Windows Analysis Report
Mtcn_3259356251.jar

Overview

General Information

Sample name: Mtcn_3259356251.jar
Analysis ID: 1524314
MD5: 7fefa6601ba7798f5a92c4907a04d675
SHA1: a44d75a42ac89a7d5060578e681f20993eccb76f
SHA256: 3dbba68c10b532ecbd126c1172717d7f6c63d3e3fc4978aa8f58a919269b6374
Infos:

Detection

Branchlock Obfuscator
Score: 56
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Multi AV Scanner detection for submitted file
Yara detected Branchlock Obfuscator

Classification

AV Detection

barindex
Source: Mtcn_3259356251.jar ReversingLabs: Detection: 23%
Source: classification engine Classification label: mal56.evad.winJAR@2/6@0/0
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6496:120:WilError_03
Source: C:\Windows\System32\7za.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: Mtcn_3259356251.jar ReversingLabs: Detection: 23%
Source: unknown Process created: C:\Windows\System32\7za.exe 7za.exe x -y -oC:\jar "C:\Users\user\Desktop\Mtcn_3259356251.jar"
Source: C:\Windows\System32\7za.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\7za.exe Section loaded: 7z.dll

Data Obfuscation

barindex
Source: Yara match File source: Mtcn_3259356251.jar, type: SAMPLE
Source: Yara match File source: 00000000.00000003.7023392945.00000000031B0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000002.7023950005.00000000014F0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000002.7024085039.0000000003185000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000003.7023068203.00000000030AF000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000003.7023135764.00000000031B0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000003.7020393491.00000000031B0000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
⊘No contacted IP infos