Windows
Analysis Report
BthA2dp.sys
Overview
General Information
Detection
Score: | 1 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Static PE information: |
Source: | Classification label: |
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Static PE information: | ||
Source: | Static PE information: |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | ReversingLabs | |||
0% | Virustotal | Browse |
Joe Sandbox Version: | 38.0.0 Ammolite |
Analysis ID: | 1320194 |
Start date and time: | 2023-10-05 13:06:20 +02:00 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 3m 32s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Analysis system description: | Windows 10 64 bit version 1909 (MS Office 2019, IE 11, Chrome 104, Firefox 88, Adobe Reader DC 21, Java 8 u291, 7-Zip) |
Number of analysed new started processes analysed: | 5 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample file name: | BthA2dp.sys |
Detection: | UNKNOWN |
Classification: | unknown1.winSYS@0/0@0/0 |
Cookbook Comments: |
|
- No process behavior to analyse
as no analysis process or sam ple was found
- Exclude process from analysis
(whitelisted): WMIADAP.exe, SI HClient.exe, svchost.exe - Excluded domains from analysis
(whitelisted): fs.microsoft.c om, slscr.update.microsoft.com , ctldl.windowsupdate.com
File type: | |
Entropy (8bit): | 6.302485076495764 |
TrID: |
|
File name: | BthA2dp.sys |
File size: | 280'064 bytes |
MD5: | 2b008704767e827e81021743b2b6f336 |
SHA1: | 8c65fb4148e3017e9dd856d6e3ba56727eff8715 |
SHA256: | 30e37705524fa79d8c09e48665b349f0fcd9021b8244da1a16613cc8c2d58245 |
SHA512: | facb140a2121284eadecdf68bd6f182c123f55033c27044e1e21a9238a3ea0bddaa147047173a6014f5a1ea7df647c6be50cbc74a8abd210ee733bd84e126059 |
SSDEEP: | 3072:lpXOxOjY/afLTMzPQ7d7WeNTtOyzYe41CMgu7Q2haaLs92rjRacYDnACOvs0QHA4:TMI1Iu7RTIuYnUMQ2haaQdes0vWg |
TLSH: | AD545A4E12BA5872FCBBC67E85B78116E2F13C210366E7DF259482789F03CD4A978B15 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........\........................^...................................................Rich....................PE..d......6.........." |
Icon Hash: | 7ae282899bbab082 |
Entrypoint: | 0x1c001ab70 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x1c0000000 |
Subsystem: | native |
Image File Characteristics: | EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE |
DLL Characteristics: | HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, WDM_DRIVER, GUARD_CF |
Time Stamp: | 0x36A69CC9 [Thu Jan 21 03:19:37 1999 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 10 |
OS Version Minor: | 0 |
File Version Major: | 10 |
File Version Minor: | 0 |
Subsystem Version Major: | 10 |
Subsystem Version Minor: | 0 |
Import Hash: | fa2c2b3f8a076630b2f56e184ac82ee6 |
Instruction |
---|
dec eax |
mov dword ptr [esp+08h], ebx |
push edi |
dec eax |
sub esp, 20h |
dec eax |
mov ebx, edx |
dec eax |
mov edi, ecx |
call 00007FDA68B08578h |
dec eax |
mov edx, ebx |
dec eax |
mov ecx, edi |
call 00007FDA68ADEEE9h |
dec eax |
mov ebx, dword ptr [esp+30h] |
dec eax |
add esp, 20h |
pop edi |
ret |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
dec eax |
mov eax, esp |
dec eax |
mov dword ptr [eax+08h], ebx |
dec eax |
mov dword ptr [eax+10h], ebp |
dec eax |
mov dword ptr [eax+18h], esi |
dec eax |
mov dword ptr [eax+20h], edi |
inc ecx |
push esi |
dec eax |
sub esp, 30h |
xor ebp, ebp |
dec eax |
mov esi, edx |
dec eax |
mov edi, ecx |
dec eax |
test ecx, ecx |
jne 00007FDA68ADEEDCh |
call 00007FDA68AD8D2Ah |
jmp 00007FDA68ADEF75h |
