\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
ProgramId
|
|
|
TargetID: |
3
|
Path: |
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
Value name: |
ProgramId
|
Value data: |
00067e492d768e79731624bcdf2e7615f9180000ffff
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Antivirus / Scanner detection for submitted sample |
AV Detection |
|
Multi AV Scanner detection for submitted file |
AV Detection |
|
Machine Learning detection for sample |
AV Detection |
|
PE file contains section with special chars |
System Summary |
|
PE file contains an invalid checksum |
Data Obfuscation |
|
PE file contains sections with non-standard names |
Data Obfuscation |
|
Uses 32bit PE files |
Compliance, System Summary |
|
Binary may include packed or encrypted code |
Data Obfuscation |
Obfuscated Files or Information
|
PE file has section (not .text) which is very likely to contain packed code (zlib compression ratio < 0.011) |
System Summary |
|
Sample is known by Antivirus |
System Summary |
|
PE file has a big raw section |
System Summary |
|
Submission file is bigger than most known malware samples |
System Summary |
|
|
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
FileId
|
|
|
TargetID: |
3
|
Path: |
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
Value name: |
FileId
|
Value data: |
0000756ab7a405b31345bc40ae5a55d5b3940ccf3b44
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Antivirus / Scanner detection for submitted sample |
AV Detection |
|
Multi AV Scanner detection for submitted file |
AV Detection |
|
Machine Learning detection for sample |
AV Detection |
|
PE file contains section with special chars |
System Summary |
|
PE file contains an invalid checksum |
Data Obfuscation |
|
PE file contains sections with non-standard names |
Data Obfuscation |
|
Uses 32bit PE files |
Compliance, System Summary |
|
Binary may include packed or encrypted code |
Data Obfuscation |
Obfuscated Files or Information
|
PE file has section (not .text) which is very likely to contain packed code (zlib compression ratio < 0.011) |
System Summary |
|
Sample is known by Antivirus |
System Summary |
|
PE file has a big raw section |
System Summary |
|
Submission file is bigger than most known malware samples |
System Summary |
|
|
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
LowerCaseLongPath
|
|
|
TargetID: |
3
|
Path: |
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
Value name: |
LowerCaseLongPath
|
Value data: |
c:\users\user\desktop\file.exe
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Antivirus / Scanner detection for submitted sample |
AV Detection |
|
Multi AV Scanner detection for submitted file |
AV Detection |
|
Machine Learning detection for sample |
AV Detection |
|
PE file contains section with special chars |
System Summary |
|
PE file contains an invalid checksum |
Data Obfuscation |
|
PE file contains sections with non-standard names |
Data Obfuscation |
|
Uses 32bit PE files |
Compliance, System Summary |
|
Binary may include packed or encrypted code |
Data Obfuscation |
Obfuscated Files or Information
|
PE file has section (not .text) which is very likely to contain packed code (zlib compression ratio < 0.011) |
System Summary |
|
Sample is known by Antivirus |
System Summary |
|
PE file has a big raw section |
System Summary |
|
Submission file is bigger than most known malware samples |
System Summary |
|
|
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
LongPathHash
|
|
|
TargetID: |
3
|
Path: |
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
Value name: |
LongPathHash
|
Value data: |
file.exe|5c6ea74fda3dfec0
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Antivirus / Scanner detection for submitted sample |
AV Detection |
|
