Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
MUMPS_5.7.1.atm

Overview

General Information

Sample name:MUMPS_5.7.1.atm
(renamed file extension from tar to atm)
Original sample name:MUMPS_5.7.1.tar
Analysis ID:1438599
MD5:c16c9f437660d0bae179133f55975791
SHA1:bf33a5563bffe0fc4079e526ef3d235e6832c5f1
SHA256:58984a5b9039a31077f5598058420155e53e081044a744f4aef47dab0c98ff69

Detection

Score:1
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Program does not show much activity (idle)
Queries the volume information (name, serial number etc) of a device

Classification

  • System is w10x64
  • OpenWith.exe (PID: 1052 cmdline: C:\Windows\system32\OpenWith.exe -Embedding MD5: E4A834784FA08C17D47A1E72429C5109)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: MUMPS_5.7.1.atmString found in binary or memory: http://brew.sh
Source: MUMPS_5.7.1.atmString found in binary or memory: http://dx.doi.org/10.1051/0004-6361/201219605
Source: MUMPS_5.7.1.atmString found in binary or memory: http://gforge.inria.fr/projects/scotch/)
Source: MUMPS_5.7.1.atmString found in binary or memory: http://mumps-solver.org
Source: MUMPS_5.7.1.atmString found in binary or memory: http://mumps-solver.org).
Source: MUMPS_5.7.1.atmString found in binary or memory: http://mumps-solver.org/
Source: MUMPS_5.7.1.atmString found in binary or memory: http://mumps-tech.com).
Source: MUMPS_5.7.1.atmString found in binary or memory: http://www.netlib.org/lapack/)
Source: MUMPS_5.7.1.atmString found in binary or memory: http://www2.cs.uni-paderborn.de/cs/ag-monien/PERSONAL/SCHLUNZ/vrp.html)
Source: MUMPS_5.7.1.atmString found in binary or memory: https://cecill.info/licences/Licence_CeCILL-C_V1-en.html)
Source: MUMPS_5.7.1.atmString found in binary or memory: https://sxauroratsubasa.sakura.ne.jp/documents/sdk/SDK_NLC/UsersGuide/man/dgemmt.html
Source: MUMPS_5.7.1.atmString found in binary or memory: https://web.archive.org/web/20140426002151/http://www2.cs.uni-paderborn.de/cs/ag-monien/PERSONAL/SCH
Source: MUMPS_5.7.1.atmString found in binary or memory: https://www.intel.com/content/www/us/en/docs/onemkl/developer-reference-fortran/2023-0/gemmt.html
Source: classification engineClassification label: clean1.winATM@1/0@0/0
Source: C:\Windows\System32\OpenWith.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1052:120:WilError_03
Source: C:\Windows\System32\OpenWith.exeFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Windows\System32\OpenWith.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: twinui.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: dwmapi.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: pdh.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: onecorecommonproxystub.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: actxprxy.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: windows.staterepositoryps.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: windows.ui.appdefaults.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: windows.ui.immersive.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: uiautomationcore.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: dui70.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: duser.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: dwrite.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: bcp47mrm.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: uianimation.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d11.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: dxgi.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: resourcepolicyclient.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: dxcore.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: dcomp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: oleacc.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: edputil.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: windows.ui.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: windowmanagementapi.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: inputhost.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: twinapi.appcore.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: twinapi.appcore.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: windowscodecs.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: thumbcache.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: policymanager.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: appresolver.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: bcp47langs.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: slc.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: sppc.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: tiledatarepository.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: staterepository.core.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: windows.staterepository.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: wtsapi32.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: windows.staterepositorycore.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: mrmcorer.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: sxs.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: directmanipulation.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\System32\OpenWith.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32Jump to behavior
Source: MUMPS_5.7.1.atmStatic file information: File size 22476800 > 1048576
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Windows\System32\OpenWith.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
Source: C:\Windows\System32\OpenWith.exeQueries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformationJump to behavior
Source: C:\Windows\System32\OpenWith.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformationJump to behavior
Source: C:\Windows\System32\OpenWith.exeQueries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
DLL Side-Loading
1
DLL Side-Loading
1
DLL Side-Loading
OS Credential Dumping1
File and Directory Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory11
System Information Discovery
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://mumps-solver.org).0%Avira URL Cloudsafe
http://mumps-tech.com).0%Avira URL Cloudsafe
http://mumps-solver.org/0%Avira URL Cloudsafe
http://mumps-solver.org0%Avira URL Cloudsafe
https://sxauroratsubasa.sakura.ne.jp/documents/sdk/SDK_NLC/UsersGuide/man/dgemmt.html0%Avira URL Cloudsafe
https://cecill.info/licences/Licence_CeCILL-C_V1-en.html)0%Avira URL Cloudsafe
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
https://www.intel.com/content/www/us/en/docs/onemkl/developer-reference-fortran/2023-0/gemmt.htmlMUMPS_5.7.1.atmfalse
    high
    http://mumps-solver.org).MUMPS_5.7.1.atmfalse
    • Avira URL Cloud: safe
    low
    https://cecill.info/licences/Licence_CeCILL-C_V1-en.html)MUMPS_5.7.1.atmfalse
    • Avira URL Cloud: safe
    unknown
    http://brew.shMUMPS_5.7.1.atmfalse
      high
      http://gforge.inria.fr/projects/scotch/)MUMPS_5.7.1.atmfalse
        high
        https://web.archive.org/web/20140426002151/http://www2.cs.uni-paderborn.de/cs/ag-monien/PERSONAL/SCHMUMPS_5.7.1.atmfalse
          high
          http://mumps-solver.orgMUMPS_5.7.1.atmfalse
          • Avira URL Cloud: safe
          unknown
          http://www.netlib.org/lapack/)MUMPS_5.7.1.atmfalse
            high
            http://mumps-solver.org/MUMPS_5.7.1.atmfalse
            • Avira URL Cloud: safe
            unknown
            http://www2.cs.uni-paderborn.de/cs/ag-monien/PERSONAL/SCHLUNZ/vrp.html)MUMPS_5.7.1.atmfalse
              high
              https://sxauroratsubasa.sakura.ne.jp/documents/sdk/SDK_NLC/UsersGuide/man/dgemmt.htmlMUMPS_5.7.1.atmfalse
              • Avira URL Cloud: safe
              unknown
              http://mumps-tech.com).MUMPS_5.7.1.atmfalse
              • Avira URL Cloud: safe
              low
              http://dx.doi.org/10.1051/0004-6361/201219605MUMPS_5.7.1.atmfalse
                high
                No contacted IP infos
                Joe Sandbox version:40.0.0 Tourmaline
                Analysis ID:1438599
                Start date and time:2024-05-08 21:57:07 +02:00
                Joe Sandbox product:CloudBasic
                Overall analysis duration:0h 4m 4s
                Hypervisor based Inspection enabled:false
                Report type:full
                Cookbook file name:default.jbs
                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                Number of analysed new started processes analysed:6
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Sample name:MUMPS_5.7.1.atm
                (renamed file extension from tar to atm)
                Original Sample Name:MUMPS_5.7.1.tar
                Detection:CLEAN
                Classification:clean1.winATM@1/0@0/0
                EGA Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                • Excluded domains from analysis (whitelisted): fs.microsoft.com, ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtOpenKeyEx calls found.
                • Report size getting too big, too many NtProtectVirtualMemory calls found.
                • Report size getting too big, too many NtQueryValueKey calls found.
                • VT rate limit hit for: MUMPS_5.7.1.atm
                TimeTypeDescription
                21:57:55API Interceptor1x Sleep call for process: OpenWith.exe modified
                No context
                No context
                No context
                No context
                No context
                No created / dropped files found
                File type:POSIX tar archive (GNU)
                Entropy (8bit):5.030130198510387
                TrID:
                • Vue D'Esprit 4 Atmosphere Preset (5501/1) 97.28%
                • TAR - Tape ARchive (154/5) 2.72%
                File name:MUMPS_5.7.1.atm
                File size:22'476'800 bytes
                MD5:c16c9f437660d0bae179133f55975791
                SHA1:bf33a5563bffe0fc4079e526ef3d235e6832c5f1
                SHA256:58984a5b9039a31077f5598058420155e53e081044a744f4aef47dab0c98ff69
                SHA512:78b2f098a3d6346e2b600ac30d8437eeb3129946c06576a26dd7eee0b6007cd8d4e0138e720ae3a4b6e851fc99ba69e81371664fb810fca7c611a0e66eb0fff8
                SSDEEP:49152:RHjU8F/9K4Kacy5eA59ZICPFrp1LgeLZ5BYuoCk6Oo3+9mV2p7nl3u9ml53J9sMC:h7n0ysA5XzPFN1x3+9x3u943J9h3z9
                TLSH:9437E70D3E105634EE53D1BB2D1BDA88F26A8D374F633416786C7168EF4832256BC9E9
                File Content Preview:MUMPS_5.7.1/........................................................................................0000775.0001750.0001750.00000000000.14614663706.012746. 5..................................................................................................
                Icon Hash:72e2a2a292a2a2b2
                No network behavior found

                Click to jump to process

                Click to jump to process

                Target ID:0
                Start time:21:57:55
                Start date:08/05/2024
                Path:C:\Windows\System32\OpenWith.exe
                Wow64 process (32bit):false
                Commandline:C:\Windows\system32\OpenWith.exe -Embedding
                Imagebase:0x7ff6851a0000
                File size:123'984 bytes
                MD5 hash:E4A834784FA08C17D47A1E72429C5109
                Has elevated privileges:false
                Has administrator privileges:false
                Programmed in:C, C++ or other language
                Reputation:moderate
                Has exited:true

                No disassembly