Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
file.zip

Overview

General Information

Sample Name:file.zip
Analysis ID:1314451
MD5:bfd4303cead7b992c6d8582bf00ebccd
SHA1:586a97c675f1abb8423dd05f731651add8d5a4e3
SHA256:26642f30dc75d56d3c7f3d5432b9906a320627e6681f387c72923a24f13484bb
Infos:

Detection

Score:72
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Connects to many ports of the same IP (likely port scanning)
Sample is not signed and drops a device driver
Uses known network protocols on non-standard ports
Suspicious powershell command line found
Drops large PE files
May check the online IP address of the machine
DLL side loading technique detected
Creates autostart registry keys with suspicious names
Queries the volume information (name, serial number etc) of a device
Drops PE files to the application program directory (C:\ProgramData)
May sleep (evasive loops) to hinder dynamic analysis
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Queries the installation date of Windows
Found dropped PE file which has not been started or loaded
Contains long sleeps (>= 3 min)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Queries information about the installed CPU (vendor, model number etc)
Drops PE files
Tries to load missing DLLs
Uses a known web browser user agent for HTTP communication
Detected TCP or UDP traffic on non-standard ports
Creates driver files
Creates a process in suspended mode (likely to inject code)

Classification

  • System is w10x64_ra
  • file.exe (PID: 5020 cmdline: "C:\Users\user\AppData\Local\Temp\Temp1_file.zip\file.exe" MD5: 8CA18F31DB0E5051F432050162F94CFE)
    • ypkwfDriverDetectMastertvDriverRepairPro.exe (PID: 948 cmdline: "C:\ProgramData\ypkiExpertDriverToolkit\ypkwfDriverDetectMastertvDriverRepairPro.exe" MD5: 4F2321A7D7EC44F7A6EF21D43CF4D470)
      • cmd.exe (PID: 4164 cmdline: cmd.exe /C powershell.exe -Command ""Set-ItemProperty -Path HKLM:\Software\Microsoft\Windows\CurrentVersion\Run -Name AMDDefaultValueCPUK.N0P/24#$YA -Value 'C:\ProgramData\ypkiExpertDriverToolkit\ypkwfDriverDetectMastertvDriverRepairPro.exe /runas'"" MD5: 4943BA1A9B41D69643F69685E35B2943)
        • conhost.exe (PID: 5220 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: C5E9B1D1103EDCEA2E408E9497A5A88F)
        • powershell.exe (PID: 5028 cmdline: powershell.exe -Command ""Set-ItemProperty -Path HKLM:\Software\Microsoft\Windows\CurrentVersion\Run -Name AMDDefaultValueCPUK.N0P/24#$YA -Value 'C:\ProgramData\ypkiExpertDriverToolkit\ypkwfDriverDetectMastertvDriverRepairPro.exe /runas'"" MD5: BCC5A6493E0641AA1E60CBF69469E579)
      • cmd.exe (PID: 5240 cmdline: cmd.exe /C powershell.exe -Command ""Set-ItemProperty -Path HKCU:\Software\Microsoft\Windows\CurrentVersion\Run -Name AMDDefaultValueCPUK.N0P/24#$YA -Value 'C:\ProgramData\ypkiExpertDriverToolkit\ypkwfDriverDetectMastertvDriverRepairPro.exe'"" MD5: 4943BA1A9B41D69643F69685E35B2943)
        • conhost.exe (PID: 1228 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: C5E9B1D1103EDCEA2E408E9497A5A88F)
        • powershell.exe (PID: 2608 cmdline: powershell.exe -Command ""Set-ItemProperty -Path HKCU:\Software\Microsoft\Windows\CurrentVersion\Run -Name AMDDefaultValueCPUK.N0P/24#$YA -Value 'C:\ProgramData\ypkiExpertDriverToolkit\ypkwfDriverDetectMastertvDriverRepairPro.exe'"" MD5: BCC5A6493E0641AA1E60CBF69469E579)
      • powershell.exe (PID: 2856 cmdline: powershell.exe -Command "Set-ItemProperty -Path HKLM:\Software\Microsoft\Windows\CurrentVersion\Run -Name AMDDefaultValueCPUK.N0P/24#$YA -Value 'C:\ProgramData\ypkiExpertDriverToolkit\ypkwfDriverDetectMastertvDriverRepairPro.exe /runas'" MD5: BCC5A6493E0641AA1E60CBF69469E579)
        • conhost.exe (PID: 2824 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: C5E9B1D1103EDCEA2E408E9497A5A88F)
      • powershell.exe (PID: 4648 cmdline: powershell.exe -Command "Set-ItemProperty -Path HKCU:\Software\Microsoft\Windows\CurrentVersion\Run -Name AMDDefaultValueCPUK.N0P/24#$YA -Value 'C:\ProgramData\ypkiExpertDriverToolkit\ypkwfDriverDetectMastertvDriverRepairPro.exe'" MD5: BCC5A6493E0641AA1E60CBF69469E579)
        • conhost.exe (PID: 4284 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: C5E9B1D1103EDCEA2E408E9497A5A88F)
  • cleanup
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results
Source: C:\ProgramData\ypkiExpertDriverToolkit\ypkwfDriverDetectMastertvDriverRepairPro.exeFile opened: C:\Windows\SysWOW64\wininet.dll
Source: C:\ProgramData\ypkiExpertDriverToolkit\ypkwfDriverDetectMastertvDriverRepairPro.exeFile opened: C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.18362.418_none_5f5edc43821bf931
Source: C:\ProgramData\ypkiExpertDriverToolkit\ypkwfDriverDetectMastertvDriverRepairPro.exeFile opened: C:\Windows\SysWOW64\winspool.drv
Source: C:\ProgramData\ypkiExpertDriverToolkit\ypkwfDriverDetectMastertvDriverRepairPro.exeFile opened: C:\Windows\SysWOW64\oleacc.dll
Source: C:\ProgramData\ypkiExpertDriverToolkit\ypkwfDriverDetectMastertvDriverRepairPro.exeFile opened: C:\Windows\SysWOW64\winmm.dll
Source: C:\ProgramData\ypkiExpertDriverToolkit\ypkwfDriverDetectMastertvDriverRepairPro.exeFile opened: C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.418_none_2e73e95e27897f63\COMCTL32.dll

