Windows Analysis Report
EmptyStandbyList.exe

Overview

General Information

Sample name: EmptyStandbyList.exe
Analysis ID: 1427157
MD5: 3555e25964bf8e983e863daaf1e4d0d6
SHA1: de5133bdbb40cfb0119dec5ac54dfbbff21b47d0
SHA256: 6d2b18f8a8ba787d3fa4c6e36ed6c7af66b10083ce555a21ec24b2ada3821cbe

Detection

Score: 1
Range: 0 - 100
Whitelisted: false
Confidence: 80%

Signatures

Program does not show much activity (idle)
Uses 32bit PE files

Classification

Source: EmptyStandbyList.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: EmptyStandbyList.exe Static PE information: certificate valid
Source: EmptyStandbyList.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: EmptyStandbyList.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: classification engine Classification label: clean1.winEXE@3/0@0/0
Source: C:\Windows\System32\conhost.exe Mutant created: \BaseNamedObjects\Local\SM0:6192:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7148:120:WilError_03
Source: EmptyStandbyList.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\EmptyStandbyList.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: unknown Process created: C:\Users\user\Desktop\EmptyStandbyList.exe "C:\Users\user\Desktop\EmptyStandbyList.exe"
Source: C:\Users\user\Desktop\EmptyStandbyList.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\EmptyStandbyList.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\EmptyStandbyList.exe Section loaded: apphelp.dll
Source: C:\Users\user\Desktop\EmptyStandbyList.exe Section loaded: cryptbase.dll
Source: C:\Users\user\Desktop\EmptyStandbyList.exe Section loaded: kernel.appcore.dll
Source: EmptyStandbyList.exe Static PE information: certificate valid
Source: EmptyStandbyList.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: EmptyStandbyList.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: EmptyStandbyList.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: EmptyStandbyList.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: EmptyStandbyList.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: EmptyStandbyList.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: EmptyStandbyList.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: EmptyStandbyList.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: EmptyStandbyList.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: EmptyStandbyList.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: EmptyStandbyList.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: EmptyStandbyList.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: EmptyStandbyList.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
⊘No contacted IP infos