Edit tour
Analysis Report
General Information
Score: | 42 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Score: | 36 |
Range: | 0 - 100 |
Detected unpacking (changes PE section rights)
AI detected suspicious sample
Hides threads from debuggers
PE file contains section with special chars
Performs DNS TXT record lookups
Tries to detect process monitoring tools (Task Manager, Process Explorer etc.)
Tries to detect sandboxes / dynamic malware analysis system (registry check)
Tries to detect sandboxes and other dynamic analysis tools (window names)
Tries to detect virtualization through RDTSC time measurements
Tries to evade debugger and weak emulator (self modifying code)
Abnormal high CPU Usage
Allocates memory with a write watch (potentially for evading sandboxes)
Checks for debuggers (devices)
Checks if the current process is being debugged
Contains capabilities to detect virtual machines
Contains functionality for read data from the clipboard
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to shutdown / reboot the system
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Detected non-DNS traffic on DNS port
Detected potential crypto function
Drops PE files
EXE planting / hijacking vulnerabilities found
Enables debug privileges
Entry point lies outside standard sections
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
PE file contains an invalid checksum
PE file contains sections with non-standard names
Potential key logger detected (key state polling based)
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Searches for user specific document files
Sigma detected: Explorer Process Tree Break
Stores files to the Windows start menu directory
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Uses taskkill to terminate processes
- System is w10x64
- SecuriteInfo.com.W32.PossibleThreat.20282.14864.exe (PID: 6304 cmdline:
"C:\Users\ user\Deskt op\Securit eInfo.com. W32.Possib leThreat.2 0282.14864 .exe" MD5: 7268329D169F985BE48D34007C4FD957) - cmd.exe (PID: 6548 cmdline:
"cmd.exe" /c taskkil l /f /im " BlackBerry BackupExtr actor.exe" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 3320 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - taskkill.exe (PID: 6880 cmdline:
taskkill / f /im "Bla ckBerryBac kupExtract or.exe" MD5: CA313FD7E6C2A778FFD21CFB5C1C56CD) - explorer.exe (PID: 6636 cmdline:
"C:\Window s\explorer .exe" C:\U sers\user\ AppData\Ro aming\Rein cubate\Bla ckBerry Ba ckup Extra ctor\Black BerryBacku pExtractor .exe MD5: 662F4F92FDE3557E86D110526BB578D5)
- explorer.exe (PID: 6196 cmdline:
C:\Windows \explorer. exe /facto ry,{75dff2 b7-6936-4c 06-a8bb-67 6a7b00b24b } -Embeddi ng MD5: 662F4F92FDE3557E86D110526BB578D5) - BlackBerryBackupExtractor.exe (PID: 420 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Reincubat e\BlackBer ry Backup Extractor\ BlackBerry BackupExtr actor.exe" MD5: 8CD8B27DAB255BA25B5283FB4496709D)
- cleanup
⊘No configs have been found
⊘No yara matches
System Summary |
Source: | Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), @gott_cyber: |
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
Source: | Integrated Neural Analysis Model: |
Source: | EXE: | Jump to behavior | ||
Source: | EXE: | Jump to behavior | ||
Source: | EXE: | Jump to behavior |
Compliance |
Source: | EXE: | Jump to behavior | ||
Source: | EXE: | Jump to behavior | ||
Source: | EXE: | Jump to behavior |
Source: | Static PE information: |
Source: | Window detected: |