Edit tour
Windows
Analysis Report
AIDE.dll
Overview
General Information
Detection
Score: | 4 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 60% |
Signatures
AV process strings found (often used to terminate AV products)
Checks if the current process is being debugged
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
One or more processes crash
PE file contains sections with non-standard names
Sample execution stops while process was sleeping (likely an evasion)
Uses 32bit PE files
Classification
- System is w10x64
- loaddll32.exe (PID: 5344 cmdline:
loaddll32. exe "C:\Us ers\user\D esktop\AID E.dll" MD5: 51E6071F9CBA48E79F10C84515AAE618) - conhost.exe (PID: 1776 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - cmd.exe (PID: 3132 cmdline:
cmd.exe /C rundll32. exe "C:\Us ers\user\D esktop\AID E.dll",#1 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - rundll32.exe (PID: 1912 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\AIDE .dll",#1 MD5: 889B99C52A60DD49227C5E485A016679) - WerFault.exe (PID: 1220 cmdline:
C:\Windows \SysWOW64\ WerFault.e xe -u -p 1 912 -s 568 MD5: C31336C1EFC2CCB44B4326EA793040F2) - rundll32.exe (PID: 2548 cmdline:
rundll32.e xe C:\User s\user\Des ktop\AIDE. dll,??0AID EDimension @AIDE@@QAE @II@Z MD5: 889B99C52A60DD49227C5E485A016679) - WerFault.exe (PID: 3416 cmdline:
C:\Windows \SysWOW64\ WerFault.e xe -u -p 2 548 -s 604 MD5: C31336C1EFC2CCB44B4326EA793040F2) - rundll32.exe (PID: 6728 cmdline:
rundll32.e xe C:\User s\user\Des ktop\AIDE. dll,??0AID EDimension @AIDE@@QAE @XZ MD5: 889B99C52A60DD49227C5E485A016679) - WerFault.exe (PID: 988 cmdline:
C:\Windows \SysWOW64\ WerFault.e xe -u -p 6 728 -s 624 MD5: C31336C1EFC2CCB44B4326EA793040F2) - rundll32.exe (PID: 1268 cmdline:
rundll32.e xe C:\User s\user\Des ktop\AIDE. dll,??0AID EFormatTyp e@AIDE@@QA E@H@Z MD5: 889B99C52A60DD49227C5E485A016679) - WerFault.exe (PID: 5396 cmdline:
C:\Windows \SysWOW64\ WerFault.e xe -u -p 1 268 -s 632 MD5: C31336C1EFC2CCB44B4326EA793040F2) - rundll32.exe (PID: 3708 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\AIDE .dll",??0A IDEDimensi on@AIDE@@Q AE@II@Z MD5: 889B99C52A60DD49227C5E485A016679) - rundll32.exe (PID: 6596 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\AIDE .dll",??0A IDEDimensi on@AIDE@@Q AE@XZ MD5: 889B99C52A60DD49227C5E485A016679) - rundll32.exe (PID: 3576 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\AIDE .dll",??0A IDEFormatT ype@AIDE@@ QAE@H@Z MD5: 889B99C52A60DD49227C5E485A016679) - rundll32.exe (PID: 716 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\AIDE .dll",AIDE WritePriva teChunk MD5: 889B99C52A60DD49227C5E485A016679) - rundll32.exe (PID: 6068 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\AIDE .dll",AIDE WebPEncode OptionsSet ImageQuali ty MD5: 889B99C52A60DD49227C5E485A016679) - rundll32.exe (PID: 1016 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\AIDE .dll",AIDE WebPEncode OptionsSet Compressio nType MD5: 889B99C52A60DD49227C5E485A016679) - rundll32.exe (PID: 4600 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\AIDE .dll",AIDE TiffEncode OptionsSet TileSize MD5: 889B99C52A60DD49227C5E485A016679) - rundll32.exe (PID: 1088 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\AIDE .dll",AIDE TiffEncode OptionsSet PyramidPar amsCustomL ayers MD5: 889B99C52A60DD49227C5E485A016679) - rundll32.exe (PID: 368 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\AIDE .dll",AIDE TiffEncode OptionsSet PyramidPar ams MD5: 889B99C52A60DD49227C5E485A016679) - rundll32.exe (PID: 1112 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\AIDE .dll",AIDE TiffEncode OptionsSet CustomEnco deParams MD5: 889B99C52A60DD49227C5E485A016679) - rundll32.exe (PID: 2324 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\AIDE .dll",AIDE TiffEncode OptionsSet Compressio nScheme MD5: 889B99C52A60DD49227C5E485A016679) - rundll32.exe (PID: 5580 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\AIDE .dll",AIDE TiffEncode OptionsDia bleLayer MD5: 889B99C52A60DD49227C5E485A016679) - rundll32.exe (PID: 2100 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\AIDE .dll",AIDE RawEncodeO ptionsSetB lurMethod MD5: 889B99C52A60DD49227C5E485A016679) - rundll32.exe (PID: 5660 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\AIDE .dll",AIDE PngEncodeO ptionsSetP alettizati onTechniqu e MD5: 889B99C52A60DD49227C5E485A016679) - rundll32.exe (PID: 4460 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\AIDE .dll",AIDE PngEncodeO ptionsSetP HYChunk MD5: 889B99C52A60DD49227C5E485A016679) - rundll32.exe (PID: 6548 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\AIDE .dll",AIDE PngEncodeO ptionsSetI nterlaced MD5: 889B99C52A60DD49227C5E485A016679) - rundll32.exe (PID: 1816 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\AIDE .dll",AIDE PngEncodeO ptionsSetF orcedPalet teCreation MD5: 889B99C52A60DD49227C5E485A016679) - rundll32.exe (PID: 1912 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\AIDE .dll",AIDE PngEncodeO ptionsSetF ilterType MD5: 889B99C52A60DD49227C5E485A016679) - rundll32.exe (PID: 2188 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\AIDE .dll",AIDE PngEncodeO ptionsSetC ompression Level MD5: 889B99C52A60DD49227C5E485A016679) - rundll32.exe (PID: 6108 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\AIDE .dll",AIDE PngEncodeO ptionsSetA ttemptPale tteCreatio n MD5: 889B99C52A60DD49227C5E485A016679)
- cleanup
⊘No configs have been found
⊘No yara matches
⊘No Sigma rule has matched
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
There are no malicious signatures, click here to show all signatures.
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: |