Windows Analysis Report
Mcafe.exe

Overview

General Information

Sample Name: Mcafe.exe
Analysis ID: 877004
MD5: 76166c4ad30e3da0060f41fe59e465f1
SHA1: 31d887a689a2a6fab9723589bd02d5c15ec09924
SHA256: 908d00c0d3a8fe68b7cb0da154143ac81e357b1ca043ff25ac3581d2186defcb

Detection

Score: 3
Range: 0 - 100
Whitelisted: false
Confidence: 80%

Signatures

Tries to load missing DLLs
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Program does not show much activity (idle)
PE file contains sections with non-standard names
Detected potential crypto function
Contains functionality to query CPU information (cpuid)

Classification

Source: Mcafe.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: C:\buildslave\unity\build\artifacts\WindowsPlayer\Win64_VS2019_nondev_m_r\WindowsPlayer_Master_mono_x64.pdb source: Mcafe.exe
Source: C:\Users\user\Desktop\Mcafe.exe Code function: 0_2_00007FF6C31349B8 _invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose,FindClose, 0_2_00007FF6C31349B8
Source: C:\Users\user\Desktop\Mcafe.exe Section loaded: unityplayer.dll Jump to behavior
Source: C:\Users\user\Desktop\Mcafe.exe Code function: 0_2_00007FF6C3133738 0_2_00007FF6C3133738
Source: C:\Users\user\Desktop\Mcafe.exe Code function: 0_2_00007FF6C31385EC 0_2_00007FF6C31385EC
Source: C:\Users\user\Desktop\Mcafe.exe Code function: 0_2_00007FF6C31349B8 0_2_00007FF6C31349B8
Source: C:\Users\user\Desktop\Mcafe.exe Code function: 0_2_00007FF6C313A608 0_2_00007FF6C313A608
Source: Mcafe.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\Mcafe.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: classification engine Classification label: clean3.winEXE@1/0@0/0
Source: Mcafe.exe Static PE information: Image base 0x140000000 > 0x60000000
Source: Mcafe.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: Mcafe.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: Mcafe.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: Mcafe.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Mcafe.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: Mcafe.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: Mcafe.exe Static PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Mcafe.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: C:\buildslave\unity\build\artifacts\WindowsPlayer\Win64_VS2019_nondev_m_r\WindowsPlayer_Master_mono_x64.pdb source: Mcafe.exe
Source: Mcafe.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: Mcafe.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: Mcafe.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: Mcafe.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: Mcafe.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: Mcafe.exe Static PE information: section name: _RDATA
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Users\user\Desktop\Mcafe.exe Code function: 0_2_00007FF6C31349B8 _invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose,FindClose, 0_2_00007FF6C31349B8
Source: C:\Users\user\Desktop\Mcafe.exe Code function: 0_2_00007FF6C313444C RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 0_2_00007FF6C313444C
Source: C:\Users\user\Desktop\Mcafe.exe Code function: 0_2_00007FF6C31370F0 GetProcessHeap, 0_2_00007FF6C31370F0
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: C:\Users\user\Desktop\Mcafe.exe Code function: 0_2_00007FF6C313444C RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 0_2_00007FF6C313444C
Source: C:\Users\user\Desktop\Mcafe.exe Code function: 0_2_00007FF6C313ABA4 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 0_2_00007FF6C313ABA4
Source: C:\Users\user\Desktop\Mcafe.exe Code function: 0_2_00007FF6C31315EC IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 0_2_00007FF6C31315EC
Source: C:\Users\user\Desktop\Mcafe.exe Code function: 0_2_00007FF6C31317D0 SetUnhandledExceptionFilter, 0_2_00007FF6C31317D0
Source: C:\Users\user\Desktop\Mcafe.exe Code function: 0_2_00007FF6C313A450 cpuid 0_2_00007FF6C313A450
Source: C:\Users\user\Desktop\Mcafe.exe Code function: 0_2_00007FF6C31314C4 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter, 0_2_00007FF6C31314C4
No contacted IP infos