Windows Analysis Report
SecuriteInfo.com.Win64.Malware-gen.324.4623.exe

Overview

General Information

Sample name: SecuriteInfo.com.Win64.Malware-gen.324.4623.exe
Analysis ID: 1532115
MD5: eaa5207750d5fc8204170ec6bda64cca
SHA1: 34828c5aa252a5e83127d1185edcee869f611567
SHA256: 1ed69b65f453f2f8363a8988d0b069c66c045cc28232dfd2935dddbd9fcfe011
Tags: exe
Infos:

Detection

Score: 60
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
AI detected suspicious sample
PE file contains sections with non-standard names
Potential time zone aware malware
Program does not show much activity (idle)

Classification

AV Detection

barindex
Source: SecuriteInfo.com.Win64.Malware-gen.324.4623.exe Avira: detected
Source: SecuriteInfo.com.Win64.Malware-gen.324.4623.exe ReversingLabs: Detection: 45%
Source: SecuriteInfo.com.Win64.Malware-gen.324.4623.exe Virustotal: Detection: 25% Perma Link
Source: Submited Sample Integrated Neural Analysis Model: Matched 97.8% probability
Source: SecuriteInfo.com.Win64.Malware-gen.324.4623.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: classification engine Classification label: mal60.winEXE@2/0@0/0
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5772:120:WilError_03
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.Malware-gen.324.4623.exe File opened: C:\Windows\system32\28501ae350293497c738636705a7a44473f465a663f2f99209fc78cd0d15cf63AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA Jump to behavior
Source: SecuriteInfo.com.Win64.Malware-gen.324.4623.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.Malware-gen.324.4623.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: SecuriteInfo.com.Win64.Malware-gen.324.4623.exe ReversingLabs: Detection: 45%
Source: SecuriteInfo.com.Win64.Malware-gen.324.4623.exe Virustotal: Detection: 25%
Source: unknown Process created: C:\Users\user\Desktop\SecuriteInfo.com.Win64.Malware-gen.324.4623.exe "C:\Users\user\Desktop\SecuriteInfo.com.Win64.Malware-gen.324.4623.exe"
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.Malware-gen.324.4623.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.Malware-gen.324.4623.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.Malware-gen.324.4623.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.Malware-gen.324.4623.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.Malware-gen.324.4623.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.Malware-gen.324.4623.exe Section loaded: umpdc.dll Jump to behavior
Source: SecuriteInfo.com.Win64.Malware-gen.324.4623.exe Static PE information: Virtual size of .text is bigger than: 0x100000
Source: SecuriteInfo.com.Win64.Malware-gen.324.4623.exe Static file information: File size 5777920 > 1048576
Source: SecuriteInfo.com.Win64.Malware-gen.324.4623.exe Static PE information: Raw size of .text is bigger than: 0x100000 < 0x2a1600
Source: SecuriteInfo.com.Win64.Malware-gen.324.4623.exe Static PE information: Raw size of .rdata is bigger than: 0x100000 < 0x27c200
Source: SecuriteInfo.com.Win64.Malware-gen.324.4623.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: SecuriteInfo.com.Win64.Malware-gen.324.4623.exe Static PE information: section name: .symtab
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.Malware-gen.324.4623.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.Malware-gen.324.4623.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\SecuriteInfo.com.Win64.Malware-gen.324.4623.exe System information queried: CurrentTimeZoneInformation Jump to behavior
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: SecuriteInfo.com.Win64.Malware-gen.324.4623.exe, 00000000.00000002.2195510150.00000223168CC000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
No contacted IP infos