Summary | ZeroBOX
Malicious Library PE32 PE File
Category Machine Started Completed
ARCHIVE s1_win7_x6401 June 29, 2021, 8:04 p.m. June 29, 2021, 8:07 p.m.

Archive waads.bin @ waads.bin.zip

Summary

Size 14.0KB
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 72e4f355907b6c91e6f8508d102bd896
SHA1 ae68bd08cd621b8049d0418bea514d6ddbfb0acf
SHA256 232a5fe454c9537ddea265d805d1daa8e016b1ed30cd2ebde7feb12f866f5608
SHA512
fe0356f479eac1f6125a909f5b331430bf73f36d8a33170d372dd2c0cd568cf7841316a17986803c900ea1b1ff4afbf6f8264b1c28a7373a4b7c85aae9b7ecd4
CRC32 BD395B30
ssdeep 192:AlH+DgGK83SxHn2OQ/dmBI4KBfTgir+xzARbqUqV/Qjo7AGa:A9+kGKqbOCdWIVBff+xz6fCXAn
Yara
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
  • Malicious_Library_Zero - Malicious_Library

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch
45.227.253.66 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GetComputerNameA

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 2444
region_size: 4194304
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x035d0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2444
region_size: 253952
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x03210000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0xffffffff
1 0 0
description waads.bin tried to sleep 171 seconds, actually delayed analysis time by 171 seconds
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2444
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 4096
protection: 32 (PAGE_EXECUTE_READ)
base_address: 0x00480000
process_handle: 0xffffffff
1 0 0
host 45.227.253.66
process waads.bin useragent
process waads.bin useragent Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0; yie9)