Windows Analysis Report
norm01.exe

Overview

General Information

Sample name: norm01.exe
Analysis ID: 1592461
MD5: 0bb4432c16cf4ee494e38cbc599d8864
SHA1: 52d543bca80575234ed3242e8c07cbc096e9e1b2
SHA256: 53998441d1cdcbb1b48eab7ce59b29a596e0b8e9b919e95029e68bcde3857c62
Infos:

Detection

Score: 22
Range: 0 - 100
Whitelisted: false
Confidence: 80%

Signatures

AI detected suspicious sample
PE file contains more sections than normal
PE file contains sections with non-standard names
Program does not show much activity (idle)
Sample execution stops while process was sleeping (likely an evasion)

Classification

AV Detection

barindex
Source: Submited Sample Integrated Neural Analysis Model: Matched 80.5% probability
Source: norm01.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT
Source: norm01.exe Static PE information: Number of sections : 17 > 10
Source: classification engine Classification label: sus22.winEXE@2/0@0/0
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7348:120:WilError_03
Source: norm01.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\norm01.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\norm01.exe "C:\Users\user\Desktop\norm01.exe"
Source: C:\Users\user\Desktop\norm01.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\norm01.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\norm01.exe Section loaded: libgcc_s_seh-1.dll Jump to behavior
Source: C:\Users\user\Desktop\norm01.exe Section loaded: libstdc++-6.dll Jump to behavior
Source: norm01.exe Static PE information: Image base 0x140000000 > 0x60000000
Source: norm01.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT
Source: norm01.exe Static PE information: section name: .xdata
Source: norm01.exe Static PE information: section name: /4
Source: norm01.exe Static PE information: section name: /19
Source: norm01.exe Static PE information: section name: /31
Source: norm01.exe Static PE information: section name: /45
Source: norm01.exe Static PE information: section name: /57
Source: norm01.exe Static PE information: section name: /70
Source: norm01.exe Static PE information: section name: /81
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
No contacted IP infos