MS-Access Email Attachment Drops Keylogger | VMRay Analyzer Report
Try VMRay Analyzer
VTI SCORE: 100/100
Dynamic Analysis Report
Classification: Dropper, Keylogger, Downloader

18f0b09725c3f4cea286aae7fceaec0cd6e49f90c9aa72dcc9c6d748bfe716cd (SHA256)

October_Invoiceb91a6edbc0ialmb3ce5ebc15abba7fe01fda93.accde

Microsoft Access Database

Created at 2019-01-21 16:18:00

Top Threat Indicators (View all 40 threat indicators)

Screenshots

Monitored Processes

Analysis Information

Creation Time 2019-01-21 17:18 (UTC+1)
Analysis Duration 00:02:07
Number of Monitored Processes 15
Execution Successful True
Reputation Enabled True
WHOIS Enabled True
YARA Enabled True
Termination Reason Timeout
Tags
#keylogger #malware

Sample Information

ID #2186759
MD5 2601895cfe5909f5f66e98524bcd2aaf Copy to Clipboard
SHA1 c81a4306207d6aedd9d4ec5b6e4b828bca8e20ab Copy to Clipboard
SHA256 18f0b09725c3f4cea286aae7fceaec0cd6e49f90c9aa72dcc9c6d748bfe716cd Copy to Clipboard
SSDeep 768:JlRTCFe+9BdQBrZ4oq03yfXwfksidQpcjEAZrsbVzoFrROlK0GLxt7kzRM/dw/d8:Jl5CArZ4vI0dN+z0lI6L34uSy Copy to Clipboard
Filename October_Invoiceb91a6edbc0ialmb3ce5ebc15abba7fe01fda93.accde
File Size 336.00 KB
File Type Microsoft Access Database
Has VBA Macros False

Analyzer Information

Dynamic Analyzer Build Date 2019-01-08 13:30 (UTC+1)
Dynamic Analyzer Version 2.3.2
Static Analyzer Version 1.0.1
VTI Ruleset Version 3.1
YARA Built-in Ruleset Version 1.1
Analysis Report Layout Version 3
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image