Windows Analysis Report
test_sample.zip

Overview

General Information

Sample name: test_sample.zip
Analysis ID: 1541924
MD5: 518aadbdab537e34d2447b55c60ce8a5
SHA1: 6998fd87906b269a3aa9f79ea34b58019f3b30b3
SHA256: d7840d7673e23d80673792b451f095e4e2c656f8ea1e17f016b93340938e27a8
Infos:

Detection

Score: 0
Range: 0 - 100
Whitelisted: false
Confidence: 80%

Signatures

Program does not show much activity (idle)

Classification

Source: Binary string: D:\File_Transfer\04-Jul-18\assetbuild\1681204\ASSET\agent\windows\tcp\Service.pdb source: 7ad889d43b865efd2dd27f116845fc7839db8d7b
Source: classification engine Classification label: clean0.winZIP@3/0@0/0
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:504:120:WilError_03
Source: C:\Windows\System32\rundll32.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: unknown Process created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: unknown Process created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: unknown Process created: C:\Users\user\Desktop\7ad889d43b865efd2dd27f116845fc7839db8d7b.exe "C:\Users\user\Desktop\7ad889d43b865efd2dd27f116845fc7839db8d7b.exe"
Source: C:\Users\user\Desktop\7ad889d43b865efd2dd27f116845fc7839db8d7b.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\7ad889d43b865efd2dd27f116845fc7839db8d7b.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\7ad889d43b865efd2dd27f116845fc7839db8d7b.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Users\user\Desktop\7ad889d43b865efd2dd27f116845fc7839db8d7b.exe Section loaded: wtsapi32.dll Jump to behavior
Source: C:\Users\user\Desktop\7ad889d43b865efd2dd27f116845fc7839db8d7b.exe Section loaded: oleacc.dll Jump to behavior
Source: C:\Users\user\Desktop\7ad889d43b865efd2dd27f116845fc7839db8d7b.exe Section loaded: uxtheme.dll Jump to behavior
Source: Binary string: D:\File_Transfer\04-Jul-18\assetbuild\1681204\ASSET\agent\windows\tcp\Service.pdb source: 7ad889d43b865efd2dd27f116845fc7839db8d7b
Source: C:\Windows\System32\rundll32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
No contacted IP infos