NOEYLi2d1228sBv%2BwfWhvVdWg7mZgbxWNiH3rDr3t2KHolilrDVALsHxFY%2FFCTBgpgyM8aikojeLmM%2FIhV4BORTiZ4Epw%3D%3D&kbetu=1&maxads=0&kld=1061&prvtof=wXdhG6Ld75vZgmZPGDO9nyws5oCYcc4%2F96N0Mt%2FhaS8%3D&ETy8ylH=vtDhz8EkqI1GNUSgsThQbC9R7or5Lo1HKyrysTnaT+XPPVEx+OYfUj9d1VVYwOfWlSM5mVvH&OT80=ZvaxiRmh&&kt=112&&ki=72996&ktd=0&kld=1061&kp=5 |
Show WHOIS
|
N/A
|
- |
...
|
http://www.school-prosto.store/music_videos.cfm?fp=l87I1JsRijIhUaKYzG14poZ9EuXB0RFIic4LNN5BwQo7CdEdtUpYwqTMj5vQTDv%2BSX0IMcW3CB8P4BebnBxGFJ6E7oA197De3PLIH7Tu6BChgq9KDY74m7Sj2NOEYLi2d1228sBv%2BwfWhvVdWg7mZgbxWNiH3rDr3t2KHolilrDVALsHxFY%2FFCTBgpgyM8aikojeLmM%2FIhV4BORTiZ4Epw%3D%3D&kbetu=1&maxads=0&kld=1061&prvtof=wXdhG6Ld75vZgmZPGDO9nyws5oCYcc4%2F96N0Mt%2FhaS8%3D&ETy8ylH=vtDhz8EkqI1GNUSgsThQbC9R7or5Lo1HKyrysTnaT+XPPVEx+OYfUj9d1VVYwOfWlSM5mVvH&OT80=ZvaxiRmh&&kt=112&&ki=19945831&ktd=0&kld=1061&kp=6 |
Show WHOIS
|
N/A
|
- |
...
|
http://www.school-prosto.store/Accident_Lawyers.cfm?fp=l87I1JsRijIhUaKYzG14poZ9EuXB0RFIic4LNN5BwQo7CdEdtUpYwqTMj5vQTDv%2BSX0IMcW3CB8P4BebnBxGFJ6E7oA197De3PLIH7Tu6BChgq9KDY74m7Sj2NOEYLi2d1228sBv%2BwfWhvVdWg7mZgbxWNiH3rDr3t2KHolilrDVALsHxFY%2FFCTBgpgyM8aikojeLmM%2FIhV4BORTiZ4Epw%3D%3D&kbetu=1&maxads=0&kld=1061&prvtof=wXdhG6Ld75vZgmZPGDO9nyws5oCYcc4%2F96N0Mt%2FhaS8%3D&ETy8ylH=vtDhz8EkqI1GNUSgsThQbC9R7or5Lo1HKyrysTnaT+XPPVEx+OYfUj9d1VVYwOfWlSM5mVvH&OT80=ZvaxiRmh&&kt=112&&ki=795812&ktd=0&kld=1061&kp=7 |
Show WHOIS
|
N/A
|
- |
...
|
http://www.school-prosto.store/sk-privacy.php |
Show WHOIS
|
N/A
|
- |
...
|
http://www.school-prosto.store/px.js?ch=1 |
Show WHOIS
|
N/A
|
- |
...
|
http://www.school-prosto.store/px.js?ch=2 |
Show WHOIS
|
N/A
|
- |
...
|
http://i4.cdn-image.com/__media__/js/min.js?v2.3 |
Show WHOIS
|
N/A
|
- |
...
|
http://www.school-prosto.store/display.cfm |
Show WHOIS
|
N/A
|
- |
...
|
var abp;
function handleABPDetect(){try{if(!abp) return;var imglog = document.createElement("img");imglog.style.height="0px";imglog.style.width="0px";imglog.src="http://www.school-prosto.store/sk-logabpstatus.php?a=QUxnMW5FNmE2eUxNRTNjU2owdE52ZHd1Z2hGQ0JPUkdMZW5ub0ZvZ0RYNm5xdUhVRnZ5UHhMY3FJWUcvZzJTVDNQVEpBcmtSRXlXYkorRmdKSnMvSmk4ZlZueFVhMEU4alQ1MWhuczZpQ09TUXpZUTd2T3h4SndtMWZXdHB3Wkw=&b="+abp;document.body.appendChild(imglog);if(typeof abperurl !== "undefined" && abperurl!="")window.top.location=abperurl;}catch(err){}}
try{handleABPDetect();}catch(err){}
if(setBrowserDetails) setBrowserDetails();
var __pp = []; atevt();
650b12f93748bb37bef17e446e31d3805ab48db0f6801cb53bd1901c4e9ea134 | Downloaded File | HTML |
clean
|
...
|
5bd9706fd44fe90cc287e6398c8a6a2fcbec106b51befd69902bfdcbd96b2162 | Downloaded File | HTML |
clean
|
...
|
URL | WHOIS Data | Reputation Status | Recursively Submitted | Actions |
---|---|---|---|---|
https://www.google.com |
Show WHOIS
|
N/A
|
- |
...
|
https://parking.bodiscdn.com |
Show WHOIS
|
N/A
|
- |
...
|
https://fonts.googleapis.com |
Show WHOIS
|
N/A
|
- |
...
|
window.park = "eyJ1dWlkIjoiYjFmMzk1ZDItNjNkNi0wODM5LWJiYmMtZGRlODI4MzAwMDNhIiwicGFnZV90aW1lIjoxNjQxOTc4NTc1LCJwYWdlX3VybCI6Imh0dHA6XC9cL3d3dy5wcmlvcmxha2VjYXJwZXRjbGVhbmluZy5jb21cL2J0MzNcLz9FVHk4eWxIPTE2bTd2aFdnY3JBK3dRNnlETGpyUkpSREFzN3Z1TFJIbVJmWVVIaGZxb3JRemNLa201ZythRVIreG5QbkZmMll3OVhXUDVOVCZPVDgwPVp2YXhpUm1oIiwicGFnZV9tZXRob2QiOiJHRVQiLCJwYWdlX3JlcXVlc3QiOnsiRVR5OHlsSCI6IjE2bTd2aFdnY3JBIHdRNnlETGpyUkpSREFzN3Z1TFJIbVJmWVVIaGZxb3JRemNLa201ZyBhRVIgeG5QbkZmMll3OVhXUDVOVCIsIk9UODAiOiJadmF4aVJtaCJ9LCJwYWdlX2hlYWRlcnMiOnsiY29ubmVjdGlvbiI6WyJjbG9zZSJdLCJob3N0IjpbInd3dy5wcmlvcmxha2VjYXJwZXRjbGVhbmluZy5jb20iXX0sImhvc3QiOiJ3d3cucHJpb3JsYWtlY2FycGV0Y2xlYW5pbmcuY29tIiwiaXAiOiI4NC4xODIuMjQ4LjE0MyJ9";
bb39114d204e3749044b0ac7e2b2039ec10feee4713d962432dd18317553310d | Downloaded File | HTML |
clean
|
...
|
URL | WHOIS Data | Reputation Status | Recursively Submitted | Actions |
---|---|---|---|---|
http://www.aodiskoo.com |
Show WHOIS
|
N/A
|
- |
...
|