Windows Analysis Report

Overview

General Information

Analysis ID: 1427702
Infos:

Detection

Score: 1
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Program does not show much activity (idle)
Sample execution stops while process was sleeping (likely an evasion)

Classification

Source: classification engine Classification label: clean1.win@2/0@0/0
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1220:120:WilError_03
Source: unknown Process created: C:\Windows\SysWOW64\cmd.exe cmd /C "152806710990800000114981760417202421471027801102024150837872C:\WINDOWS\system32\msdt.exe"C:\WINDOWS\system32\msdt.exe" ms-msdt:-id AudioPlaybackDiagnostic -skip true -ep SndVolToast"
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
No contacted IP infos