Analysis Report
General Information
Score: | 88 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
AI detected suspicious sample
Machine Learning detection for dropped file
Allocates memory with a write watch (potentially for evading sandboxes)
Binary contains a suspicious time stamp
Contains functionality for read data from the clipboard
Contains functionality to call native functions
Contains functionality to dynamically determine API calls
Contains functionality to shutdown / reboot the system
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Dropped file seen in connection with other malware
Drops PE files
Enables debug privileges
Found dropped PE file which has not been started or loaded
IP address seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Shows file infection / information gathering behavior (enumerates multiple directory for files)
Sigma detected: CurrentVersion Autorun Keys Modification
Too many similar processes found
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
- System is w10x64
- HDKuOe.exe (PID: 7312 cmdline:
"C:\Users\ user\Deskt op\HDKuOe. exe" MD5: 4EBFFCED85203BC1C3C5D9F3AFD1045D) - setup.exe (PID: 7968 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\setup. exe" MD5: 12F9523E0ADA8BDABC28FA142D6E56BD) - Snetchball.exe (PID: 8100 cmdline:
C:\Users\u ser\AppDat a\Roaming\ Snetchball \Snetchbal l.exe MD5: A011E4E8E7502FDFCD1C52A98392FF46) - Snetchball.exe (PID: 6204 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Snetchbal l\Snetchba ll.exe" -- type=gpu-p rocess --n o-sandbox --log-seve rity=disab le --user- agent="Moz illa/5.0 ( iPhone; CP U iPhone O S 11_0 lik e Mac OS X ) AppleWeb Kit/605.1. 15 (KHTML, like Geck o) Version /17.6 Mobi le/15E148 Safari/604 .1" --lang =en-US --u ser-data-d ir="C:\Use rs\user\Ap pData\Loca l\CEF\User Data" --g pu-prefere nces=WAAAA AAAAADgAAA MAAAAAAAAA AAAAAAAAAB gAAAAAAA4A AAAAAAAAAA AAAAEAAAAA AAAAAAAAAA AAAAAAAAAA AAAAAAAAAA AGAAAAAAAA AAYAAAAAAA AAAgAAAAAA AAACAAAAAA AAAAIAAAAA AAAAA== -- log-file=" C:\Users\u ser\AppDat a\Roaming\ Snetchball \debug.log " --mojo-p latform-ch annel-hand le=2900 -- field-tria l-handle=2 940,i,7047 2076597467 40151,5034 4031484750 7221,26214 4 --disabl e-features =BackForwa rdCache,Ca lculateNat iveWinOccl usion,Docu mentPictur eInPicture API /prefe tch:2 MD5: A011E4E8E7502FDFCD1C52A98392FF46) - Snetchball.exe (PID: 5820 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Snetchbal l\Snetchba ll.exe" -- type=utili ty --utili ty-sub-typ e=storage. mojom.Stor ageService --lang=en -US --serv ice-sandbo x-type=ser vice --no- sandbox -- log-severi ty=disable --user-ag ent="Mozil la/5.0 (iP hone; CPU iPhone OS 11_0 like Mac OS X) AppleWebKi t/605.1.15 (KHTML, l ike Gecko) Version/1 7.6 Mobile /15E148 Sa fari/604.1 " --lang=e n-US --use r-data-dir ="C:\Users \user\AppD ata\Local\ CEF\User D ata" --log -file="C:\ Users\user \AppData\R oaming\Sne tchball\de bug.log" - -mojo-plat form-chann el-handle= 3192 --fie ld-trial-h andle=2940 ,i,7047207 6597467401 51,5034403 1484750722 1,262144 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,Documen tPictureIn PictureAPI /prefetch :8 MD5: A011E4E8E7502FDFCD1C52A98392FF46) - Snetchball.exe (PID: 4564 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Snetchbal l\Snetchba ll.exe" -- type=utili ty --utili ty-sub-typ e=network. mojom.Netw orkService --lang=en -US --serv ice-sandbo x-type=non e --no-san dbox --log -severity= disable -- user-agent ="Mozilla/ 5.0 (iPhon e; CPU iPh one OS 11_ 0 like Mac OS X) App leWebKit/6 05.1.15 (K HTML, like Gecko) Ve rsion/17.6 Mobile/15 E148 Safar i/604.1" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Use rs\user\Ap pData\Roam ing\Snetch ball\debug .log" --mo jo-platfor m-channel- handle=324 8 --field- trial-hand le=2940,i, 7047207659 746740151, 5034403148 47507221,2 62144 --di sable-feat ures=BackF orwardCach e,Calculat eNativeWin