Multi AV Scanner detection for submitted file |
AV Detection |
|
Machine Learning detection for sample |
AV Detection |
|
PE file contains section with special chars |
System Summary |
|
PE file contains an invalid checksum |
Data Obfuscation |
|
PE file contains sections with non-standard names |
Data Obfuscation |
|
Uses 32bit PE files |
Compliance, System Summary |
|
Binary may include packed or encrypted code |
Data Obfuscation |
Obfuscated Files or Information
|
PE file has section (not .text) which is very likely to contain packed code (zlib compression ratio < 0.011) |
System Summary |
|
Sample is known by Antivirus |
System Summary |
|
PE file has a big raw section |
System Summary |
|
Submission file is bigger than most known malware samples |
System Summary |
|
|
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
Name
|
|
|
TargetID: |
3
|
Path: |
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
Value name: |
Name
|
Value data: |
file.exe
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Antivirus / Scanner detection for submitted sample |
AV Detection |
|
Multi AV Scanner detection for submitted file |
AV Detection |
|
Machine Learning detection for sample |
AV Detection |
|
PE file contains section with special chars |
System Summary |
|
PE file contains an invalid checksum |
Data Obfuscation |
|
PE file contains sections with non-standard names |
Data Obfuscation |
|
Uses 32bit PE files |
Compliance, System Summary |
|
Binary may include packed or encrypted code |
Data Obfuscation |
Obfuscated Files or Information
|
PE file has section (not .text) which is very likely to contain packed code (zlib compression ratio < 0.011) |
System Summary |
|
Sample is known by Antivirus |
System Summary |
|
PE file has a big raw section |
System Summary |
|
Submission file is bigger than most known malware samples |
System Summary |
|
|
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
OriginalFileName
|
|
|
TargetID: |
3
|
Path: |
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
Value name: |
OriginalFileName
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Antivirus / Scanner detection for submitted sample |
AV Detection |
|
Multi AV Scanner detection for submitted file |
AV Detection |
|
Machine Learning detection for sample |
AV Detection |
|
PE file contains section with special chars |
System Summary |
|
PE file contains an invalid checksum |
Data Obfuscation |
|
PE file contains sections with non-standard names |
Data Obfuscation |
|
Uses 32bit PE files |
Compliance, System Summary |
|
Binary may include packed or encrypted code |
Data Obfuscation |
Obfuscated Files or Information
|
PE file has section (not .text) which is very likely to contain packed code (zlib compression ratio < 0.011) |
System Summary |
|
Sample is known by Antivirus |
System Summary |
|
PE file has a big raw section |
System Summary |
|
Submission file is bigger than most known malware samples |
System Summary |
|
|
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
Publisher
|
|
|
TargetID: |
3
|
Path: |
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
Value name: |
Publisher
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Antivirus / Scanner detection for submitted sample |
AV Detection |
|
Multi AV Scanner detection for submitted file |
AV Detection |
|
Machine Learning detection for sample |
AV Detection |
|
PE file contains section with special chars |
System Summary |
|
PE file contains an invalid checksum |
Data Obfuscation |
|
PE file contains sections with non-standard names |
Data Obfuscation |
|
Uses 32bit PE files |
Compliance, System Summary |
|
Binary may include packed or encrypted code |
Data Obfuscation |
Obfuscated Files or Information
|
