Windows
Analysis Report
https://jamartech.net/Files/softwareinstalls/STARnext Install 1.3.4.0.exe
Overview
General Information
Detection
Score: | 4 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 60% |
Signatures
PE file does not import any functions
PE file contains an invalid checksum
Drops PE files
Tries to load missing DLLs
PE file contains sections with non-standard names
Found dropped PE file which has not been started or loaded
PE file overlay found
PE file contains executable resources (Code or Archives)
Classification
Analysis Advice
Sample drops PE files which have not been started, submit dropped PE samples for a secondary analysis to Joe Sandbox |
Sample tries to load a library which is not present or installed on the analysis machine, adding the library might reveal more behavior |
- System is w10x64native
chrome.exe (PID: 8152 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" --sta rt-maximiz ed "about: blank MD5: 464953824E644F10FFDC9E093FD18F94) chrome.exe (PID: 4880 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -field-tri al-handle= 1648,12610 9027506400 63951,9451 3289771122 28190,1310 72 --disab le-feature s=Optimiza tionGuideM odelDownlo ading,Opti mizationHi nts,Optimi zationHint sFetching, Optimizati onTargetPr ediction - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =1992 /pre fetch:8 MD5: 464953824E644F10FFDC9E093FD18F94) chrome.exe (PID: 8116 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= chrome.moj om.UtilRea dIcon --fi eld-trial- handle=164 8,12610902 7506400639 51,9451328 9771122281 90,131072 --disable- features=O ptimizatio nGuideMode lDownloadi ng,Optimiz ationHints ,Optimizat ionHintsFe tching,Opt imizationT argetPredi ction --la ng=en-US - -service-s andbox-typ e=icon_rea der --mojo -platform- channel-ha ndle=2880 /prefetch: 8 MD5: 464953824E644F10FFDC9E093FD18F94) chrome.exe (PID: 7500 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= chrome.moj om.UtilRea dIcon --fi eld-trial- handle=164 8,12610902 7506400639 51,9451328 9771122281 90,131072 --disable- features=O ptimizatio nGuideMode lDownloadi ng,Optimiz ationHints ,Optimizat ionHintsFe tching,Opt imizationT argetPredi ction --la ng=en-US - -service-s andbox-typ e=icon_rea der --mojo -platform- channel-ha ndle=3208 /prefetch: 8 MD5: 464953824E644F10FFDC9E093FD18F94) chrome.exe (PID: 4804 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= chrome.moj om.UtilRea dIcon --fi eld-trial- handle=164 8,12610902 7506400639 51,9451328 9771122281 90,131072 --disable- features=O ptimizatio nGuideMode lDownloadi ng,Optimiz ationHints ,Optimizat ionHintsFe tching,Opt imizationT argetPredi ction --la ng=en-US - -service-s andbox-typ e=icon_rea der --mojo -platform- channel-ha ndle=4520 /prefetch: 8 MD5: 464953824E644F10FFDC9E093FD18F94) chrome.exe (PID: 7212 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= chrome.moj om.UtilRea dIcon --fi eld-trial- handle=164 8,12610902 7506400639 51,9451328 9771122281 90,131072 --disable- features=O ptimizatio nGuideMode lDownloadi ng,Optimiz ationHints ,Optimizat ionHintsFe tching,Opt imizationT argetPredi ction --la ng=en-US - -service-s andbox-typ e=icon_rea der --mojo -platform- channel-ha ndle=4548 /prefetch: 8 MD5: 464953824E644F10FFDC9E093FD18F94) STARnext Install 1.3.4.0.exe (PID: 1756 cmdline:
"C:\Users\ user\Downl oads\STARn ext Instal l 1.3.4.0. exe" MD5: 31132F615BB6B9A7386F80FA64433E3E) STARnext Install 1.3.4.0.tmp (PID: 4252 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\is-PJK 1A.tmp\STA Rnext Inst all 1.3.4. 0.tmp" /SL 5="$1B5001 C,38811898 ,832512,C: \Users\use r\Download s\STARnext Install 1 .3.4.0.exe " MD5: 5C7D7547470BD0AD53E917EB3B41B245)
chrome.exe (PID: 5344 cmdline:
C:\Program Files\Goo gle\Chrome \Applicati on\chrome. exe" "http s://jamart ech.net/Fi les/softwa reinstalls /STARnext% 20Install% 201.3.4.0. exe MD5: 464953824E644F10FFDC9E093FD18F94)
- cleanup
⊘No configs have been found
⊘No yara matches
⊘No Sigma rule has matched
⊘No Snort rule has matched
- • Compliance
- • Networking
- • System Summary
- • Data Obfuscation
- • Persistence and Installation Behavior
- • Hooking and other Techniques for Hiding and Protection
- • Malware Analysis System Evasion
Click to jump to signature section
Show All Signature Results
There are no malicious signatures, click here to show all signatures.
Source: | Window detected: |