Occlusion, DocumentPi ctureInPic tureAPI /p refetch:8 MD5: A011E4E8E7502FDFCD1C52A98392FF46) - Snetchball.exe (PID: 7368 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Snetchbal l\Snetchba ll.exe" -- type=rende rer --log- severity=d isable --u ser-agent= "Mozilla/5 .0 (iPhone ; CPU iPho ne OS 11_0 like Mac OS X) Appl eWebKit/60 5.1.15 (KH TML, like Gecko) Ver sion/17.6 Mobile/15E 148 Safari /604.1" -- user-data- dir="C:\Us ers\user\A ppData\Loc al\CEF\Use r Data" -- first-rend erer-proce ss --no-sa ndbox --lo g-file="C: \Users\use r\AppData\ Roaming\Sn etchball\d ebug.log" --lang=en- US --devic e-scale-fa ctor=1 --n um-raster- threads=2 --enable-m ain-frame- before-act ivation -- renderer-c lient-id=6 --time-ti cks-at-uni x-epoch=-1 7251308579 39097 --la unch-time- ticks=4955 405705 --m ojo-platfo rm-channel -handle=34 20 --field -trial-han dle=2940,i ,704720765 9746740151 ,503440314 847507221, 262144 --d isable-fea tures=Back ForwardCac he,Calcula teNativeWi nOcclusion ,DocumentP ictureInPi ctureAPI / prefetch:1 MD5: A011E4E8E7502FDFCD1C52A98392FF46) - Snetchball.exe (PID: 7024 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Snetchbal l\Snetchba ll.exe" -- type=rende rer --log- severity=d isable --u ser-agent= "Mozilla/5 .0 (iPhone ; CPU iPho ne OS 11_0 like Mac OS X) Appl eWebKit/60 5.1.15 (KH TML, like Gecko) Ver sion/17.6 Mobile/15E 148 Safari /604.1" -- user-data- dir="C:\Us ers\user\A ppData\Loc al\CEF\Use r Data" -- no-sandbox --log-fil e="C:\User s\user\App Data\Roami ng\Snetchb all\debug. log" --lan g=en-US -- device-sca le-factor= 1 --num-ra ster-threa ds=2 --ena ble-main-f rame-befor e-activati on --rende rer-client -id=5 --ti me-ticks-a t-unix-epo ch=-172513 0857939097 --launch- time-ticks =495542467 2 --mojo-p latform-ch annel-hand le=3620 -- field-tria l-handle=2 940,i,7047 2076597467 40151,5034 4031484750 7221,26214 4 --disabl e-features =BackForwa rdCache,Ca lculateNat iveWinOccl usion,Docu mentPictur eInPicture API /prefe tch:1 MD5: A011E4E8E7502FDFCD1C52A98392FF46)
- Snetchball.exe (PID: 3896 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Snetchbal l\Snetchba ll.exe" MD5: A011E4E8E7502FDFCD1C52A98392FF46) - Snetchball.exe (PID: 5184 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Snetchbal l\Snetchba ll.exe" MD5: A011E4E8E7502FDFCD1C52A98392FF46) - Snetchball.exe (PID: 3336 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Snetchbal l\Snetchba ll.exe" MD5: A011E4E8E7502FDFCD1C52A98392FF46) - Snetchball.exe (PID: 5628 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Snetchbal l\Snetchba ll.exe" MD5: A011E4E8E7502FDFCD1C52A98392FF46) - Snetchball.exe (PID: 2496 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Snetchbal l\Snetchba ll.exe" MD5: A011E4E8E7502FDFCD1C52A98392FF46) - Snetchball.exe (PID: 4296 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Snetchbal l\Snetchba ll.exe" MD5: A011E4E8E7502FDFCD1C52A98392FF46) - Snetchball.exe (PID: 5744 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Snetchbal l\Snetchba ll.exe" MD5: A011E4E8E7502FDFCD1C52A98392FF46) - Snetchball.exe (PID: 5088 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Snetchbal l\Snetchba ll.exe" MD5: A011E4E8E7502FDFCD1C52A98392FF46) - Snetchball.exe (PID: 5888 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Snetchbal l\Snetchba ll.exe" MD5: A011E4E8E7502FDFCD1C52A98392FF46) - Snetchball.exe (PID: 6252 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Snetchbal l\Snetchba ll.exe" MD5: A011E4E8E7502FDFCD1C52A98392FF46) - Snetchball.exe (PID: 2136 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Snetchbal l\Snetchba ll.exe" MD5: A011E4E8E7502FDFCD1C52A98392FF46) - Snetchball.exe (PID: 5084 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Snetchbal l\Snetchba ll.exe" MD5: A011E4E8E7502FDFCD1C52A98392FF46) - Snetchball.exe (PID: 6316 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Snetchbal l\Snetchba