Windows
Analysis Report
f1215887448.exe
Overview
General Information
Detection
Score: | 48 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Found strings related to Crypto-Mining
Maps a DLL or memory area into another process
Checks if the current process is being debugged
Connects to many different domains
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected non-DNS traffic on DNS port
IP address seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
PE file contains an invalid checksum
PE file does not import any functions
Queries keyboard layouts
Queries the volume information (name, serial number etc) of a device
Uses 32bit PE files
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Classification
- System is w11x64_office
msedge.exe (PID: 4332 cmdline:
"C:\Progra m Files (x 86)\Micros oft\Edge\A pplication \msedge.ex e" MD5: 438D99FEE85BB97BDE75E5F1C9EDCACA) msedge.exe (PID: 1744 cmdline:
"C:\Progra m Files (x 86)\Micros oft\Edge\A pplication \msedge.ex e" --type= utility -- utility-su b-type=net work.mojom .NetworkSe rvice --la ng=en-US - -service-s andbox-typ e=none --m ojo-platfo rm-channel -handle=23 00 --field -trial-han dle=2124,i ,100533918 9595612465 9,91072007 0434880470 9,131072 / prefetch:3 MD5: 438D99FEE85BB97BDE75E5F1C9EDCACA) identity_helper.exe (PID: 5076 cmdline:
"C:\Progra m Files (x 86)\Micros oft\Edge\A pplication \100.0.118 5.36\ident ity_helper .exe" --ty pe=utility --utility -sub-type= winrt_app_ id.mojom.W inrtAppIdS ervice --l ang=en-US --service- sandbox-ty pe=none -- mojo-platf orm-channe l-handle=3 964 --fiel d-trial-ha ndle=2124, i,10053391 8959561246 59,9107200 7043488047 09,131072 /prefetch: 8 MD5: 799B8192198E431938AD498DA9EFE217) conhost.exe (PID: 5780 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 9698384842DA735D80D278A427A229AB) identity_helper.exe (PID: 2000 cmdline:
"C:\Progra m Files (x 86)\Micros oft\Edge\A pplication \100.0.118 5.36\ident ity_helper .exe" --ty pe=utility --utility -sub-type= winrt_app_ id.mojom.W inrtAppIdS ervice --l ang=en-US --service- sandbox-ty pe=none -- mojo-platf orm-channe l-handle=3 964 --fiel d-trial-ha ndle=2124, i,10053391 8959561246 59,9107200 7043488047 09,131072 /prefetch: 8 MD5: 799B8192198E431938AD498DA9EFE217) msedge.exe (PID: 6100 cmdline:
"C:\Progra m Files (x 86)\Micros oft\Edge\A pplication \msedge.ex e" --type= utility -- utility-su b-type=ent ity_extrac tion_servi ce.mojom.E xtractor - -lang=en-U S --servic e-sandbox- type=entit y_extracti on --mojo- platform-c hannel-han dle=4252 - -field-tri al-handle= 2124,i,100 5339189595 6124659,91 0720070434 8804709,13 1072 /pref etch:8 MD5: 438D99FEE85BB97BDE75E5F1C9EDCACA)
chrome.exe (PID: 2848 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" MD5: 290DF23002E9B52249B5549F0C668A86) chrome.exe (PID: 4600 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --string-a nnotations =is-enterp rise-manag ed=no --fi eld-trial- handle=178 0,i,337133 3862956838 881,133807 1938895083 2742,26214 4 --variat ions-seed- version=20 250129-180 207.876000 --mojo-pl atform-cha nnel-handl e=2028 /pr efetch:11 MD5: 290DF23002E9B52249B5549F0C668A86) chrome.exe (PID: 7752 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= audio.mojo m.AudioSer vice --lan g=en-US -- service-sa ndbox-type =audio --s tring-anno tations=is -enterpris e-managed= no --field -trial-han dle=6396,i ,337133386 2956838881 ,133807193 8895083274 2,262144 - -variation s-seed-ver sion=20250 129-180207 .876000 -- mojo-platf orm-channe l-handle=6 388 /prefe tch:12 MD5: 290DF23002E9B52249B5549F0C668A86) chrome.exe (PID: 1760 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= video_capt ure.mojom. VideoCaptu reService --lang=en- US --servi ce-sandbox -type=none --string- annotation s=is-enter prise-mana ged=no --f ield-trial -handle=65 04,i,33713 3386295683 8881,13380 7193889508 32742,2621 44 --varia tions-seed -version=2 0250129-18 0207.87600 0 --mojo-p latform-ch annel-hand le=6368 /p refetch:14 MD5: 290DF23002E9B52249B5549F0C668A86)
WebViewHost.exe (PID: 7692 cmdline:
"C:\Progra m Files\Wi ndowsApps\ Microsoft. MicrosoftO fficeHub_1 8.2411.116 3.0_x64__8 wekyb3d8bb we\WebView Host.exe" MD5: 737C3D5A23C7B81B3969762D79E817BD) msedgewebview2.exe (PID: 2280 cmdline:
"C:\Progra m Files (x 86)\Micros oft\EdgeWe bView\Appl ication\10 0.0.1185.3 6\msedgewe bview2.exe " --embedd ed-browser -webview=1 --webview -exe-name= WebViewHos t.exe --we bview-exe- version=18 .2411.1163 .0 --user- data-dir=" C:\Users\u ser\AppDat a\Local\Pa ckages\Mic rosoft.Mic rosoftOffi ceHub_8wek yb3d8bbwe\ LocalState \EBWebView " --noerrd ialogs --e mbedded-br owser-webv iew-dpi-aw areness=2 --enable-f eatures=ms SingleSign OnOSForPri maryAccoun tIsShared --mojo-nam ed-platfor m-channel- pipe=7692. 5272.14083 5598071009 69314 MD5: 7333249A2DA2F769900496F812DFBD57) msedgewebview2.exe (PID: 6576 cmdline:
"C:\Progra m Files (x 86)\Micros oft\EdgeWe bView\Appl ication\10 0.0.1185.3 6\msedgewe bview2.exe " --type=c rashpad-ha ndler --us er-data-di r=C:\Users \user\AppD ata\Local\ Packages\M icrosoft.M icrosoftOf ficeHub_8w ekyb3d8bbw e\LocalSta te\EBWebVi ew /prefet ch:7 --mon itor-self- annotation =ptype=cra shpad-hand ler --data base=C:\Us ers\user\A ppData\Loc al\Package s\Microsof t.Microsof tOfficeHub _8wekyb3d8 bbwe\Local State\EBWe bView\Cras hpad --ann otation=Is OfficialBu ild=1 --an notation=c hannel= -- annotation =chromium- version=10 0.0.4896.7 5 "--annot ation=exe= C:\Program Files (x8 6)\Microso ft\EdgeWeb View\Appli cation\100 .0.1185.36 \msedgeweb view2.exe" --annotat ion=plat=W in64 "--an notation=p rod=Edge W ebView2" - -annotatio n=ver=100. 0.1185.36 --initial- client-dat a=0x138,0x 13c,0x140, 0x114,0x14 8,0x7ff9b4 ffd840,0x7 ff9b4ffd85 0,0x7ff9b4 ffd860 MD5: 7333249A2DA2F769900496F812DFBD57) msedgewebview2.exe (PID: 1444 cmdline:
"C:\Progra m Files (x 86)\Micros oft\EdgeWe bView\Appl ication\10 0.0.1185.3 6\msedgewe bview2.exe " --type=g pu-process --noerrdi alogs --us er-data-di r="C:\User s\user\App Data\Local \Packages\ Microsoft. MicrosoftO fficeHub_8 wekyb3d8bb we\LocalSt ate\EBWebV iew" --web view-exe-n ame=WebVie wHost.exe --webview- exe-versio n=18.2411. 1163.0 --e mbedded-br owser-webv iew=1 --em bedded-bro wser-webvi ew-dpi-awa reness=2 - -gpu-prefe rences=UAA AAAAAAADgA AAYAAAAAAA AAAAAAAAAA ABgAAAAAAA wAAAAAAAAA AAAAAAAAAA AAAAAAAAAA AAAAAAAAAA AAEgAAAAAA AAASAAAAAA AAAAYAAAAA gAAABAAAAA AAAAAGAAAA AAAAAAQAAA AAAAAAAAAA AAOAAAAEAA AAAAAAAABA AAADgAAAAg AAAAAAAAAC AAAAAAAAAA = --mojo-p latform-ch annel-hand le=1884 -- field-tria l-handle=1 940,i,1044 7704658551 006847,474 0937541044 747648,131 072 --enab le-feature s=msSingle SignOnOSFo rPrimaryAc countIsSha red /prefe tch:2 MD5: 7333249A2DA2F769900496F812DFBD57) msedgewebview2.exe (PID: 7452 cmdline:
"C:\Progra m Files (x 86)\Micros oft\EdgeWe bView\Appl ication\10 0.0.1185.3 6\msedgewe bview2.exe " --type=u tility --u tility-sub -type=netw ork.mojom. NetworkSer vice --lan g=en-US -- service-sa ndbox-type =none --no errdialogs --user-da ta-dir="C: \Users\use r\AppData\ Local\Pack ages\Micro soft.Micro softOffice Hub_8wekyb 3d8bbwe\Lo calState\E BWebView" --webview- exe-name=W ebViewHost .exe --web view-exe-v ersion=18. 2411.1163. 0 --embedd ed-browser -webview=1 --embedde d-browser- webview-dp i-awarenes s=2 --mojo -platform- channel-ha ndle=2068 --field-tr ial-handle =1940,i,10 4477046585 51006847,4 7409375410 44747648,1 31072 --en able-featu res=msSing leSignOnOS ForPrimary AccountIsS hared /pre fetch:3 MD5: 7333249A2DA2F769900496F812DFBD57) msedgewebview2.exe (PID: 1184 cmdline:
"C:\Progra m Files (x 86)\Micros oft\EdgeWe bView\Appl ication\10 0.0.1185.3 6\msedgewe bview2.exe " --type=u tility --u tility-sub -type=stor age.mojom. StorageSer vice --lan g=en-US -- service-sa ndbox-type =utility - -noerrdial ogs --user -data-dir= "C:\Users\ user\AppDa ta\Local\P ackages\Mi crosoft.Mi crosoftOff iceHub_8we kyb3d8bbwe \LocalStat e\EBWebVie w" --webvi ew-exe-nam e=WebViewH ost.exe -- webview-ex e-version= 18.2411.11 63.0 --emb edded-brow ser-webvie w=1 --embe dded-brows er-webview -dpi-aware ness=2 --m ojo-platfo rm-channel -handle=23 32 --field -trial-han dle=1940,i ,104477046 5855100684 7,47409375 4104474764 8,131072 - -enable-fe atures=msS ingleSignO nOSForPrim aryAccount IsShared / prefetch:8 MD5: 7333249A2DA2F769900496F812DFBD57) msedgewebview2.exe (PID: 6444 cmdline:
"C:\Progra m Files (x 86)\Micros oft\EdgeWe bView\Appl ication\10 0.0.1185.3 6\msedgewe bview2.exe " --type=r enderer -- noerrdialo gs --user- data-dir=" C:\Users\u ser\AppDat a\Local\Pa ckages\Mic rosoft.Mic rosoftOffi ceHub_8wek yb3d8bbwe\ LocalState \EBWebView " --webvie w-exe-name =WebViewHo st.exe --w ebview-exe -version=1 8.2411.116 3.0 --embe dded-brows er-webview =1 --embed ded-browse r-webview- dpi-awaren ess=2 --di sable-clie nt-side-ph ishing-det ection --d isplay-cap ture-permi ssions-pol icy-allowe d --js-fla gs="--harm ony-weak-r efs-with-c leanup-som e --expose -gc" --lan g=en-US -- device-sca le-factor= 1 --num-ra ster-threa ds=2 --ena ble-main-f rame-befor e-activati on --rende rer-client -id=5 --la unch-time- ticks=7486 409138 --m ojo-platfo rm-channel -handle=33 92 --field -trial-han dle=1940,i ,104477046 5855100684 7,47409375 4104474764 8,131072 - -enable-fe atures=msS ingleSignO nOSForPrim aryAccount IsShared / prefetch:1 MD5: 7333249A2DA2F769900496F812DFBD57)
- cleanup
⊘No configs have been found
⊘No yara matches
⊘No Sigma rule has matched
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
Source: | Binary or memory string: | memstr_4eca15ff-5 |
Bitcoin Miner |
---|
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Static PE information: |
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Source: | Binary string: |