General Information
Sample name: | ZXQ3AcEN5Q.exerenamed because original name is a hash value |
Original sample name: | 8ceb54209abb88fbc1c17fcb1035fb49.exe |
Analysis ID: | 1445843 |
MD5: | 8ceb54209abb88fbc1c17fcb1035fb49 |
SHA1: | f255dbe63698aa8d1dbfca2da9a794bf42556312 |
SHA256: | 3737e4e4ffbcc654013a2d52e25fb67092b36c5b80fb9b7e3a1b12ae0560d604 |
Tags: | exe |
Score: | 80 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Antivirus detection for dropped file
Multi AV Scanner detection for submitted file
AI detected suspicious sample
Machine Learning detection for dropped file
Allocates memory with a write watch (potentially for evading sandboxes)
Binary contains a suspicious time stamp
Contains functionality for read data from the clipboard
Contains functionality to call native functions
Contains functionality to dynamically determine API calls
Contains functionality to shutdown / reboot the system
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Dropped file seen in connection with other malware
Drops PE files
Enables debug privileges
Found dropped PE file which has not been started or loaded
IP address seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Shows file infection / information gathering behavior (enumerates multiple directory for files)
Sigma detected: CurrentVersion Autorun Keys Modification
Too many similar processes found
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
System is w10x64
- ZXQ3AcEN5Q.exe (PID: 6788 cmdline:
setup.exe (PID: 5588 cmdline: "C:\Users\user\AppData\Local\Temp\setup.exe" MD5: E4C96146FC1754DC1B99E96E0D7AEF91)
Pinball.exe (PID: 3664 cmdline: C:\Users\user\AppData\Roaming\Pinball\Pinball.exe MD5: 4B690D1CA31A2224A761AD9D8690C94D)
C:\Users\u ser\AppDat a\Roaming\ Pinball\Pi nball.exe MD5: 4B690D1CA31A2224A761AD9D8690C94D) - Pinball.exe (PID: 7004 cmdline:
Pinball.exe (PID: 5176 cmdline: "C:\Users\user\AppData\Roaming\Pinball\Pinball.exe" --type=utility --utility-sub-type=storage.mojom.StorageService MD5: 4B690D1CA31A2224A761AD9D8690C94D)
Pinball.exe (PID: 1868 cmdline: "C:\Users\user\AppData\Roaming\Pinball\Pinball.exe" --type=utility --utility-sub-type=network.mojom.NetworkService MD5: 4B690D1CA31A2224A761AD9D8690C94D)
Pinball.exe (PID: 1560 cmdline: "C:\Users\user\AppData\Roaming\Pinball\Pinball.exe" --type=renderer --first-renderer-process MD5: 4B690D1CA31A2224A761AD9D8690C94D)
Pinball.exe (PID: 3208 cmdline: "C:\Users\user\AppData\Roaming\Pinball\Pinball.exe" --type=renderer MD5: 4B690D1CA31A2224A761AD9D8690C94D)
"C:\Users\ user\AppDa ta\Roaming \Pinball\P inball.exe " --type=r enderer -- log-severi ty=disable --user-ag ent="Mozil la/5.0 (Li nux; Andro id 10; K) AppleWebKi t/537.36 ( KHTML, lik e Gecko) C hrome/125. 0.6422.53 Mobile Saf ari/537.36 " --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --no-san dbox --log -file="C:\ Users\user \AppData\R oaming\Pin ball\debug .log" --la ng=en-US - -device-sc ale-factor =1 --num-r aster-thre ads=2 --en able-main- frame-befo re-activat ion --rend erer-clien t-id=5 --t ime-ticks- at-unix-ep och=-17163 8680640729 5 --launch -time-tick s=41937781 55 --mojo- platform-c hannel-han dle=3812 - -field-tri al-handle= 2972,i,184 4530987671 7897179,34 9345164858 7661161,26 2144 --dis able-featu res=BackFo rwardCache ,Calculate NativeWinO cclusion,D ocumentPic tureInPict ureAPI /pr efetch:1 MD5: 4B690D1CA31A2224A761AD9D8690C94D)
- Pinball.exe (PID: 6504 cmdline:
- cleanup
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
⊘No Snort rule has matched
AV Detection |
Source: | Avira: |
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | Registry value created: | Jump to behavior |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Directory queried: |
Source: | Code function: | 0_2_00405B6F | |
Source: | Code function: | 0_2_00406724 | |
Source: | Code function: | 0_2_004027AA | |
Source: | Code function: | 4_2_00405B4A | |
Source: | Code function: | 4_2_004066FF | |
Source: | Code function: | 4_2_004027AA |
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: |
Source: | Code function: | 0_2_0040560C |
Source: | Process created: |
Source: | Code function: | 0_2_100010D0 |
Source: | Code function: | 0_2_004034F1 | |
Source: | Code function: | 4_2_004034CC |
Source: | Code function: | 0_2_004073D5 | |
Source: | Code function: | 0_2_00406BFE | |
Source: | Code function: | 4_2_00406A88 | |
Source: | Code function: | 7_2_01434F58 | |
Source: | Code function: | 7_2_01431049 | |
Source: | Code function: | 8_2_01244F58 | |
Source: | Code function: | 8_2_01243860 | |
Source: | Code function: | 8_2_01241049 | |
Source: | Code function: | 9_2_00B54F58 | |
Source: | Code function: | 9_2_00B53860 | |
Source: | Code function: | 10_2_028B4F58 | |
Source: | Code function: | 11_2_00964F58 | |
Source: | Code function: | 11_2_0096F660 | |
Source: | Code function: | 11_2_00963860 | |
Source: | Code function: | 17_2_02A53860 | |
Source: | Code function: | 17_2_02A54F58 | |
Source: | Code function: | 23_2_00F13860 | |
Source: | Code function: | 23_2_00F14F58 | |
Source: | Code function: | 23_2_00F11049 | |
Source: | Code function: | 36_2_00B34F58 | |
Source: | Code function: | 36_2_00B33860 | |
Source: | Code function: | 36_2_00B31049 |
Source: | Dropped File: | ||
Source: | Dropped File: |
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | Base64 encoded string: |