Windows Analysis Report
antispam_account.exe

Overview

General Information

Sample name: antispam_account.exe
Analysis ID: 1533406
MD5: ceef2ab4f8f6993c358ea309f87a96f5
SHA1: dccca05c9833b78dc75c7045e80056b35815ae93
SHA256: d30cab7db9542e23b3371e20d16758d0930e9d021e67745f6c53fd88135b6873
Tags: exeuser-Racco42
Infos:

Detection

Score: 52
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Multi AV Scanner detection for submitted file
AI detected suspicious sample
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to dynamically determine API calls
Contains functionality to query CPU information (cpuid)
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Detected potential crypto function
PE file contains sections with non-standard names
Program does not show much activity (idle)

Classification

AV Detection

barindex
Source: antispam_account.exe ReversingLabs: Detection: 23%
Source: Submited Sample Integrated Neural Analysis Model: Matched 90.9% probability
Source: antispam_account.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: C:\Users\lfkmf\source\repos\AddMachineAccount\x64\Release\AddMachineAccount.pdb source: antispam_account.exe
Source: C:\Users\user\Desktop\antispam_account.exe Code function: 0_2_00007FF69E49EAC4 _invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose, 0_2_00007FF69E49EAC4
Source: C:\Users\user\Desktop\antispam_account.exe Code function: 0_2_00007FF69E4910D0 0_2_00007FF69E4910D0
Source: C:\Users\user\Desktop\antispam_account.exe Code function: 0_2_00007FF69E49734C 0_2_00007FF69E49734C
Source: C:\Users\user\Desktop\antispam_account.exe Code function: 0_2_00007FF69E496F3C 0_2_00007FF69E496F3C
Source: C:\Users\user\Desktop\antispam_account.exe Code function: 0_2_00007FF69E498098 0_2_00007FF69E498098
Source: C:\Users\user\Desktop\antispam_account.exe Code function: 0_2_00007FF69E49E06C 0_2_00007FF69E49E06C
Source: C:\Users\user\Desktop\antispam_account.exe Code function: 0_2_00007FF69E496928 0_2_00007FF69E496928
Source: C:\Users\user\Desktop\antispam_account.exe Code function: 0_2_00007FF69E497148 0_2_00007FF69E497148
Source: C:\Users\user\Desktop\antispam_account.exe Code function: 0_2_00007FF69E496D38 0_2_00007FF69E496D38
Source: C:\Users\user\Desktop\antispam_account.exe Code function: 0_2_00007FF69E49D558 0_2_00007FF69E49D558
Source: C:\Users\user\Desktop\antispam_account.exe Code function: 0_2_00007FF69E49B200 0_2_00007FF69E49B200
Source: C:\Users\user\Desktop\antispam_account.exe Code function: 0_2_00007FF69E4A6A28 0_2_00007FF69E4A6A28
Source: C:\Users\user\Desktop\antispam_account.exe Code function: 0_2_00007FF69E4A2620 0_2_00007FF69E4A2620
Source: C:\Users\user\Desktop\antispam_account.exe Code function: 0_2_00007FF69E49D9EC 0_2_00007FF69E49D9EC
Source: C:\Users\user\Desktop\antispam_account.exe Code function: 0_2_00007FF69E498A38 0_2_00007FF69E498A38
Source: C:\Users\user\Desktop\antispam_account.exe Code function: 0_2_00007FF69E498E70 0_2_00007FF69E498E70
Source: C:\Users\user\Desktop\antispam_account.exe Code function: 0_2_00007FF69E496B2C 0_2_00007FF69E496B2C
Source: C:\Users\user\Desktop\antispam_account.exe Code function: 0_2_00007FF69E49EAC4 0_2_00007FF69E49EAC4
Source: C:\Users\user\Desktop\antispam_account.exe Code function: 0_2_00007FF69E4A2ABC 0_2_00007FF69E4A2ABC
Source: classification engine Classification label: mal52.winEXE@2/1@0/0
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7276:120:WilError_03
Source: antispam_account.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\antispam_account.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: antispam_account.exe ReversingLabs: Detection: 23%
Source: unknown Process created: C:\Users\user\Desktop\antispam_account.exe "C:\Users\user\Desktop\antispam_account.exe"
Source: C:\Users\user\Desktop\antispam_account.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\antispam_account.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\antispam_account.exe Section loaded: netapi32.dll Jump to behavior
Source: C:\Users\user\Desktop\antispam_account.exe Section loaded: logoncli.dll Jump to behavior
Source: C:\Users\user\Desktop\antispam_account.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\Desktop\antispam_account.exe Section loaded: activeds.dll Jump to behavior
Source: C:\Users\user\Desktop\antispam_account.exe Section loaded: adsldpc.dll Jump to behavior
Source: C:\Users\user\Desktop\antispam_account.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: antispam_account.exe Static PE information: Image base 0x140000000 > 0x60000000
Source: antispam_account.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: antispam_account.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: antispam_account.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: antispam_account.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: antispam_account.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: antispam_account.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: antispam_account.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: antispam_account.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: C:\Users\lfkmf\source\repos\AddMachineAccount\x64\Release\AddMachineAccount.pdb source: antispam_account.exe
Source: antispam_account.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: antispam_account.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: antispam_account.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: antispam_account.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: antispam_account.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: C:\Users\user\Desktop\antispam_account.exe Code function: 0_2_00007FF69E4910D0 LoadLibraryA,GetProcAddress,DsGetDcNameW,CoInitializeEx,IIDFromString,IIDFromString,VariantInit,GetProcAddress,CharLowerW,NetApiBufferFree,CoUninitialize, 0_2_00007FF69E4910D0
Source: antispam_account.exe Static PE information: section name: _RDATA
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Users\user\Desktop\antispam_account.exe Code function: 0_2_00007FF69E49EAC4 _invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose, 0_2_00007FF69E49EAC4
Source: C:\Users\user\Desktop\antispam_account.exe Code function: 0_2_00007FF69E491F90 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 0_2_00007FF69E491F90
Source: C:\Users\user\Desktop\antispam_account.exe Code function: 0_2_00007FF69E4910D0 LoadLibraryA,GetProcAddress,DsGetDcNameW,CoInitializeEx,IIDFromString,IIDFromString,VariantInit,GetProcAddress,CharLowerW,NetApiBufferFree,CoUninitialize, 0_2_00007FF69E4910D0
Source: C:\Users\user\Desktop\antispam_account.exe Code function: 0_2_00007FF69E4A0FF4 GetProcessHeap, 0_2_00007FF69E4A0FF4
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Users\user\Desktop\antispam_account.exe Code function: 0_2_00007FF69E491F90 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 0_2_00007FF69E491F90
Source: C:\Users\user\Desktop\antispam_account.exe Code function: 0_2_00007FF69E49C06C RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 0_2_00007FF69E49C06C
Source: C:\Users\user\Desktop\antispam_account.exe Code function: 0_2_00007FF69E492134 SetUnhandledExceptionFilter, 0_2_00007FF69E492134
Source: C:\Users\user\Desktop\antispam_account.exe Code function: 0_2_00007FF69E491AB4 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 0_2_00007FF69E491AB4
Source: C:\Users\user\Desktop\antispam_account.exe Code function: 0_2_00007FF69E4A6870 cpuid 0_2_00007FF69E4A6870
Source: C:\Users\user\Desktop\antispam_account.exe Code function: 0_2_00007FF69E491E70 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter, 0_2_00007FF69E491E70
No contacted IP infos