Created 2 years ago
Blacksmith Installer(1).exe
Remarks (2/2)
(0x0200001B): The maximum number of file Reputation Analysis requests per analysis (150) was exceeded.
(0x0200000E): The overall sleep time of all monitored processes was truncated from "2 hours, 45 minutes, 42 seconds" to "5 minutes, 40 seconds" to reveal dormant functionality.
VMRay Threat Identifiers (20 rules, 232 matches)
| Score | Category | Operation | Count | Classification | |
|---|---|---|---|---|---|
4/5 | Defense Evasion | Loads a dropped DLL into a system binary | 24 | - | |
3/5 | Anti Analysis | Tries to evade debugger | 1 | - | |
2/5 | Privilege Escalation | Enables critical process privilege | 1 | - | |
2/5 | Anti Analysis | Delays execution | 1 | - | |
2/5 | Hide Tracks | Deletes file after execution | 3 | - | |
2/5 | Anti Analysis | Tries to detect debugger | 1 | - | |
2/5 | Anti Analysis | Tries to detect kernel debugger | 1 | - | |
2/5 | Anti Analysis | Tries to detect virtual machine | 1 | - | |
2/5 | Anti Analysis | Makes direct system call to possibly evade hooking based sandboxes | 10 | - | |
1/5 | Defense Evasion | Accesses volumes directly | 1 | - | |
Screenshots
MITRE ATT&CK™ Matrix - Windows
Sample Information
| ID | #8562853 |
| MD5 | |
| SHA1 | |
| SHA256 | |
| SSDeep | |
| ImpHash | |
| File Name | Blacksmith Installer(1).exe |
| File Size | 87330.07 KB |
| Sample Type | Windows Exe (x86-32) |
| Verification Status | Valid |
| Certificate Issuer | DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 |
| Certificate Subject | IRONMACE Co., Ltd. |
Analysis Information
| Creation Time | 2023-08-08 12:08 (UTC+9) |
| Analysis Duration | 00:04:00 |
| Termination Reason | Timeout |
| Number of Monitored Processes | 9 |
| Execution Successful | |
| Reputation Enabled | |
| Built-in AV Enabled | |
| Number of AV Matches | 0 |
| YARA Enabled | |
| Number of YARA Matches | 0 |