Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
ActivitiesCache.sqlite

Overview

General Information

Sample Name:ActivitiesCache.sqlite
(renamed file extension from db to sqlite, renamed because original name is a hash value)
Original Sample Name:ActivitiesCache.db
Analysis ID:1304597
MD5:ca79add6e3d289a62ca2079634ce9da1
SHA1:baa22c1dc503e6854cfa76eb2f192d097c208ce3
SHA256:424c1c7bcf7cc970878c6ec61315f83bc700a93d2e0af988967967a33df2866d

Detection

Score:2
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
OS version to string mapping found (often used in BOTs)
Program does not show much activity (idle)

Classification

  • System is w10x64
  • OpenWith.exe (PID: 6916 cmdline: C:\Windows\system32\OpenWith.exe -Embedding MD5: D179D03728E95E040A889F760C1FC402)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: Binary string: C:\temp\build\thehoff\Quicksilver_MR40.0902791019568\Quicksilver_MR4\vpn\tools\DART\DARTOffline\WINXP\Win32\Release\DartOffline.pdb source: ActivitiesCache.sqlite
Source: Binary string: AppVlp.pdb source: ActivitiesCache.sqlite
Source: Binary string: powershell_ise.pdb94 source: ActivitiesCache.sqlite
Source: Binary string: a\AgentExecutor.pdb source: ActivitiesCache.sqlite
Source: Binary string: powershell.pdbUGP source: ActivitiesCache.sqlite
Source: Binary string: D:\T\BuildResults\bin\Release\AcroRd32Exe.pdb source: ActivitiesCache.sqlite
Source: Binary string: powershell.pdb source: ActivitiesCache.sqlite
Source: Binary string: C:\temp\build\thehoff\Quicksilver_MR40.0902791019568\Quicksilver_MR4\vpn\tools\DART\DARTOffline\WINXP\Win32\Release\DartOffline.pdbHHFGCTL source: ActivitiesCache.sqlite
Source: Binary string: C:\drone\src\build_output\Win32\Release\csc_ui.pdb source: ActivitiesCache.sqlite
Source: Binary string: "\AgentExecutor.pdb source: ActivitiesCache.sqlite
Source: Binary string: AppVlp.pdbGCTL source: ActivitiesCache.sqlite
Source: Binary string: powershell_ise.pdb source: ActivitiesCache.sqlite
Source: ActivitiesCache.sqliteString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
Source: ActivitiesCache.sqliteString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
Source: ActivitiesCache.sqliteString found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDCodeSigningCA.crt0
Source: ActivitiesCache.sqliteString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
Source: ActivitiesCache.sqliteString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
Source: ActivitiesCache.sqliteString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
Source: ActivitiesCache.sqliteString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0O
Source: ActivitiesCache.sqliteString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
Source: ActivitiesCache.sqliteString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
Source: ActivitiesCache.sqliteString found in binary or memory: http://crl3.digicert.com/sha2-assured-cs-g1.crl05
Source: ActivitiesCache.sqliteString found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
Source: ActivitiesCache.sqliteString found in binary or memory: http://crl4.digicert.com/sha2-assured-cs-g1.crl0K
Source: ActivitiesCache.sqliteString found in binary or memory: http://ocsp.digicert.com0A
Source: ActivitiesCache.sqliteString found in binary or memory: http://ocsp.digicert.com0C
Source: ActivitiesCache.sqliteString found in binary or memory: http://ocsp.digicert.com0N
Source: ActivitiesCache.sqliteString found in binary or memory: http://ocsp.digicert.com0X
Source: ActivitiesCache.sqliteString found in binary or memory: http://www.cisco.com0
Source: ActivitiesCache.sqliteString found in binary or memory: http://www.digicert.com/CPS0
Source: ActivitiesCache.sqliteString found in binary or memory: https://clients2.google.com/service/update2/crxupdate_urlBrowser
Source: ActivitiesCache.sqliteString found in binary or memory: https://crbug.com/820996
Source: ActivitiesCache.sqliteString found in binary or memory: https://crbug.com/820996LaunchElevatedProcessataProtectionIdEnterpriseDataPrADMDialogCopyPasteFixADM
Source: ActivitiesCache.sqliteString found in binary or memory: https://ims-na1-stg1.adobelogin.com/ims/authorize/v1?https://ims-na1.adobelogin.com/ims/authorize/v1
Source: ActivitiesCache.sqliteString found in binary or memory: https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/AES
Source: ActivitiesCache.sqliteString found in binary or memory: https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/BalTerm
Source: ActivitiesCache.sqliteString found in binary or memory: https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/BalTerm%20Terminal
Source: ActivitiesCache.sqliteString found in binary or memory: https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/CWiles
Source: ActivitiesCache.sqliteString found in binary or memory: https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/CWiles%20Items/C%2
