Analyzing...
|
File Name:   1710151010_10.exe
SHA1:   f93d38089fbe0ef17b8ed44412bd3b40e65edecb
MD5:   3426d42bb915adcd5c364cde0ddc6f78
First Seen Date:  2017-10-28 17:10:28.712709 ( )
Number of Clients Seen:   3
Last Analysis Date:  2017-10-28 17:10:28.712709 ( )
Human Expert Analysis Result:   No human expert analysis verdict given to this sample yet.
Analysis Summary
Analysis Type | Date | Verdict | |
---|---|---|---|
Signature Based Detection | 2017-10-28 17:10:28.712709 | Malware | |
Static Analysis Overall Verdict | 2017-10-28 17:10:28.712709 | No Threat Found | help |
Precise Detectors Overall Verdict | 2017-10-28 17:10:28.712709 | No Match | help |
Static Analysis
Static Analysis Overall Verdict | Result |
---|---|
No Threat Found | help |
Detector | Result | |
---|---|---|
Optional Header LoaderFlags field is valued illegal | Clean | |
Non-ascii or empty section names detected | Clean | |
Illegal size of optional Header | Clean | |
Packer detection on signature database | Unknown | help |
Based on the sections entropy check! file is possibly packed | Suspicious | |
Timestamp value suspicious | Clean | |
Header Checksum is zero! | Suspicious | |
Enrty point is outside the 1st(.code) section! Binary is possibly packed | Clean | |
Optional Header NumberOfRvaAndSizes field is valued illegal | Clean | |
Anti-vm present | Clean | |
The Size Of Raw data is valued illegal! Binary might crash your disassembler/debugger | Clean | |
TLS callback functions array detected | Clean |
Packer detection on signature database
Microsoft Visual C# / Basic .NET
.NET executable
Dynamic Analysis
Dynamic Analysis Overall Verdict | Result |
---|---|
No Threat Found | help |
Suspicious Behaviors | |
---|---|
Injects code to another process | |
Creates a child process | |
Writes to address space of another process | |
Uses a function clandestinely | |
Reads memory of another process | |
Opens a file in a system directory | |
Has no visible windows |
Behavioral Information
ConfigMask
DisplayName
NoClientChecks
CLRLoadLogDir
ForceLog
MissingDependencies
System
System.Security
NIUsageMask
NIDependencies
SIG
LoggingLevel
System.Runtime.Serialization.Formatters.Soap
LogResourceBinds
OnlyUseLatestCLR
Status
DevOverrideEnable
System.Drawing
UseLegacyIdentityFormat
ILUsageMask
System.Xml
mscorlib
ILDependencies
System.Core
DbgManagedDebugger
DisableMSIPeek
LegacyPolicyTimeStamp
LastModTime
Modules
CacheLocation
System.Configuration
System.Deployment
MVID
DbgJITDebugLaunchSetting
VersioningLog
LogFailures
DisableConfigCache
index1
InstallRoot
Latest
LatestIndex
GCStressStart
GCStressStartAtJit
Accessibility
EvalationData
System.Windows.Forms
DownloadCacheQuotaInKB
ConfigString
EnableLog
RegCloseKey(b8)
RegCloseKey() -> 0
RegCloseKey(b4)
RegCloseKey(bc)
RegCloseKey(cc)
RegCloseKey(c8)
RegCloseKey(12c)
RegCloseKey(128)
RegCloseKey(184)
RegCloseKey(178)
RegCloseKey(198)
RegCloseKey(1a8)
RegCloseKey(1d8)
RegCloseKey(1f8)
RegCloseKey(1fc)
RegCloseKey(80000004)
RegCloseKey(1a0)
C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18834_none_72d38c5186679d48\gdiplus.dll
C:\Windows\SYSTEM32\MSCOREE.DLL
C:\1710151010_10.exe
C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\MSVCR80.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
file
12c
1f8
198
1a0
bc
cc
1a8
b4
c8
80000004
184
178
128
b8
1d8
1fc
{"dwCreationDisposition": "3", "path": "C:\\Windows\\assembly\\GAC_32\\mscorlib\\2.0.0.0__b77a5c561934e089\\sorttbls.nlp", "dwDesiredAccess": "80000000", "dwShareMode": "5"}