PE file has section (not .text) which is very likely to contain packed code (zlib compression ratio < 0.011) |
System Summary |
|
Sample is known by Antivirus |
System Summary |
|
PE file has a big raw section |
System Summary |
|
Submission file is bigger than most known malware samples |
System Summary |
|
|
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
Version
|
|
|
TargetID: |
3
|
Path: |
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
Value name: |
Version
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Antivirus / Scanner detection for submitted sample |
AV Detection |
|
Multi AV Scanner detection for submitted file |
AV Detection |
|
Machine Learning detection for sample |
AV Detection |
|
PE file contains section with special chars |
System Summary |
|
PE file contains an invalid checksum |
Data Obfuscation |
|
PE file contains sections with non-standard names |
Data Obfuscation |
|
Uses 32bit PE files |
Compliance, System Summary |
|
Binary may include packed or encrypted code |
Data Obfuscation |
Obfuscated Files or Information
|
PE file has section (not .text) which is very likely to contain packed code (zlib compression ratio < 0.011) |
System Summary |
|
Sample is known by Antivirus |
System Summary |
|
PE file has a big raw section |
System Summary |
|
Submission file is bigger than most known malware samples |
System Summary |
|
|
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
BinFileVersion
|
|
|
TargetID: |
3
|
Path: |
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
Value name: |
BinFileVersion
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Antivirus / Scanner detection for submitted sample |
AV Detection |
|
Multi AV Scanner detection for submitted file |
AV Detection |
|
Machine Learning detection for sample |
AV Detection |
|
PE file contains section with special chars |
System Summary |
|
PE file contains an invalid checksum |
Data Obfuscation |
|
PE file contains sections with non-standard names |
Data Obfuscation |
|
Uses 32bit PE files |
Compliance, System Summary |
|
Binary may include packed or encrypted code |
Data Obfuscation |
Obfuscated Files or Information
|
PE file has section (not .text) which is very likely to contain packed code (zlib compression ratio < 0.011) |
System Summary |
|
Sample is known by Antivirus |
System Summary |
|
PE file has a big raw section |
System Summary |
|
Submission file is bigger than most known malware samples |
System Summary |
|
|
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
BinaryType
|
|
|
TargetID: |
3
|
Path: |
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
Value name: |
BinaryType
|
Value data: |
pe32_i386
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Antivirus / Scanner detection for submitted sample |
AV Detection |
|
Multi AV Scanner detection for submitted file |
AV Detection |
|
Machine Learning detection for sample |
AV Detection |
|
PE file contains section with special chars |
System Summary |
|
PE file contains an invalid checksum |
Data Obfuscation |
|
PE file contains sections with non-standard names |
Data Obfuscation |
|
Uses 32bit PE files |
Compliance, System Summary |
|
Binary may include packed or encrypted code |
Data Obfuscation |
Obfuscated Files or Information
|
PE file has section (not .text) which is very likely to contain packed code (zlib compression ratio < 0.011) |
System Summary |
|
Sample is known by Antivirus |
System Summary |
|
PE file has a big raw section |
System Summary |
|
Submission file is bigger than most known malware samples |
System Summary |
|
|
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
ProductName
|
|
|
TargetID: |
3
|
Path: |
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
Value name: |
ProductName
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Antivirus / Scanner detection for submitted sample |