ll.exe" MD5: A011E4E8E7502FDFCD1C52A98392FF46) - Snetchball.exe (PID: 6928 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Snetchbal l\Snetchba ll.exe" MD5: A011E4E8E7502FDFCD1C52A98392FF46) - Snetchball.exe (PID: 676 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Snetchbal l\Snetchba ll.exe" MD5: A011E4E8E7502FDFCD1C52A98392FF46) - Snetchball.exe (PID: 6008 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Snetchbal l\Snetchba ll.exe" MD5: A011E4E8E7502FDFCD1C52A98392FF46) - Snetchball.exe (PID: 3284 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Snetchbal l\Snetchba ll.exe" MD5: A011E4E8E7502FDFCD1C52A98392FF46) - Snetchball.exe (PID: 3588 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Snetchbal l\Snetchba ll.exe" MD5: A011E4E8E7502FDFCD1C52A98392FF46) - Snetchball.exe (PID: 4556 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Snetchbal l\Snetchba ll.exe" MD5: A011E4E8E7502FDFCD1C52A98392FF46) - Snetchball.exe (PID: 772 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Snetchbal l\Snetchba ll.exe" MD5: A011E4E8E7502FDFCD1C52A98392FF46) - Snetchball.exe (PID: 4548 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Snetchbal l\Snetchba ll.exe" MD5: A011E4E8E7502FDFCD1C52A98392FF46) - Snetchball.exe (PID: 2520 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Snetchbal l\Snetchba ll.exe" MD5: A011E4E8E7502FDFCD1C52A98392FF46) - Snetchball.exe (PID: 4488 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Snetchbal l\Snetchba ll.exe" MD5: A011E4E8E7502FDFCD1C52A98392FF46) - Snetchball.exe (PID: 7596 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Snetchbal l\Snetchba ll.exe" MD5: A011E4E8E7502FDFCD1C52A98392FF46) - Snetchball.exe (PID: 3020 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Snetchbal l\Snetchba ll.exe" MD5: A011E4E8E7502FDFCD1C52A98392FF46) - Snetchball.exe (PID: 980 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Snetchbal l\Snetchba ll.exe" MD5: A011E4E8E7502FDFCD1C52A98392FF46) - Snetchball.exe (PID: 6332 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Snetchbal l\Snetchba ll.exe" MD5: A011E4E8E7502FDFCD1C52A98392FF46) - Snetchball.exe (PID: 6952 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Snetchbal l\Snetchba ll.exe" MD5: A011E4E8E7502FDFCD1C52A98392FF46)
Source: Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split):
AV Detection |
Source: | Avira: |
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: |
Source: | Virustotal: | Perma Link |
Source: | Virustotal: | Perma Link |
Source: | Virustotal: | Perma Link |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | Registry value created: | Jump to behavior |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Directory queried: |
Source: | Code function: | 0_2_00405B4A | |
Source: | Code function: | 0_2_004066FF | |
Source: | Code function: | 0_2_004027AA | |
Source: | Code function: | 5_2_00405B4A | |
Source: | Code function: | 5_2_004066FF | |
Source: | Code function: | 5_2_004027AA |
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Code function: | 0_2_004055E7 |
Source: | Process created: |
Source: | Code function: | 0_2_100010D0 |
Source: | Code function: | 0_2_004034CC | |
Source: | Code function: | 5_2_004034CC |
Source: | Code function: | 0_2_00406A88 | |
Source: | Code function: | 5_2_00406A88 | |
Source: | Code function: | 8_2_00CC4F58 | |
Source: | Code function: | 9_2_008E4F58 | |
Source: | Code function: | 10_2_017F4F58 | |
Source: | Code function: | 10_2_017F1049 | |
Source: | Code function: | 11_2_00A84F58 | |
Source: | Code function: | 12_2_01314F58 | |
Source: | Code function: | 12_2_0131F660 | |
Source: | Code function: | 12_2_01311049 | |
Source: | Code function: | 12_2_0131F648 | |
Source: | Code function: | 28_2_00FB4F58 | |
Source: | Code function: | 28_2_00FB3860 |
Source: | Dropped File: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | Base64 encoded string: |