Edit tour
Windows
Analysis Report
General_Player_Eng_WIN32_V3.44.0.R.170421.exe
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Tries to delay execution (extensive OutputDebugStringW loop)
Monitors registry run keys for changes
Uses 32bit PE files
Queries the volume information (name, serial number etc) of a device
Searches for the Microsoft Outlook file path
Allocates memory with a write watch (potentially for evading sandboxes)
Drops PE files
Tries to load missing DLLs
Deletes files inside the Windows folder
Drops PE files to the windows directory (C:\Windows)
Creates files inside the system directory
Queries the installation date of Windows
Contains capabilities to detect virtual machines
Stores files to the Windows start menu directory
Queries time zone information
Checks for available system drives (often done to infect USB drives)
Found dropped PE file which has not been started or loaded
Creates a process in suspended mode (likely to inject code)
Classification
- System is w10x64_ra
- General_Player_Eng_WIN32_V3.44.0.R.170421.exe (PID: 236 cmdline:
C:\Users\a lfredo\Des ktop\Gener al_Player_ Eng_WIN32_ V3.44.0.R. 170421.exe MD5: 4DEEE269D4808B3CB033CABA3DE5B815) - vcredist_x86.exe (PID: 6432 cmdline:
"C:\Users\ alfredo\Ap pData\Loca l\Temp\nss 5DC1.tmp\I nclude\vcr edist_x86. exe" /q MD5: 199CCBE11966C1B636CC6316C7FE8C07) - VCREDI~3.EXE (PID: 6472 cmdline:
C:\Users\a lfredo\App Data\Local \Temp\IXP0 00.TMP\VCR EDI~3.EXE MD5: 1F8E9FEC647700B21D45E6CDA97C39B7) - msiexec.exe (PID: 6508 cmdline:
msiexec /i vcredist. msi MD5: F9A3EEE1C3A4067702BC9A59BC894285) - cmd.exe (PID: 4044 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\Prog ram Files (x86)\Smar tPlayer\Re flushIcon. bat" " MD5: 4943BA1A9B41D69643F69685E35B2943) - conhost.exe (PID: 1504 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: C5E9B1D1103EDCEA2E408E9497A5A88F) - rundll32.exe (PID: 380 cmdline:
RUNDLL32 S ETUPAPI.DL L,InstallH infSection DefaultIn stall 128 C:\Users\a lfredo\App Data\Local \Temp\TmpI nf.inf MD5: D0432468FA4B7F66166C430E1334DBDA) - runonce.exe (PID: 6128 cmdline:
"C:\Window s\system32 \runonce.e xe" -r MD5: AC215E26CE0D0CFAFDFAEA7C6E159208) - grpconv.exe (PID: 2872 cmdline:
"C:\Window s\System32 \grpconv.e xe" -o MD5: 91D455C47F71B38647ACAA3D18018B7F) - SmartPlayer.exe (PID: 6608 cmdline:
C:\Program Files (x8 6)\SmartPl ayer\Smart Player.exe MD5: 24F3228701C1FEA39F45A49F97F15197) - regini.exe (PID: 5768 cmdline:
regini.exe "C:/Progr am Files ( x86)/Smart Player/reg UserChoice .ini" MD5: 92D7CDD79F53E56612F8252B1BCD562E) - conhost.exe (PID: 4100 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: C5E9B1D1103EDCEA2E408E9497A5A88F) - regini.exe (PID: 4812 cmdline:
regini.exe "C:/Progr am Files ( x86)/Smart Player/reg UserChoice .ini" MD5: 92D7CDD79F53E56612F8252B1BCD562E) - conhost.exe (PID: 5128 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: C5E9B1D1103EDCEA2E408E9497A5A88F) - regini.exe (PID: 4980 cmdline:
regini.exe "C:/Progr am Files ( x86)/Smart Player/reg UserChoice .ini" MD5: 92D7CDD79F53E56612F8252B1BCD562E) - conhost.exe (PID: 5016 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: C5E9B1D1103EDCEA2E408E9497A5A88F)
- msiexec.exe (PID: 6540 cmdline:
C:\Windows \system32\ msiexec.ex e /V MD5: 2D9F692E71D9985F1C6237F063F6FE76) - msiexec.exe (PID: 6628 cmdline:
C:\Windows \syswow64\ MsiExec.ex e -Embeddi ng A0D5E52 B889E09972 31E86FA133 B251D MD5: F9A3EEE1C3A4067702BC9A59BC894285)
- Taskmgr.exe (PID: 6784 cmdline:
"C:\Window s\system32 \taskmgr.e xe" /4 MD5: 0C08189067FCB42C520B970D1FA7D5BF)
- Taskmgr.exe (PID: 6840 cmdline:
"C:\Window s\system32 \taskmgr.e xe" /4 MD5: 0C08189067FCB42C520B970D1FA7D5BF)
- cleanup
⊘No yara matches
⊘No Sigma rule has matched
⊘No Snort rule has matched
Click to jump to signature section
Show All Signature Results
Source: | Static PE information: |
Source: | Window detected: |