Summary | ZeroBOX

sd3672.exe

Category Machine Started Completed
FILE s1_win7_x6401 April 8, 2021, 9:15 a.m. April 8, 2021, 9:37 a.m.
Size 897.4KB
Type PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5 3478322eeb8ae0134a8bbea54b6e1c7c
SHA256 499152e32014e83e6b81900a2399008aef7babacfbb26da4cb283fb1ee6e26bd
CRC32 BA3350F1
ssdeep 24576:Q4jC/o89OW0vwfhFv1u4AvBiLiSEwYTBxolZlYy8UXIRVc/t:LjCo8UW0ofhFv1u4ZLiSEwWxqQyNXIR8
Yara
  • escalate_priv - Escalade priviledges
  • screenshot - Take screenshot
  • win_registry - Affect system registries
  • win_token - Affect system token
  • win_private_profile - Affect private profile
  • win_files_operation - Affect private profile
  • PE_Header_Zero - PE File Signature Zero
  • IsPE32 - (no description)
  • IsWindowsGUI - (no description)
  • IsPacked - Entropy Check
  • HasOverlay - Overlay Check
  • HasDigitalSignature - DigitalSignature Check
  • HasRichSignature - Rich Signature Check

IP Address Status Action
121.201.30.167 Active Moloch
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
file C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section .ndata
request GET http://a.clickdata.37wan.com/controller/istat.controller.php?item=8133tay6p9&platform=37wan&game_id=237&ext_1=2&ext_2=37wancom&ext_3=sd3672&ext_4=C2E2596C4C464D049761EA216CC6557D&ext_5=bc117b1625961482d7217427f2af8340&ext_6=2&browser_type=3003
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 1868
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x10004000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2552
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x724f2000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2672
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72492000
process_handle: 0xffffffff
1 0 0
Time & API Arguments Status Return Repeated

GetDiskFreeSpaceExW

total_number_of_free_bytes: 0
free_bytes_available: 13724016640
root_path: C:\Users\test22\AppData\Local\Microsoft\Windows\Explorer
total_number_of_bytes: 0
1 1 0

GetDiskFreeSpaceExW

total_number_of_free_bytes: 13727387648
free_bytes_available: 13727387648
root_path: C:\
total_number_of_bytes: 34252779520
1 1 0
name RT_VERSION language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x00039358 size 0x00000210
file C:\Users\test22\Desktop\ÍøÒ³ÓÎÏ·.lnk
file C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ÍøÂçÓÎÏ·ÖÐÐÄ\ÍøÒ³ÓÎÏ·\ÍøÒ³ÓÎÏ·.lnk
file C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\ÍøÒ³ÓÎÏ·.lnk
file C:\Users\test22\AppData\Roaming\ÓÎÏ·\sd3672\sd3672.exe
file C:\Users\test22\AppData\Roaming\ÓÎÏ·\sd3672\uninst.exe
file C:\Users\test22\AppData\Local\Temp\nsf6155.tmp\System.dll
file C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ÍøÂçÓÎÏ·ÖÐÐÄ\ÍøÒ³ÓÎÏ·\жÔØÍøÒ³ÓÎÏ·.lnk
file C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ÍøÂçÓÎÏ·ÖÐÐÄ\ÍøÒ³ÓÎÏ·\ÍøÒ³ÓÎÏ·.lnk
file C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\ÍøÒ³ÓÎÏ·.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ÍøÂçÓÎÏ·ÖÐÐÄ\ÍøÒ³ÓÎÏ·\жÔØÍøÒ³ÓÎÏ·.lnk
file C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Chrome.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\한컴 사전.lnk
file C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ÍøÂçÓÎÏ·ÖÐÐÄ\ÍøÒ³ÓÎÏ·\жÔØÍøÒ³ÓÎÏ·.lnk
file C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
file C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\한컴오피스 한글 2010.lnk
file C:\Users\test22\Desktop\ÍøÒ³ÓÎÏ·.lnk
file C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ÍøÂçÓÎÏ·ÖÐÐÄ\ÍøÒ³ÓÎÏ·\ÍøÒ³ÓÎÏ·.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Chrome.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk
file C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EditPlus.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk
file C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\ÍøÒ³ÓÎÏ·.lnk
file C:\Users\test22\AppData\Roaming\ÓÎÏ·\sd3672\sd3672.exe
file C:\Users\test22\AppData\Local\Temp\nsf6155.tmp\System.dll
file C:\Users\test22\AppData\Roaming\ÓÎÏ·\sd3672\uninst.exe
Time & API Arguments Status Return Repeated

Process32NextW

snapshot_handle: 0x000000d4
process_name: sd3672.exe
process_identifier: 2672
0 0

Process32NextW

snapshot_handle: 0x000000d4
process_name: sd3672.exe
process_identifier: 2672
0 0

Process32NextW

snapshot_handle: 0x000000d4
process_name: sd3672.exe
process_identifier: 2672
0 0

Process32NextW

snapshot_handle: 0x000000d4
process_name: sd3672.exe
process_identifier: 2672
0 0

Process32NextW

snapshot_handle: 0x000000d4
process_name: sd3672.exe
process_identifier: 2672
0 0

Process32NextW

snapshot_handle: 0x000000d4
process_name: sd3672.exe
process_identifier: 2672
0 0

Process32NextW

snapshot_handle: 0x000000d4
process_name: sd3672.exe
process_identifier: 2672
0 0

Process32NextW

snapshot_handle: 0x000000d4
process_name: sd3672.exe
process_identifier: 2672
0 0

Process32NextW

snapshot_handle: 0x000000d4
process_name: sd3672.exe
process_identifier: 2672
0 0

Process32NextW

snapshot_handle: 0x000000d4
process_name: sd3672.exe
process_identifier: 2672
0 0
Time & API Arguments Status Return Repeated

RegOpenKeyExW

regkey_r: \SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\网升游戏更新客户端
base_handle: 0x80000002
key_handle: 0x00000000
options: 0
access: 0x00000001
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\网升游戏更新客户端
161 0
cmdline C:\Users\test22\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\ÍøÒ³ÓÎÏ·.lnk SW_SHOWNORMAL
Bkav W32.HfsAdware.AFDF
CAT-QuickHeal Application.Agent.ZZ5
VIPRE Adware.Win32.Wews87
K7GW Unwanted-Program ( 0050eb4a1 )
K7AntiVirus Unwanted-Program ( 0050eb4a1 )
NANO-Antivirus Riskware.Win32.FileFinder.eyvluu
Symantec ML.Attribute.HighConfidence
Kaspersky not-a-virus:AdWare.Win32.FileFinder.gen
AegisLab Troj.Downloader.Nsis!c
Sophos Generic PUA EG (PUA)
Comodo Application.Win32.Wews87.B
Zillya Dropper.AgentCRTD.Win32.7861
Cyren W32/GenPua.3478322E!Olympus
Jiangmin AdWare.Wews87.g
Fortinet Adware/Wews87
Antiy-AVL GrayWare[AdWare]/Win32.Wews87
Endgame malicious (moderate confidence)
ZoneAlarm not-a-virus:AdWare.Win32.FileFinder.gen
Microsoft PUA:Win32/Youxun
AVware Adware.Win32.Wews87
VBA32 AdWare.Wews87
ESET-NOD32 a variant of Win32/Wews87.A potentially unwanted
Yandex PUA.Wews87!
Ikarus PUA.Wews87