Windows Analysis Report
rslogixbuddy.exe

Overview

General Information

Sample name: rslogixbuddy.exe
Analysis ID: 1391063
MD5: 03f24da6e7ec5e9162d4b7c60fd77740
SHA1: 6325073e38c7aa678ed2de526e8610fce710cdec
SHA256: 41db1d3979d423bfcc410706f73fed14d7145e609b0a25e8b8858831adaaaf8f
Infos:

Detection

Score: 48
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

.NET source code contains potential unpacker
Machine Learning detection for sample
Allocates memory with a write watch (potentially for evading sandboxes)
Contains long sleeps (>= 3 min)
Enables debug privileges
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Sigma detected: PSScriptPolicyTest Creation By Uncommon Process
Tries to load missing DLLs
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)

Classification

AV Detection

barindex
Source: rslogixbuddy.exe Joe Sandbox ML: detected
Source: rslogixbuddy.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: rslogixbuddy.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: rslogixbuddy.exe, 00000000.00000002.1689846216.0000000002B3A000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
Source: rslogixbuddy.exe, 00000000.00000002.1689846216.0000000002B6F000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFileName vs rslogixbuddy.exe
Source: rslogixbuddy.exe, 00000000.00000002.1689846216.0000000002F0F000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: ,\\StringFileInfo\\000004B0\\OriginalFilename vs rslogixbuddy.exe
Source: rslogixbuddy.exe, 00000000.00000002.1689846216.00000000029FF000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenameSystem.Management.Automation.dllv+ vs rslogixbuddy.exe
Source: rslogixbuddy.exe, 00000000.00000002.1689846216.00000000029FF000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilename vs rslogixbuddy.exe
Source: rslogixbuddy.exe, 00000000.00000002.1689846216.00000000029FF000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: ,\\StringFileInfo\\000004B0\\OriginalFilename vs rslogixbuddy.exe
Source: C:\Users\user\Desktop\rslogixbuddy.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Section loaded: msisip.dll Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Section loaded: wshext.dll Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Section loaded: appxsip.dll Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Section loaded: opcservices.dll Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Section loaded: userenv.dll Jump to behavior
Source: rslogixbuddy.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: rslogixbuddy.exe, MainApp.cs Base64 encoded string: 'UmVtb3ZlLUl0ZW0gLVJlY3Vyc2UgLUZvcmNlIC1Db25maXJtOiRmYWxzZSBDOlxQcm9ncmFtRGF0YVwiUm9ja3dlbGwgQXV0b21hdGlvbiJcIkZhY3RvcnlUYWxrIEFjdGl2YXRpb24iXCA='
Source: classification engine Classification label: mal48.evad.winEXE@2/4@0/0
Source: C:\Users\user\Desktop\rslogixbuddy.exe File created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\rslogixbuddy.exe.log Jump to behavior
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7264:120:WilError_03
Source: C:\Users\user\Desktop\rslogixbuddy.exe Mutant created: NULL
Source: C:\Users\user\Desktop\rslogixbuddy.exe File created: C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_bpnaoii5.d1s.ps1 Jump to behavior
Source: rslogixbuddy.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: rslogixbuddy.exe Static file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.83%
Source: C:\Users\user\Desktop\rslogixbuddy.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\rslogixbuddy.exe C:\Users\user\Desktop\rslogixbuddy.exe
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\rslogixbuddy.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0EE7644B-1BAD-48B1-9889-0281C206EB85}\InprocServer32 Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe File opened: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dll Jump to behavior
Source: rslogixbuddy.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
Source: rslogixbuddy.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE

Data Obfuscation

barindex
Source: rslogixbuddy.exe, MainModuleUI.cs .Net Code: Prompt
Source: C:\Users\user\Desktop\rslogixbuddy.exe Code function: 0_2_00007FFD9B77D2A5 pushad ; iretd 0_2_00007FFD9B77D2A6
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Memory allocated: DE0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Memory allocated: 1A9F0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe TID: 7348 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Users\user\Desktop\rslogixbuddy.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process information queried: ProcessInformation Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Process token adjusted: Debug Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Memory allocated: page read and write | page guard Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Queries volume information: C:\Users\user\Desktop\rslogixbuddy.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\rslogixbuddy.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
No contacted IP infos