dec eax |
lea eax, dword ptr [0001C735h] |
mov dword ptr [0001C71Bh], 02080000h |
dec esp |
lea esi, dword ptr [0001C714h] |
dec eax |
mov dword ptr [0001C715h], eax |
dec ecx |
mov ecx, esi |
dec eax |
call dword ptr [00020743h] |
nop dword ptr [eax+eax+00h] |
dec esp |
lea ecx, dword ptr [0001C91Fh] |
dec ecx |
mov edx, esi |
dec esp |
lea eax, dword ptr [0001C525h] |
dec eax |
mov ecx, edi |
dec eax |
call dword ptr [00020443h] |
nop dword ptr [eax+eax+00h] |
test eax, eax |
js 00007FDA68ADEF20h |
call 00007FDA68ADEF76h |
mov ebx, eax |
test eax, eax |
js 00007FDA68ADEF0Eh |
call 00007FDA68ADF143h |
mov ebx, eax |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x3b4f0 | 0xb4 | .idata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x46000 | 0x2a48 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x39000 | 0x1dc4 | .pdata |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x49000 | 0x294 | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x34160 | 0x54 | .rdata |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x313c0 | 0x118 | .rdata |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x3b000 | 0x4e0 | .idata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x2edea | 0x2ee00 | False | 0.46951041666666665 | data | 6.357062975937825 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_NOT_PAGED, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x30000 | 0x6ed8 | 0x7000 | False | 0.38741629464285715 | data | 5.3176983446773844 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_NOT_PAGED, IMAGE_SCN_MEM_READ |
.data | 0x37000 | 0x1990 | 0x400 | False | 0.1630859375 | data | 1.6565173179171375 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_NOT_PAGED, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.pdata | 0x39000 | 0x1dc4 | 0x1e00 | False | 0.5291666666666667 | data | 5.494910481716635 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_NOT_PAGED, IMAGE_SCN_MEM_READ |
.idata | 0x3b000 | 0x1922 | 0x1a00 | False | 0.3317307692307692 | data | 4.699329088655764 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_NOT_PAGED, IMAGE_SCN_MEM_READ |
NONPAGE | 0x3d000 | 0xb0 | 0x200 | False | 0.060546875 | data | 0.27354613835361985 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_NOT_PAGED, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
PAGE | 0x3e000 | 0x574b | 0x5800 | False | 0.5312056107954546 | data | 6.360260146051718 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
INIT | 0x44000 | 0x256 | 0x400 | False | 0.51953125 | data | 4.437036250450268 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
GFIDS | 0x45000 | 0x36c | 0x400 | False | 0.5537109375 | data | 4.350022576219208 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
.rsrc | 0x46000 | 0x2a48 | 0x2c00 | False | 0.27769886363636365 | data | 3.6825507158095765 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x49000 | 0x1870 | 0x1a00 | False | 0.7219050480769231 | Targa image data - Mono 40976 x 40984 x 32 +40960 +40968 - top - four way interleave | 5.823151560099651 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
MUI | 0x48960 | 0xe8 | data | English | United States | 0.5646551724137931 |
WEVT_TEMPLATE | 0x46c50 | 0x1d0a | data | English | United States | 0.2932472423997848 |
RT_MESSAGETABLE | 0x464f8 | 0x758 | data | English | United States | 0.31170212765957445 |
RT_VERSION | 0x46160 | 0x398 | OpenPGP Secret Key | English | United States | 0.4641304347826087 |
DLL | Import |
---|---|
