Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Headers.txt

Overview

General Information

Sample name:Headers.txt
Analysis ID:1546030
MD5:1210ed0fc10fd3598822db02c16f56a5
SHA1:8252a8f82d5b3622e3069f6da284ef98a67f23b5
SHA256:ad677ec47beae162c66aa0db251184118ee4137f1f486648653d39ae05e3c231
Infos:

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Queries the volume information (name, serial number etc) of a device
Suricata IDS alerts with low severity for network traffic

Classification

  • System is w10x64
  • notepad.exe (PID: 6912 cmdline: "C:\Windows\system32\NOTEPAD.EXE" C:\Users\user\Desktop\Headers.txt MD5: 27F71B12CB585541885A31BE22F61C83)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2024-10-31T11:54:00.844961+010020229301A Network Trojan was detected20.109.210.53443192.168.2.749790TCP
2024-10-31T11:54:39.617021+010020229301A Network Trojan was detected20.109.210.53443192.168.2.749975TCP

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: Network trafficSuricata IDS: 2022930 - Severity 1 - ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow : 20.109.210.53:443 -> 192.168.2.7:49790
Source: Network trafficSuricata IDS: 2022930 - Severity 1 - ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow : 20.109.210.53:443 -> 192.168.2.7:49975
Source: notepad.exe, 00000001.00000003.1313683575.000001DD6B251000.00000004.00000020.00020000.00000000.sdmp, notepad.exe, 00000001.00000002.2570826877.000001DD6B251000.00000004.00000020.00020000.00000000.sdmp, Headers.txtString found in binary or memory: https://info.nhanow.com/hs/subscription-preferences/v2/unsubscribe-all?data=W2nXS-N30h-H8W34gPnK3LG4
Source: notepad.exe, 00000001.00000003.1313683575.000001DD6B251000.00000004.00000020.00020000.00000000.sdmp, notepad.exe, 00000001.00000002.2570826877.000001DD6B251000.00000004.00000020.00020000.00000000.sdmp, Headers.txtString found in binary or memory: https://policy.hubspot.com/abuse-complaints)
Source: classification engineClassification label: clean1.winTXT@1/0@0/0
Source: C:\Windows\System32\notepad.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: mrmcorer.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: efswrt.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: twinapi.appcore.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: oleacc.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: policymanager.dllJump to behavior
Source: C:\Windows\System32\notepad.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Windows\System32\notepad.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11659a23-5884-4d1b-9cf6-67d6f4f90b36}\InProcServer32Jump to behavior
Source: C:\Windows\System32\notepad.exeQueries volume information: C:\Users\user\Desktop\Headers.txt VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
DLL Side-Loading
1
DLL Side-Loading
1
DLL Side-Loading
OS Credential Dumping11
System Information Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
https://policy.hubspot.com/abuse-complaints)notepad.exe, 00000001.00000003.1313683575.000001DD6B251000.00000004.00000020.00020000.00000000.sdmp, notepad.exe, 00000001.00000002.2570826877.000001DD6B251000.00000004.00000020.00020000.00000000.sdmp, Headers.txtfalse
    unknown
    https://info.nhanow.com/hs/subscription-preferences/v2/unsubscribe-all?data=W2nXS-N30h-H8W34gPnK3LG4notepad.exe, 00000001.00000003.1313683575.000001DD6B251000.00000004.00000020.00020000.00000000.sdmp, notepad.exe, 00000001.00000002.2570826877.000001DD6B251000.00000004.00000020.00020000.00000000.sdmp, Headers.txtfalse
      unknown
      No contacted IP infos
      Joe Sandbox version:41.0.0 Charoite
      Analysis ID:1546030
      Start date and time:2024-10-31 11:52:34 +01:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 3m 53s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:default.jbs
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:8
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • EGA enabled
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Sample name:Headers.txt
      Detection:CLEAN
      Classification:clean1.winTXT@1/0@0/0
      Cookbook Comments:
      • Found application associated with file extension: .txt
      • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
      • Excluded domains from analysis (whitelisted): otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com, time.windows.com, fe3cr.delivery.mp.microsoft.com
      • Not all processes where analyzed, report is missing behavior information
      • VT rate limit hit for: Headers.txt
      No simulations
      No context
      No context
      No context
      No context
      No context
      No created / dropped files found
      File type:RFC 822 mail, ASCII text, with very long lines (1326), with CRLF line terminators
      Entropy (8bit):6.0169142315936615
      TrID:
        File name:Headers.txt
        File size:9'358 bytes
        MD5:1210ed0fc10fd3598822db02c16f56a5
        SHA1:8252a8f82d5b3622e3069f6da284ef98a67f23b5
        SHA256:ad677ec47beae162c66aa0db251184118ee4137f1f486648653d39ae05e3c231
        SHA512:83e4b9427c06f813192c0ed0f82045e3252e6932f5ebe09abf12549b25007d3400be3c5c8e80a1f01cf55152fdf5c95b2379211a0cc3ab8df15d4ebb1af92a98
        SSDEEP:192:oHeZpXqXOC2spbDPNAF6poKN+7THtUI6YPnPvz2pyFCdZ:oaXCZpnlFpoblUILb2/
        TLSH:0B124C12A423C858589653C62F026E19B76354AA13B0C3C0F6DECBF577461AD73DD703
        File Content Preview:Received: from PRDHCCEXCH05.lrmcad.lrmcnet.com (10.152.37.21) by PRDPWCEXCH03.lrmcad.lrmcnet.com (172.23.129.67) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.11 via Mailbox Transport; Wed, 30 Oct 2
        Icon Hash:72eaa2aaa2a2a292
        No network behavior found

        Click to jump to process

        Click to jump to process

        Click to dive into process behavior distribution

        Target ID:1
        Start time:06:53:40
        Start date:31/10/2024
        Path:C:\Windows\System32\notepad.exe
        Wow64 process (32bit):false
        Commandline:"C:\Windows\system32\NOTEPAD.EXE" C:\Users\user\Desktop\Headers.txt
        Imagebase:0x7ff711430000
        File size:201'216 bytes
        MD5 hash:27F71B12CB585541885A31BE22F61C83
        Has elevated privileges:true
        Has administrator privileges:true
        Programmed in:C, C++ or other language
        Reputation:moderate
        Has exited:false

        No disassembly