{"dwCreationDisposition": "3", "path": "C:\\WINDOWS\\FONTS\\MSJH.TTF", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "C:\\WINDOWS\\FONTS\\MALGUN.TTF", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\config\\enterprisesec.config.cch", "dwDesiredAccess": "80000000", "dwShareMode": "5"}
{"dwCreationDisposition": "3", "path": "C:\\WINDOWS\\FONTS\\SEGOEUI.TTF", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "C:\\WINDOWS\\FONTS\\TAHOMA.TTF", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "C:\\Windows\\assembly\\GAC_32\\mscorlib\\2.0.0.0__b77a5c561934e089\\sortkey.nlp", "dwDesiredAccess": "80000000", "dwShareMode": "5"}
{"dwCreationDisposition": "3", "path": "C:\\1710151010_10.exe.config", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "C:\\Windows\\assembly\\pubpol1.dat", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "C:\\WINDOWS\\FONTS\\MICROSS.TTF", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "C:\\WINDOWS\\FONTS\\MSYH.TTF", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\config\\machine.config", "dwDesiredAccess": "80000000", "dwShareMode": "5"}
{"dwCreationDisposition": "3", "path": "C:\\Users\\win7\\AppData\\Local\\GDIPFONTCACHEV1.DAT", "dwDesiredAccess": "c0000000", "dwShareMode": "3"}
{"dwCreationDisposition": "3", "path": "C:\\Windows\\system32\\rsaenh.dll", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "C:\\1710151010_10.exe", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "C:\\Windows\\assembly\\NativeImages_v2.0.50727_32\\index1c2.dat", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "C:\\Users\\win7\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch", "dwDesiredAccess": "80000000", "dwShareMode": "5"}
{"dwCreationDisposition": "3", "path": "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\config\\security.config.cch", "dwDesiredAccess": "80000000", "dwShareMode": "5"}
{"dwCreationDisposition": "3", "path": "C:\\Users\\win7\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config", "dwDesiredAccess": "80000000", "dwShareMode": "5"}
{"dwCreationDisposition": "3", "path": "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\config\\security.config", "dwDesiredAccess": "80000000", "dwShareMode": "5"}
{"dwCreationDisposition": "3", "path": "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\config\\enterprisesec.config", "dwDesiredAccess": "80000000", "dwShareMode": "5"}
{"dwCreationDisposition": "3", "path": "C:\\Windows\\system32\\l_intl.nls", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\config\\machine.config", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
<NULL>
{"hKey": "17c", "phkResult": "0", "lpSubKey": "NI\\b224c3a\\f574bf8"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\.NETFramework"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "SOFTWARE\\Microsoft\\.NETFramework\\Policy\\APTCA"}
{"hKey": "17c", "phkResult": "0", "lpSubKey": "NI\\7ac727df\\7b5311d7"}
{"hKey": "1a0", "phkResult": "0", "lpSubKey": "policy.2.0.System.Windows.Forms__b77a5c561934e089"}
{"hKey": "17c", "phkResult": "0", "lpSubKey": "IL\\2dd6ac50\\553abeb3\\58"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\.NETFramework"}
{"hKey": "17c", "phkResult": "0", "lpSubKey": "IL\\41c04c7e\\4bf62c79\\50"}
{"hKey": "17c", "phkResult": "0", "lpSubKey": "NI\\61e7e666\\c991064"}
{"hKey": "128", "phkResult": "0", "lpSubKey": "LocalIntranet"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Fusion\\NativeImagesIndex\\v2.0.50727_32"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\Managed\\S-1-5-21-3979321414-2393373014-2172761192-1000\\Installer\\Assemblies\\Global"}
{"hKey": "17c", "phkResult": "0", "lpSubKey": "NI\\181938c6\\7950e2c5\\16"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\StrongName"}
{"hKey": "17c", "phkResult": "0", "lpSubKey": "IL\\475dce40\\1c022996\\5b"}
{"hKey": "17c", "phkResult": "0", "lpSubKey": "IL\\3f50fe4f\\265c633d\\60"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Fusion"}
{"hKey": "17c", "phkResult": "0", "lpSubKey": "IL\\6dc7d4c0\\c47ad54\\56"}
{"hKey": "17c", "phkResult": "0", "lpSubKey": "NI\\3cca06a0\\6dc7d4c0\\b"}
{"hKey": "17c", "phkResult": "0", "lpSubKey": "NI\\6e26edba\\6d177e67"}
{"hKey": "1a0", "phkResult": "0", "lpSubKey": "policy.3.5.System.Core__b77a5c561934e089"}
{"hKey": "17c", "phkResult": "0", "lpSubKey": "IL\\c991064\\5086dba8\\51"}
{"hKey": "17c", "phkResult": "0", "lpSubKey": "NI\\7ac727df\\7b5311d7\\22"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\.NETFramework\\v2.0.50727\\Security\\Policy"}
{"hKey": "1a0", "phkResult": "0", "lpSubKey": "policy.2.0.System.Drawing__b03f5f7f11d50a3a"}
{"hKey": "b8", "phkResult": "0", "lpSubKey": "v2.0.50727"}
{"hKey": "17c", "phkResult": "0", "lpSubKey": "NI\\6e26edba\\55a63b85"}
{"hKey": "1a0", "phkResult": "0", "lpSubKey": "policy.2.0.System.Deployment__b03f5f7f11d50a3a"}
{"hKey": "17c", "phkResult": "0", "lpSubKey": "NI\\181938c6\\7950e2c5"}
{"hKey": "17c", "phkResult": "0", "lpSubKey": "IL\\7950e2c5\\4b5f28af\\5f"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Installer\\Assemblies\\Global"}
{"hKey": "17c", "phkResult": "0", "lpSubKey": "IL\\424bd4d8\\324708cb\\5c"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\.NETFramework\\Security\\Policy\\Extensions\\NamedPermissionSets"}
{"hKey": "1a0", "phkResult": "0", "lpSubKey": "policy.2.0.System.Xml__b77a5c561934e089"}
{"hKey": "17c", "phkResult": "0", "lpSubKey": "NI\\1b68f7a3\\74147a4"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\.NETFramework\\Policy\\"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "SOFTWARE\\Classes\\Installer\\Assemblies\\Global"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options"}
{"hKey": "17c", "phkResult": "0", "lpSubKey": "index1c2"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-3979321414-2393373014-2172761192-1000"}
{"hKey": "17c", "phkResult": "0", "lpSubKey": "NI\\61e7e666\\c991064\\a"}
{"hKey": "128", "phkResult": "0", "lpSubKey": "Internet"}
{"hKey": "b4", "phkResult": "0", "lpSubKey": "AppPatch"}
{"hKey": "b4", "phkResult": "0", "lpSubKey": "v2.0"}
{"hKey": "1a0", "phkResult": "0", "lpSubKey": "policy.2.0.System__b77a5c561934e089"}
{"hKey": "1a0", "phkResult": "0", "lpSubKey": "policy.2.0.System.Security__b03f5f7f11d50a3a"}
{"hKey": "17c", "phkResult": "0", "lpSubKey": "NI\\774c9d67\\182e0f68"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\1710151010_10.exe"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Fusion"}
{"hKey": "1a0", "phkResult": "0", "lpSubKey": "policy.2.0.Accessibility__b03f5f7f11d50a3a"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Installer\\Assemblies\\C:|1710151010_10.exe"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Installer\\Managed\\S-1-5-21-3979321414-2393373014-2172761192-1000\\Installer\\Assemblies\\C:|1710151010_10.exe"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\.NETFramework\\Policy\\Standards"}
{"hKey": "17c", "phkResult": "0", "lpSubKey": "IL\\7b5311d7\\1b0ed4d\\39"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Fusion\\PublisherPolicy\\Default"}
{"hKey": "17c", "phkResult": "0", "lpSubKey": "IL\\19ab8d57\\c91dbb2\\5e"}
{"hKey": "1a0", "phkResult": "0", "lpSubKey": "policy.2.0.System.Configuration__b03f5f7f11d50a3a"}
{"hKey": "b4", "phkResult": "0", "lpSubKey": "Standards"}
{"hKey": "1a0", "phkResult": "0", "lpSubKey": "policy.2.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a"}