ntoskrnl.exe | KeQueryInterruptTimePrecise, EtwActivityIdControl, ExCancelTimer, ExAllocateTimer, ExSetTimer, IoRegisterDeviceInterface, KeQuerySystemTimePrecise, IoSetDevicePropertyData, KeQueryUnbiasedInterruptTime, IoSetDeviceInterfacePropertyData, IoQueueWorkItemEx, EtwWriteTransfer, RtlRegisterFeatureConfigurationChangeNotification, IoCsqInsertIrp, IoCsqRemoveNextIrp, IoCsqInitialize, ZwOpenKey, RtlQueryFeatureConfiguration, DbgPrintEx, ZwClose, IoWMIRegistrationControl, ZwQueryValueKey, MmGetSystemRoutineAddress, RtlCopyUnicodeString, RtlInitUnicodeString, RtlAppendUnicodeToString, ExFreePool, IofCompleteRequest, IofCallDriver, KeCancelTimer, KeClearEvent, IoBuildDeviceIoControlRequest, KeInitializeTimer, IoInitializeRemoveLockEx, KeInitializeDpc, IoReleaseRemoveLockEx, IoAcquireRemoveLockEx, KeSetTimer, EtwSetInformation, KeWaitForSingleObject, KeInitializeEvent, ExFreePoolWithTag, ExAllocatePoolWithTag, IoFreeWorkItem, IoGetDeviceInterfaces, IoGetDeviceObjectPointer, ObfDereferenceObject, IoFreeIrp, IoSetCompletionRoutineEx, IoAllocateIrp, IoReleaseRemoveLockAndWaitEx, IoCancelIrp, IoReleaseCancelSpinLock, KeQueryTimeIncrement, RtlFreeAnsiString, RtlFreeUnicodeString, RtlUnicodeStringToAnsiString, RtlInitAnsiString, KseQueryDeviceFlags, MmIsDriverVerifyingByAddress, RtlQueryRegistryValuesEx, DbgkWerCaptureLiveKernelDump, KeSetEvent, KeReleaseSpinLock, KeInitializeSpinLock, KeAcquireSpinLockRaiseToDpc, IoAllocateWorkItem, RtlQueryFeatureConfigurationChangeStamp, RtlUnregisterFeatureConfigurationChangeNotification, EtwUnregister, EtwRegister, RtlAnsiCharToUnicodeChar, KeResetEvent, memcmp |
HAL.DLL | KeQueryPerformanceCounter |
ks.sys | KsGetNodeIdFromIrp, KsGetObjectFromFileObject, KsGenerateEvent, KsDefaultAddEventHandler, KsGetPinFromIrp, KsAddEvent, KsInitializeDriver, KsStreamPointerUnlock, KsCompletePendingRequest, KsStreamPointerAdvance, KsPinAcquireProcessingMutex, KsStreamPointerGetNextClone, KsStreamPointerClone, KsPinReleaseProcessingMutex, KsReleaseControl, KsPinGetFirstCloneStreamPointer, KsPinGetLeadingEdgeStreamPointer, KsStreamPointerSetStatusCode, KsStreamPointerAdvanceOffsets, KsGetFilterFromIrp, KsGetDevice, KsAcquireControl, KsStreamPointerDelete, KsGetDeviceForDeviceObject, KsFilterFactoryGetSymbolicLink, KsFilterFactoryUpdateCacheData, KsGetNextSibling, KsFreeObjectCreateItemsByContext, KsFreeObjectBag, KsAllocateObjectBag, KsPinGetParentFilter, _KsEdit, KsGetFirstChild, KsPinAttemptProcessing, KsFilterFactorySetDeviceClassesState, KsAcquireDevice, KsGenerateEvents, KsCreateFilterFactory, KsReleaseDevice, KsGetParent |
btampm.sys | BtaMpmGetRemoteDeviceProfileVersionAndAttribute, BtaMpmUpdatePlayStatus, BtaMpmRegister, BtaMpmUnregister, BtaMpmUpdateSuspendStatus, BtaMpmUnregisterPnp, BtaMpmConnectionRequest, BtaMpmBuildIndirectStringFromMessageWithSingleUTF8Arg, BtaMpmRegisterPnp, BtaMpmUpdateConnectionStatus |
WppRecorder.sys | imp_WppRecorderReplay, WppAutoLogStart, WppAutoLogTrace, WppAutoLogStop |
SleepStudyHelper.sys | SleepstudyHelper_ComponentActive, SleepstudyHelper_UnregisterComponent, SleepstudyHelper_RegisterComponentEx, SleepstudyHelper_ComponentInactive, SleepstudyHelper_GenerateGuid, SleepstudyHelper_Uninitialize, SleepstudyHelper_Initialize, SleepstudyHelper_GetPdoFriendlyName |
WDFLDR.SYS | WdfVersionUnbind, WdfVersionBind, WdfVersionUnbindClass, WdfVersionBindClass |
ksecdd.sys | BCryptCloseAlgorithmProvider, BCryptFinishHash, BCryptOpenAlgorithmProvider, BCryptGetProperty, BCryptHashData, BCryptDestroyHash, BCryptCreateHash |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |