Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
system.dat

Overview

General Information

Sample name:system.dat
(renamed file extension from none to dat)
Original sample name:system
Analysis ID:1545070
MD5:debb100904620161abb9aa41952d517d
SHA1:4c60f0278b50588b7a87299fd7ec22213cb6e8b4
SHA256:8f1ce3583699abfedc9d5c2bfb760d2fed2ca8f56cb21295e1c5de01378a47ee

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Program does not show much activity (idle)
Queries the volume information (name, serial number etc) of a device

Classification

  • System is w10x64
  • OpenWith.exe (PID: 2752 cmdline: C:\Windows\system32\OpenWith.exe -Embedding MD5: E4A834784FA08C17D47A1E72429C5109)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: system.datString found in binary or memory: http://www.passport.com
Source: system.datBinary string: \Device\LanmanRedirector
Source: system.datBinary string: \Device\Tcpip_{2B2A698E-59EA-43E1-B19A-50131FCE77C2}\Device\Tcpip_{78EABA17-4CEA-4E66-AA8C-495268357685}\Device\Tcpip_{48AC5D70-0249-4A99-B4D2-54FBAED35584}
Source: system.datBinary string: \Device\RasPppoe_{2B2A698E-59EA-43E1-B19A-50131FCE77C2}1
Source: system.datBinary string: \Device\RdpDr
Source: system.datBinary string: \Device\NetBIOS_NetBT_Tcpip_{2B2A698E-59EA-43E1-B19A-50131FCE77C2}\Device\NetBIOS_NetBT_Tcpip_{78EABA17-4CEA-4E66-AA8C-495268357685}\Device\NetBIOS_NetBT_Tcpip_{48AC5D70-0249-4A99-B4D2-54FBAED35584}
Source: system.datBinary string: MSAFD NetBIOS [\Device\NetBT_Tcpip_{78EABA17-4CEA-4E66-AA8C-495268357685}] DATAGRAM 1
Source: system.datBinary string: \Device\NamedPipe
Source: system.datBinary string: \Device\{C31BDA2C-D3D1-46A2-B70A-758970BB962E}
Source: system.datBinary string: \Device\{2B2A698E-59EA-43E1-B19A-50131FCE77C2}vk
Source: system.datBinary string: \Device\MailSlot
Source: system.datBinary string: \Device\Video0d L
Source: system.datBinary string: g\Device\Video0
Source: system.datBinary string: \Device\{9E8DC26F-458C-44A5-A80D-21B7A96AF20E}s
Source: system.datBinary string: \Device\Mup
Source: system.datBinary string: \Device\LanmanWorkstation_NetbiosSmb\Device\LanmanWorkstation_NetBT_Tcpip_{2B2A698E-59EA-43E1-B19A-50131FCE77C2}\Device\LanmanWorkstation_NetBT_Tcpip_{78EABA17-4CEA-4E66-AA8C-495268357685}\Device\LanmanWorkstation_NetBT_Tcpip_{48AC5D70-0249-4A99-B4D2-54FBAED35584}
Source: system.datBinary string: \Device\{2B2A698E-59EA-43E1-B19A-50131FCE77C2}PN
Source: system.datBinary string: \Device\WebDavRedirector
Source: system.datBinary string: \Device\NetbiosSmb\Device\NetBT_Tcpip_{2B2A698E-59EA-43E1-B19A-50131FCE77C2}\Device\NetBT_Tcpip_{78EABA17-4CEA-4E66-AA8C-495268357685}\Device\NetBT_Tcpip_{48AC5D70-0249-4A99-B4D2-54FBAED35584}
Source: system.datBinary string: \Device\Ndisuio_{2B2A698E-59EA-43E1-B19A-50131FCE77C2}m
Source: system.datBinary string: \Device\
Source: system.datBinary string: \Device\NdisWanIp2}
Source: system.datBinary string: MSAFD NetBIOS [\Device\NetBT_Tcpip_{78EABA17-4CEA-4E66-AA8C-495268357685}] SEQPACKET 1
Source: system.datBinary string: MSAFD NetBIOS [\Device\NetBT_Tcpip_{48AC5D70-0249-4A99-B4D2-54FBAED35584}] SEQPACKET 2
Source: system.datBinary string: \Device\Video0
Source: system.datBinary string: \Device\NdisWan_{C31BDA2C-D3D1-46A2-B70A-758970BB962E}\Device\NdisWan_{1F6A35C7-19E4-4BB8-8660-D3F5A5C2025B}\Device\NdisWan_{E5FE635E-3B12-43B4-BB2D-795EF4835211}\Device\NdisWan_{6BC895D6-85DD-4266-BF84-BC678968CEB1}\Device\NdisWan_{9E8DC26F-458C-44A5-A80D-21B7A96AF20E}
Source: system.datBinary string: \Device\{54C7D140-09EF-11D1-B25A-F5FE627ED95E}
Source: system.datBinary string: \Device\{6BC895D6-85DD-4266-BF84-BC678968CEB1}
Source: system.datBinary string: MSAFD NetBIOS [\Device\NetBT_Tcpip_{2B2A698E-59EA-43E1-B19A-50131FCE77C2}] SEQPACKET 0
Source: system.datBinary string: \Device\{1F6A35C7-19E4-4BB8-8660-D3F5A5C2025B}
Source: system.datBinary string: \Device\{2B2A698E-59EA-43E1-B19A-50131FCE77C2}-5
Source: system.datBinary string: \Device\{E5FE635E-3B12-43B4-BB2D-795EF4835211}
Source: system.datBinary string: \Device\LanmanServer_NetbiosSmb\Device\LanmanServer_NetBT_Tcpip_{2B2A698E-59EA-43E1-B19A-50131FCE77C2}\Device\LanmanServer_NetBT_Tcpip_{78EABA17-4CEA-4E66-AA8C-495268357685}\Device\LanmanServer_NetBT_Tcpip_{48AC5D70-0249-4A99-B4D2-54FBAED35584}
Source: system.datBinary string: \Device\{C31BDA2C-D3D1-46A2-B70A-758970BB962E}\Device\{1F6A35C7-19E4-4BB8-8660-D3F5A5C2025B}\Device\{E5FE635E-3B12-43B4-BB2D-795EF4835211}\Device\{6BC895D6-85DD-4266-BF84-BC678968CEB1}\Device\{9E8DC26F-458C-44A5-A80D-21B7A96AF20E}
Source: system.datBinary string: \Device\HarddiskVolume1ion1
Source: system.datBinary string: \Device\NetBT_Tcpip_{2B2A698E-59EA-43E1-B19A-50131FCE77C2}\Device\NetBT_Tcpip_{78EABA17-4CEA-4E66-AA8C-495268357685}\Device\NetBT_Tcpip_{48AC5D70-0249-4A99-B4D2-54FBAED35584}
Source: system.datBinary string: MSAFD NetBIOS [\Device\NetBT_Tcpip_{48AC5D70-0249-4A99-B4D2-54FBAED35584}] DATAGRAM 2
Source: system.datBinary string: \Device\{2B2A698E-59EA-43E1-B19A-50131FCE77C2}\Device\NdisWanIp
Source: system.datBinary string: \Device\Video0x
Source: system.datBinary string: \Device\NetBT_Tcpip_{48AC5D70-0249-4A99-B4D2-54FBAED35584}\Device\NetBT_Tcpip_{48AC5D70-0249-4A99-B4D2-54FBAED35584}\Device\NetBT_Tcpip_{78EABA17-4CEA-4E66-AA8C-495268357685}\Device\NetBT_Tcpip_{78EABA17-4CEA-4E66-AA8C-495268357685}\Device\NetBT_Tcpip_{2B2A698E-59EA-43E1-B19A-50131FCE77C2}\Device\NetBT_Tcpip_{2B2A698E-59EA-43E1-B19A-50131FCE77C2}
Source: system.datBinary string: MSAFD NetBIOS [\Device\NetBT_Tcpip_{2B2A698E-59EA-43E1-B19A-50131FCE77C2}] DATAGRAM 0
Source: system.datBinary string: \Device\Null
Source: system.datBinary string: \Device\NetbiosSmbtom
Source: classification engineClassification label: clean1.winDAT@1/0@0/0
Source: C:\Windows\System32\OpenWith.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2752:120:WilError_03
Source: C:\Windows\System32\OpenWith.exeFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Windows\System32\OpenWith.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: twinui.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: dwmapi.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: pdh.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: onecorecommonproxystub.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: actxprxy.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: windows.staterepositoryps.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: windows.ui.appdefaults.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: windows.ui.immersive.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: uiautomationcore.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: dui70.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: duser.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: dwrite.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: bcp47mrm.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: uianimation.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d11.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: dxgi.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: resourcepolicyclient.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: dxcore.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: dcomp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: oleacc.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: edputil.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: windows.ui.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: windowmanagementapi.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: inputhost.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: twinapi.appcore.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: twinapi.appcore.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: windowscodecs.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: thumbcache.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: policymanager.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: appresolver.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: bcp47langs.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: slc.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: sppc.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: tiledatarepository.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: staterepository.core.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: windows.staterepository.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: wtsapi32.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: windows.staterepositorycore.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: mrmcorer.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: appxdeploymentclient.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: sxs.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: directmanipulation.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32Jump to behavior
Source: system.datStatic file information: File size 2621440 > 1048576
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: system.datBinary or memory string: \??\IDE#CdRomNECVMWar_VMware_IDE_CDR10_______________1.00____#3031303030303030303030303030303030303130#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Source: system.datBinary or memory string: \\?\SCSI#Disk&Ven_VMware_&Prod_VMware_Virtual_S&Rev_1.0#4&1588251b&0&000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
Source: system.datBinary or memory string: ##?#IDE#CdRomNECVMWar_VMware_IDE_CDR10_______________1.00____#3031303030303030303030303030303030303130#{1186654d-47b8-48b9-beb9-7df113ae3c67}0
Source: system.datBinary or memory string: Disk&Ven_VMware_&Prod_VMware_Virtual_S&Rev_1.0
Source: system.datBinary or memory string: \\?\IDE#CdRomNECVMWar_VMware_IDE_CDR10_______________1.00____#3031303030303030303030303030303030303130#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}
Source: system.datBinary or memory string: VMware Virtual USB Mouse
Source: system.datBinary or memory string: ##?#IDE#CdRomNECVMWar_VMware_IDE_CDR10_______________1.00____#3031303030303030303030303030303030303130#{1186654d-47b8-48b9-beb9-7df113ae3c67}
Source: system.datBinary or memory string: .Disk&Ven_VMware_&Prod_VMware_Virtual_S&Rev_1.0
Source: system.datBinary or memory string: \\?\IDE#CdRomNECVMWar_VMware_IDE_CDR10_______________1.00____#3031303030303030303030303030303030303130#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}h
Source: system.datBinary or memory string: CdRomNECVMWar_VMware_IDE_CDR10_______________1.00____
Source: system.datBinary or memory string: \??\IDE#CdRomNECVMWar_VMware_IDE_CDR10_______________1.00____#3031303030303030303030303030303030303130#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}X
Source: system.datBinary or memory string: SCSI\Disk&Ven_VMware_&Prod_VMware_Virtual_S&Rev_1.0\4&1588251b&0&000
Source: system.datBinary or memory string: ##?#IDE#CdRomNECVMWar_VMware_IDE_CDR10_______________1.00____#3031303030303030303030303030303030303130#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}
Source: system.datBinary or memory string: SCSI\DiskVMware__VMware_Virtual_S1.0_SCSI\DiskVMware__VMware_Virtual_SSCSI\DiskVMware__SCSI\VMware__VMware_Virtual_S1VMware__VMware_Virtual_S1GenDisk
Source: system.datBinary or memory string: \\?\IDE#CdRomNECVMWar_VMware_IDE_CDR10_______________1.00____#3031303030303030303030303030303030303130#{1186654d-47b8-48b9-beb9-7df113ae3c67}p
Source: system.datBinary or memory string: ##?#IDE#CdRomNECVMWar_VMware_IDE_CDR10_______________1.00____#3031303030303030303030303030303030303130#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}0
Source: system.datBinary or memory string: IDE\CdRomNECVMWar_VMware_IDE_CDR10_______________1.00____IDE\NECVMWar_VMware_IDE_CDR10_______________1.00____IDE\CdRomNECVMWar_VMware_IDE_CDR10_______________NECVMWar_VMware_IDE_CDR10_______________1.00____GenCdRom
Source: system.datBinary or memory string: VMware Virtual USB Hub
Source: system.datBinary or memory string: o##?#SCSI#Disk&Ven_VMware_&Prod_VMware_Virtual_S&Rev_1.0#4&1588251b&0&000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}p
Source: system.datBinary or memory string: P5CdRomNECVMWar_VMware_IDE_CDR10_______________1.00____
Source: system.datBinary or memory string: \\?\IDE#CdRomNECVMWar_VMware_IDE_CDR10_______________1.00____#3031303030303030303030303030303030303130#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Source: system.datBinary or memory string: ##?#IDE#CdRomNECVMWar_VMware_IDE_CDR10_______________1.00____#3031303030303030303030303030303030303130#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Source: system.datBinary or memory string: \\?\IDE#CdRomNECVMWar_VMware_IDE_CDR10_______________1.00____#3031303030303030303030303030303030303130#{1186654d-47b8-48b9-beb9-7df113ae3c67}H
Source: system.datBinary or memory string: ##?#SCSI#Disk&Ven_VMware_&Prod_VMware_Virtual_S&Rev_1.0#4&1588251b&0&000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
Source: system.datBinary or memory string: VMware, VMware Virtual S SCSI Disk Device
