Windows Analysis Report
msys2-x86_64-20240727.exe

Overview

General Information

Sample name: msys2-x86_64-20240727.exe
Analysis ID: 1524032
MD5: 148a068b7e058ceeb682da549a9e6e5b
SHA1: 43dd6b7e3bb94461fe196106da9efc03ef5898ea
SHA256: 20d452e66cc95f975b2a8c5d814ba02e92481071580e80a3e3502a391fff6d2a

Detection

Score: 21
Range: 0 - 100
Whitelisted: false
Confidence: 80%

Signatures

Creates files with lurking names (e.g. Crack.exe)
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device

Classification

Source: msys2-x86_64-20240727.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic DNS traffic detected: DNS query: openpgpkey.gmail.com
Source: global traffic DNS traffic detected: DNS query: _openpgpkey._tcp.gmail.com
Source: global traffic DNS traffic detected: DNS query: gmail.com
Source: global traffic DNS traffic detected: DNS query: _pgpkey-https._tcp.keyserver.ubuntu.com
Source: global traffic DNS traffic detected: DNS query: keyserver.ubuntu.com
Source: global traffic DNS traffic detected: DNS query: openpgpkey.martellmalone.com
Source: global traffic DNS traffic detected: DNS query: _openpgpkey._tcp.martellmalone.com
Source: global traffic DNS traffic detected: DNS query: martellmalone.com

System Summary

barindex
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe File created: C:\msys64\usr\share\bash-completion\completions\dnssec-keygen
Source: msys2-x86_64-20240727.exe Static PE information: Section: .qtmimed ZLIB complexity 0.9988839285714286
Source: classification engine Classification label: sus21.evad.winEXE@2/1025@26/0
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe File created: C:\Users\user\AppData\Local\cache
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2348:120:WilError_03
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe File created: C:\Users\user\AppData\Local\Temp\msys2-x86_64-202407271234865.lock
Source: msys2-x86_64-20240727.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe File read: C:\Users\user\Desktop\msys2-x86_64-20240727.exe
Source: unknown Process created: C:\Users\user\Desktop\msys2-x86_64-20240727.exe "C:\Users\user\Desktop\msys2-x86_64-20240727.exe"
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: apphelp.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: mpr.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: secur32.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: uxtheme.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: dwmapi.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: dwrite.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: winhttp.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: netapi32.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: authz.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: userenv.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: version.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: winmm.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: ncrypt.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: iphlpapi.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: wtsapi32.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: d3d9.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: dxgi.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: d3d12.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: d3d11.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: usp10.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: windows.storage.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: wldp.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: cryptbase.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: sspicli.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: netutils.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: srvcli.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: ntasn1.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: profapi.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: powrprof.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: umpdc.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: devobj.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: netprofm.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: npmproxy.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: zlib1.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: cryptsp.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: rsaenh.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: dataexchange.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: dcomp.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: twinapi.appcore.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: textinputframework.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: coreuicomponents.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: coremessaging.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: ntmarta.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Section loaded: textshaping.dll
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}\InProcServer32
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe File written: C:\msys64\clang32.ini
Source: msys2-x86_64-20240727.exe Static PE information: More than 160 > 100 exports found
Source: msys2-x86_64-20240727.exe Static PE information: Virtual size of .text is bigger than: 0x100000
Source: msys2-x86_64-20240727.exe Static PE information: Image base 0x140000000 > 0x60000000
Source: msys2-x86_64-20240727.exe Static file information: File size 83299730 > 1048576
Source: msys2-x86_64-20240727.exe Static PE information: Raw size of .text is bigger than: 0x100000 < 0x1b91400
Source: msys2-x86_64-20240727.exe Static PE information: Raw size of .rdata is bigger than: 0x100000 < 0x73e800
Source: msys2-x86_64-20240727.exe Static PE information: More than 200 imports for KERNEL32.dll
Source: msys2-x86_64-20240727.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: msys2-x86_64-20240727.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: msys2-x86_64-20240727.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: msys2-x86_64-20240727.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: msys2-x86_64-20240727.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: msys2-x86_64-20240727.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: msys2-x86_64-20240727.exe Static PE information: section name: .qtmimed
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Queries volume information: C:\Users\user\Desktop\msys2-x86_64-20240727.exe VolumeInformation
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Queries volume information: C:\Users\user\Desktop\msys2-x86_64-20240727.exe VolumeInformation
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Queries volume information: C:\Users\user\Desktop\msys2-x86_64-20240727.exe VolumeInformation
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Queries volume information: C:\Users\user\Desktop\msys2-x86_64-20240727.exe VolumeInformation
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Queries volume information: C:\Users\user\Desktop\msys2-x86_64-20240727.exe VolumeInformation
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Queries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation
Source: C:\Users\user\Desktop\msys2-x86_64-20240727.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
⊘No contacted IP infos