Windows
Analysis Report
Sysmon64.exe
Overview
General Information
Detection
Score: | 36 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 40% |
Signatures
Found evasive API chain (may stop execution after checking mutex)
Sigma detected: Suspicious New Service Creation
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a debugger is running (OutputDebugString,GetLastError)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Enables debug privileges
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
PE file contains executable resources (Code or Archives)
PE file contains sections with non-standard names
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Tries to load missing DLLs
Classification
Analysis Advice
Initial sample is implementing a service and should be registered / started as service |
Sample tries to load a library which is not present or installed on the analysis machine, adding the library might reveal more behavior |
Sample may offer command line options, please run it with the 'Execute binary with arguments' cookbook (it's possible that the command line switches require additional characters like: "-", "/", "--") |
- System is w10x64
cmd.exe (PID: 7728 cmdline:
cmd /c sc create CNV kE binpath = "C:\User s\user\Des ktop\Sysmo n64.exe" > > C:\servi cereg.log 2>&1 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) conhost.exe (PID: 7736 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) sc.exe (PID: 7780 cmdline:
sc create CNVkE binp ath= "C:\U sers\user\ Desktop\Sy smon64.exe " MD5: D9D7684B8431A0D10D0E76FE9F5FFEC8)
cmd.exe (PID: 7860 cmdline:
cmd /c sc start CNVk E >> C:\se rvicestart .log 2>&1 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) conhost.exe (PID: 7868 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) sc.exe (PID: 7912 cmdline:
sc start C NVkE MD5: D9D7684B8431A0D10D0E76FE9F5FFEC8)
Sysmon64.exe (PID: 7944 cmdline:
C:\Users\u ser\Deskto p\Sysmon64 .exe MD5: DBB70DF036B6811F1328BB06BF8671FE)
unsecapp.exe (PID: 7976 cmdline:
C:\Windows \system32\ wbem\unsec app.exe -E mbedding MD5: 9B782B1E1D7A2C28302755F963EAC907)
- cleanup
⊘No configs have been found
⊘No yara matches
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Timur Zinniatullin, Daniil Yugoslavskiy, oscd.community: |
⊘No Snort rule has matched
- • Compliance
- • Networking
- • System Summary
- • Data Obfuscation
- • Boot Survival
- • Hooking and other Techniques for Hiding and Protection
- • Malware Analysis System Evasion
- • Anti Debugging
- • HIPS / PFW / Operating System Protection Evasion
- • Language, Device and Operating System Detection
Click to jump to signature section
Show All Signature Results
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Code function: | 6_2_00007FF7873CC870 | |
Source: | Code function: | 6_2_00007FF787517848 | |
Source: | Code function: | 6_2_00007FF7873D40E0 | |
Source: | Code function: | 6_2_00007FF7873DA8A0 | |
Source: | Code function: | 6_2_00007FF787546098 | |
Source: | Code function: | 6_2_00007FF787409F30 | |
Source: | Code function: | 6_2_00007FF7873D4F30 | |
Source: | Code function: | 6_2_00007FF7875187EC | |
Source: | Code function: | 6_2_00007FF787405FB0 | |
Source: | Code function: | 6_2_00007FF7873DAE60 | |
Source: | Code function: | 6_2_00007FF7873D5EB0 | |
Source: | Code function: | 6_2_00007FF7873DED70 | |
Source: | Code function: | 6_2_00007FF7873D4550 | |
Source: | Code function: | 6_2_00007FF7873C4DE0 | |
Source: | Code function: | 6_2_00007FF787536E04 | |
Source: | Code function: | 6_2_00007FF7873E2C30 | |
Source: | Code function: | 6_2_00007FF7873DCC40 | |
Source: | Code function: | 6_2_00007FF7873D2510 | |
Source: | Code function: | 6_2_00007FF7873DFB60 | |
Source: | Code function: | 6_2_00007FF7873D1B70 | |
Source: | Code function: | 6_2_00007FF7873D8380 | |
Source: | Code function: | 6_2_00007FF78740C270 | |
Source: | Code function: | 6_2_00007FF787518218 | |
Source: | Code function: | 6_2_00007FF7873C5240 | |
Source: | Code function: | 6_2_00007FF7873C22A0 | |
Source: | Code function: | 6_2_00007FF787518ACC | |
Source: | Code function: | 6_2_00007FF7873C2920 | |
Source: | Code function: | 6_2_00007FF7873CC940 | |
Source: | Code function: | 6_2_00007FF7873D5940 | |
Source: | Code function: | 6_2_00007FF7873C7150 |
Source: | Code function: |
Source: | Static PE information: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |