Edit tour
Windows
Analysis Report
SecuriteInfo.com.Win32.Trojan-Downloader.Generic.XVN7C1.21480.14818.exe
Overview
General Information
Detection
Score: | 72 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Multi AV Scanner detection for submitted file
AI detected suspicious sample
Machine Learning detection for dropped file
Allocates memory with a write watch (potentially for evading sandboxes)
Binary contains a suspicious time stamp
Contains functionality for read data from the clipboard
Contains functionality to call native functions
Contains functionality to dynamically determine API calls
Contains functionality to shutdown / reboot the system
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Drops PE files
Enables debug privileges
Found dropped PE file which has not been started or loaded
IP address seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Shows file infection / information gathering behavior (enumerates multiple directory for files)
Sigma detected: CurrentVersion Autorun Keys Modification
Too many similar processes found
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Classification
- System is w10x64
- SecuriteInfo.com.Win32.Trojan-Downloader.Generic.XVN7C1.21480.14818.exe (PID: 4708 cmdline:
"C:\Users\ user\Deskt op\Securit eInfo.com. Win32.Troj an-Downloa der.Generi c.XVN7C1.2 1480.14818 .exe" MD5: E9521EC55C41641CC645A0223B1E9AC1) - setup.exe (PID: 6444 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\setup. exe" MD5: 2B4BA70B5C6115ADD73FDEF28AAEAA8A) - GamePall.exe (PID: 5408 cmdline:
C:\Users\u ser\AppDat a\Roaming\ GamePall\G amePall.ex e MD5: 46A3A9D4CA0EBE2BC40FA28BBFCD7200) - GamePall.exe (PID: 4396 cmdline:
"C:\Users\ user\AppDa ta\Roaming \GamePall\ GamePall.e xe" --type =gpu-proce ss --no-sa ndbox --lo g-severity =disable - -user-agen t="Mozilla /5.0 (Maci ntosh; Int el Mac OS X 10_15_7) AppleWebK it/537.36 (KHTML, li ke Gecko) Chrome/127 .0.0.0 Saf ari/537.36 OPR/113.0 .0.0" --la ng=en-US - -user-data -dir="C:\U sers\user\ AppData\Lo cal\CEF\Us er Data" - -gpu-prefe rences=WAA AAAAAAADgA AAMAAAAAAA AAAAAAAAAA ABgAAAAAAA 4AAAAAAAAA AAAAAAEAAA AAAAAAAAAA AAAAAAAAAA AAAAAAAAAA AAAGAAAAAA AAAAYAAAAA AAAAAgAAAA AAAAACAAAA AAAAAAIAAA AAAAAAA== --log-file ="C:\Users \user\AppD ata\Roamin g\GamePall \debug.log " --mojo-p latform-ch annel-hand le=3256 -- field-tria l-handle=3 248,i,1138 0243691243 800328,179 6618718091 5203330,26 2144 --dis able-featu res=BackFo rwardCache ,Calculate NativeWinO cclusion,D ocumentPic tureInPict ureAPI /pr efetch:2 MD5: 46A3A9D4CA0EBE2BC40FA28BBFCD7200) - GamePall.exe (PID: 5684 cmdline:
"C:\Users\ user\AppDa ta\Roaming \GamePall\ GamePall.e xe" --type =utility - -utility-s ub-type=st orage.mojo m.StorageS ervice --l ang=en-US --service- sandbox-ty pe=service --no-sand box --log- severity=d isable --u ser-agent= "Mozilla/5 .0 (Macint osh; Intel Mac OS X 10_15_7) A ppleWebKit /537.36 (K HTML, like Gecko) Ch rome/127.0 .0.0 Safar i/537.36 O PR/113.0.0 .0" --lang =en-US --u ser-data-d ir="C:\Use rs\user\Ap pData\Loca l\CEF\User Data" --l og-file="C :\Users\us er\AppData \Roaming\G amePall\de bug.log" - -mojo-plat form-chann el-handle= 3720 --fie ld-trial-h andle=3248 ,i,1138024 3691243800 328,179661 8718091520 3330,26214 4 --disabl e-features =BackForwa rdCache,Ca lculateNat iveWinOccl usion,Docu mentPictur eInPicture API /prefe tch:8 MD5: 46A3A9D4CA0EBE2BC40FA28BBFCD7200) - GamePall.exe (PID: 5148 cmdline:
"C:\Users\ user\AppDa ta\Roaming \GamePall\ GamePall.e xe" --type =utility - -utility-s ub-type=ne twork.mojo m.NetworkS ervice --l ang=en-US --service- sandbox-ty pe=none -- no-sandbox --log-sev erity=disa ble --user -agent="Mo zilla/5.0 (Macintosh ; Intel Ma c OS X 10_ 15_7) Appl eWebKit/53 7.36 (KHTM L, like Ge cko) Chrom e/127.0.0. 0 Safari/5 37.36 OPR/ 113.0.0.0" --lang=en -US --user -data-dir= "C:\Users\ user\AppDa ta\Local\C EF\User Da ta" --log- file="C:\U sers\user\ AppData\Ro aming\Game Pall\debug .log" --mo jo-platfor m-channel- handle=379 6 --field- trial-hand le=3248,i, 1138024369 1243800328 ,179661871 8091520333 0,262144 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,Documen tPictureIn PictureAPI /prefetch :8 MD5: 46A3A9D4CA0EBE2BC40FA28BBFCD7200) - GamePall.exe (PID: 4408 cmdline:
"C:\Users\ user\AppDa ta\Roaming \GamePall\ GamePall.e xe" --type =renderer --log-seve rity=disab le --user- agent="Moz illa/5.0 ( Macintosh; Intel Mac OS X 10_1 5_7) Apple WebKit/537 .36 (KHTML , like Gec ko) Chrome /127.0.0.0 Safari/53 7.36 OPR/1 13.0.0.0" --user-dat a-dir="C:\ Users\user \AppData\L ocal\CEF\U ser Data" --first-re nderer-pro cess --no- sandbox -- log-file=" C:\Users\u ser\AppDat a\Roaming\ GamePall\d ebug.log" --lang=en- US --devic e-scale-fa ctor=1 --n um-raster- threads=2 --enable-m ain-frame- before-act ivation -- renderer-c lient-id=6 --time-ti cks-at-uni x-epoch=-1 7253395585 29135 --la unch-time- ticks=6350 788134 --m ojo-platfo rm-channel -handle=38 36 --field -trial-han dle=3248,i ,113802436 9124380032 8,17966187 1809152033 30,262144 --disable- features=B ackForward Cache,Calc ulateNativ eWinOcclus ion,Docume ntPictureI nPictureAP I /prefetc h:1 MD5: 46A3A9D4CA0EBE2BC40FA28BBFCD7200) - GamePall.exe (PID: 3596 cmdline:
"C:\Users\ user\AppDa ta\Roaming \GamePall\ GamePall.e xe" --type =renderer --log-seve rity=disab le --user- agent="Moz illa/5.0 ( Macintosh; Intel Mac OS X 10_1 5_7) Apple WebKit/537 .36 (KHTML , like Gec ko) Chrome /127.0.0.0 Safari/53 7.36 OPR/1 13.0.0.0" --user-dat a-dir="C:\ Users\user \AppData\L ocal\CEF\U ser Data" --no-sandb ox --log-f ile="C:\Us ers\user\A ppData\Roa ming\GameP all\debug. log" --lan g=en-US -- device-sca le-factor= 1 --num-ra ster-threa ds=2 --ena ble-main-f rame-befor e-activati on --rende rer-client -id=5 --ti me-ticks-a t-unix-epo ch=-172533 9558529135 --launch- time-ticks =635082670 9 --mojo-p latform-ch annel-hand le=3940 -- field-tria l-handle=3 248,i,1138 0243691243 800328,179 6618718091 5203330,26 2144 --dis able-featu res=BackFo rwardCache ,Calculate NativeWinO cclusion,D ocumentPic tureInPict ureAPI /pr efetch:1 MD5: 46A3A9D4CA0EBE2BC40FA28BBFCD7200) - GamePall.exe (PID: 4480 cmdline:
"C:\Users\ user\AppDa ta\Roaming \GamePall\ GamePall.e xe" --type =renderer --log-seve rity=disab le --user- agent="Moz illa/5.0 ( Macintosh; Intel Mac OS X 10_1 5_7) Apple WebKit/537 .36 (KHTML , like Gec ko) Chrome /127.0.0.0 Safari/53 7.36 OPR/1 13.0.0.0" --user-dat a-dir="C:\ Users\user \AppData\L ocal\CEF\U ser Data" --no-sandb ox --log-f ile="C:\Us ers\user\A ppData\Roa ming\GameP all\debug. log" --dis able-gpu-c ompositing --lang=en -US --devi ce-scale-f actor=1 -- num-raster -threads=2 --enable- main-frame -before-ac tivation - -renderer- client-id= 7 --time-t icks-at-un ix-epoch=- 1725339558 529135 --l aunch-time -ticks=635 7847939 -- mojo-platf orm-channe l-handle=2 060 --fiel d-trial-ha ndle=3248, i,11380243 6912438003 28,1796618 7180915203 330,262144 --disable -features= BackForwar dCache,Cal culateNati veWinOcclu sion,Docum entPicture InPictureA PI /prefet ch:1 MD5: 46A3A9D4CA0EBE2BC40FA28BBFCD7200)
- GamePall.exe (PID: 2848 cmdline:
"C:\Users\ user\AppDa ta\Roaming \GamePall\ GamePall.e xe" MD5: 46A3A9D4CA0EBE2BC40FA28BBFCD7200) - GamePall.exe (PID: 2384 cmdline:
"C:\Users\ user\AppDa ta\Roaming \GamePall\ GamePall.e xe" MD5: 46A3A9D4CA0EBE2BC40FA28BBFCD7200) - GamePall.exe (PID: 3364 cmdline:
"C:\Users\ user\AppDa ta\Roaming \GamePall\ GamePall.e xe" MD5: 46A3A9D4CA0EBE2BC40FA28BBFCD7200) - GamePall.exe (PID: 6524 cmdline:
"C:\Users\ user\AppDa ta\Roaming \GamePall\ GamePall.e xe" MD5: 46A3A9D4CA0EBE2BC40FA28BBFCD7200) - GamePall.exe (PID: 6412 cmdline:
"C:\Users\ user\AppDa ta\Roaming \GamePall\ GamePall.e xe" MD5: 46A3A9D4CA0EBE2BC40FA28BBFCD7200) - GamePall.exe (PID: 5752 cmdline:
"C:\Users\ user\AppDa ta\Roaming \GamePall\ GamePall.e xe" MD5: 46A3A9D4CA0EBE2BC40FA28BBFCD7200) - GamePall.exe (PID: 3924 cmdline:
"C:\Users\ user\AppDa ta\Roaming \GamePall\ GamePall.e xe" MD5: 46A3A9D4CA0EBE2BC40FA28BBFCD7200) - GamePall.exe (PID: 3588 cmdline:
"C:\Users\ user\AppDa ta\Roaming \GamePall\ GamePall.e xe" MD5: 46A3A9D4CA0EBE2BC40FA28BBFCD7200) - GamePall.exe (PID: 7200 cmdline:
"C:\Users\ user\AppDa ta\Roaming \GamePall\ GamePall.e xe" MD5: 46A3A9D4CA0EBE2BC40FA28BBFCD7200) - GamePall.exe (PID: 7328 cmdline:
"C:\Users\ user\AppDa ta\Roaming \GamePall\ GamePall.e xe" MD5: 46A3A9D4CA0EBE2BC40FA28BBFCD7200) - GamePall.exe (PID: 7144 cmdline:
"C:\Users\ user\AppDa ta\Roaming \GamePall\ GamePall.e xe" MD5: 46A3A9D4CA0EBE2BC40FA28BBFCD7200) - GamePall.exe (PID: 7320 cmdline:
"C:\Users\ user\AppDa ta\Roaming \GamePall\ GamePall.e xe" MD5: 46A3A9D4CA0EBE2BC40FA28BBFCD7200) - GamePall.exe (PID: 3892 cmdline:
"C:\Users\ user\AppDa ta\Roaming \GamePall\ GamePall.e xe" MD5: 46A3A9D4CA0EBE2BC40FA28BBFCD7200) - GamePall.exe (PID: 3340 cmdline:
"C:\Users\ user\AppDa ta\Roaming \GamePall\ GamePall.e xe" MD5: 46A3A9D4CA0EBE2BC40FA28BBFCD7200) - GamePall.exe (PID: 7352 cmdline:
"C:\Users\ user\AppDa ta\Roaming \GamePall\ GamePall.e xe" MD5: 46A3A9D4CA0EBE2BC40FA28BBFCD7200) - GamePall.exe (PID: 4336 cmdline:
"C:\Users\ user\AppDa ta\Roaming \GamePall\ GamePall.e xe" MD5: 46A3A9D4CA0EBE2BC40FA28BBFCD7200) - GamePall.exe (PID: 4524 cmdline:
"C:\Users\ user\AppDa ta\Roaming \GamePall\ GamePall.e xe" MD5: 46A3A9D4CA0EBE2BC40FA28BBFCD7200) - GamePall.exe (PID: 5768 cmdline:
"C:\Users\ user\AppDa ta\Roaming \GamePall\ GamePall.e xe" MD5: 46A3A9D4CA0EBE2BC40FA28BBFCD7200) - GamePall.exe (PID: 6116 cmdline:
"C:\Users\ user\AppDa ta\Roaming \GamePall\ GamePall.e xe" MD5: 46A3A9D4CA0EBE2BC40FA28BBFCD7200) - GamePall.exe (PID: 2284 cmdline:
"C:\Users\ user\AppDa ta\Roaming \GamePall\ GamePall.e xe" MD5: 46A3A9D4CA0EBE2BC40FA28BBFCD7200) - GamePall.exe (PID: 5596 cmdline:
"C:\Users\ user\AppDa ta\Roaming \GamePall\ GamePall.e xe" MD5: 46A3A9D4CA0EBE2BC40FA28BBFCD7200) - GamePall.exe (PID: 5764 cmdline:
"C:\Users\ user\AppDa ta\Roaming \GamePall\ GamePall.e xe" MD5: 46A3A9D4CA0EBE2BC40FA28BBFCD7200) - GamePall.exe (PID: 5264 cmdline:
"C:\Users\ user\AppDa ta\Roaming \GamePall\ GamePall.e xe" MD5: 46A3A9D4CA0EBE2BC40FA28BBFCD7200) - GamePall.exe (PID: 6128 cmdline:
"C:\Users\ user\AppDa ta\Roaming \GamePall\ GamePall.e xe" MD5: 46A3A9D4CA0EBE2BC40FA28BBFCD7200) - GamePall.exe (PID: 2000 cmdline:
"C:\Users\ user\AppDa ta\Roaming \GamePall\ GamePall.e xe" MD5: 46A3A9D4CA0EBE2BC40FA28BBFCD7200) - GamePall.exe (PID: 7300 cmdline:
"C:\Users\ user\AppDa ta\Roaming \GamePall\ GamePall.e xe" MD5: 46A3A9D4CA0EBE2BC40FA28BBFCD7200)
- cleanup
⊘No configs have been found
⊘No yara matches
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | Avira: | ||
Source: | Avira: |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | Registry value created: | Jump to behavior |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Directory queried: |
Source: | Code function: | 0_2_00405B4A | |
Source: | Code function: | 0_2_004066FF | |
Source: | Code function: | 0_2_004027AA | |
Source: | Code function: | 5_2_00405B4A | |
Source: | Code function: | 5_2_004066FF | |
Source: | Code function: | 5_2_004027AA |
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Code function: | 0_2_004055E7 |
Source: | Process created: |
Source: | Code function: | 0_2_100010D0 |
Source: | Code function: | 0_2_004034CC | |
Source: | Code function: | 5_2_004034CC |
Source: | Code function: | 0_2_00406A88 | |
Source: | Code function: | 5_2_00406A88 | |
Source: | Code function: | 10_2_00C54F58 | |
Source: | Code function: | 11_2_01664F58 | |
Source: | Code function: | 11_2_0166F5C8 | |
Source: | Code function: | 11_2_01663860 | |
Source: | Code function: | 11_2_01661049 | |
Source: | Code function: | 11_2_0166F44A | |
Source: | Code function: | 11_2_0166F4D7 | |
Source: | Code function: | 12_2_00AE4F58 | |
Source: | Code function: | 12_2_00AEF660 | |
Source: | Code function: | 13_2_03054F58 | |
Source: | Code function: | 13_2_03051049 | |
Source: | Code function: | 26_2_01234F58 | |
Source: | Code function: | 26_2_01233860 | |
Source: | Code function: | 26_2_01231049 | |
Source: | Code function: | 35_2_01264F58 | |
Source: | Code function: | 35_2_01263860 | |
Source: | Code function: | 35_2_01261049 | |
Source: | Code function: | 37_2_01191049 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | Base64 encoded string: |