Loading ...

Analysis Report

Overview

General Information

Joe Sandbox Version:22.0.0
Analysis ID:49332
Start time:14:34:43
Joe Sandbox Product:CloudBasic
Start date:07.03.2018
Overall analysis duration:0h 9m 30s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:tzres.dll.mui (renamed file extension from mui to dll)
Cookbook file name:default.jbs
Analysis system description:Windows 7 SP1 (with Office 2010 SP2, IE 11, FF 54, Chrome 60, Acrobat Reader DC 17, Flash 26, Java 8.0.1440.1)
Number of analysed new started processes analysed:5
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies
  • HCA enabled
  • EGA enabled
  • HDC enabled
Analysis stop reason:Timeout
Detection:CLEAN
Classification:clean1.winDLL@1/1@0/0
HCA Information:
  • Successful, ratio: 100%
  • Number of executed functions: 0
  • Number of non-executed functions: 0
EGA Information:Failed
HDC Information:Failed
Cookbook Comments:
  • Adjust boot time
  • Correcting counters for adjusted boot time
  • Adjusted system time to: 2/1/1970
  • Stop behavior analysis, all processes terminated
Warnings:
Show All
  • Exclude process from analysis (whitelisted): WmiApSrv.exe, dllhost.exe


Detection

StrategyScoreRangeReportingDetection
Threshold10 - 100Report FP / FNclean


Confidence

StrategyScoreRangeFurther Analysis Required?Confidence
Threshold40 - 5false
ConfidenceConfidence


Classification

Analysis Advice

Sample is a resource Dll without any import or exported function, cannot be analyzed



Signature Overview

Click to jump to signature section


System Summary:

barindex
Contains modern PE file flags such as dynamic base (ASLR) or NXShow sources
Source: tzres.dl.dllStatic PE information: NO_SEH, DYNAMIC_BASE, NX_COMPAT
PE file contains a debug data directoryShow sources
Source: tzres.dl.dllStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Classification labelShow sources
Source: classification engineClassification label: clean1.winDLL@1/1@0/0
Reads software policiesShow sources
Source: C:\Windows\System32\loaddll32.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Sample is known by Antivirus (Virustotal or Metascan)Show sources
Source: tzres.dl.dllMetascan Online: hash found
PE file does not import any functionsShow sources
Source: tzres.dl.dllStatic PE information: No import functions for PE file found
Sample file is different than original file name gathered from version infoShow sources
Source: tzres.dl.dllBinary or memory string: OriginalFilenametzres.dll.muij% vs tzres.dl.dll

Anti Debugging:

barindex
Program does not show much activity (idle)Show sources
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected

Malware Analysis System Evasion:

barindex
Program does not show much activity (idle)Show sources
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
behaviorgraph top1 process2 2 Behavior Graph ID: 49332 Sample: tzres.dll.mui Startdate: 07/03/2018 Architecture: WINDOWS Score: 1 4 loaddll32.exe 2->4         started       

Simulations

Behavior and APIs

No simulations

Antivirus Detection

Initial Sample

SourceDetectionScannerLabelLink
tzres.dl.dll0%metadefenderBrowse

Dropped Files

No Antivirus matches

Unpacked PE Files

No Antivirus matches

Domains

No Antivirus matches

Yara Overview

Initial Sample

No yara matches

PCAP (Network Traffic)

No yara matches

Dropped Files

No yara matches

Memory Dumps

No yara matches

Unpacked PEs

No yara matches

Joe Sandbox View / Context

IPs

No context

Domains

No context

ASN

No context

Dropped Files

No context

Screenshot