Networking

barindex
Source: global trafficTCP traffic: 18.230.148.111 ports 30281,1,3,157,4,8,4318
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 4318
Source: unknownNetwork traffic detected: HTTP traffic on port 4318 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 30281
Source: unknownNetwork traffic detected: HTTP traffic on port 30281 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 4318
Source: unknownNetwork traffic detected: HTTP traffic on port 4318 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 157
Source: unknownNetwork traffic detected: HTTP traffic on port 157 -> 49739
Source: C:\Users\user\AppData\Local\Temp\Temp1_file.zip\file.exeDNS query: name: ip-api.com
Source: C:\Users\user\AppData\Local\Temp\Temp1_file.zip\file.exeDNS query: name: ip-api.com
Source: C:\Users\user\AppData\Local\Temp\Temp1_file.zip\file.exeDNS query: name: ip-api.com
Source: C:\Users\user\AppData\Local\Temp\Temp1_file.zip\file.exeDNS query: name: ip-api.com
Source: C:\Users\user\AppData\Local\Temp\Temp1_file.zip\file.exeDNS query: name: ip-api.com
Source: C:\ProgramData\ypkiExpertDriverToolkit\ypkwfDriverDetectMastertvDriverRepairPro.exeDNS query: name: ip-api.com
Source: global trafficHTTP traffic detected: GET /json HTTP/1.1Host: ip-api.comAccept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8User-Agent: Mozilla/3.0 (compatible; Indy Library)
Source: global trafficHTTP traffic detected: GET /json HTTP/1.1Host: ip-api.comAccept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8User-Agent: Mozilla/3.0 (compatible; Indy Library)
Source: global trafficHTTP traffic detected: GET /json HTTP/1.1Host: ip-api.comAccept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8User-Agent: Mozilla/3.0 (compatible; Indy Library)
Source: global trafficHTTP traffic detected: GET /json HTTP/1.1Host: ip-api.comAccept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8User-Agent: Mozilla/3.0 (compatible; Indy Library)
Source: global trafficHTTP traffic detected: GET /json HTTP/1.1Host: i