Edit tour
Windows
Analysis Report
http://74.248.121.8/d/msdownload/update/software/defu/2024/10/updateplatform.amd64fre_d3f6f8300855e56b8ed00da6dac55a3c4cbf8c20.exe?cacheHostOrigin=au.download.windowsupdate.com
Overview
General Information
Detection
Score: | 52 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Suspicious iFrame src set
Call-Chain indicates evasion measures
AV process strings found (often used to terminate AV products)
Downloads executable code via HTTP
Drops PE files
Dynamic code execution using eval()
PE file contains an invalid checksum
PE file contains executable resources (Code or Archives)
PE file does not import any functions
PE file overlay found
Script element or tag injection
Classification
- System is w10x64_ra
- chrome.exe (PID: 5632 cmdline:
"C:\Users\ user\AppDa ta\Local\C hromium\Ap plication\ chrome.exe " --start- maximized "about:bla nk" MD5: B6CB00FCB81D3B66870817AEBE7163BB) - chrome.exe (PID: 2972 cmdline:
"C:\Users\ user\AppDa ta\Local\C hromium\Ap plication\ chrome.exe " --no-san dbox --typ e=utility --utility- sub-type=n etwork.moj om.Network Service -- lang=en-GB --service -sandbox-t ype=none - -start-sta ck-profile r --mojo-p latform-ch annel-hand le=2056 -- field-tria l-handle=1 996,i,1775 9283859254 00890,1395 3614706138 782368,262 144 --disa ble-featur es=Optimiz ationGuide ModelDownl oading,Opt imizationH ints,Optim izationHin tsFetching ,Optimizat ionTargetP rediction /prefetch: 8 MD5: B6CB00FCB81D3B66870817AEBE7163BB) - chrome.exe (PID: 7952 cmdline:
"C:\Users\ user\AppDa ta\Local\C hromium\Ap plication\ chrome.exe " --no-san dbox --typ e=utility --utility- sub-type=c hrome.mojo m.UtilRead Icon --lan g=en-GB -- service-sa ndbox-type =icon_read er --mojo- platform-c hannel-han dle=5184 - -field-tri al-handle= 1996,i,177 5928385925 400890,139 5361470613 8782368,26 2144 --dis able-featu res=Optimi zationGuid eModelDown loading,Op timization Hints,Opti mizationHi ntsFetchin g,Optimiza tionTarget Prediction /prefetch :8 MD5: B6CB00FCB81D3B66870817AEBE7163BB) - chrome.exe (PID: 8108 cmdline:
"C:\Users\ user\AppDa ta\Local\C hromium\Ap plication\ chrome.exe " --no-san dbox --typ e=utility --utility- sub-type=c hrome.mojo m.UtilRead Icon --lan g=en-GB -- service-sa ndbox-type =icon_read er --mojo- platform-c hannel-han dle=5208 - -field-tri al-handle= 1996,i,177 5928385925 400890,139 5361470613 8782368,26 2144 --dis able-featu res=Optimi zationGuid eModelDown loading,Op timization Hints,Opti mizationHi ntsFetchin g,Optimiza tionTarget Prediction /prefetch :8 MD5: B6CB00FCB81D3B66870817AEBE7163BB)
- chrome.exe (PID: 6244 cmdline:
"C:\Users\ user\AppDa ta\Local\C hromium\Ap plication\ chrome.exe " "http:// 74.248.121 .8/d/msdow nload/upda te/softwar e/defu/202 4/10/updat eplatform. amd64fre_d 3f6f830085 5e56b8ed00 da6dac55a3 c4cbf8c20. exe?cacheH ostOrigin= au.downloa d.windowsu pdate.com" MD5: B6CB00FCB81D3B66870817AEBE7163BB)
- rundll32.exe (PID: 2064 cmdline:
C:\Windows \System32\ rundll32.e xe C:\Wind ows\System 32\shell32 .dll,SHCre ateLocalSe rverRunDll {9aa46009 -3ce0-458a -a354-7156 10a075e6} -Embedding MD5: EF3179D498793BF4234F708D3BE28633)
- cleanup
⊘No configs have been found
⊘No yara matches
⊘No Sigma rule has matched
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
Phishing |
---|
Source: | JavaScript Tracing: |
Source: | JavaScript Tracing: |
Source: | JavaScript Tracing: | ||
Source: | JavaScript Tracing: |
Source: | JavaScript Tracing: | ||
Source: | JavaScript Tracing: | ||
Source: | JavaScript Tracing: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Binary string: | ||
Source: | Binary string: |
Source: | HTTP traffic detected: |