AV Detection |
|
Multi AV Scanner detection for submitted file |
AV Detection |
|
Machine Learning detection for sample |
AV Detection |
|
PE file contains section with special chars |
System Summary |
|
PE file contains an invalid checksum |
Data Obfuscation |
|
PE file contains sections with non-standard names |
Data Obfuscation |
|
Uses 32bit PE files |
Compliance, System Summary |
|
Binary may include packed or encrypted code |
Data Obfuscation |
Obfuscated Files or Information
|
PE file has section (not .text) which is very likely to contain packed code (zlib compression ratio < 0.011) |
System Summary |
|
Sample is known by Antivirus |
System Summary |
|
PE file has a big raw section |
System Summary |
|
Submission file is bigger than most known malware samples |
System Summary |
|
|
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
ProductVersion
|
|
|
TargetID: |
3
|
Path: |
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
Value name: |
ProductVersion
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Antivirus / Scanner detection for submitted sample |
AV Detection |
|
Multi AV Scanner detection for submitted file |
AV Detection |
|
Machine Learning detection for sample |
AV Detection |
|
PE file contains section with special chars |
System Summary |
|
PE file contains an invalid checksum |
Data Obfuscation |
|
PE file contains sections with non-standard names |
Data Obfuscation |
|
Uses 32bit PE files |
Compliance, System Summary |
|
Binary may include packed or encrypted code |
Data Obfuscation |
Obfuscated Files or Information
|
PE file has section (not .text) which is very likely to contain packed code (zlib compression ratio < 0.011) |
System Summary |
|
Sample is known by Antivirus |
System Summary |
|
PE file has a big raw section |
System Summary |
|
Submission file is bigger than most known malware samples |
System Summary |
|
|
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
LinkDate
|
|
|
TargetID: |
3
|
Path: |
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
Value name: |
LinkDate
|
Value data: |
10/27/2024 16:45:44
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Antivirus / Scanner detection for submitted sample |
AV Detection |
|
Multi AV Scanner detection for submitted file |
AV Detection |
|
Machine Learning detection for sample |
AV Detection |
|
PE file contains section with special chars |
System Summary |
|
PE file contains an invalid checksum |
Data Obfuscation |
|
PE file contains sections with non-standard names |
Data Obfuscation |
|
Uses 32bit PE files |
Compliance, System Summary |
|
Binary may include packed or encrypted code |
Data Obfuscation |
Obfuscated Files or Information
|
PE file has section (not .text) which is very likely to contain packed code (zlib compression ratio < 0.011) |
System Summary |
|
Sample is known by Antivirus |
System Summary |
|
PE file has a big raw section |
System Summary |
|
Submission file is bigger than most known malware samples |
System Summary |
|
|
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
BinProductVersion
|
|
|
TargetID: |
3
|
Path: |
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
Value name: |
BinProductVersion
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Antivirus / Scanner detection for submitted sample |
AV Detection |
|
Multi AV Scanner detection for submitted file |
AV Detection |
|
Machine Learning detection for sample |
AV Detection |
|
PE file contains section with special chars |
System Summary |
|
PE file contains an invalid checksum |
Data Obfuscation |
|
PE file contains sections with non-standard names |
Data Obfuscation |
|
Uses 32bit PE files |
Compliance, System Summary |
|
Binary may include packed or encrypted code |
