Windows Analysis Report

Overview

General Information

Analysis ID: 1540249
Infos:

Detection

Score: 2
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Program does not show much activity (idle)
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: Suspicious Execution From GUID Like Folder Names
Very long cmdline option found, this is very uncommon (may be encrypted or packed)

Classification

Source: classification engine Classification label: clean2.win@2/0@0/0
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6944:120:WilError_03
Source: unknown Process created: C:\Windows\SysWOW64\cmd.exe cmd /C ""C:\Users\aullom\AppData\Roaming\{28e56cfb-e30e-4f66-85d8-339885b726b8}\Helper.exe" http:%2F%2Fsearch.easytelevisionaccess.com%2F%3Fuc=20200418%26uid=d805634c-a765-41aa-8b89-ace0e55d48c3%26i_id=tv_spt__1.30%26ap=appfocus686%26source=gdn_v1-bb9-iei-msn-su 21600 true"
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: unknown Process created: C:\Windows\SysWOW64\cmd.exe cmd /c ""c:\users\aullom\appdata\roaming\{28e56cfb-e30e-4f66-85d8-339885b726b8}\helper.exe" http:%2f%2fsearch.easytelevisionaccess.com%2f%3fuc=20200418%26uid=d805634c-a765-41aa-8b89-ace0e55d48c3%26i_id=tv_spt__1.30%26ap=appfocus686%26source=gdn_v1-bb9-iei-msn-su 21600 true"
No contacted IP infos