Windows Analysis Report
self_updater.exe

Overview

General Information

Sample name: self_updater.exe
Analysis ID: 1430873
MD5: a6e4bd1b55655a29a1b25f2a567a65b7
SHA1: 7a40ce5381449e369042f7a9adc1ae49ff1b22d3
SHA256: 34077f9227c2fd9ee9949a0ff0ee436d80b0ac5322a02c524327be953be08c70
Tags: exe
Infos:

Detection

Score: 5
Range: 0 - 100
Whitelisted: false
Confidence: 80%

Signatures

Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to dynamically determine API calls
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Detected potential crypto function
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
PE file contains sections with non-standard names
Program does not show much activity (idle)
Sample execution stops while process was sleeping (likely an evasion)
Uses Microsoft's Enhanced Cryptographic Provider

Classification

Source: C:\Users\user\Desktop\self_updater.exe Code function: 0_2_00007FF76B1B9A40 BCryptGenRandom,GetCurrentProcessId,BCryptGenRandom,CreateNamedPipeW,GetLastError,BCryptGenRandom,CloseHandle,BCryptGenRandom, 0_2_00007FF76B1B9A40
Source: self_updater.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: D:\a\clangen\clangen\self_updater\target\release\deps\self_updater.pdb source: self_updater.exe
Source: C:\Users\user\Desktop\self_updater.exe Code function: 0_2_00007FF76B1B7CB0 CloseHandle,FindFirstFileW,FindClose, 0_2_00007FF76B1B7CB0
Source: C:\Users\user\Desktop\self_updater.exe Code function: 0_2_00007FF76B1B6960 FindFirstFileW,GetLastError, 0_2_00007FF76B1B6960
Source: C:\Users\user\Desktop\self_updater.exe Code function: 0_2_00007FF76B1B8150 NtWriteFile,WaitForSingleObject,RtlNtStatusToDosError, 0_2_00007FF76B1B8150
Source: C:\Users\user\Desktop\self_updater.exe Code function: 0_2_00007FF76B1B6730 CloseHandle,NtCreateFile,RtlNtStatusToDosError, 0_2_00007FF76B1B6730
Source: C:\Users\user\Desktop\self_updater.exe Code function: 0_2_00007FF76B1AEC40 0_2_00007FF76B1AEC40
Source: C:\Users\user\Desktop\self_updater.exe Code function: 0_2_00007FF76B1A2000 0_2_00007FF76B1A2000
Source: C:\Users\user\Desktop\self_updater.exe Code function: 0_2_00007FF76B1AC430 0_2_00007FF76B1AC430
Source: C:\Users\user\Desktop\self_updater.exe Code function: 0_2_00007FF76B1BFCC0 0_2_00007FF76B1BFCC0
Source: C:\Users\user\Desktop\self_updater.exe Code function: 0_2_00007FF76B1C3CD0 0_2_00007FF76B1C3CD0
Source: C:\Users\user\Desktop\self_updater.exe Code function: 0_2_00007FF76B1CD4A0 0_2_00007FF76B1CD4A0
Source: C:\Users\user\Desktop\self_updater.exe Code function: 0_2_00007FF76B1CDBA0 0_2_00007FF76B1CDBA0
Source: C:\Users\user\Desktop\self_updater.exe Code function: 0_2_00007FF76B1B9A40 0_2_00007FF76B1B9A40
Source: C:\Users\user\Desktop\self_updater.exe Code function: 0_2_00007FF76B1C2A50 0_2_00007FF76B1C2A50
Source: C:\Users\user\Desktop\self_updater.exe Code function: 0_2_00007FF76B1C9260 0_2_00007FF76B1C9260
Source: C:\Users\user\Desktop\self_updater.exe Code function: 0_2_00007FF76B1BA970 0_2_00007FF76B1BA970
Source: C:\Users\user\Desktop\self_updater.exe Code function: 0_2_00007FF76B1A69A0 0_2_00007FF76B1A69A0
Source: C:\Users\user\Desktop\self_updater.exe Code function: 0_2_00007FF76B1B5860 0_2_00007FF76B1B5860
Source: C:\Users\user\Desktop\self_updater.exe Code function: 0_2_00007FF76B1B8DC0 0_2_00007FF76B1B8DC0
Source: C:\Users\user\Desktop\self_updater.exe Code function: String function: 00007FF76B1CCD60 appears 73 times
Source: classification engine Classification label: clean5.winEXE@2/0@0/0
Source: C:\Users\user\Desktop\self_updater.exe Code function: 0_2_00007FF76B1B82A0 GetModuleHandleW,FormatMessageW,GetLastError, 0_2_00007FF76B1B82A0
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7144:120:WilError_03
Source: self_updater.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\self_updater.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\self_updater.exe "C:\Users\user\Desktop\self_updater.exe"
Source: C:\Users\user\Desktop\self_updater.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\self_updater.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\self_updater.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\self_updater.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: self_updater.exe Static PE information: Image base 0x140000000 > 0x60000000
Source: self_updater.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: self_updater.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: D:\a\clangen\clangen\self_updater\target\release\deps\self_updater.pdb source: self_updater.exe
Source: C:\Users\user\Desktop\self_updater.exe Code function: 0_2_00007FF76B1C26B0 WaitForSingleObjectEx,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetCurrentProcess,GetProcAddress,GetCurrentProcessId,CreateMutexA,CloseHandle,ReleaseMutex,ReleaseMutex, 0_2_00007FF76B1C26B0
Source: self_updater.exe Static PE information: section name: _RDATA
Source: C:\Users\user\Desktop\self_updater.exe API coverage: 2.6 %
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Users\user\Desktop\self_updater.exe Code function: 0_2_00007FF76B1B7CB0 CloseHandle,FindFirstFileW,FindClose, 0_2_00007FF76B1B7CB0
Source: C:\Users\user\Desktop\self_updater.exe Code function: 0_2_00007FF76B1B6960 FindFirstFileW,GetLastError, 0_2_00007FF76B1B6960
Source: C:\Users\user\Desktop\self_updater.exe Code function: 0_2_00007FF76B1CFBB0 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 0_2_00007FF76B1CFBB0
Source: C:\Users\user\Desktop\self_updater.exe Code function: 0_2_00007FF76B1C26B0 WaitForSingleObjectEx,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetCurrentProcess,GetProcAddress,GetCurrentProcessId,CreateMutexA,CloseHandle,ReleaseMutex,ReleaseMutex, 0_2_00007FF76B1C26B0
Source: C:\Users\user\Desktop\self_updater.exe Code function: 0_2_00007FF76B1B5810 GetProcessHeap,HeapAlloc, 0_2_00007FF76B1B5810
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Users\user\Desktop\self_updater.exe Code function: 0_2_00007FF76B1AB260 RtlAddVectoredExceptionHandler,SetThreadStackGuarantee,GetLastError, 0_2_00007FF76B1AB260
Source: C:\Users\user\Desktop\self_updater.exe Code function: 0_2_00007FF76B1CFBB0 IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 0_2_00007FF76B1CFBB0
Source: C:\Users\user\Desktop\self_updater.exe Code function: 0_2_00007FF76B1D398C SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 0_2_00007FF76B1D398C
Source: C:\Users\user\Desktop\self_updater.exe Code function: 0_2_00007FF76B1CFD54 SetUnhandledExceptionFilter, 0_2_00007FF76B1CFD54
Source: C:\Users\user\Desktop\self_updater.exe Memory allocated: page read and write | page guard Jump to behavior
Source: C:\Users\user\Desktop\self_updater.exe Code function: 0_2_00007FF76B1B9A40 BCryptGenRandom,GetCurrentProcessId,BCryptGenRandom,CreateNamedPipeW,GetLastError,BCryptGenRandom,CloseHandle,BCryptGenRandom, 0_2_00007FF76B1B9A40
Source: C:\Users\user\Desktop\self_updater.exe Code function: 0_2_00007FF76B1CFA8C GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter, 0_2_00007FF76B1CFA8C
No contacted IP infos