Edit tour
Windows
Analysis Report
CuteWriter.exe
Overview
General Information
Detection
Score: | 26 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 20% |
Compliance
Score: | 35 |
Range: | 0 - 100 |
Signatures
Suricata IDS alerts for network traffic
AI detected landing page (webpage, office document or email)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Downloads executable code via HTTP
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
HTML page contains hidden javascript code
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
PE file contains executable resources (Code or Archives)
PE file contains sections with non-standard names
Sample file is different than original file name gathered from version info
Stores files to the Windows start menu directory
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses insecure TLS / SSL version for HTTPS connection
Classification
- System is w10x64
- CuteWriter.exe (PID: 2268 cmdline:
"C:\Users\ user\Deskt op\CuteWri ter.exe" MD5: 604FDAF426407ABE31F9AFDD0028059F) - CuteWriter.tmp (PID: 3992 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\is-OJ6 AG.tmp\Cut eWriter.tm p" /SL5="$ 20434,3034 260,56832, C:\Users\u ser\Deskto p\CuteWrit er.exe" MD5: FFCF263A020AA7794015AF0EDEE5DF0B) - Setup.exe (PID: 5640 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\is-EJP G2.tmp\Set up.exe" /i nscpw4 -d" C:\Program Files (x8 6)\CutePDF Writer" MD5: A8EFE2A017079497FE948191F8904A17) - converter.exe (PID: 5020 cmdline:
C:\Users\u ser\AppDat a\Local\Te mp\\conver ter.exe /a uto MD5: BF9F58A65F6954406E6DCD29BB458A19) - Setup.exe (PID: 7232 cmdline:
Setup.exe MD5: 78A9054B6FD6A7249B67A63BA827A84B) - conhost.exe (PID: 7260 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - unInstcpw64.exe (PID: 508 cmdline:
unInstcpw6 4.exe /cop y MD5: 7B17AE1C9AED3C8C89FF6CDEF68F9FD5) - splwow64.exe (PID: 1764 cmdline:
C:\Windows \splwow64. exe 12288 MD5: 77DE7761B037061C7C112FD3C5B91E73) - chrome.exe (PID: 1080 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed --sing le-argumen t https:// www.cutepd f-editor.c om/support /writer.as p MD5: 5BBFA6CBDF4C254EB368D534F9E23C92) - chrome.exe (PID: 7084 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2124 --fi eld-trial- handle=198 4,i,118507 4701902119 5928,44106 4506813679 0906,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
- cleanup
⊘No configs have been found
⊘No yara matches
⊘No Sigma rule has matched
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-24T13:30:28.992812+0200 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.6 | 49858 | 64.34.201.145 | 80 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-24T13:30:28.992812+0200 | 2812710 | 1 | Malware Command and Control Activity Detected | 192.168.2.6 | 49858 | 64.34.201.145 | 80 | TCP |
Click to jump to signature section
Show All Signature Results
Source: | HTTP Parser: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Compliance |
---|
Source: | Static PE information: |
Source: | HTTPS traffic detected: |
Source: | Window detected: |