Data Obfuscation |
Obfuscated Files or Information
|
PE file has section (not .text) which is very likely to contain packed code (zlib compression ratio < 0.011) |
System Summary |
|
Sample is known by Antivirus |
System Summary |
|
PE file has a big raw section |
System Summary |
|
Submission file is bigger than most known malware samples |
System Summary |
|
|
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
AppxPackageFullName
|
|
|
TargetID: |
3
|
Path: |
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
Value name: |
AppxPackageFullName
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Antivirus / Scanner detection for submitted sample |
AV Detection |
|
Multi AV Scanner detection for submitted file |
AV Detection |
|
Machine Learning detection for sample |
AV Detection |
|
PE file contains section with special chars |
System Summary |
|
PE file contains an invalid checksum |
Data Obfuscation |
|
PE file contains sections with non-standard names |
Data Obfuscation |
|
Uses 32bit PE files |
Compliance, System Summary |
|
Binary may include packed or encrypted code |
Data Obfuscation |
Obfuscated Files or Information
|
PE file has section (not .text) which is very likely to contain packed code (zlib compression ratio < 0.011) |
System Summary |
|
Sample is known by Antivirus |
System Summary |
|
PE file has a big raw section |
System Summary |
|
Submission file is bigger than most known malware samples |
System Summary |
|
|
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
AppxPackageRelativeId
|
|
|
TargetID: |
3
|
Path: |
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
Value name: |
AppxPackageRelativeId
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Antivirus / Scanner detection for submitted sample |
AV Detection |
|
Multi AV Scanner detection for submitted file |
AV Detection |
|
Machine Learning detection for sample |
AV Detection |
|
PE file contains section with special chars |
System Summary |
|
PE file contains an invalid checksum |
Data Obfuscation |
|
PE file contains sections with non-standard names |
Data Obfuscation |
|
Uses 32bit PE files |
Compliance, System Summary |
|
Binary may include packed or encrypted code |
Data Obfuscation |
Obfuscated Files or Information
|
PE file has section (not .text) which is very likely to contain packed code (zlib compression ratio < 0.011) |
System Summary |
|
Sample is known by Antivirus |
System Summary |
|
PE file has a big raw section |
System Summary |
|
Submission file is bigger than most known malware samples |
System Summary |
|
|
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
Size
|
|
|
TargetID: |
3
|
Path: |
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
Value name: |
Size
|
Value data: |
00 A8 1F 00 00 00 00 00
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Antivirus / Scanner detection for submitted sample |
AV Detection |
|
Multi AV Scanner detection for submitted file |
AV Detection |
|
Machine Learning detection for sample |
AV Detection |
|
PE file contains section with special chars |
System Summary |
|
PE file contains an invalid checksum |
Data Obfuscation |
|
PE file contains sections with non-standard names |
Data Obfuscation |
|
Uses 32bit PE files |
Compliance, System Summary |
|
Binary may include packed or encrypted code |
Data Obfuscation |
Obfuscated Files or Information
|
PE file has section (not .text) which is very likely to contain packed code (zlib compression ratio < 0.011) |
System Summary |
|
Sample is known by Antivirus |
System Summary |
|
PE file has a big raw section |
System Summary |
|
Submission file is bigger than most known malware samples |
System Summary |
|
|
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
Language
|
|
|
TargetID: |
3
|
Path: |