{"hKey": "17c", "phkResult": "0", "lpSubKey": "NI\\30bc7c4f\\3f50fe4f\\18"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "SOFTWARE\\Classes\\Installer\\Assemblies\\C:|1710151010_10.exe"}
{"hKey": "b4", "phkResult": "0", "lpSubKey": "Upgrades"}
{"hKey": "17c", "phkResult": "0", "lpSubKey": "IL\\3ced59c5\\48d69eb2\\54"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\.NETFramework\\Policy\\Standards"}
Global\CLR_CASOFF_MUTEX
"C:\1710151010_10.exe"
ADVAPI32.dll
SHLWAPI.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
mscoree.dll
ntdll
advapi32.dll
shell32.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\ole32.dll
ole32.dll
kernel32.dll
AdvApi32.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\908ba9e296e92b4e14bdc2437edac603\System.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\5a401fd2a7689ff13fb54182953f9c40\System.Drawing.ni.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6949c4470a81970ec3de0a575d93babc\System.Windows.Forms.ni.dll
C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\uxtheme.dll
uxtheme.dll
user32.dll
gdi32.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\Gdiplus.dll
gdiplus.dll
C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18834_none_72d38c5186679d48\gdiplus.dll
API-MS-Win-Core-LocalRegistry-L1-1-0.dll
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\63e9d5c341d64a753cde97f5a3d65c71\System.Core.ni.dll
C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\bcrypt.dll
bcrypt.dll
CRYPTSP.dll
CRYPTBASE.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\culture.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\en-US\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\en\mscorrc.dll
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll
kernel32
C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\psapi.dll
psapi.dll
advapi32
WindowsCodecs.dll
OLEAUT32.dll
API-MS-Win-Security-LSALookup-L1-1-0.dll
C:/1710151010_10.exe:Zone.Identifier
C:\Windows\Microsoft.NET\Framework\v2.0.50727\config\security.config.cch.648.169484
C:\Windows\Microsoft.NET\Framework\v2.0.50727\config\enterprisesec.config.cch.648.169484
C:\Users\win7\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\security.config.cch.648.169515
OpenProcess
OpenProcessW
ReadProcessMemory
CreateProcessW
{"h_key": "80000002", "samDesired": "20119", "Reserved": "0", "lpSecurityAttributes": "0", "lpdwDisposition": "0", "dwOptions": "0", "lpClass": "<NULL>", "phkResult": "74505a00", "lpSubKey": "Software\\Microsoft\\Fusion\\GACChangeNotification\\Default"}
Precise Detectors Analysis Results
Detector Name | Date | Verdict | Reason | |
---|---|---|---|---|
Static Precise PUA Detector 1 | 2017-10-28 17:10:05.220438 | No Match | help | NotDetected |
Static Precise Virus Detector | 2017-10-28 17:10:05.415683 | No Match | help | NotDetected |
Static Precise Trojan Detector | 2017-10-28 17:10:05.276832 | No Match | help | NotDetected |
Static Precise Adware InstallCore Detector 1 | 2017-10-28 17:10:05.223645 | No Match | help | NotDetected |
Static Precise Trojan Detector 2 | 2017-10-28 17:10:05.258898 | No Match | help | NotDetected |
Static Precise Trojan Detector 3 | 2017-10-28 17:10:05.263869 | No Match | help | NotDetected |
Static Precise Trojan Generic Cryptor Detector 1 | 2017-10-28 17:10:05.280701 | No Match | help | NotDetected |
Static Precise Virus Detector 2 | 2017-10-28 17:10:05.283818 | No Match | help | NotDetected |
Advance Heuristics
No Advanced Heuristic Analysis Result Received
Additional File Information
Property | Value |
---|
Name | Virtual Address | Virtual Size | Raw Size | Entropy | MD5 |
---|