Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
dfsvc.exe

Overview

General Information

Sample name:dfsvc.exe
Analysis ID:1541340
MD5:3597d9e93852fddb92e0a0cf0452bb61
SHA1:d25c62a57ac3000244741bda129f483f2347efa6
SHA256:6e6cb0729cb902420739148ae23bf1c7959bc8ea2bf6b6277c5c0de45aa77df6
Infos:

Detection

Score:22
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

AI detected suspicious sample
Allocates memory with a write watch (potentially for evading sandboxes)
Contains long sleeps (>= 3 min)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device

Classification

  • System is w10x64
  • dfsvc.exe (PID: 6532 cmdline: "C:\Users\user\Desktop\dfsvc.exe" MD5: 3597D9E93852FDDB92E0A0CF0452BB61)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Submited SampleIntegrated Neural Analysis Model: Matched 81.0% probability
Source: dfsvc.exeStatic PE information: certificate valid
Source: dfsvc.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: Binary string: dfsvc.pdbD.^. P._CorExeMainmscoree.dll source: dfsvc.exe
Source: Binary string: dfsvc.pdb source: dfsvc.exe
Source: classification engineClassification label: sus22.winEXE@1/1@0/0
Source: C:\Users\user\Desktop\dfsvc.exeFile created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\dfsvc.exe.logJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeMutant created: NULL
Source: dfsvc.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: dfsvc.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 50.01%
Source: C:\Users\user\Desktop\dfsvc.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeSection loaded: version.dllJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeSection loaded: cryptbase.dllJump to behavior
Source: dfsvc.exeStatic PE information: certificate valid
Source: initial sampleStatic PE information: Valid certificate with Microsoft Issuer
Source: dfsvc.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
Source: dfsvc.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: dfsvc.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: dfsvc.pdbD.^. P._CorExeMainmscoree.dll source: dfsvc.exe
Source: Binary string: dfsvc.pdb source: dfsvc.exe
Source: C:\Users\user\Desktop\dfsvc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeMemory allocated: 18F37C40000 memory reserve | memory write watchJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeMemory allocated: 18F515E0000 memory reserve | memory write watchJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 922337203685477Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 600000Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 599875Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 599766Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 599657Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 599532Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 599407Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 599282Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 599157Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 599032Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 598922Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 598813Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 598563Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 598438Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 598282Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 598079Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 597947Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 597828Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 597719Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 597609Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 597500Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 597391Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 597281Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 597172Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 597063Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 596938Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 596813Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 596688Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 596578Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 596469Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 596344Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 596235Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 596110Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 595985Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 595860Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 595735Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 595610Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 595453Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 595344Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 595222Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 595094Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 594984Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 594875Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 594766Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 594657Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 594532Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 594407Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 594297Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 594188Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 594063Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 593938Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeWindow / User API: threadDelayed 8419Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeWindow / User API: threadDelayed 1421Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep count: 39 > 30Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -35971150943733603s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -600000s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -599875s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6644Thread sleep count: 8419 > 30Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6644Thread sleep count: 1421 > 30Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -599766s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -599657s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -599532s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -599407s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -599282s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -599157s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -599032s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -598922s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -598813s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -598563s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -598438s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -598282s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -598079s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -597947s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -597828s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -597719s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -597609s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -597500s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -597391s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -597281s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -597172s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -597063s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -596938s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -596813s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -596688s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -596578s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -596469s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -596344s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -596235s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -596110s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -595985s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -595860s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -595735s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -595610s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -595453s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -595344s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -595222s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -595094s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -594984s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -594875s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -594766s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -594657s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -594532s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -594407s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -594297s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -594188s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -594063s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exe TID: 6648Thread sleep time: -593938s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 922337203685477Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 600000Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 599875Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 599766Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 599657Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 599532Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 599407Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 599282Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 599157Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 599032Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 598922Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 598813Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 598563Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 598438Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 598282Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 598079Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 597947Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 597828Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 597719Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 597609Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 597500Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 597391Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 597281Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 597172Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 597063Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 596938Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 596813Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 596688Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 596578Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 596469Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 596344Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 596235Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 596110Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 595985Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 595860Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 595735Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 595610Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 595453Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 595344Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 595222Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 595094Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 594984Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 594875Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 594766Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 594657Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 594532Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 594407Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 594297Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 594188Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 594063Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeThread delayed: delay time: 593938Jump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeMemory allocated: page read and write | page guardJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeQueries volume information: C:\Users\user\Desktop\dfsvc.exe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\dfsvc.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
DLL Side-Loading
1
DLL Side-Loading
1
Masquerading
OS Credential Dumping31
Virtualization/Sandbox Evasion
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Disable or Modify Tools
LSASS Memory1
Application Window Discovery
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)31
Virtualization/Sandbox Evasion
Security Account Manager12
System Information Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
DLL Side-Loading
NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
dfsvc.exe0%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1541340
Start date and time:2024-10-24 17:55:21 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 3m 41s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:6
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:dfsvc.exe
Detection:SUS
Classification:sus22.winEXE@1/1@0/0
Cookbook Comments:
  • Found application associated with file extension: .exe
  • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
  • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, 7.4.8.4.4.3.1.4.0.0.0.0.0.0.0.0.0.0.0.a.0.0.1.f.1.1.1.0.1.0.a.2.ip6.arpa, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
  • Not all processes where analyzed, report is missing behavior information
  • VT rate limit hit for: dfsvc.exe
TimeTypeDescription
11:56:13API Interceptor1280662x Sleep call for process: dfsvc.exe modified
No context
No context
No context
No context
No context
Process:C:\Users\user\Desktop\dfsvc.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):752
Entropy (8bit):5.379271095432949
Encrypted:false
SSDEEP:12:Q3La/hPAbDLI4M9tDLI4MWuPXcp151KDLI4MN5I/k1BakvoDLI4MWuPakEOsk7v:ML1XE4qpE4KQ71qE4GIs0E4KD
MD5:CBC56B59542A4F86288C49E21361FDCE
SHA1:256A520BB33AC1F9CB671B4737BD2192C30E9332
SHA-256:A408EDACF122DACCC364501556A9345126DEAB4419D1544246AC12B3014C39D7
SHA-512:D307B0560E7E2EE8A6EEBC0EA35F6ACE057965ECBE039CFC7599C7AE90B06BC850D8A6E507F9D37DC2531B6F078BB646BF36AAF58EE8C4E0589CF912B03FBDF3
Malicious:false
Reputation:low
Preview:1,"fusion","GAC",0..1,"WinRT","NotApp",1..2,"System.Deployment, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a",0..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_64\System\b187b7f31cee3e87b56c8edca55324e0\System.ni.dll",0..3,"System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Drawing\567ff6b0de7f9dcd8111001e94ab7cf6\System.Drawing.ni.dll",0..3,"System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Windows.Forms\2a7fffeef3976b2a6f273db66b1f0107\System.Windows.Forms.ni.dll",0..
File type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
Entropy (8bit):6.618100720659971
TrID:
  • Win32 Executable (generic) Net Framework (10011505/4) 50.01%
  • Win32 Executable (generic) a (10002005/4) 49.97%
  • Generic Win/DOS Executable (2004/3) 0.01%
  • DOS Executable Generic (2002/1) 0.01%
  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
File name:dfsvc.exe
File size:18'336 bytes
MD5:3597d9e93852fddb92e0a0cf0452bb61
SHA1:d25c62a57ac3000244741bda129f483f2347efa6
SHA256:6e6cb0729cb902420739148ae23bf1c7959bc8ea2bf6b6277c5c0de45aa77df6
SHA512:5af245a68516698f0bcb63829f1c3abe429a06e94755ab50a29f51914b39e4719a901d2174550b691d5b0fdf1e23ca921714a2c5b2739925ef902766e4ab10d0
SSDEEP:384:kNqQPZrpWKvX16WVFeyHRN7kpQtR9zusk0jUNu:k4IZbX1hYuCQP9zuDwUNu
TLSH:22826CD28BAC5113EC9718B016A5EA837E3C53DB48C6996B31CEE5593F837C1CB21369
File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....:.b.........."...0.............n.... ...@....@.. ....................................`................................
Icon Hash:90cececece8e8eb0
Entrypoint:0x402e6e
Entrypoint Section:.text
Digitally signed:true
Imagebase:0x400000
Subsystem:windows gui
Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Time Stamp:0x62B63ABF [Fri Jun 24 22:29:19 2022 UTC]
TLS Callbacks:
CLR (.Net) Version:
OS Version Major:4
OS Version Minor:0
File Version Major:4
File Version Minor:0
Subsystem Version Major:4
Subsystem Version Minor:0
Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744
Signature Valid:true
Signature Issuer:CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
Signature Validation Error:The operation completed successfully
Error Number:0
Not Before, Not After
  • 02/09/2021 19:32:59 01/09/2022 19:32:59
Subject Chain
  • CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
Version:3
Thumbprint MD5:D15B2B9631F8B37BA8D83A5AE528A8BB
Thumbprint SHA-1:8740DF4ACB749640AD318E4BE842F72EC651AD80
Thumbprint SHA-256:2EB421FBB33BBF9C8F6B58C754B0405F40E02CB6328936AAE39DB7A24880EA21
Serial:33000002528B33AAF895F339DB000000000252
Instruction
jmp dword ptr [00402000h]
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
NameVirtual AddressVirtual Size Is in Section
IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IMPORT0x2e1c0x4f.text
IMAGE_DIRECTORY_ENTRY_RESOURCE0x40000xa0c.rsrc
IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
IMAGE_DIRECTORY_ENTRY_SECURITY0x20000x27a0
IMAGE_DIRECTORY_ENTRY_BASERELOC0x60000xc.reloc
IMAGE_DIRECTORY_ENTRY_DEBUG0x2ce40x1c.text
IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
IMAGE_DIRECTORY_ENTRY_TLS0x00x0
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IAT0x20000x8.text
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48.text
IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
.text0x20000xe740x10001b510bfedb939f08b6dc96ba7e47c02eFalse0.55712890625data5.389483992507497IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
.rsrc0x40000xa0c0xc00c1ecdb1eda940036a01100f23ed09cf8False0.3424479166666667data4.225801393109791IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.reloc0x60000xc0x200ef563e389af6842eb23cd90f4dcd24b2False0.044921875data0.08153941234324169IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
NameRVASizeTypeLanguageCountryZLIB Complexity
RT_VERSION0x40900x3b0dataEnglishUnited States0.4713983050847458
RT_MANIFEST0x44500x5b5exported SGML document, ASCII textEnglishUnited States0.37782340862423
DLLImport
mscoree.dll_CorExeMain
Language of compilation systemCountry where language is spokenMap
EnglishUnited States
TimestampSource PortDest PortSource IPDest IP
Oct 24, 2024 17:56:59.291615009 CEST5350900162.159.36.2192.168.2.4
Oct 24, 2024 17:56:59.927233934 CEST53620111.1.1.1192.168.2.4

Click to jump to process

Click to jump to process

Click to dive into process behavior distribution

Target ID:0
Start time:11:56:12
Start date:24/10/2024
Path:C:\Users\user\Desktop\dfsvc.exe
Wow64 process (32bit):false
Commandline:"C:\Users\user\Desktop\dfsvc.exe"
Imagebase:0x18f37910000
File size:18'336 bytes
MD5 hash:3597D9E93852FDDB92E0A0CF0452BB61
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low
Has exited:true

No disassembly