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
Value name: |
Language
|
Value data: |
0
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Antivirus / Scanner detection for submitted sample |
AV Detection |
|
Multi AV Scanner detection for submitted file |
AV Detection |
|
Machine Learning detection for sample |
AV Detection |
|
PE file contains section with special chars |
System Summary |
|
PE file contains an invalid checksum |
Data Obfuscation |
|
PE file contains sections with non-standard names |
Data Obfuscation |
|
Uses 32bit PE files |
Compliance, System Summary |
|
Binary may include packed or encrypted code |
Data Obfuscation |
Obfuscated Files or Information
|
PE file has section (not .text) which is very likely to contain packed code (zlib compression ratio < 0.011) |
System Summary |
|
Sample is known by Antivirus |
System Summary |
|
PE file has a big raw section |
System Summary |
|
Submission file is bigger than most known malware samples |
System Summary |
|
|
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
Usn
|
|
|
TargetID: |
3
|
Path: |
\REGISTRY\A\{ad225988-f5f3-a2e1-5ed2-a7e542fa84e9}\Root\InventoryApplicationFile\file.exe|5c6ea74fda3dfec0
|
Value name: |
Usn
|
Value data: |
10 BB B7 06 00 00 00 00
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Antivirus / Scanner detection for submitted sample |
AV Detection |
|
Multi AV Scanner detection for submitted file |
AV Detection |
|
Machine Learning detection for sample |
AV Detection |
|
PE file contains section with special chars |
System Summary |
|
PE file contains an invalid checksum |
Data Obfuscation |
|
PE file contains sections with non-standard names |
Data Obfuscation |
|
Uses 32bit PE files |
Compliance, System Summary |
|
Binary may include packed or encrypted code |
Data Obfuscation |
Obfuscated Files or Information
|
PE file has section (not .text) which is very likely to contain packed code (zlib compression ratio < 0.011) |
System Summary |
|
Sample is known by Antivirus |
System Summary |
|
PE file has a big raw section |
System Summary |
|
Submission file is bigger than most known malware samples |
System Summary |
|
|
HKEY_CURRENT_USER\SOFTWARE\Microsoft\IdentityCRL\Immersive\production\Token\{67082621-8D18-4333-9C64-10DE93676363}
|
DeviceTicket
|
|
|
TargetID: |
3
|
Path: |
HKEY_CURRENT_USER\SOFTWARE\Microsoft\IdentityCRL\Immersive\production\Token\{67082621-8D18-4333-9C64-10DE93676363}
|
Value name: |
DeviceTicket
|
Value data: |
01 00 00 00 01 00 00 00 D0 8C 9D DF 01 15 D1 11 8C 7A 00 C0 4F C2 97 EB 01 00 00 00 8B FB 4A 60 96 CE 74 42 B3 20 6F 20 55
7D 29 C1 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 03 88 A1 21 D2 E6 9C 6C 43 E5 61 0B 62 1E 16 0C
81 FE 13 D5 73 65 A7 7C 5B 82 68 01 A7 5D 7E A2 00 00 00 00 0E 80 00 00 00 02 00 00 20 00 00 00 85 03 2E E2 AB DB CB 54 5B
0F 7E 26 8B F9 71 8C 16 E8 D3 23 D6 DD 95 21 9C E2 F2 25 5F 13 A3 90 20 08 00 00 F4 69 AC 89 8A 96 6D 62 8C 29 3D DE 18 D0
1D 55 52 0C 7A 50 93 32 51 E6 1F B3 DE 64 87 9A 20 28 36 D7 A2 DC 54 BB 23 A8 1F 1B 8D 7F 87 85 AC A2 5F 6B E4 65 00 E5 E0
D9 8F B0 87 99 51 C4 F4 77 8E 10 53 13 9F 86 59 A4 AE 06 2D 16 CC 1D D3 04 84 C8 3E 06 C4 5F 91 BD 67 7B 39 FC 32 84 79 41
18 CD A7 00 79 D1 33 24 9D 11 17 E0 13 13 43 ED 11 B1 09 88 1B E9 BA 16 B2 17 7F F2 F7 5F F4 F4 15 7C 98 6C 69 DC 1A F8 22
BF BC 14 E2 AB 5B 80 7A 22 5B B1 01 A4 B3 FD 80 02 F4 82 F1 4D 03 2A 91 08 54 B2 8F 6E DF 26 1E 11 03 A9 82 C7 34 F4 CD 06
01 B0 E3 A1 90 9E 40 4C 7D E1 59 4A 0E C8 72 6F 01 EE 6B 8F B8 99 6C B9 65 C0 34 3E 9C 40 7D 99 69 65 FA F1 3C F8 99 84 7B
B6 F5 67 63 52 0F A8 54 B7 75 2F 3B 63 4A EC EE C8 15 33 6C 7C 03 0C 52 8E 07 12 9B 14 21 6E D0 6C 0E 1F 89 1D FA E3 A0 A1
C5 38 3E 45 89 B4 10 86 FA A3 29 DD 90 99 96 F6 36 51 87 FC FA B0 13 45 24 62 83 A7 9D CE D6 54 AC 4D 22 49 14 67 EE 69 99
