Windows
Analysis Report
https://handbrake.fr/
Overview
Detection
Score: | 2 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 40% |
Signatures
Drops PE files
Found dropped PE file which has not been started or loaded
Queries the volume information (name, serial number etc) of a device
Stores files to the Windows start menu directory
Tries to load missing DLLs
Classification
Analysis Advice
Sample drops PE files which have not been started, submit dropped PE samples for a secondary analysis to Joe Sandbox |
Sample tries to load a library which is not present or installed on the analysis machine, adding the library might reveal more behavior |
Uses HTTPS for network communication, use the 'Proxy HTTPS (port 443) to read its encrypted data' cookbook for further analysis |
- System is w10x64_ra
chrome.exe (PID: 1472 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed --sing le-argumen t https:// handbrake. fr/ MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) chrome.exe (PID: 2548 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2188 --fi eld-trial- handle=198 4,i,112111 4406548994 0303,85477 6880326674 1001,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) chrome.exe (PID: 1428 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= chrome.moj om.UtilRea dIcon --la ng=en-US - -service-s andbox-typ e=icon_rea der --mojo -platform- channel-ha ndle=3208 --field-tr ial-handle =1984,i,11 2111440654 89940303,8 5477688032 66741001,2 62144 --di sable-feat ures=Optim izationGui deModelDow nloading,O ptimizatio nHints,Opt imizationH intsFetchi ng,Optimiz ationTarge tPredictio n /prefetc h:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) HandBrake-1.7.3-x86_64-Win_GUI.exe (PID: 3224 cmdline:
"C:\Users\ user\Downl oads\HandB rake-1.7.3 -x86_64-Wi n_GUI.exe" MD5: 1A1598A4F8A2D8D6B1925CB22A74D5AA) HandBrake-1.7.3-x86_64-Win_GUI.exe (PID: 4200 cmdline:
"C:\Users\ user\Downl oads\HandB rake-1.7.3 -x86_64-Wi n_GUI.exe" MD5: 1A1598A4F8A2D8D6B1925CB22A74D5AA) uninstallhb.exe (PID: 4124 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\uninst allhb.exe" _?=C:\Pro gram Files \HandBrake MD5: 34A742F98E351D54AE0DF55F9E0E960E)
HandBrake.exe (PID: 4608 cmdline:
"C:\Progra m Files\Ha ndBrake\Ha ndBrake.ex e" MD5: EE3CBF592C24B1BF04D906DED5C7D1A9)
- cleanup
⊘No yara matches
⊘No Sigma rule has matched
⊘No Snort rule has matched
- • Phishing
- • Compliance
- • Networking
- • System Summary
- • Persistence and Installation Behavior
- • Boot Survival
- • Hooking and other Techniques for Hiding and Protection
- • Malware Analysis System Evasion
- • Language, Device and Operating System Detection
Click to jump to signature section
Show All Signature Results
There are no malicious signatures, click here to show all signatures.
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | Window detected: |