Report #13639 check_circle
- Creation Date: Sept. 11, 2021, 9:22 p.m.
- Last Update: Sept. 11, 2021, 9:27 p.m.
- File: NewHello.exe
- Results:
Binary
DLL
False cancel
Size
5.00KB
trid
81.0% Generic CIL Executable7.2% Win32 Dynamic Link Library4.9% Win32 Executable2.2% OS/2 Executable2.2% Generic Win/DOS Executable
type
PE
wordsize
32
Subsystem
Windows CLI
Hashes
md5
62d2761bd5c33184f5f394b8a5232af6
sha1
ae8f31dad61e272b84048dc896318982e619a901
crc32
0xb335d9
sha224
fbf080dd05761d6a60c896b5335779d923c399159e06be6e3c85d34e
sha256
cb722390fb9e87f12974af6f8a5c458b46335631adb9e486fc3bdb012d9188a4
sha384
d435e476aeaab489c3b0bf3c05d387560ffab0bb9d7f9b1a8ac7068062d24a8161f986e307591fc2dc2e023b3fe3570b
sha512
f938e757eb84b782e5428261651809727011882f440816353c2f6239671391e5306ccd9cf6e77954d3bedb100e3e3005a5d3b72700a2eca9c4ee00dfe6672f6f
ssdeep
48:60FMtHYxdZ6BWuJLiAOtPgl66LCDMlYol34mgFWSfbNtm:tv+Otos6t9ozNt
Community
Google
False cancel
HashLib
False cancel
YARA
Matches
NET_executable, contentis_base64, Microsoft_Visual_C_v70_Basic_NET, Microsoft_Visual_Studio_NET_additional, IP, IsNET_EXE, NETexecutableMicrosoft, Microsoft_Visual_C_Basic_NET, Microsoft_Visual_Studio_NET, HasDebugData, IsConsole, NET_executable_, domain, IsPE32, Microsoft_Visual_C_v70_Basic_NET_additional
Suspicious
True check_circle
Imports
mscoree.dll
_CorExeMain
Strings
List
c:\Users\Win\Documents\Visual Studio 2012\Projects\NewHello\NewHello\obj\Release\NewHello.pdb<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>1.0.0.01.0.0.01.0.0.01.0.0.0NewHello.exeNewHello.exeNewHello.exemscoree.dllDebuggableAttributeDebuggingModes$ec4a2ec5-9dd8-4a3f-9a0a-149ae8e7beab<requestedExecutionLevel level="asInvoker" uiAccess="false"/>_CorExeMain#StringsRuntimeCompatibilityAttributeComVisibleAttribute<Module></assembly>ProductNameTargetFrameworkAttributeAssemblyCultureAttributeGuidAttributeAssemblyTitleAttributeInternalNameOriginalFilenameFileDescriptionWriteLineVarFileInfoStringFileInfoFileVersionmscorlibHello, world!TranslationNewHelloNewHelloNewHelloNewHello#GUIDProgramCopyrightCopyrightAssembly VersionConsole.ctorObject`.rsrcSystemMain<security>args20212021</security>RSDS!This program cannot be run in DOS mode.VS_VERSION_INFO.NETFramework,Version=v4.5<?xml version="1.0" encoding="UTF-8" standalone="yes"?>AssemblyCopyrightAttributeSystem.Runtime.InteropServicesAssemblyProductAttributeAssemblyCompanyAttributeSystem.Runtime.VersioningSystem.Runtime.CompilerServicesSystem.ReflectionCompilationRelaxationsAttributeAssemblyVersionAttributeAssemblyTrademarkAttributeAssemblyFileVersionAttributeAssemblyDescriptionAttributeAssemblyConfigurationAttribute</requestedPrivileges>LegalCopyrightSystem.Diagnostics.NET Framework 4.5WrapNonExceptionThrowsFrameworkDisplayName</trustInfo>@.relocProductVersion<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">000004b0#Blob.textv4.0.30319*BSJBvyfF<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">.3x.;<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
Foremost
Matches
0.exe, 5 KB
Suspicious
True check_circle
Heuristics
IPs
hasIPs: False cancelAllowedSuspicioushasAllowed: False cancelhasSuspicious: False cancel
URLs
AllowedhasURLs: False cancelSuspicioushasAllowed: False cancelhasSuspicious: False cancel
Files
Allowed: mscoree.dllhasFiles: True check_circleSuspicioushasAllowed: True check_circlehasSuspicious: False cancel
Binary
Sizes
RVARVA: 16Suspicious: False cancelCodeSize: 2048Suspicious: False cancelImageAddress: 4194304Suspicious: False cancelStackStack: 4096Suspicious: False cancelHeadersHeaders: 512Suspicious: False cancelSuspicious: False cancel
Symbols
NumberNumber: 0Suspicious: True check_circlePointerPointer: 0Suspicious: True check_circleDirectoriesNumber: 16Suspicious: False cancel
Checksum
Value: 0Suspicous: True check_circle
Sections
Allowed: .text, .rsrc, .relocSuspicioushasAllowed: True check_circlehasSections: True check_circlehasSuspicious: False cancel
Versions
OSVersion: 4Suspicious: False cancelImageVersion: True check_circleSuspicious: 4LinkerVersion: 11.0Suspicious: False cancelSubsystemVersion: 6.0Suspicious: False cancelSuspicious: False cancel
EntryPoint
Address: 10238Suspicious: False cancel
Anomalies
Anomalies: The header checksum and the calculated checksum do not match.hasAnomalies: True check_circle
Libraries
Allowed: mscoree.dllhasLibs: True check_circleSuspicioushasAllowed: True check_circlehasSuspicious: False cancel
Timestamp
Past: False cancelValid: True check_circleValue: 2021-08-20 12:36:51Future: False cancel
Compilation
Packed: False cancelMissing: False cancelPackersCompiled: True check_circleCompilers: Microsoft Visual C# / Basic .NET, Microsoft Visual Studio .NET, .NET executable, Microsoft Visual C# v7.0 / Basic .NET
Obfuscation
XOR: False cancelFuzzing: False cancel
PEDetector
Matches
None
Suspicious
False cancel
Disassembly
hasTricks
False cancel
Tricks
AVclass
File
Trace
11/9/2021 - 20:45:43.418 | Open | 2476 | C:\malware.exe | C:\Windows\SysWOW64\mscorrc.dll | |
11/9/2021 - 20:45:43.418 | Open | 2476 | C:\malware.exe | C:\Windows\SysWOW64\mscorrc.dll.DLL | |
11/9/2021 - 20:45:43.418 | Open | 2476 | C:\malware.exe | C:\Windows\System32\mscorrc.dll | |
11/9/2021 - 20:45:43.418 | Open | 2476 | C:\malware.exe | C:\Windows\System32\mscorrc.dll.DLL | |
11/9/2021 - 20:45:43.418 | Open | 2476 | C:\malware.exe | C:\mscorrc.dll | |
11/9/2021 - 20:45:43.418 | Open | 2476 | C:\malware.exe | C:\Windows\SysWOW64\mscorrc.dll | |
11/9/2021 - 20:45:43.418 | Open | 2476 | C:\malware.exe | C:\Windows\system\mscorrc.dll | |
11/9/2021 - 20:45:43.418 | Open | 2476 | C:\malware.exe | C:\Windows\mscorrc.dll | |
11/9/2021 - 20:45:43.418 | Open | 2476 | C:\malware.exe | C:\Monitor\mscorrc.dll | |
11/9/2021 - 20:45:43.418 | Open | 2476 | C:\malware.exe | C:\Windows\SysWOW64\mscorrc.dll | |
11/9/2021 - 20:45:43.418 | Open | 2476 | C:\malware.exe | C:\Windows\mscorrc.dll | |
11/9/2021 - 20:45:43.418 | Open | 2476 | C:\malware.exe | C:\Windows\SysWOW64\wbem\mscorrc.dll | |
11/9/2021 - 20:45:43.418 | Open | 2476 | C:\malware.exe | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\mscorrc.dll | |
11/9/2021 - 20:45:43.418 | Open | 2476 | C:\malware.exe | C:\malware.exe.config | |
11/9/2021 - 20:45:43.418 | Open | 2476 | C:\malware.exe | C:\Windows\Microsoft.NET\Framework\v4.0.40305 | |
11/9/2021 - 20:45:43.418 | Open | 2476 | C:\malware.exe | C:\Windows\Microsoft.NET\Framework\v4.0.40305 | |
11/9/2021 - 20:45:43.434 | Open | 2476 | C:\malware.exe | C:\Windows\Fonts\StaticCache.dat | |
11/9/2021 - 20:45:43.434 | Read | 2476 | C:\malware.exe | C:\Windows\Fonts\StaticCache.dat | StaticCache.dat |
11/9/2021 - 20:45:43.434 | Open | 2476 | C:\malware.exe | C:\Windows\SysWOW64\uxtheme.dll | |
11/9/2021 - 20:45:43.434 | Open | 2476 | C:\malware.exe | C:\Windows\SysWOW64\uxtheme.dll | |
11/9/2021 - 20:45:43.481 | Open | 2476 | C:\malware.exe | C:\dwmapi.dll | |
11/9/2021 - 20:45:43.481 | Open | 2476 | C:\malware.exe | C:\Windows\SysWOW64\dwmapi.dll | |
11/9/2021 - 20:45:43.481 | Open | 2476 | C:\malware.exe | C:\Windows\SysWOW64\dwmapi.dll | |
11/9/2021 - 20:45:43.481 | Open | 2476 | C:\malware.exe | C:\Windows\SysWOW64\ole32.dll | |
11/9/2021 - 20:45:43.481 | Open | 2476 | C:\malware.exe | C:\Windows\SysWOW64\ole32.dll | |
11/9/2021 - 20:45:43.481 | Open | 2476 | C:\malware.exe | C:\Windows\SysWOW64\rpcss.dll | |
11/9/2021 - 20:45:43.481 | Open | 2476 | C:\malware.exe | C:\Windows\SysWOW64\rpcss.dll | |
11/9/2021 - 20:45:43.481 | Open | 2476 | C:\malware.exe | C:\Windows\Globalization\Sorting\SortDefault.nls | |
11/9/2021 - 20:45:43.481 | Unknown | 2476 | C:\malware.exe | C:\Windows\Globalization\Sorting\SortDefault.nls | SortDefault.nls |
Process
Trace
Analysis
Reason
Timeout
Status
Sucessfully Executed
Results
1
Registry
Trace
File Summary
Created
Identified: False cancel
Deleted
Identified: False cancel
Process Summary
Created
Identified: False cancel
Deleted
Identified: False cancel
Registry Summary
Proxy
Identified: False cancel
AutoRun
Identified: False cancel
Created
Identified: False cancel
Deleted
Identified: False cancel
Browsers
Identified: False cancel
Internet
Identified: False cancel
Loading...
DNS
Query
Response
TCP
Info
UDP
Info
HTTP
Info
Summary
DNS
False cancel
TCP
False cancel
UDP
False cancel
HTTP
False cancel
Results
BINARY
NFS 2.0 (Threshold = 0.8)
confidence: 75.00%suspicious: False cancel
NFS 3.0 (Threshold = 0.75)
confidence: 64.00%suspicious: False cancel
Decision Tree (NFS-BRMalware)
confidence: 100.00%suspicious: True check_circle
MalConv (Ember: Raw Bytes, Threshold=0.5)
confidence: 98.02%suspicious: True check_circle
Random Forest (100 estimators, NFS-BRMalware)
confidence: 59.00%suspicious: True check_circle
Non-Negative MalConv (Ember: Raw Bytes, Threshold=0.35)
confidence: 89.15%suspicious: True check_circle
LightGDM (Ember: File Characteristics, Threshold=0.8336)
confidence: 99.99%suspicious: False cancel