3A 2A B5 E2 D9 29 4E CB D5 99 39 32 A1 0F A6 B6 41 BE 31 4F 3B 39 FC 5E 65 C0 39 11 38 60 B4 DE 32 B5 A3 14 82 F2 AA 16 5C
F6 3D 03 FF 8D 43 60 51 27 CF 6D 71 99 F5 46 81 D5 0F 61 D7 49 81 5C FF 06 CC 81 FF C1 01 84 07 3B 35 4E 8F 9D 29 8C EA 2F
9B 0A 4E 3E F4 1C FF 3A E6 24 31 37 0E C2 85 9D F0 C2 88 F0 AD 0E D9 23 7A 37 98 2D AE BC FA 61 E9 36 EF F3 4D 56 7F 7B A1
B8 E0 07 C6 73 1F 18 48 EF 3D A5 0F 95 3C B4 3D 9E 66 98 10 12 64 31 EA 05 90 E8 01 6C 93 87 CF 5F 18 B8 2A 8C 78 73 C1 25
A8 7D CC EC E7 EF 80 A0 7B 31 CD CE C7 29 9F 13 9C 10 52 D2 CD D0 7D 04 CA 5E E0 0B 8B DC 0D 73 C2 3D 29 98 2E 4D 03 37 62
F1 13 34 62 06 4D D6 54 3B DF C6 89 2B 9F 2A 26 0D 0D 0A B4 B1 F7 91 33 DE 93 9B F0 ED 0D 73 D8 CE 73 B5 E0 80 E2 9D 62 39
74 F5 52 F7 C7 39 14 F7 E1 51 DF 91 BD 47 09 AB 8A 5F 89 D0 66 D7 80 5F 53 31 3B BA F8 74 6D DB 64 F5 39 F0 75 74 C3 F5 C8
CB CD CC 93 AD 64 DD 9B E1 25 08 D2 25 4E B2 00 D6 A4 61 49 63 BC 9E 1C E6 3F DB A4 72 70 9B 7E B1 75 A6 8F 09 20 66 76 5B
B3 E4 82 85 D0 32 2C C9 96 A5 03 37 40 93 07 F4 79 2C 75 56 9A 96 26 2E 34 C4 DD 94 9B B0 CA 8F 2F 2C 60 DD 61 62 53 D8 8B
3D 3B 19 B5 32 AF F0 60 AC BE 6D DD D0 DC E5 BD 29 69 53 C9 FB 31 77 46 74 1F 30 FF E6 FF D2 6D 80 27 16 83 79 F7 D3 DA ED
72 B6 25 B8 BD E1 BD DC E5 10 7C 4E 19 EA EF A2 E3 14 7B 74 94 C3 CA BD F3 0C 2B C1 BF E1 79 46 0C 1B EB 9B 46 BD 28 CB 9B
3D 9D 1E 5D B3 C4 70 F3 2C 6E E0 C8 97 E2 E6 68 3B 86 50 30 AB 32 CC F3 45 F0 CB 03 B2 84 14 CD 29 EB EE 0D AD CA EA 80 B3
90 F6 03 53 B5 3B 79 B6 0F 29 B6 E9 A6 BF 63 B3 EB 4D 80 E0 AB 0F 1B 6E 5C 6B 4E A3 5B 9D 7A 17 A2 E8 1A 2C 07 DB 1F D4 20
BD BC 78 3F C2 93 32 E9 F0 A6 29 B4 8B B3 4B B7 3D EC 4B 18 38 D3 C8 6B 08 2C 6B 59 87 DF FF 8F C1 94 77 0E 18 CB 02 8E DE
66 2C F1 1F 8D 00 44 AB B5 DB BC A6 6B 1E 2C 4A 27 63 81 FA B3 59 39 0D 23 34 78 88 E7 3A 78 6D 5B FD D6 84 0A 6D 17 F7 CC
9A 92 AA E0 5D A6 10 75 A7 41 03 DA 57 4A 06 D9 02 EA 2B 40 C7 BA 67 9B BF 63 A9 65 28 22 5D F4 01 9C 52 C9 E0 8B B3 61 26
E6 FB C8 70 D0 94 79 51 B6 4F B7 15 F9 42 4C 38 C6 1B B6 AD B9 37 0D 2E D2 C5 4A 27 C8 A4 35 92 15 BA 71 5B 9D 48 23 AA EA
7B 09 8C 69 0E 5C 4F 86 EA CA C6 D0 13 D3 2C 3E AA 43 0A CF 65 81 B7 77 E0 58 EE 10 40 7A 04 88 E0 C5 D5 DD B7 38 FB 74 BC
71 84 01 A2 51 6C A7 CD 18 A9 04 FF 99 7D C3 A6 4E CE 09 ED 3C F1 E7 EF BD 87 7E DE E3 08 E7 85 32 D8 F8 97 A4 9B 96 5E C0
B5 58 5B A0 19 84 97 A0 1E 75 A4 2D 9D 9E F2 12 C8 F2 24 90 34 95 FF 18 F4 CA 1F 38 1F 62 63 B8 98 0F B7 FB 9E 65 AA A1 11
C4 37 7D 63 38 7D 62 B1 09 25 EC 2C 15 6A 34 53 1F E0 D9 1C 04 FE 66 BF 3F CE 25 4A 93 94 49 E9 6F 0D 80 06 FD 45 3A 1B B2
65 01 C8 6D FF 2C 9B 64 AB 3D 0D A4 FA 2E 4B 6F 22 B6 3F 26 36 78 CC 1A 9A 0F 42 BE 6D 85 16 E1 38 74 8E EB FA F3 83 B8 80
62 F8 27 A9 2C 2F BC BB 0A 86 BD FF 1B 21 74 27 34 6E 76 10 33 64 70 86 A1 1A F6 9E 73 BE 9B 97 CC 45 15 8C 1A B9 ED AB 2A
30 EB 41 7A 2E 38 94 AB 99 F0 22 F9 99 8B 5A 7A 99 72 EF B6 0A 2E B7 DD E2 0E 7C D6 54 B8 AF 04 81 4A F6 40 EF D4 8E 82 08
A6 75 0C F6 99 00 AD 6C 2F B8 2E 3C 47 B2 F1 BB 04 A1 F5 BC 92 A8 E4 E3 6D B9 F0 F8 7A B8 6F B1 44 2E 4E 4C 9E 54 43 73 0D
3D 25 A2 60 CE 06 68 08 66 1A AD 41 DD 1B FF B1 16 5B A8 5E CB 8A 53 82 D1 96 D3 5E 55 A0 8F 1A 06 C7 CE 83 0A 6B 9D AD 9D
5F 18 18 28 EC C6 B3 87 C9 6C D6 39 4E 22 D7 AE AB D6 7D B9 71 A2 24 20 24 87 16 DA 3A A8 10 A7 00 4F D4 D6 CC 08 C6 8B 4E
FF CC BB F2 81 3A E5 12 43 A5 BE ED 76 32 DF 50 AA C5 D8 41 57 D0 62 7A D4 EA 50 3F 90 C2 BE 6B 45 4D DF 1B 43 94 58 59 F1
1B E4 5F DD 23 0B D6 E3 69 BD 56 2C 41 19 86 93 DC 86 3D 31 E2 BD 15 86 AF 9D C3 33 31 D4 A9 69 00 78 DA 3A 0B FD 5C 4C 43
8B E8 E7 E3 A5 E8 71 42 96 97 83 7A 2E C8 60 CD 9E 06 2C 7E FB 8D 37 37 2E CB C3 19 63 87 A9 85 41 C1 9E EF 4B 6E A2 ED 4C
E8 90 8C 87 1F D4 6B 44 8A DC C8 07 D2 B0 DD 82 B5 D7 0D B1 39 96 64 6A 76 B0 F8 8C AC 40 8D AF 50 3D CF 53 85 53 96 C6 73
C7 5D DD 4E 85 79 1A 04 07 1F 40 FE 59 92 A8 BA D8 83 93 32 AE 13 6B AA 0D A1 91 CA A4 7A 28 81 C9 D9 FF D2 E4 A1 4C E3 86
ED 61 38 60 19 2E 91 E1 17 21 40 72 3E 07 6F E4 62 D1 61 F6 EE 6C 62 2F 8A FE 27 CA E4 B8 04 23 03 47 C1 F6 AF A3 4B 56 6F
EA 2A 25 21 35 81 6B 45 E6 4D 28 B5 AE FB 55 DC 64 7F CA B8 5C 62 99 C3 AF 73 91 91 FD A3 0F DA C9 B8 1A B5 49 0F 11 E5 FC
76 2B B0 AB B9 24 43 49 E8 77 2D 19 EA C3 81 01 AD 89 71 01 4B D6 43 FD 66 3D 69 05 4D 90 05 57 45 82 84 7B 77 8F D5 72 C8
35 35 3D 0D D2 98 85 2A 9D B0 06 F0 FA C1 5D CD 03 19 19 59 7F ED 6E 5F 13 66 F8 23 18 FA 86 1B 4C 82 7C 71 CF 84 32 BC 33
9A 6F 9B 5F 91 FA 09 9E B7 86 63 07 01 4B BA 06 7D C3 3A 63 E0 75 48 85 97 F5 5D B5 6F E8 FE 8C 66 14 2A 8D 67 31 E7 F2 52
9C F2 FF 3D 67 A9 15 D7 08 BE 46 F1 34 00 58 47 82 AD 92 10 8C 36 04 58 AC 7C EA B8 A2 59 E6 7A 0D 6D E0 72 FB F2 58 EF C7
BB 2E FF 8F A9 4A 05 2C 4B 84 37 71 6B BC C4 EF 71 DC 90 77 A0 14 6B 10 BF C3 79 B5 45 8E EC 2D D8 3D 4E CD 95 44 99 5E 2D
B2 CF DD 00 2B A3 54 CF 76 10 AD 70 34 95 8E 44 3A 11 C8 B4 48 06 43 05 FD 66 AA B9 63 46 84 7E 03 EE CB 39 49 7A E7 C3 4B
BB E0 95 5B F7 B5 14 27 C4 08 78 AA F6 1C 78 F7 A2 60 86 3F DB 98 B3 B0 6F F9 49 3E 4C E1 B4 86 7F FD FA 38 FC 57 AB B7 E7
38 9C 32 E8 D3 FB B9 41 B8 58 E0 9E 1D B3 56 74 57 D3 BD 01 4D 5E 61 B6 76 2C 7E 24 04 60 1A D2 AF 10 54 6A CB A5 C5 BC 63
90 62 5D 66 49 E3 D0 BF 7B B8 04 4B 9B 82 91 9D 6B 0C D6 B5 C4 EF 66 0B D8 48 E1 8E 7C 39 64 48 56 57 DC A4 E9 E1 BB 9E C2
CB 86 50 5A EE 16 18 2D 53 A2 D4 0F EB 04 C4 82 40 00 00 00 CC B1 93 62 31 DF F3 57 A1 9A BE 3D BE 57 F5 00 21 44 D6 AD ED
63 F0 13 96 25 CD 39 7E 5E C5 F2 5B 8D 27 2D C1 E7 24 32 CE 1D DD 2B 31 6C FA 57 4C 6D 3F C1 5D 0C D8 C5 EE B0 2A A7 A3 24
4C B7
|
|
HKEY_CURRENT_USER\SOFTWARE\Microsoft\IdentityCRL\Immersive\production\Token\{67082621-8D18-4333-9C64-10DE93676363}
|
DeviceId
|
|
|
TargetID: |
3
|
Path: |
HKEY_CURRENT_USER\SOFTWARE\Microsoft\IdentityCRL\Immersive\production\Token\{67082621-8D18-4333-9C64-10DE93676363}
|
Value name: |
DeviceId
|
Value data: |
0018000DDABBE6B3
|
|
HKEY_CURRENT_USER\SOFTWARE\Microsoft\IdentityCRL\Immersive\production\Token\{67082621-8D18-4333-9C64-10DE93676363}
|
ApplicationFlags
|
|
|
TargetID: |
3
|
Path: |
HKEY_CURRENT_USER\SOFTWARE\Microsoft\IdentityCRL\Immersive\production\Token\{67082621-8D18-4333-9C64-10DE93676363}
|
Value name: |
ApplicationFlags
|
Value data: |
1
|
|
HKEY_CURRENT_USER\SOFTWARE\Microsoft\IdentityCRL\Immersive\production\Property
|
0018000DDABBE6B3
|
|
|
TargetID: |
3
|
Path: |
HKEY_CURRENT_USER\SOFTWARE\Microsoft\IdentityCRL\Immersive\production\Property
|
Value name: |
0018000DDABBE6B3
|
Value data: |
01 00 00 00 01 00 00 00 D0 8C 9D DF 01 15 D1 11 8C 7A 00 C0 4F C2 97 EB 01 00 00 00 8B FB 4A 60 96 CE 74 42 B3 20 6F 20 55
7D 29 C1 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 4E E7 F4 03 50 8D 97 B2 4F EC AC 99 4A 09 EC 4E
18 39 D0 54 10 26 7C CC 7E 65 BB 9D EE 9A D6 93 00 00 00 00 0E 80 00 00 00 02 00 00 20 00 00 00 56 F1 60 78 D6 8A E1 4F 41
85 6B 3E 7F 9E 62 13 79 58 8B B3 C3 40 09 AD EC 6D EC 4D C7 BD 18 A6 80 00 00 00 DB C1 98 A0 6A 10 DE 39 95 C3 3E 19 F0 6F
8F 37 7D 01 D4 2C D6 22 09 F4 1E 8D 24 2A EB 46 4F 13 1E 07 B3 44 BA 78 9A 13 7F 11 68 A3 B5 ED 75 AB A3 66 58 37 1F 1F AD
8A 8F 47 6A 0A F3 28 0F 44 BC CB 1E CE 5A 93 8A AC D3 C2 C6 83 D9 E0 1E 08 5D D3 8E A4 1F 91 B6 41 A2 0A 41 20 5E F2 85 28
B6 C2 2D A8 3D E0 82 B4 2D 03 E1 1B 44 3E 6B 76 AC 0B 2D 4F BA 23 34 A1 C3 2C 27 28 DD 9D 14 15 40 00 00 00 25 77 7E 85 DE
39 BD F9 F2 E4 13 20 EB 49 3C A1 6A 65 C4 AB 49 A6 64 1A 3A 69 72 73 48 B7 25 E7 7C CF DA 2B 8E CF 05 FC EF 6E 8F D6 68 14
AA 85 45 EC A4 85 81 A3 04 07 16 CB D6 D4 63 4E E4 5D
|
|