Windows Analysis Report
antiunpack_norm01_upx.exe

Overview

General Information

Sample name: antiunpack_norm01_upx.exe
Analysis ID: 1592452
MD5: 6516298cb80c3c4fc4d23a792ad647d8
SHA1: 3e198036ab2b1bcd9384bcd5670ad8390114ea4a
SHA256: b5ca4b3b318823ed414fca0b0d2aeda2954afd6a0f72eea76c02947a86a301c4
Infos:

Detection

Score: 48
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

AI detected suspicious sample
PE file has nameless sections
Detected non-DNS traffic on DNS port
PE file contains sections with non-standard names
Sample execution stops while process was sleeping (likely an evasion)
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)

Classification

AV Detection

barindex
Source: Submited Sample Integrated Neural Analysis Model: Matched 99.9% probability
Source: antiunpack_norm01_upx.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT
Source: global traffic TCP traffic: 192.168.2.4:65042 -> 162.159.36.2:53
Source: unknown DNS traffic detected: query: 171.39.242.20.in-addr.arpa replaycode: Name error (3)
Source: unknown TCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknown TCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknown TCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknown TCP traffic detected without corresponding DNS query: 162.159.36.2
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic DNS traffic detected: DNS query: 171.39.242.20.in-addr.arpa

System Summary

barindex
Source: antiunpack_norm01_upx.exe Static PE information: section name:
Source: antiunpack_norm01_upx.exe Static PE information: section name:
Source: antiunpack_norm01_upx.exe Static PE information: section name:
Source: classification engine Classification label: mal48.winEXE@2/0@1/0
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7316:120:WilError_03
Source: C:\Users\user\Desktop\antiunpack_norm01_upx.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\antiunpack_norm01_upx.exe "C:\Users\user\Desktop\antiunpack_norm01_upx.exe"
Source: C:\Users\user\Desktop\antiunpack_norm01_upx.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\antiunpack_norm01_upx.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\antiunpack_norm01_upx.exe Section loaded: libgcc_s_seh-1.dll Jump to behavior
Source: C:\Users\user\Desktop\antiunpack_norm01_upx.exe Section loaded: libstdc++-6.dll Jump to behavior
Source: antiunpack_norm01_upx.exe Static PE information: Image base 0x140000000 > 0x60000000
Source: antiunpack_norm01_upx.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT
Source: antiunpack_norm01_upx.exe Static PE information: section name:
Source: antiunpack_norm01_upx.exe Static PE information: section name:
Source: antiunpack_norm01_upx.exe Static PE information: section name:
Source: antiunpack_norm01_upx.exe Static PE information: section name: entropy: 7.838183543535868
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
No contacted IP infos