Edit tour
Windows
Analysis Report
https://github.com/eclipse-ecal/ecal/releases/download/v5.13.3/ecal_5.13.3-win64.exe
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Sigma detected: Invoke-Obfuscation CLIP+ Launcher
Sigma detected: Invoke-Obfuscation VAR+ Launcher
Drops PE files
Found dropped PE file which has not been started or loaded
PE file contains executable resources (Code or Archives)
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: Usage Of Web Request Commands And Cmdlets
Stores files to the Windows start menu directory
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Classification
- System is w10x64
- cmd.exe (PID: 6872 cmdline:
C:\Windows \system32\ cmd.exe /c wget -t 2 -v -T 60 -P "C:\Use rs\user\De sktop\down load" --no -check-cer tificate - -content-d isposition --user-ag ent="Mozil la/5.0 (Wi ndows NT 6 .1; WOW64; Trident/7 .0; AS; rv :11.0) lik e Gecko" " https://gi thub.com/e clipse-eca l/ecal/rel eases/down load/v5.13 .3/ecal_5. 13.3-win64 .exe" > cm dline.out 2>&1 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 6896 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - wget.exe (PID: 7036 cmdline:
wget -t 2 -v -T 60 - P "C:\User s\user\Des ktop\downl oad" --no- check-cert ificate -- content-di sposition --user-age nt="Mozill a/5.0 (Win dows NT 6. 1; WOW64; Trident/7. 0; AS; rv: 11.0) like Gecko" "h ttps://git hub.com/ec lipse-ecal /ecal/rele ases/downl oad/v5.13. 3/ecal_5.1 3.3-win64. exe" MD5: 3DADB6E2ECE9C4B3E1E322E617658B60)
- ecal_5.13.3-win64.exe (PID: 4428 cmdline:
"C:\Users\ user\Deskt op\downloa d\ecal_5.1 3.3-win64. exe" MD5: 333C92633D239E787B05DEB077446BCC) - ecal_5.13.3-win64.tmp (PID: 6508 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\is-MCO U1.tmp\eca l_5.13.3-w in64.tmp" /SL5="$204 1C,7015236 6,845824,C :\Users\us er\Desktop \download\ ecal_5.13. 3-win64.ex e" MD5: 2A7019D6551F63D54843D11967E03B91)
- cleanup
⊘No configs have been found
⊘No yara matches
System Summary |
---|
Source: | Author: Jonathan Cheong, oscd.community: |
Source: | Author: Jonathan Cheong, oscd.community: |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
Source: | Window detected: |