Summary | ZeroBOX

download.blog

OS Processor Check PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6402 April 29, 2021, 10:18 p.m. April 29, 2021, 10:20 p.m.
Size 2.6MB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 0e65369ce84e7693c3a2bad17fdc1a57
SHA256 5d8eca5ffd91ba9db05c4c81d4433f09d5f2a192ea9ce05e6114fd6a7a52a091
CRC32 F283B10F
ssdeep 49152:RUwVmcGxgeqQkrdv2Racqo1nNoL35YKPK5LZwz2lrCv2+NOElWsvJwj6:RUwVmcGkP9OapkNQGKgN14vlCj6
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
172.217.25.14 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
packer Armadillo v1.71
Time & API Arguments Status Return Repeated

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: 81 7b 4e 54 68 69 73 75 0c 8b 43 3c 03 c3 66 81
exception.symbol: pxplay+0x971022
exception.instruction: cmp dword ptr [ebx + 0x4e], 0x73696854
exception.module: pxplay.exe
exception.exception_code: 0xc0000005
exception.offset: 9900066
exception.address: 0xd71022
registers.esp: 1638276
registers.edi: 0
registers.eax: 1970484152
registers.ebp: 9895936
registers.edx: 14094336
registers.ebx: 1970470656
registers.esi: 0
registers.ecx: 0
1 0 0
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 5580
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x73772000
process_handle: 0xffffffff
1 0 0
file C:\Users\test22\AppData\Local\Temp\mvuFF29.tmp\pxplay.exe
file C:\Users\test22\AppData\Local\Temp\mvuFF29.tmp\ddt.dnt
file C:\Users\test22\AppData\Local\Temp\mvuFF29.tmp\pxplay.exe
host 172.217.25.14
file C:\Users\test22\AppData\Local\Temp\mvuFF29.tmp
file C:\Users\test22\AppData\Local\Temp\mvuFF29.tmp\pxplay.exe
McAfee Artemis!0E65369CE84E
AegisLab Virus.Win32.Virut.n!c
Sangfor Virus.Win32.Virut.A
K7AntiVirus Riskware ( 0040eff71 )
K7GW Riskware ( 0040eff71 )
Kaspersky UDS:Virus.Win32.Virut.a
Alibaba Virus:Win32/Virut.c5f0fcc2
NANO-Antivirus Trojan.Win32.DownLoad2.epaaqp
Avast FileRepMalware
Rising Virus.Virut!8.44 (CLOUD)
McAfee-GW-Edition Artemis
Sophos Mal/Generic-S
Microsoft Program:Win32/Wacapew.C!ml
GData Win32.Worm.Bobax.7F6CRN
VBA32 Virus.Win32.Virut.A
Ikarus Worm.Win32.Bobax
Fortinet W32/PossibleThreat
AVG FileRepMalware