Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
License premium.txt

Overview

General Information

Sample name:License premium.txt
Analysis ID:1543753
MD5:638b7f072b4aecfe9303dfaf33614a70
SHA1:228a1675b39774963d9fc29d415b177401955fa5
SHA256:660cd27e753e9fcc806947f9638b01400d1d8459617181ca244de3f6e1449253
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Queries the volume information (name, serial number etc) of a device

Classification

  • System is w10x64
  • notepad.exe (PID: 6956 cmdline: "C:\Windows\system32\NOTEPAD.EXE" C:\Users\user\Desktop\License premium.txt MD5: 27F71B12CB585541885A31BE22F61C83)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Windows\System32\notepad.exeWindow detected: IMPORTANT NOTICE: This license only applies if you downloaded this content asa subscribed (or "premium") user. If you are an unsubscribed user (or "free"user) you are bound to the license terms described in the accompanying file"License free.txt".---------------------You can download from your profile in Freepik a personalized license statingyour right to use this content as a "premium" user: https://profile.freepik.com/my_downloadsYou are free to use this image:- For both personal and commercial projects and to modify it.- In a website or presentation template or application or as part of your design.You are not allowed to:- Sub-license resell or rent it.- Include it in any online or offline archive or database.The full terms of the license are described in sections 7 and 8 of the Freepikterms of use available online in the following link: http://www.freepik.com/terms_of_useThe terms described in the above link have precedence over the terms describedin the present document. In case of disagreement the Freepik Terms of Usewill prevail.
Source: notepad.exe, 00000000.00000002.3435965402.000002922DF8C000.00000004.00000020.00020000.00000000.sdmp, License premium.txtString found in binary or memory: http://www.freepik.com/terms_of_use
Source: notepad.exe, 00000000.00000002.3435965402.000002922DF8C000.00000004.00000020.00020000.00000000.sdmp, License premium.txtString found in binary or memory: https://profile.freepik.com/my_downloads
Source: classification engineClassification label: clean0.winTXT@1/0@0/0
Source: C:\Windows\System32\notepad.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: mrmcorer.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: efswrt.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: twinapi.appcore.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: oleacc.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: policymanager.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Windows\System32\notepad.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11659a23-5884-4d1b-9cf6-67d6f4f90b36}\InProcServer32Jump to behavior
Source: C:\Windows\System32\notepad.exeWindow detected: IMPORTANT NOTICE: This license only applies if you downloaded this content asa subscribed (or "premium") user. If you are an unsubscribed user (or "free"user) you are bound to the license terms described in the accompanying file"License free.txt".---------------------You can download from your profile in Freepik a personalized license statingyour right to use this content as a "premium" user: https://profile.freepik.com/my_downloadsYou are free to use this image:- For both personal and commercial projects and to modify it.- In a website or presentation template or application or as part of your design.You are not allowed to:- Sub-license resell or rent it.- Include it in any online or offline archive or database.The full terms of the license are described in sections 7 and 8 of the Freepikterms of use available online in the following link: http://www.freepik.com/terms_of_useThe terms described in the above link have precedence over the terms describedin the present document. In case of disagreement the Freepik Terms of Usewill prevail.
Source: C:\Windows\System32\notepad.exeQueries volume information: C:\Users\user\Desktop\License premium.txt VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
DLL Side-Loading
1
DLL Side-Loading
1
DLL Side-Loading
OS Credential Dumping11
System Information Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
License premium.txt0%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://www.freepik.com/terms_of_usenotepad.exe, 00000000.00000002.3435965402.000002922DF8C000.00000004.00000020.00020000.00000000.sdmp, License premium.txtfalse
    unknown
    https://profile.freepik.com/my_downloadsnotepad.exe, 00000000.00000002.3435965402.000002922DF8C000.00000004.00000020.00020000.00000000.sdmp, License premium.txtfalse
      unknown
      No contacted IP infos
      Joe Sandbox version:41.0.0 Charoite
      Analysis ID:1543753
      Start date and time:2024-10-28 11:29:22 +01:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 3m 48s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:default.jbs
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:6
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Sample name:License premium.txt
      Detection:CLEAN
      Classification:clean0.winTXT@1/0@0/0
      EGA Information:Failed
      HCA Information:
      • Successful, ratio: 100%
      • Number of executed functions: 0
      • Number of non-executed functions: 0
      Cookbook Comments:
      • Found application associated with file extension: .txt
      • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
      • Excluded domains from analysis (whitelisted): client.wns.windows.com, ocsp.digicert.com, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
      • VT rate limit hit for: License premium.txt
      No simulations
      No context
      No context
      No context
      No context
      No context
      No created / dropped files found
      File type:ASCII text, with CRLF, LF line terminators
      Entropy (8bit):4.648478672913304
      TrID:
        File name:License premium.txt
        File size:1'115 bytes
        MD5:638b7f072b4aecfe9303dfaf33614a70
        SHA1:228a1675b39774963d9fc29d415b177401955fa5
        SHA256:660cd27e753e9fcc806947f9638b01400d1d8459617181ca244de3f6e1449253
        SHA512:bc0130046cb601e0bc3db2df73b6194e83ce734f55596f89202b1af6d02c6c3f71d096917498349057e52a27dae136334d244457776cdecfaf40311d26603f10
        SSDEEP:24:IKneSw06Hbx25HEYfDhjPu3wWZhc+Vr+3IibZaMortQ6JgluvI1+T:IKd767Q5HEeDhj8hc0+rbZaMsu6Jglut
        TLSH:8221B16F7E09535212A3C85579DB52C6F31521257F0AEA52F0A0801C7771B7C1FBE449
        File Content Preview:IMPORTANT NOTICE: This license only applies if you downloaded this content as..a subscribed (or "premium") user. If you are an unsubscribed user (or "free".user) you are bound to the license terms described in the accompanying file."License free.txt".....
        Icon Hash:72eaa2aaa2a2a292
        No network behavior found

        Click to jump to process

        Click to jump to process

        Click to dive into process behavior distribution

        Target ID:0
        Start time:06:30:22
        Start date:28/10/2024
        Path:C:\Windows\System32\notepad.exe
        Wow64 process (32bit):false
        Commandline:"C:\Windows\system32\NOTEPAD.EXE" C:\Users\user\Desktop\License premium.txt
        Imagebase:0x7ff6a0030000
        File size:201'216 bytes
        MD5 hash:27F71B12CB585541885A31BE22F61C83
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:moderate
        Has exited:false

        No disassembly