Summary | ZeroBOX

file.exe

OS Processor Check PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6402 July 3, 2021, 9:18 a.m. July 3, 2021, 9:20 a.m.
Size 767.0KB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 5a3bc03f57ab36fb016ab8c6c8d248f2
SHA256 756ccf827ebe06d96fe8f88a43693332b0fc618ac747304b5b372b74f208abae
CRC32 C4A1FF99
ssdeep 12288:gzQadEV6h4thKzwogAT0KBBiwpbYdYMPXKRBhy4ZQxLM:gGjtRoUKlAYMfKRztQxL
PDB Path C:\zemitisora\ruhuzoya-tekozeyu\rawoduson_m.pdb
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)

Name Response Post-Analysis Lookup
d2js2viceajwla.cloudfront.net
AAAA 2600:9000:2139:7a00:11:6feb:6f80:93a1
AAAA 2600:9000:2139:0:11:6feb:6f80:93a1
AAAA 2600:9000:2139:5c00:11:6feb:6f80:93a1
AAAA 2600:9000:2139:3000:11:6feb:6f80:93a1
AAAA 2600:9000:2139:bc00:11:6feb:6f80:93a1
AAAA 2600:9000:2139:4c00:11:6feb:6f80:93a1
AAAA 2600:9000:2139:6c00:11:6feb:6f80:93a1
AAAA 2600:9000:2139:4000:11:6feb:6f80:93a1
99.86.202.125
aus.thunderbird.net 99.86.202.125
prod.balrog.prod.cloudops.mozgcp.net 35.244.181.201
d2js2viceajwla.cloudfront.net 99.86.202.125
aus5.mozilla.org 35.244.181.201
prod.balrog.prod.cloudops.mozgcp.net 35.244.181.201
IP Address Status Action
164.124.101.2 Active Moloch
35.244.181.201 Active Moloch
99.86.144.100 Active Moloch
99.86.144.46 Active Moloch
99.86.144.61 Active Moloch
99.86.144.82 Active Moloch
99.86.202.125 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

Flow Issuer Subject Fingerprint
TLS 1.2
192.168.56.102:49322
35.244.181.201:443
C=US, O=DigiCert Inc, CN=DigiCert SHA2 Secure Server CA C=US, ST=California, L=Mountain View, O=Mozilla Corporation, CN=aus5.mozilla.org 37:1a:8a:6e:ae:e7:b7:ae:1f:a9:c0:87:53:e5:a0:94:ef:0b:de:0c
TLS 1.2
192.168.56.102:49321
99.86.202.125:443
C=US, O=Let's Encrypt, CN=R3 CN=thunderbird.net dd:92:a0:f3:c5:f2:3a:c7:42:66:30:75:8a:b3:b3:03:6b:8c:df:9d

pdb_path C:\zemitisora\ruhuzoya-tekozeyu\rawoduson_m.pdb
resource name DAXEGAJOBAREHOKEZOPUKE
resource name NEVOM
resource name None
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 8292
region_size: 507904
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04510000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 8292
region_size: 921600
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x045a0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0
name DAXEGAJOBAREHOKEZOPUKE language LANG_SERBIAN filetype ASCII text, with very long lines, with no line terminators sublanguage SUBLANG_DEFAULT offset 0x040407e8 size 0x00000685
name NEVOM language LANG_SERBIAN filetype ASCII text, with very long lines, with no line terminators sublanguage SUBLANG_DEFAULT offset 0x04040e70 size 0x00000acd
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_DEFAULT offset 0x04040308 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_DEFAULT offset 0x04040308 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_DEFAULT offset 0x04040308 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_DEFAULT offset 0x04040308 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_DEFAULT offset 0x04040308 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_DEFAULT offset 0x04040308 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_DEFAULT offset 0x04040308 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_DEFAULT offset 0x04040308 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_DEFAULT offset 0x04040308 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_DEFAULT offset 0x04040308 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_DEFAULT offset 0x04040308 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_DEFAULT offset 0x04040308 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_DEFAULT offset 0x04040308 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_DEFAULT offset 0x04040308 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_DEFAULT offset 0x04040308 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_DEFAULT offset 0x04040308 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_DEFAULT offset 0x04040308 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_DEFAULT offset 0x04040308 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_DEFAULT offset 0x04040308 size 0x00000468
name RT_STRING language LANG_SERBIAN filetype data sublanguage SUBLANG_DEFAULT offset 0x04044408 size 0x00000292
name RT_STRING language LANG_SERBIAN filetype data sublanguage SUBLANG_DEFAULT offset 0x04044408 size 0x00000292
name RT_ACCELERATOR language LANG_SERBIAN filetype data sublanguage SUBLANG_DEFAULT offset 0x04041940 size 0x00000008
name RT_GROUP_ICON language LANG_SERBIAN filetype data sublanguage SUBLANG_DEFAULT offset 0x04040770 size 0x00000076
name RT_GROUP_ICON language LANG_SERBIAN filetype data sublanguage SUBLANG_DEFAULT offset 0x04040770 size 0x00000076
name RT_GROUP_ICON language LANG_SERBIAN filetype data sublanguage SUBLANG_DEFAULT offset 0x04040770 size 0x00000076
section {u'size_of_data': u'0x0008f600', u'virtual_address': u'0x00001000', u'entropy': 7.94665179681334, u'name': u'.text', u'virtual_size': u'0x0008f40c'} entropy 7.94665179681 description A section with a high entropy has been found
entropy 0.748694516971 description Overall entropy of this PE file is high
host 99.86.144.100
host 99.86.144.46
host 99.86.144.61
host 99.86.144.82