Windows Analysis Report
DelTempDM.cmd

Overview

General Information

Sample name: DelTempDM.cmd
Analysis ID: 1416960
MD5: 2de2f3a97d02661f773f9e775a7e62e9
SHA1: fd43304c94512c614493fe6cda4590d6306a7349
SHA256: 3283227468242e06cc192223ef39817d1cff5546471d782e3c72872f36c07096
Infos:

Detection

Score: 48
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Multi AV Scanner detection for submitted file
Program does not show much activity (idle)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Tries to load missing DLLs

Classification

AV Detection

barindex
Source: DelTempDM.cmd Virustotal: Detection: 13% Perma Link
Source: C:\Windows\System32\cmd.exe Section loaded: cmdext.dll Jump to behavior
Source: classification engine Classification label: mal48.winCMD@2/0@0/0
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7652:120:WilError_03
Source: DelTempDM.cmd Virustotal: Detection: 13%
Source: unknown Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\Desktop\DelTempDM.cmd" "
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\cmd.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Windows\System32\cmd.exe Queries volume information: C:\ VolumeInformation Jump to behavior
No contacted IP infos