Suspicious 86% windows Download

laurentiu021.SysManager

Unsigned, obfuscated, AMSI evasion

Managed AMSI bypass via vectored hardware breakpointManaged AMSI evasion through a vectored breakpoint handler

Evidence

English function-word token "this" 0x0–0xb0
0x04d5a90000300000004000000ffff0000MZ..............
0x10b8000000000000004000000000000000........@.......
0x2000000000000000000000000000000000................
0x3000000000000000000000000018010000................
0x400e1fba0e00b409cd21b8014ccd215468........!..L.!Th
0x5069732070726f6772616d2063616e6e6fis program canno
⋯6 more rows
.NET native function-pointer delegate conversion 0x73a428–0x73a5a8
⋯7 more rows
0x73a498696e746572496e7465726e616c000000interInternal...
0x73a4a8416c6c6f63436f5461736b4d656d0000AllocCoTaskMem..
0x73a4b847657446756e6374696f6e506f696e74GetFunctionPoint
0x73a4c86572466f7244656c6567617465000000erForDelegate...
0x73a4d847657444656c6567617465466f724675GetDelegateForFu
0x73a4e86e6374696f6e506f696e746572000000nctionPointer...
0x73a4f8507472546f5374727563747572650000PtrToStructure..
⋯11 more rows
References Windows AMSI library 0x74d088–0x74d208
⋯7 more rows
0x74d0f8476574496e7374616e63650000000000GetInstance.....
0x74d10861006d00730069002e0064006c006c00a.m.s.i...d.l.l.
0x74d1180000000000000000416d7369496e6974........AmsiInit
0x74d12869616c697a65000063006f0072006500ialize..c.o.r.e.
0x74d13863006c0072000000416d73695363616ec.l.r...AmsiScan
0x74d14842756666657200004100720067005f00Buffer..A.r.g._.
0x74d1584f006c00650041007500740044006100O.l.e.A.u.t.D.a.
⋯11 more rows
AddVectoredExceptionHandler API name reference 0x7f3288–0x7f34d8
⋯10 more rows
0x7f3328536574556e68616e646c656445786365SetUnhandledExce
0x7f33387074696f6e46696c7465720014004164ptionFilter...Ad
0x7f334864566563746f72656445786365707469dVectoredExcepti
0x7f33586f6e48616e646c6572002a0347657454onHandler.*.GetT
0x7f33686872656164436f6e7465787400009d05hreadContext....
0x7f3378536574546872656164436f6e74657874SetThreadContext
0x7f338800005e02476574456e61626c65645853..^.GetEnabledXS
⋯10 more rows
0x7f34386f0086014578697450726f6365737300o...ExitProcess.
0x7f34484b044f75747075744465627567537472K.OutputDebugStr
0x7f3458696e675700000f0552746c496e737461ingW....RtlInsta
0x7f34686c6c46756e6374696f6e5461626c6543llFunctionTableC
⋯7 more rows
PE overlay has high entropy 0x409bb97–0x409bc67
0x409bb977574653132005468726573686f6c6432ute12.Threshold2
0x409bba732004174747269627574653232004b652.Attribute22.Ke
0x409bbb7726e656c333200557365723332004366rnel32.User32.Cf
0x409bbc7674d6772333200546f55496e74333200gMgr32.ToUInt32.
0x409bbd752656164496e74333200577269746549ReadInt32.WriteI
0x409bbe76e74333200546f496e74333200434d44nt32.ToInt32.CMD
0x409bbf75f545950455f414d445f524332004765_TYPE_AMD_RC2.Ge
0x409bc0774536d61727444617461414d445f5243tSmartDataAMD_RC
0x409bc173200476574536d6172745468726573682.GetSmartThresh
0x409bc276f6c64414d445f5243320048616e646coldAMD_RC2.Handl
0x409bc37655f43320048616e646c655f46320050e_C2.Handle_F2.P
0x409bc47525032003c3e395f5f32325f32003c48RP2.<>9__22_2.<H
0x409bc57616e646c65556e706172746974696f6eandleUnpartition
0x409bc6765644472 edDr

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.