Windows
Analysis Report
dpnhupnp.dll
Overview
General Information
Detection
Dridex
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Yara detected Dridex unpacked file
Multi AV Scanner detection for submitted file
Benign windows process drops PE files
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Changes memory attributes in foreign processes to executable or writable
Machine Learning detection for sample
Queues an APC in another process (thread injection)
Sigma detected: Suspicious Call by Ordinal
Machine Learning detection for dropped file
Uses Atom Bombing / ProGate to inject into other processes
Uses a Windows Living Off The Land Binaries (LOL bins)
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to query locales information (e.g. system language)
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
PE file contains sections with non-standard names
Queries the installation date of Windows
Detected potential crypto function
Found potential string decryption / allocating functions
Stores files to the Windows start menu directory
Contains functionality to call native functions
Contains functionality to dynamically determine API calls
Found dropped PE file which has not been started or loaded
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Contains functionality for execution timing, often used to detect debuggers
Installs a raw input device (often for capturing keystrokes)
Sample file is different than original file name gathered from version info
PE file contains strange resources
Drops PE files
Tries to load missing DLLs
Found evasive API chain checking for process token information
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to launch a program with higher privileges
Binary contains a suspicious time stamp
PE file contains more sections than normal
Contains functionality to retrieve information about pressed keystrokes
Found large amount of non-executed APIs
Uses Microsoft's Enhanced Cryptographic Provider
Creates a process in suspended mode (likely to inject code)
Contains functionality to simulate mouse events
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to block mouse and keyboard input (often used to hinder debugging)
Contains functionality for read data from the clipboard
Classification
- System is w10x64
loaddll64.exe (PID: 4592 cmdline:
loaddll64. exe "C:\Us ers\user\D esktop\dpn hupnp.dll" MD5: 4E8A40CAD6CCC047914E3A7830A2D8AA) cmd.exe (PID: 4532 cmdline:
cmd.exe /C rundll32. exe "C:\Us ers\user\D esktop\dpn hupnp.dll" ,#1 MD5: 4E2ACF4F8A396486AB4268C94A6A245F) rundll32.exe (PID: 4356 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\dpnh upnp.dll", #1 MD5: 73C519F050C20580F8A62C849D49215A) rundll32.exe (PID: 2332 cmdline:
rundll32.e xe C:\User s\user\Des ktop\dpnhu pnp.dll,Ge tFileVersi onInfoA MD5: 73C519F050C20580F8A62C849D49215A) explorer.exe (PID: 3352 cmdline:
C:\Windows \Explorer. EXE MD5: AD5296B280E8F522A8A897C96BAB0E1D) DisplaySwitch.exe (PID: 2172 cmdline:
C:\Windows \system32\ DisplaySwi tch.exe MD5: 97411B8A84E5980E509E500C3209E5C0) DisplaySwitch.exe (PID: 1740 cmdline:
C:\Users\u ser\AppDat a\Local\4x eLXaDKW\Di splaySwitc h.exe MD5: 97411B8A84E5980E509E500C3209E5C0) wusa.exe (PID: 5472 cmdline:
C:\Windows \system32\ wusa.exe MD5: 04CE745559916B99248F266BBF5F9ED9) GamePanel.exe (PID: 4868 cmdline:
C:\Windows \system32\ GamePanel. exe MD5: 4EF330EFAE954723B1F2800C15FDA7EB) GamePanel.exe (PID: 5712 cmdline:
C:\Users\u ser\AppDat a\Local\uR SIQRt4\Gam ePanel.exe MD5: 4EF330EFAE954723B1F2800C15FDA7EB) msdt.exe (PID: 4792 cmdline:
C:\Windows \system32\ msdt.exe MD5: 8BE43BAF1F37DA5AB31A53CA1C07EE0C) msdt.exe (PID: 4796 cmdline:
C:\Users\u ser\AppDat a\Local\1X XGC21\msdt .exe MD5: 8BE43BAF1F37DA5AB31A53CA1C07EE0C) cmstp.exe (PID: 6272 cmdline:
C:\Windows \system32\ cmstp.exe MD5: 2A9828E0C405422D166E0141054A04B3) cmstp.exe (PID: 6384 cmdline:
C:\Users\u ser\AppDat a\Local\M4 eXJF\cmstp .exe MD5: 2A9828E0C405422D166E0141054A04B3) PresentationHost.exe (PID: 4516 cmdline:
C:\Windows \system32\ Presentati onHost.exe MD5: E3053C73EA240F4C2F7971B3905A91CF) PresentationHost.exe (PID: 2208 cmdline:
C:\Users\u ser\AppDat a\Local\a6 o\Presenta tionHost.e xe MD5: E3053C73EA240F4C2F7971B3905A91CF) cmstp.exe (PID: 2880 cmdline:
C:\Windows \system32\ cmstp.exe MD5: 2A9828E0C405422D166E0141054A04B3) cmstp.exe (PID: 5004 cmdline:
C:\Users\u ser\AppDat a\Local\96 P3D\cmstp. exe MD5: 2A9828E0C405422D166E0141054A04B3) rundll32.exe (PID: 5880 cmdline:
rundll32.e xe C:\User s\user\Des ktop\dpnhu pnp.dll,Ge tFileVersi onInfoByHa ndle MD5: 73C519F050C20580F8A62C849D49215A) rundll32.exe (PID: 7008 cmdline:
rundll32.e xe C:\User s\user\Des ktop\dpnhu pnp.dll,Ge tFileVersi onInfoExA MD5: 73C519F050C20580F8A62C849D49215A)
- cleanup
⊘No configs have been found
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Dridex_2 | Yara detected Dridex unpacked file | Joe Security | ||
JoeSecurity_Dridex_2 | Yara detected Dridex unpacked file | Joe Security | ||
JoeSecurity_Dridex_2 | Yara detected Dridex unpacked file | Joe Security | ||
JoeSecurity_Dridex_2 | Yara detected Dridex unpacked file | Joe Security | ||
JoeSecurity_Dridex_2 | Yara detected Dridex unpacked file | Joe Security | ||
Click to see the 6 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Dridex_2 | Yara detected Dridex unpacked file | Joe Security | ||
JoeSecurity_Dridex_2 | Yara detected Dridex unpacked file | Joe Security | ||
JoeSecurity_Dridex_2 | Yara detected Dridex unpacked file | Joe Security | ||
JoeSecurity_Dridex_2 | Yara detected Dridex unpacked file | Joe Security | ||
JoeSecurity_Dridex_2 | Yara detected Dridex unpacked file | Joe Security | ||
Click to see the 6 entries |
System Summary |
---|
Source: | Author: Florian Roth: |
Source: | Author: juju4: |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Virustotal: | Perma Link | ||
Source: | Metadefender: | Perma Link | ||
Source: | ReversingLabs: |
Source: | Avira: |
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: |
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: |
Source: | Code function: | 24_2_00007FF775508534 | |
Source: | Code function: | 24_2_00007FF775508610 | |
Source: | Code function: | 24_2_00007FF775508598 | |
Source: | Code function: | 24_2_00007FF7755088F8 | |
Source: | Code function: | 24_2_00007FF77550874C | |
Source: | Code function: | 32_2_00007FF7299EDF30 |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Code function: | 0_2_00007FFC6FA3ED10 | |
Source: | Code function: | 32_2_00007FF7299E7C3C | |
Source: | Code function: | 32_2_00007FF7299E6494 | |
Source: | Code function: | 32_2_00007FF7299FA65C | |
Source: | Code function: | 32_2_00007FF7299FBD48 | |
Source: | Code function: | 32_2_00007FF7299E6720 | |
Source: | Code function: | 32_2_00007FF7299E7784 | |
Source: | Code function: | 32_2_00007FF7299E2770 | |
Source: | Code function: | 32_2_00007FFC6E2FED10 |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | DNS traffic detected: |
Source: | Code function: | 24_2_00007FF7754CFC50 |
Source: | Code function: | 20_2_00007FF701BD5E1C |
Source: | Code function: | 32_2_00007FF7299E3120 |
E-Banking Fraud |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Code function: | 0_2_00007FFC6FA15020 | |
Source: | Code function: | 0_2_00007FFC6FA297D0 | |
Source: | Code function: | 0_2_00007FFC6FA47650 | |
Source: | Code function: | 0_2_00007FFC6FA3DDC0 | |
Source: | Code function: | 0_2_00007FFC6FA4D520 | |
Source: | Code function: | 0_2_00007FFC6FA2A2C0 | |
Source: | Code function: | 0_2_00007FFC6FA1AA70 | |
Source: | Code function: | 0_2_00007FFC6FA2CA50 | |
Source: | Code function: | 0_2_00007FFC6FA159F0 | |
Source: | Code function: | 0_2_00007FFC6FA33150 | |
Source: | Code function: | 0_2_00007FFC6FA07880 | |
Source: | Code function: | 0_2_00007FFC6FA0C030 | |
Source: | Code function: | 0_2_00007FFC6FA10020 | |
Source: | Code function: | 0_2_00007FFC6FA04800 | |
Source: | Code function: | 0_2_00007FFC6F9E1010 | |
Source: | Code function: | 0_2_00007FFC6FA1F870 | |
Source: | Code function: | 0_2_00007FFC6FA2F870 | |
Source: | Code function: | 0_2_00007FFC6FA35840 | |
Source: | Code function: | 0_2_00007FFC6FA05050 | |
Source: | Code function: | 0_2_00007FFC6FA0E7B0 | |
Source: | Code function: | 0_2_00007FFC6FA5B7A0 | |
Source: | Code function: | 0_2_00007FFC6FA4C780 | |
Source: | Code function: | 0_2_00007FFC6FA5EF80 | |
Source: | Code function: | 0_2_00007FFC6F9E6790 | |
Source: | Code function: | 0_2_00007FFC6FA54FF0 | |
Source: | Code function: | 0_2_00007FFC6FA06FE0 | |
Source: | Code function: | 0_2_00007FFC6F9F8FC0 | |
Source: | Code function: | 0_2_00007FFC6F9FA7D0 | |
Source: | Code function: | 0_2_00007FFC6FA40F30 | |
Source: | Code function: | 0_2_00007FFC6FA0872B | |
Source: | Code function: | 0_2_00007FFC6FA5BF6F | |
Source: | Code function: | 0_2_00007FFC6FA40770 | |
Source: | Code function: | 0_2_00007FFC6FA45760 | |
Source: | Code function: | 0_2_00007FFC6F9FE770 | |
Source: | Code function: | 0_2_00007FFC6FA02F50 | |
Source: | Code function: | 0_2_00007FFC6FA4A6B0 | |
Source: | Code function: | 0_2_00007FFC6FA0F6B0 | |
Source: | Code function: | 0_2_00007FFC6FA106A0 | |
Source: | Code function: | 0_2_00007FFC6F9E7E80 | |
Source: | Code function: | 0_2_00007FFC6F9E6E90 | |
Source: | Code function: | 0_2_00007FFC6FA47EC0 | |
Source: | Code function: | 0_2_00007FFC6F9E1620 | |
Source: | Code function: | 0_2_00007FFC6F9EDE20 | |
Source: | Code function: | 0_2_00007FFC6FA12E10 | |
Source: | Code function: | 0_2_00007FFC6FA03610 | |
Source: | Code function: | 0_2_00007FFC6F9F8670 | |
Source: | Code function: | 0_2_00007FFC6FA30650 | |
Source: | Code function: | 0_2_00007FFC6F9EC5A0 | |
Source: | Code function: | 0_2_00007FFC6F9F65E0 | |
Source: | Code function: | 0_2_00007FFC6F9F95C0 | |
Source: | Code function: | 0_2_00007FFC6FA125C0 | |
Source: | Code function: | 0_2_00007FFC6FA11D30 | |
Source: | Code function: | 0_2_00007FFC6FA10D10 | |
Source: | Code function: | 0_2_00007FFC6F9F9D70 | |
Source: | Code function: | 0_2_00007FFC6FA0D550 | |
Source: | Code function: | 0_2_00007FFC6FA03D50 | |
Source: | Code function: | 0_2_00007FFC6FA4E4AD | |
Source: | Code function: | 0_2_00007FFC6FA4E4B6 | |
Source: | Code function: | 0_2_00007FFC6FA4E49D | |
Source: | Code function: | 0_2_00007FFC6FA42CA0 | |
Source: | Code function: | 0_2_00007FFC6FA4E4A6 | |
Source: | Code function: | 0_2_00007FFC6FA4A490 | |
Source: | Code function: | 0_2_00007FFC6FA4E494 | |
Source: | Code function: | 0_2_00007FFC6FA0AC80 | |
Source: | Code function: | 0_2_00007FFC6FA4E48B | |
Source: | Code function: | 0_2_00007FFC6FA13CF0 | |
Source: | Code function: | 0_2_00007FFC6FA15CD0 | |
Source: | Code function: | 0_2_00007FFC6F9F3CD0 | |
Source: | Code function: | 0_2_00007FFC6F9E5C20 | |
Source: | Code function: | 0_2_00007FFC6F9F5420 | |
Source: | Code function: | 0_2_00007FFC6FA49410 | |
Source: | Code function: | 0_2_00007FFC6FA4E400 | |
Source: | Code function: | 0_2_00007FFC6F9F7410 | |
Source: | Code function: | 0_2_00007FFC6FA44390 | |
Source: | Code function: | 0_2_00007FFC6F9F23F0 | |
Source: | Code function: | 0_2_00007FFC6FA34BC0 | |
Source: | Code function: | 0_2_00007FFC6FA11B30 | |
Source: | Code function: | 0_2_00007FFC6F9EBB20 | |
Source: | Code function: | 0_2_00007FFC6FA0A310 | |
Source: | Code function: | 0_2_00007FFC6FA10300 | |
Source: | Code function: | 0_2_00007FFC6FA14360 | |
Source: | Code function: | 0_2_00007FFC6FA45B50 | |
Source: | Code function: | 0_2_00007FFC6FA03340 | |
Source: | Code function: | 0_2_00007FFC6F9F8340 | |
Source: | Code function: | 0_2_00007FFC6F9E5350 | |
Source: | Code function: | 0_2_00007FFC6FA482A0 | |
Source: | Code function: | 0_2_00007FFC6FA4AAA0 | |
Source: | Code function: | 0_2_00007FFC6FA0DAA0 | |
Source: | Code function: | 0_2_00007FFC6FA47AF0 | |
Source: | Code function: | 0_2_00007FFC6FA082E0 | |
Source: | Code function: | 0_2_00007FFC6FA1BAE0 | |
Source: | Code function: | 0_2_00007FFC6FA42AE0 | |
Source: | Code function: | 0_2_00007FFC6FA092C0 | |
Source: | Code function: | 0_2_00007FFC6FA3F2C0 | |
Source: | Code function: | 0_2_00007FFC6FA4B260 | |
Source: | Code function: | 0_2_00007FFC6FA1B250 | |
Source: | Code function: | 0_2_00007FFC6F9E7A40 | |
Source: | Code function: | 0_2_00007FFC6FA0E9A0 | |
Source: | Code function: | 0_2_00007FFC6F9FE9B0 | |
Source: | Code function: | 0_2_00007FFC6FA011B0 | |
Source: | Code function: | 0_2_00007FFC6FA19990 | |
Source: | Code function: | 0_2_00007FFC6F9E2980 | |
Source: | Code function: | 0_2_00007FFC6FA0F1F0 | |
Source: | Code function: | 0_2_00007FFC6FA191F0 | |
Source: | Code function: | 0_2_00007FFC6FA189F0 | |
Source: | Code function: | 0_2_00007FFC6FA121D0 | |
Source: | Code function: | 0_2_00007FFC6FA069C0 | |
Source: | Code function: | 0_2_00007FFC6FA16130 | |
Source: | Code function: | 0_2_00007FFC6F9EB100 | |
Source: | Code function: | 0_2_00007FFC6F9FE110 | |
Source: | Code function: | 0_2_00007FFC6FA03910 | |
Source: | Code function: | 0_2_00007FFC6FA4B960 | |
Source: | Code function: | 0_2_00007FFC6FA46950 | |
Source: | Code function: | 0_2_00007FFC6FA04140 | |
Source: | Code function: | 0_2_00007FFC6F9F08B0 | |
Source: | Code function: | 0_2_00007FFC6F9FD890 | |
Source: | Code function: | 0_2_00007FFC6F9E18D0 | |
Source: | Code function: | 20_2_00007FF701BD4EC8 | |
Source: | Code function: | 20_2_00007FF701BE1670 | |
Source: | Code function: | 20_2_00007FF701BC1250 | |
Source: | Code function: | 20_2_00007FF701BCB24C | |
Source: | Code function: | 20_2_00007FF701BD41D8 | |
Source: | Code function: | 20_2_00007FF701BCFCD8 | |
Source: | Code function: | 20_2_00007FF701BD740C | |
Source: | Code function: | 20_2_00007FF701BE13B0 | |
Source: | Code function: | 24_2_00007FF77550D6B0 | |
Source: | Code function: | 24_2_00007FF77553D788 | |
Source: | Code function: | 24_2_00007FF77554D7A2 | |
Source: | Code function: | 24_2_00007FF7754D3260 | |
Source: | Code function: | 24_2_00007FF77551B26C | |
Source: | Code function: | 24_2_00007FF7754D72C8 | |
Source: | Code function: | 24_2_00007FF775535190 | |
Source: | Code function: | 24_2_00007FF77553B14C | |
Source: | Code function: | 24_2_00007FF77552B124 | |
Source: | Code function: | 24_2_00007FF775547460 | |
Source: | Code function: | 24_2_00007FF7754F9484 | |
Source: | Code function: | 24_2_00007FF77550B454 | |
Source: | Code function: | 24_2_00007FF77553137C | |
Source: | Code function: | 24_2_00007FF77550BE58 | |
Source: | Code function: | 24_2_00007FF775515F08 | |
Source: | Code function: | 24_2_00007FF7754A3D38 | |
Source: | Code function: | 24_2_00007FF7754AA058 | |
Source: | Code function: | 24_2_00007FF77553BF88 | |
Source: | Code function: | 24_2_00007FF77554BFEC | |
Source: | Code function: | 24_2_00007FF775537A20 | |
Source: | Code function: | 24_2_00007FF775511AD4 | |
Source: | Code function: | 24_2_00007FF7754AB928 | |
Source: | Code function: | 24_2_00007FF77552F920 | |
Source: | Code function: | 24_2_00007FF775517A00 | |
Source: | Code function: | 24_2_00007FF77554FC59 | |
Source: | Code function: | 24_2_00007FF7754DDC44 | |
Source: | Code function: | 24_2_00007FF77552BD14 | |
Source: | Code function: | 24_2_00007FF77554DB6C | |
Source: | Code function: | 24_2_00007FF775510644 | |
Source: | Code function: | 24_2_00007FF775500620 | |
Source: | Code function: | 24_2_00007FF7754DE560 | |
Source: | Code function: | 24_2_00007FF7754F253C | |
Source: | Code function: | 24_2_00007FF7755445E0 | |
Source: | Code function: | 24_2_00007FF77550A5D0 | |
Source: | Code function: | 24_2_00007FF7755048C0 | |
Source: | Code function: | 24_2_00007FF775540728 | |
Source: | Code function: | 24_2_00007FF7754AA7EC | |
Source: | Code function: | 24_2_00007FF7755547E5 | |
Source: | Code function: | 24_2_00007FF7754B9AF0 | |
Source: | Code function: | 24_2_00007FF7754AE7FC | |
Source: | Code function: | 24_2_00007FF7754CE224 | |
Source: | Code function: | 24_2_00007FF7754EA250 | |
Source: | Code function: | 24_2_00007FF77552C2D8 | |
Source: | Code function: | 24_2_00007FF7754E21AC | |
Source: | Code function: | 24_2_00007FF775524198 | |
Source: | Code function: | 24_2_00007FF7755221AC | |
Source: | Code function: | 24_2_00007FF7754D43B8 | |
Source: | Code function: | 24_2_00007FF77553EE40 | |
Source: | Code function: | 24_2_00007FF7754F8F14 | |
Source: | Code function: | 24_2_00007FF77552ED90 | |
Source: | Code function: | 24_2_00007FF775524DD0 | |
Source: | Code function: | 24_2_00007FF77553D010 | |
Source: | Code function: | 24_2_00007FF77550AFF0 | |
Source: | Code function: | 24_2_00007FF7754F6948 | |
Source: | Code function: | 24_2_00007FF7755089F4 | |
Source: | Code function: | 24_2_00007FF77553A998 | |
Source: | Code function: | 24_2_00007FF775530C44 | |
Source: | Code function: | 24_2_00007FF77550CCFC | |
Source: | Code function: | 24_2_00007FF7754C4CDC | |
Source: | Code function: | 24_2_00007FF7754DED00 |