Edit tour
Windows
Analysis Report
SecuriteInfo.com.BackDoor.BlackHole.55951.25738.15896.exe
Overview
General Information
Detection
Score: | 52 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
PE file has a writeable .text section
Machine Learning detection for sample
Contains functionality to modify clipboard data
Creates a DirectInput object (often for capturing keystrokes)
Uses 32bit PE files
Found inlined nop instructions (likely shell or obfuscated code)
Uses a known web browser user agent for HTTP communication
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
PE file contains sections with non-standard names
Binary contains a suspicious time stamp
Detected potential crypto function
Potential key logger detected (key state polling based)
Found potential string decryption / allocating functions
Contains functionality to call native functions
Contains functionality to check if a window is minimized (may be used to check if an application is visible)
Contains functionality to dynamically determine API calls
Contains functionality to read the clipboard data
Found large amount of non-executed APIs
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality for read data from the clipboard
Classification
- System is w10x64
- SecuriteInfo.com.BackDoor.BlackHole.55951.25738.15896.exe (PID: 6908 cmdline:
C:\Users\u ser\Deskto p\Securite Info.com.B ackDoor.Bl ackHole.55 951.25738. 15896.exe MD5: EC83B4EABDEE9D3E7D3D2C04C874D1B8)
- cleanup
⊘No configs have been found
⊘No yara matches
⊘No Sigma rule has matched
⊘No Snort rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | Code function: | 1_2_00426E50 | |
Source: | Code function: | 1_2_0042F090 | |
Source: | Code function: | 1_2_00475849 | |
Source: | Code function: | 1_2_0041BCB0 |
Source: | Code function: | 1_2_00461E13 |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: |