Source: ActivitiesCache.sqliteString found in binary or memory: https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/CWiles%20Items/Org
Source: ActivitiesCache.sqliteString found in binary or memory: https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/CWiles%20Items/Tea
Source: ActivitiesCache.sqliteString found in binary or memory: https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/CWiles%20Items/pri
Source: ActivitiesCache.sqliteString found in binary or memory: https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/CWiles%20Items/rea
Source: ActivitiesCache.sqliteString found in binary or memory: https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Prinsengracht
Source: ActivitiesCache.sqliteString found in binary or memory: https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Prinsengracht%20An
Source: ActivitiesCache.sqliteString found in binary or memory: https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Silos.docx
Source: ActivitiesCache.sqliteString found in binary or memory: https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Silos.docx?web=1
Source: ActivitiesCache.sqliteString found in binary or memory: https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Tutorials/Metsa
Source: ActivitiesCache.sqliteString found in binary or memory: https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Tutorials/Metsa%20
Source: ActivitiesCache.sqliteString found in binary or memory: https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Tutorials/Monthly
Source: ActivitiesCache.sqliteString found in binary or memory: https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Tutorials/Monthly%
Source: ActivitiesCache.sqliteString found in binary or memory: https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Tutorials/Network
Source: ActivitiesCache.sqliteString found in binary or memory: https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Tutorials/Network%
Source: ActivitiesCache.sqliteString found in binary or memory: https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Tutorials/Providen
Source: ActivitiesCache.sqliteString found in binary or memory: https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Vessel
Source: ActivitiesCache.sqliteString found in binary or memory: https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Vessel%20Pro%20For
Source: ActivitiesCache.sqliteString found in binary or memory: https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/cwiles_report_unas
Source: ActivitiesCache.sqliteString found in binary or memory: https://logistec.sharepoint.com/sites/FSSARTeam/Shared
Source: ActivitiesCache.sqliteString found in binary or memory: https://logistec.sharepoint.com/sites/lgtops/CargoHandlingMonthlyPerformanceReport/1655
Source: ActivitiesCache.sqliteString found in binary or memory: https://logistec.sharepoint.com/sites/lgtops/CargoHandlingMonthlyPerformanceReport/1655%20Balterm/16
Source: ActivitiesCache.sqliteString found in binary or memory: https://logistec.sharepoint.com/sites/lgtops/CargoHandlingMonthlyPerformanceReport/1655%20Balterm/AR
Source: ActivitiesCache.sqliteString found in binary or memory: https://logistec.sharepoint.com/sites/lgtops/CargoHandlingMonthlyPerformanceReport/2022ByCompany.xls
Source: ActivitiesCache.sqliteString found in binary or memory: https://mail.google.com/
Source: ActivitiesCache.sqliteString found in binary or memory: https://wns2-ch1p.notify.windows.com/?token=AwYAAADSjAb88iRkUDS2eKDRGw%2fxW1oV4DmPkaRPlR7%2bLwVdteGH
Source: ActivitiesCache.sqliteString found in binary or memory: https://www.cisco.com/c/en/us/about/legal/cloud-and-software/end_user_license_agreement.htmlhttps://
Source: ActivitiesCache.sqliteString found in binary or memory: https://www.digicert.com/CPS0
Source: ActivitiesCache.sqliteString found in binary or memory: https://www.google.com/m8/feedshttps://www.googleapis.com/auth/userinfo.profile
Source: ActivitiesCache.sqliteString found in binary or memory: https://www.googleapis.com/auth/contacts.readonlyofflineaccess_type2382840d-9c54-438f-af1c-8a8d1a547
Source: ActivitiesCache.sqliteString found in binary or memory: https://www.googleapis.com/auth/drivehttps://www.googleapis.com/auth/gmail.compose
Source: ActivitiesCache.sqliteString found in binary or memory: https://www.immunet.com
Source: ActivitiesCache.sqliteString found in binary or memory: https://www.immunet.comOpen
Source: ActivitiesCache.sqliteBinary or memory string: OriginalFilenameAgentExecutor.exeF vs ActivitiesCache.sqlite
Source: ActivitiesCache.sqliteBinary or memory string: OriginalFilenamecsc_ui.exeD vs ActivitiesCache.sqlite
Source: ActivitiesCache.sqliteBinary or memory string: <br/><i></i><br/><b>00:00:00</b>CDefaultPluginHandler::CDefaultPluginHandlerC:\drone\src\src\Common\Utility\DefaultPluginHandler.cppSkipping interface '%s', File: '%s'.Disposed plugin C++ based interface '%s', File '%s'.CDefaultPluginHandler::~CDefaultPluginHandlerFailed to dispose C++ plugin for interface '%s', File: '%s'.Created Default plugin handler for C++ based interface '%s', File: '%s'.WinVerifyTrustEx\Wintrust.dllCode-signing verification succeeded. File (%s)Time stamp on the file %s is earlier than the kill date.CVerifyFileSignatureWindows::IsValidC:\drone\src\src\Common\Crypt\VerifyFileSignatureWindows.cppFailed to get the time stamp of the file: %s.GetFileVersionInfoWCVerifyFileSignatureWindows::CheckFileNameAndVersionVersion.dllAuthenticodeUtils::GetSignatureInfoWinTrustData is invalid. You must call IsValid first!CVerifyFileSignatureWindows::GetSigInfoCVerifyFileSignatureWindows::CheckFileSignatureEmbedded version %s in file %s does not meet minimum requirement.Embedded original filename in file %s does not match %s.VerQueryValue\StringFileInfo\040904b0\OriginalFilenameGetFileVersionInfoGetFileVersionInfoSizeVerQueryValueWGetFileVersionInfoSizeW/0.0.0.0:messagesLC_MESSAGEScharset=%s/%s/%s/%s.moPOSIXCCTimer::~CTimerC:\drone\src\src\Common\Utility\timer.cppFailed to entry point from wintrust.dllWTHelperProvDataFromStateData\wintrust.dllCertificate trust data was not foundSigner information was not foundCountersignature was not found in the certificateTrust provider certificate was not foundSubject name was not found in the certificateFailed to load wintrust.dllWTHelperGetProvCertFromChainWTHelperGetProvSignerFromChainAuthenticodeUtils::logMsgC:\drone\src\src\Common\Crypt\AuthenticodeUtils.cpp2.5.4.3?\ vs ActivitiesCache.sqlite
Source: ActivitiesCache.sqliteBinary or memory string: OriginalFilenameDeskConfig.exe vs ActivitiesCache.sqlite
Source: ActivitiesCache.sqliteBinary or memory string: OriginalFilenamePowerShell.EXEj% vs ActivitiesCache.sqlite
Source: ActivitiesCache.sqliteBinary or memory string: OriginalFilenameHelp.exe456789012345678901234567890123456789012345678901234567890.exe vs ActivitiesCache.sqlite
Source: ActivitiesCache.sqliteBinary or memory string: OriginalFilenamepowershell_ise.EXEj% vs ActivitiesCache.sqlite
Source: ActivitiesCache.sqliteBinary or memory string: TJfile_version_info_win.ccCreateFileVersionInfoWinCompanyNameCompanyShortNameInternalNameProductNameProductShortNameProductVersionFileDescriptionFileVersionOriginalFilenameSpecialBuild\StringFileInfo\%04x%04x\%ls\VarFileInfo\Translation\SetThreadDescriptionUnknown priority.::GetThreadPriority returned g]J vs ActivitiesCache.sqlite
Source: ActivitiesCache.sqliteBinary or memory string: OriginalFilenameappvlp.exej% vs ActivitiesCache.sqlite
Source: ActivitiesCache.sqliteBinary or memory string: OriginalFilenamePreferences.exe vs ActivitiesCache.sqlite
Source: ActivitiesCache.sqliteBinary or memory string: OriginalFilenamedartoffline.exeD vs ActivitiesCache.sqlite
Source: ActivitiesCache.sqliteBinary or memory string: OriginalFilenamePenTest.exeH vs ActivitiesCache.sqlite
Source: C:\Windows\System32\OpenWith.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: ActivitiesCache.sqliteBinary string: B\\?\pipe\NGLWFPipe__INS:(ML;;NW;;;LW)D:P(A;;GA;;;OW)(A;;GA;;;AC)\\?\pipe\\Device\NamedPipe\win\src\named_pipe_policy.ccSameObject check failed: InitializeProcThreadAttributeListUpdateProcThreadAttributewin\src\process_thread_policy.ccCreateProcessWAction: STATUS_ACCESS_DENIEDapp name: command line: NtCreateProcessExntdll.dllNtSuspendProcessNtResumeProcessNtQuerySymbolicLinkObjectNtOpenSymbolicLinkObjectNtClose%d\Sessions\BNOLINKSNtCreateEventNtOpenEventwin\src\signed_policy.ccHandle AccessCheck failed: 8[CD[CP[Cm[Cu[C@ntdll.dllg_interceptionsNtMapViewOfSectionNtUnmapViewOfSectiong_originals
Source: ActivitiesCache.sqliteBinary string: \??\UNC\\\.\\Device\SftVol\ntdll.dllA:\Device\\\?\/?/UNC/\?\UNC\
Source: ActivitiesCache.sqliteBinary string: g\\\\?\UNC\\Device\Mup\\Device\LanmanRedirector\\Device\WebDavRedirector\\Device\WinDfs\\Device\NetWareRedirector\\Device\nwrdr\4202392NtQueryObjectRtlNtStatusToDosErrorRtlCompareUnicodeString\Device\WinDFSCdmRedirectorVolume\Device\HarddiskVolumeDirectoryFileEventSectionKey<>:"\|?*Software\Policies\Adobe\Acrobat Reader\DC\F
Source: ActivitiesCache.sqliteBinary string: \\.\ko.%x.%x.%xSoftware\Classes\CLSID\{054AAE20-4BEA-4347-8A35-64A533254A9D}\LocalServer320123456789abcdef\Device\HarddiskVolume:
Source: ActivitiesCache.sqliteBinary string: sbox_alternate_desktop_local_winstation_\??\\\?\\\?\UNC\\\.\\??\pipe\\??\mailslot\\/?/?\\Device\
Source: ActivitiesCache.sqliteBinary string: ^tes.ini\Justsystem\Justsystem\*\Intuit\Quicken\Log\Intuit\Quicken\Log\qw.log\Enfocus Prefs Folder\Enfocus Prefs Folder\*\Adobe\Acrobat\FeatOut\Microsoft\Speech\Adobe\Flash Player\AssetCache\Adobe\Acrobat\DC\SearchEmbdIndexacrord32_super_sbx\device\volume{*}\*?:?:\HKEY_CURRENT_USER\%sHKEY_CURRENT_USER\%s\*HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\Privileged*HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\Privileged*HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles*HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral\cFavoriteFiles*HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral\cAdHocFiles*HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\Installer\NotificationAppx*Software\Adobe\Adobe Acrobat\DC\DiskCabsSoftware\Adobe\Adobe Synchronizer\DCHKEY_CURRENT_USER\Software\Adobe\CommonFiles\UsageSoftware\Adobe\CommonFiles\Usage\AcrobatDCSoftware\Adobe\CommonFiles\Usage\Reader DCHKEY_CURRENT_USER\SOFTWARE\Lotus\Notes\Installer*HKEY_CURRENT_USER\SOFTWARE\Lotus\Notes*HKEY_CURRENT_USER\SOFTWARE\Microsoft\Speech*HKEY_CURRENT_USER\System\CurrentControlSet\Control\MediaProperties\PrivateProperties*HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache*HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache*HKEY_CURRENT_USER\SOFTWARE\Adobe\CommonFiles*HKEY_CLASSES_ROOT*HKEY_CURRENT_USER*HKEY_LOCAL_MACHINE*HKEY_USERS*HKEY_CURRENT_CONFIG*SOFTWARE\Justsystem\ATOK\Setup\FolderATFSVR\Acrobat\plug_ins\test_tools\AcroNGLTools\qe-ngl-tool.exe?ihs*_*IMSC*_Imejp.ConfigrationIO_*FileView__Satori_PropMgrGlobal_IMJP_*FileView__Satori_PropMgrGlobal_IME*SatoriKnlDict_MemoryDictionary_*_IME_*_CodeDictionarySharedMemory_*FileView___IMJP*UD_FileMapping_{**_IMJP_??_UD_FileMapping_**_IMJP_?_UD_FileMapping_**_IMJP_??_UD_ManagementBlock_**_IMJP_?_UD_ManagementBlock_**microsoft_imjp*AtlDebugAllocator_FileMappingNameStatic3_*windows_shell_global_countersMSCTF.Shared.*M
Source: ActivitiesCache.sqliteBinary string: /qnBROADCASTCEFRELOAD=1 REINSTALLMODE=omus DISABLE_FIU_CHECK=1 IGNOREAAM=1 REPAIRFROMAPP=1 /qb\/\*cef_* CLEANUP_CEFFOLDER=1 DISABLE_FIU_CHECK=1 /qn/i msiexec.exe ADD_ALL_DICT=1 REINSTALL=AdobeCommonLinguistics SKIP_WEBRCS_REINSTALL=1 SKIP_CEF_KILL=1 /qn/i msiexec.exeAcroRd32.exe ADDLOCAL=OptionalFeatures,DistillerCJKNative,DistillerCJKSupport,PaperCaptureOptional,PreFlightPlugin DISABLE_FIU_CHECK=1 TRANSITION_INSTALL_MODE=4 SKIP_WEBRCS_REINSTALL=1 SKIP_CEF_KILL=1 /qn/i msiexec.exeSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdf\OpenWithListMRUListMRUListAppDoNotTakePDFOwnershipAtLaunchAppDoNotTakePDFOwnershipAtLaunchWin10DisableOwnershipPrompt.pdf.pdfxml.acrobatsecuritysettings.fdf.xfdf.xdp.pdx.api.secstoreAdobe Reader XIRtlGetVersionntdll.dll\??\UNC\\\\\?\UNC\\Device\Mup\\Device\LanmanRedirector\\Device\WebDavRedirector\\Device\WinDfs\\Device\NetWareRedirector\\Device\nwrdr\RtlGetVersionntdll.dllAdobe Systems, IncorporatedAdobe Inc.Adobe Systems Incorporated1.3.6.1.4.1.311.2.1.121.3.6.1.4.1.311.2.1.121.3.6.1.4.1.311.2.1.121.2.840.113549.1.9.61.3.6.1.4.1.311.3.3.1kernel32IsWow64ProcessSystem\CurrentControlSet\Control\CitrixProductVersionNumSoftware\Adobe\Acrobat\ExeEnableLUASoftware\Microsoft\Windows\CurrentVersion\Policies\System /FixPDF /RegisterFileTypesOwnership /PRODUCT:Reader /VERSION:12.03305580Click on 'Change' to select default PDF handler.pdf Properties#32770Click on 'Change' to select default PDF handler Properties#32770Click on 'Change' to select default PDF handler#32770/\ADelRCP.exeClick on 'Change' to select default PDF handler.pdfpropertiesShowAppPickerForPDF.exeProgram ManagerPROGMANClick on 'Change' to select default PDF handler.pdf Properties#32770Click on 'Change' to select default PDF handler Properties#32770Click on 'Change' to select default PDF handler#32770Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdf\UserChoiceSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdf\UserChoiceSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdfApplication
Source: ActivitiesCache.sqliteBinary string: bIsUserEntitledpolicy_configurator.cppRegistry set for Kaizen Purchase from Browser CommonSoftware\Adobe\Acrobat Reader\DC\FEAT\cFeatDir*.ajt*.uifProgramW6432\Adobe\Acrobat\Privileged\DC\Microsoft\Crypto\RSA\Arcot\Ids\Microsoft\Outlook*.dll*.manifest*.config*.p12*.pfx\Adobe\Acrobat\%d.0\Adobe\Color\Microsoft\IME*\Microsoft\IMJP*\Adobe\Acrobat\DC\Replicate\Security\*\Adobe\Acrobat\DC\Security\*TEMPTMP\*\Temp\JFEAT_temp*\Temp\Low\Temp\Adobe\Acrobat\DC*.exe*.bat*.cmd*.com*.cpl*.ocx*.pif*.scr*.scf*:$**:Zone.Identifier*\/?/?\??*:\device\volume{*}\*:\Adobe\Acrobat\DC\Adobe\Linguistics\.ms-ad\Microsoft\RMSLocalStorage\com.adobe.dunamis\f2eb6c79-671d-4de2-b7be-3b2eea7abc47\com.adobe.dunamis\56079431-ea46-4833-94f9-1ff5658cdb1c\com.adobe.dunamis\6d9d9777-7ded-4768-8191-9a707d72b009\com.adobe.dunamis\61f56613-c62c-4b17-84dd-62b60d5776aa\Adobe\LogTransport2\Adobe\Headlights\Lotus\Notes\Data\Lotus\Notes\Data\*.nbf\Lotus\Notes\Data\names.nsf\Lotus\Notes\Data\JOBSCHED.NJF\Lotus\Notes\Data\cluster.ncf\Lotus\Notes\Data\ticket.idt\Lotus\Notes\Data\*.reg\Lotus\Notes\Data\no
Source: classification engineClassification label: clean2.winSQLITE@1/0@0/0
Source: C:\Windows\System32\OpenWith.exeFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Windows\System32\OpenWith.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32Jump to behavior
Source: C:\Windows\System32\OpenWith.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6916:120:WilError_01
Source: ActivitiesCache.sqliteStatic file information: File size 24514560 > 1048576
Source: Binary string: C:\temp\build\thehoff\Quicksilver_MR40.0902791019568\Quicksilver_MR4\vpn\tools\DART\DARTOffline\WINXP\Win32\Release\DartOffline.pdb source: ActivitiesCache.sqlite
Source: Binary string: AppVlp.pdb source: ActivitiesCache.sqlite
Source: Binary string: powershell_ise.pdb94 source: ActivitiesCache.sqlite
Source: Binary string: a\AgentExecutor.pdb source: ActivitiesCache.sqlite
Source: Binary string: powershell.pdbUGP source: ActivitiesCache.sqlite
Source: Binary string: D:\T\BuildResults\bin\Release\AcroRd32Exe.pdb source: ActivitiesCache.sqlite
Source: Binary string: powershell.pdb source: ActivitiesCache.sqlite
Source: Binary string: C:\temp\build\thehoff\Quicksilver_MR40.0902791019568\Quicksilver_MR4\vpn\tools\DART\DARTOffline\WINXP\Win32\Release\DartOffline.pdbHHFGCTL source: ActivitiesCache.sqlite
Source: Binary string: C:\drone\src\build_output\Win32\Release\csc_ui.pdb source: ActivitiesCache.sqlite
Source: Binary string: "\AgentExecutor.pdb source: ActivitiesCache.sqlite
Source: Binary string: AppVlp.pdbGCTL source: ActivitiesCache.sqlite
Source: Binary string: powershell_ise.pdb source: ActivitiesCache.sqlite
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\OpenWith.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: ActivitiesCache.sqliteBinary or memory string: /qnBROADCASTCEFRELOAD=1 REINSTALLMODE=omus DISABLE_FIU_CHECK=1 IGNOREAAM=1 REPAIRFROMAPP=1 /qb\/\*cef_* CLEANUP_CEFFOLDER=1 DISABLE_FIU_CHECK=1 /qn/i msiexec.exe ADD_ALL_DICT=1 REINSTALL=AdobeCommonLinguistics SKIP_WEBRCS_REINSTALL=1 SKIP_CEF_KILL=1 /qn/i msiexec.exeAcroRd32.exe ADDLOCAL=OptionalFeatures,DistillerCJKNative,DistillerCJKSupport,PaperCaptureOptional,PreFlightPlugin DISABLE_FIU_CHECK=1 TRANSITION_INSTALL_MODE=4 SKIP_WEBRCS_REINSTALL=1 SKIP_CEF_KILL=1 /qn/i msiexec.exeSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdf\OpenWithListMRUListMRUListAppDoNotTakePDFOwnershipAtLaunchAppDoNotTakePDFOwnershipAtLaunchWin10DisableOwnershipPrompt.pdf.pdfxml.acrobatsecuritysettings.fdf.xfdf.xdp.pdx.api.secstoreAdobe Reader XIRtlGetVersionntdll.dll\??\UNC\\\\\?\UNC\\Device\Mup\\Device\LanmanRedirector\\Device\WebDavRedirector\\Device\WinDfs\\Device\NetWareRedirector\\Device\nwrdr\RtlGetVersionntdll.dllAdobe Systems, IncorporatedAdobe Inc.Adobe Systems Incorporated1.3.6.1.4.1.311.2.1.121.3.6.1.4.1.311.2.1.121.3.6.1.4.1.311.2.1.121.2.840.113549.1.9.61.3.6.1.4.1.311.3.3.1kernel32IsWow64ProcessSystem\CurrentControlSet\Control\CitrixProductVersionNumSoftware\Adobe\Acrobat\ExeEnableLUASoftware\Microsoft\Windows\CurrentVersion\Policies\System /FixPDF /RegisterFileTypesOwnership /PRODUCT:Reader /VERSION:12.03305580Click on 'Change' to select default PDF handler.pdf Properties#32770Click on 'Change' to select default PDF handler Properties#32770Click on 'Change' to select default PDF handler#32770/\ADelRCP.exeClick on 'Change' to select default PDF handler.pdfpropertiesShowAppPickerForPDF.exeProgram ManagerPROGMANClick on 'Change' to select default PDF handler.pdf Properties#32770Click on 'Change' to select default PDF handler Properties#32770Click on 'Change' to select default PDF handler#32770Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdf\UserChoiceSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdf\UserChoiceSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdfApplication
Source: ActivitiesCache.sqliteBinary or memory string: o unregister plugin: %s, Result: %dFailed to Start plugin: %s, Result: %dPresentation register failed: %dFailed to Start plugin: NAM, Result: %dCMainFrame::refreshloadedModulesUnexpected NULL Module Manager.Unable to stop plugin: %s, Result: %dCMainFrame::relayoutUIAnyConnect UI Disabled.Unable to unregister plugin: NAM, Result %dCMainFrame::loadL2ModuleCMainFrame::unloadOrphanedHiddenModulesCMainFrame::loadHiddenModulesCMainFrame::constructUIFailure occured when attempting to create Statistic Window.CMainFrame::ShutdownThe GUI has been told to shutdown - [%s]CMainFrame::postQuitThe GUI has posted Quit[%s] has reported Plugin_Success to Stop() callUnable to stop plugin: %s[%s] has been told to unregister during shutdown procedure.Unexpected NULL module in the module manager at %uSoftware\Cisco\Cisco Secure Client\ComponentStatus::GetDisplayVersionCMainFrame::GetHiddenModuleInfoShell_TrayWndCMainFrame::SetToastPreferenceRegSetValueExEnableStatusPopupsCMainFrame::unregisterTrayItemsCMainFrame::KillTimerCMainFrame::registerTrayItemsCMainFrame::SetTimerCMainFrame::handleXMLUIRefreshRefresh UI received from plugin : %sCMainFrame::handleXMLApplicationNodesUnknown application node receivedUnexpected Error, invalid popup node valueCMainFrame::handleXMLPopupNotificationUnexpected input XML received for popupRefresh UI complete.
Source: C:\Windows\System32\OpenWith.exeQueries volume information: C:\Program Files\WindowsApps\Microsoft.WindowsStore_11712.1001.23.0_x64__8wekyb3d8bbwe\Assets\AppTiles\StoreAppList.scale-200.png VolumeInformationJump to behavior
Source: C:\Windows\System32\OpenWith.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
Source: C:\Windows\System32\OpenWith.exeQueries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformationJump to behavior
Source: C:\Windows\System32\OpenWith.exeQueries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformationJump to behavior
Source: C:\Windows\System32\OpenWith.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformationJump to behavior
Source: C:\Windows\System32\OpenWith.exeQueries volume information: C:\Windows\Fonts\seguisym.ttf VolumeInformationJump to behavior
Source: C:\Windows\System32\OpenWith.exeQueries volume information: C:\Windows\Fonts\segmdl2.ttf VolumeInformationJump to behavior
Source: C:\Windows\System32\OpenWith.exeQueries volume information: C:\Windows\Fonts\segmdl2.ttf VolumeInformationJump to behavior
Source: ActivitiesCache.sqliteBinary or memory string: ?IsOs_WIN_8@@YA_NXZj??1CAppLog@@QAE@XZ
Source: ActivitiesCache.sqliteBinary or memory string: ?IsOs_WIN_8@@YA_NXZ
Source: ActivitiesCache.sqliteBinary or memory string: ?IsOs_WIN_7@@YA_NXZ
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential Dumping1
Process Discovery
Remote ServicesData from Local SystemExfiltration Over Other Network MediumData ObfuscationEavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory1
File and Directory Discovery
Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothJunk DataExploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account Manager11
System Information Discovery
SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Vessel0%Avira URL Cloudsafe
https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Vessel%20Pro%20For0%Avira URL Cloudsafe
https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/CWiles0%Avira URL Cloudsafe
https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Tutorials/Monthly0%Avira URL Cloudsafe
https://www.immunet.comOpen0%Avira URL Cloudsafe
https://logistec.sharepoint.com/sites/lgtops/CargoHandlingMonthlyPerformanceReport/1655%20Balterm/160%Avira URL Cloudsafe
https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Tutorials/Metsa0%Avira URL Cloudsafe
https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/cwiles_report_unas0%Avira URL Cloudsafe
https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/CWiles%20Items/pri0%Avira URL Cloudsafe
https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Tutorials/Network%0%Avira URL Cloudsafe
https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/CWiles%20Items/rea0%Avira URL Cloudsafe
https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/AES0%Avira URL Cloudsafe
https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Silos.docx0%Avira URL Cloudsafe
https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Tutorials/Monthly%0%Avira URL Cloudsafe
https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Tutorials/Providen0%Avira URL Cloudsafe
https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/CWiles%20Items/Org0%Avira URL Cloudsafe
https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Prinsengracht%20An0%Avira URL Cloudsafe
https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Tutorials/Network0%Avira URL Cloudsafe
https://logistec.sharepoint.com/sites/FSSARTeam/Shared0%Avira URL Cloudsafe
https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/BalTerm0%Avira URL Cloudsafe
https://logistec.sharepoint.com/sites/lgtops/CargoHandlingMonthlyPerformanceReport/2022ByCompany.xls0%Avira URL Cloudsafe
https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Silos.docx?web=10%Avira URL Cloudsafe
https://crbug.com/820996LaunchElevatedProcessataProtectionIdEnterpriseDataPrADMDialogCopyPasteFixADM0%Avira URL Cloudsafe
https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/CWiles%20Items/C%20%Avira URL Cloudsafe
https://logistec.sharepoint.com/sites/lgtops/CargoHandlingMonthlyPerformanceReport/16550%Avira URL Cloudsafe
https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Tutorials/Metsa%200%Avira URL Cloudsafe
https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/CWiles%20Items/Tea0%Avira URL Cloudsafe
https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Prinsengracht0%Avira URL Cloudsafe
https://crbug.com/8209960%Avira URL Cloudsafe
http://www.cisco.com00%Avira URL Cloudsafe
https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/BalTerm%20Terminal0%Avira URL Cloudsafe
https://logistec.sharepoint.com/sites/lgtops/CargoHandlingMonthlyPerformanceReport/1655%20Balterm/AR0%Avira URL Cloudsafe
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/cwiles_report_unasActivitiesCache.sqlitefalse
  • Avira URL Cloud: safe
unknown
https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/CWiles%20Items/priActivitiesCache.sqlitefalse
  • Avira URL Cloud: safe
unknown
https://www.immunet.comOpenActivitiesCache.sqlitefalse
  • Avira URL Cloud: safe
unknown
https://ims-na1-stg1.adobelogin.com/ims/authorize/v1?https://ims-na1.adobelogin.com/ims/authorize/v1ActivitiesCache.sqlitefalse
    high
    https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Tutorials/MonthlyActivitiesCache.sqlitefalse
    • Avira URL Cloud: safe
    unknown
    https://logistec.sharepoint.com/sites/lgtops/CargoHandlingMonthlyPerformanceReport/1655%20Balterm/16ActivitiesCache.sqlitefalse
    • Avira URL Cloud: safe
    unknown
    https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/CWilesActivitiesCache.sqlitefalse
    • Avira URL Cloud: safe
    unknown
    https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Tutorials/MetsaActivitiesCache.sqlitefalse
    • Avira URL Cloud: safe
    unknown
    https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/VesselActivitiesCache.sqlitefalse
    • Avira URL Cloud: safe
    unknown
    https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Vessel%20Pro%20ForActivitiesCache.sqlitefalse
    • Avira URL Cloud: safe
    unknown
    https://www.cisco.com/c/en/us/about/legal/cloud-and-software/end_user_license_agreement.htmlhttps://ActivitiesCache.sqlitefalse
      high
      https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Tutorials/Network%ActivitiesCache.sqlitefalse
      • Avira URL Cloud: safe
      unknown
      https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Tutorials/ProvidenActivitiesCache.sqlitefalse
      • Avira URL Cloud: safe
      unknown
      https://crbug.com/820996ActivitiesCache.sqlitefalse
      • Avira URL Cloud: safe
      unknown
      https://mail.google.com/ActivitiesCache.sqlitefalse
        high
        https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/CWiles%20Items/reaActivitiesCache.sqlitefalse
        • Avira URL Cloud: safe
        unknown
        https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Prinsengracht%20AnActivitiesCache.sqlitefalse
        • Avira URL Cloud: safe
        unknown
        https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Tutorials/NetworkActivitiesCache.sqlitefalse
        • Avira URL Cloud: safe
        unknown
        https://clients2.google.com/service/update2/crxupdate_urlBrowserActivitiesCache.sqlitefalse
          high
          https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Silos.docxActivitiesCache.sqlitefalse
          • Avira URL Cloud: safe
          unknown
          https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/AESActivitiesCache.sqlitefalse
          • Avira URL Cloud: safe
          unknown
          https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Tutorials/Monthly%ActivitiesCache.sqlitefalse
          • Avira URL Cloud: safe
          unknown
          https://logistec.sharepoint.com/sites/FSSARTeam/SharedActivitiesCache.sqlitefalse
          • Avira URL Cloud: safe
          unknown
          https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/CWiles%20Items/OrgActivitiesCache.sqlitefalse
          • Avira URL Cloud: safe
          unknown
          https://wns2-ch1p.notify.windows.com/?token=AwYAAADSjAb88iRkUDS2eKDRGw%2fxW1oV4DmPkaRPlR7%2bLwVdteGHActivitiesCache.sqlitefalse
            high
            https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Silos.docx?web=1ActivitiesCache.sqlitefalse
            • Avira URL Cloud: safe
            unknown
            https://www.immunet.comActivitiesCache.sqlitefalse
              high
              https://logistec.sharepoint.com/sites/lgtops/CargoHandlingMonthlyPerformanceReport/1655ActivitiesCache.sqlitefalse
              • Avira URL Cloud: safe
              unknown
              http://www.cisco.com0ActivitiesCache.sqlitefalse
              • Avira URL Cloud: safe
              unknown
              https://crbug.com/820996LaunchElevatedProcessataProtectionIdEnterpriseDataPrADMDialogCopyPasteFixADMActivitiesCache.sqlitefalse
              • Avira URL Cloud: safe
              unknown
              https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/BalTermActivitiesCache.sqlitefalse
              • Avira URL Cloud: safe
              unknown
              https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/CWiles%20Items/C%2ActivitiesCache.sqlitefalse
              • Avira URL Cloud: safe
              unknown
              https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/CWiles%20Items/TeaActivitiesCache.sqlitefalse
              • Avira URL Cloud: safe
              unknown
              https://logistec.sharepoint.com/sites/lgtops/CargoHandlingMonthlyPerformanceReport/2022ByCompany.xlsActivitiesCache.sqlitefalse
              • Avira URL Cloud: safe
              unknown
              https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/Tutorials/Metsa%20ActivitiesCache.sqlitefalse
              • Avira URL Cloud: safe
              unknown
              https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/BalTerm%20TerminalActivitiesCache.sqlitefalse
              • Avira URL Cloud: safe
              unknown
              https://logistec-my.sharepoint.com/personal/cwiles_logistec_com/Documents/Desktop/PrinsengrachtActivitiesCache.sqlitefalse
              • Avira URL Cloud: safe
              unknown
              https://logistec.sharepoint.com/sites/lgtops/CargoHandlingMonthlyPerformanceReport/1655%20Balterm/ARActivitiesCache.sqlitefalse
              • Avira URL Cloud: safe
              unknown
              No contacted IP infos
              Joe Sandbox Version:38.0.0 Beryl
              Analysis ID:1304597
              Start date and time:2023-09-06 19:07:26 +02:00
              Joe Sandbox Product:CloudBasic
              Overall analysis duration:0h 4m 47s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:default.jbs
              Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
              Number of analysed new started processes analysed:1
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • HDC enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Sample file name:ActivitiesCache.sqlite
              (renamed file extension from db to sqlite, renamed because original name is a hash value)
              Original Sample Name:ActivitiesCache.db
              Detection:CLEAN
              Classification:clean2.winSQLITE@1/0@0/0
              EGA Information:Failed
              HDC Information:Failed
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 0
              • Number of non-executed functions: 0
              Cookbook Comments:
              • Stop behavior analysis, all processes terminated
              • Report size getting too big, too many NtOpenKeyEx calls found.
              • Report size getting too big, too many NtProtectVirtualMemory calls found.
              • Report size getting too big, too many NtQueryValueKey calls found.
              • VT rate limit hit for: ActivitiesCache.sqlite
              TimeTypeDescription
              19:08:27API Interceptor1x Sleep call for process: OpenWith.exe modified
              No context
              No context
              No context
              No context
              No context
              No created / dropped files found
              File type:SQLite 3.x database, user version 30, last written using SQLite version 3029000, writer version 2, read version 2, file counter 37, database pages 5985, 1st free page 4728, free pages 5302, cookie 0x19, schema 4, UTF-8, version-valid-for 37
              Entropy (8bit):6.7945392712642505
              TrID:
              • SQLite 3.x database (15015/1) 100.00%
              File name:ActivitiesCache.sqlite
              File size:24'514'560 bytes
              MD5:ca79add6e3d289a62ca2079634ce9da1
              SHA1:baa22c1dc503e6854cfa76eb2f192d097c208ce3
              SHA256:424c1c7bcf7cc970878c6ec61315f83bc700a93d2e0af988967967a33df2866d
              SHA512:8b5cb1a9e9b4f36a46ba9fafb50b7bcd19542115fb221a38de1132809b447cebd723714ebc30582eec40f6f8acd9fa4c6a14acc2e50c9ce3bbbd9a9faba54e71
              SSDEEP:393216:2N4+1QlBaQEx8/Rhcw/yo3Kxjj65OSZPYDenuT+d9u+g3H:2SDExKRFGjjSu0u+g3H
              TLSH:1F377C15B3048BB2E1AFD2708546D576D0B2BCAA4F7163D703E0BE2B3A332D16636957
              File Content Preview:SQLite format 3......@ ...%...a...x...........................................................%..8..................U.9...-.n.....'.I........................................../...C...indexsqlite_autoindex_Metadata_1Metadata......##...tableAppSettingsAppS
              Icon Hash:72e2a2a292a2a2b2
              No network behavior found

              Click to jump to process

              Click to jump to process

              Target ID:0
              Start time:19:08:27
              Start date:06/09/2023
              Path:C:\Windows\System32\OpenWith.exe
              Wow64 process (32bit):false
              Commandline:C:\Windows\system32\OpenWith.exe -Embedding
              Imagebase:0x7ff617150000
              File size:111'120 bytes
              MD5 hash:D179D03728E95E040A889F760C1FC402
              Has elevated privileges:false
              Has administrator privileges:false
              Programmed in:C, C++ or other language
              Reputation:high
              Has exited:true

              No disassembly