Source: system.datBinary or memory string: NECVMWar VMware IDE CDR10
Source: system.datBinary or memory string: IDE\CdRomNECVMWar_VMware_IDE_CDR10_______________1.00____\3031303030303030303030303030303030303130
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: system.datBinary or memory string: comm.drv commdlg.dll ctl3dv2.dll ddeml.dll keyboard.drv lanman.drv mmsystem.dll mouse.drv netapi.dll olecli.dll olesvr.dll pmspl.dll shell.dll sound.drv system.drv toolhelp.dll vga.drv wfwnet.drv win87em.dll winoldap.mod winsock.dll winspool.exe wowdeb.exe timer.drv rasapi16.dll compobj.dll storage.dll ole2.dll ole2disp.dll ole2nls.dll typelib.dll msvideo.dll avifile.dll msacm.dll mciavi.drv mciseq.drv mciwave.drv progman.exe avicap.dll mapi.dll
Source: C:\Windows\System32\OpenWith.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
Source: C:\Windows\System32\OpenWith.exeQueries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformationJump to behavior
Source: C:\Windows\System32\OpenWith.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformationJump to behavior
Source: C:\Windows\System32\OpenWith.exeQueries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
DLL Side-Loading
1
Process Injection
1
Process Injection
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
DLL Side-Loading
LSASS Memory1
Process Discovery
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account Manager1
File and Directory Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDS11
System Information Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
system.dat0%VirustotalBrowse
system.dat0%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://www.passport.com0%VirustotalBrowse
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://www.passport.comsystem.datfalseunknown
No contacted IP infos
Joe Sandbox version:41.0.0 Charoite
Analysis ID:1545070
Start date and time:2024-10-30 03:45:14 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 3m 59s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:5
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:system.dat
(renamed file extension from none to dat)
Original Sample Name:system
Detection:CLEAN
Classification:clean1.winDAT@1/0@0/0
EGA Information:Failed
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 0
  • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
  • Excluded domains from analysis (whitelisted): client.wns.windows.com, fs.microsoft.com, ocsp.digicert.com, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
  • Report size getting too big, too many NtOpenKeyEx calls found.
  • Report size getting too big, too many NtProtectVirtualMemory calls found.
  • Report size getting too big, too many NtQueryValueKey calls found.
TimeTypeDescription
22:46:08API Interceptor1x Sleep call for process: OpenWith.exe modified
No context
No context
No context
No context
No context
No created / dropped files found
File type:MS Windows registry file, NT/2000 or above
Entropy (8bit):4.396943121357691
TrID:
  • Windows NT Registry Hive (4004/1) 100.00%
File name:system.dat
File size:2'621'440 bytes
MD5:debb100904620161abb9aa41952d517d
SHA1:4c60f0278b50588b7a87299fd7ec22213cb6e8b4
SHA256:8f1ce3583699abfedc9d5c2bfb760d2fed2ca8f56cb21295e1c5de01378a47ee
SHA512:afa98773284b91b977100e1c98636cfc6a05c088f320f071dbe2c632e0ba97c0aca768fb13b6837b6d44587c173451ac8d06fd54e6223e16435d40979df39a79
SSDEEP:12288:sXn0tEgU891ogAZD7V+4IuTmMAsyuHpOJ/8m1H:syUfBnTlDy2C
TLSH:6AC52F01BF94D1C4E2718A329DE68F415635FD629D318B0B3394330F8EFAB85A963B56
File Content Preview:regf........h....................... .....'.....S.Y.S.T.E.M..................................................... Q.._SC_.T.._SC_hX.._SC_P\.._SC_``.._SC_.c.._SC_.g.._SC_hk.._SC_8o.._SC_....................................................................vk.
Icon Hash:74f0e4e4e4e4e0e4
No network behavior found

Click to jump to process

Click to jump to process

Target ID:0
Start time:22:46:08
Start date:29/10/2024
Path:C:\Windows\System32\OpenWith.exe
Wow64 process (32bit):false
Commandline:C:\Windows\system32\OpenWith.exe -Embedding
Imagebase:0x7ff7aa930000
File size:123'984 bytes
MD5 hash:E4A834784FA08C17D47A1E72429C5109
Has elevated privileges:false
Has administrator privileges:false
Programmed in:C, C++ or other language
Reputation:high
Has exited:true

No disassembly