Summary | ZeroBOX

G402.dll

UPX PE64 PE File DLL
Category Machine Started Completed
FILE s1_win7_x6401 July 19, 2021, 5:23 p.m. July 19, 2021, 5:25 p.m.
Size 3.2MB
Type PE32+ executable (DLL) (GUI) x86-64, for MS Windows
MD5 d37da4af6a94771d51d995d8683afed4
SHA256 978459919e8c7879f76889a4237703e4a7e58f5aaa02b4e1135dd940e8879c70
CRC32 4D418852
ssdeep 49152:vUS1miF0kU3F9A8dg1Qjtz2IAoDJUYxAVdNdfPBGYEXZpug+hnmWnuPB9bdJjmEV:zRF0b3xAxdB9EuVmguXRT
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE64 - (no description)
  • IsDLL - (no description)
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
123.57.142.8 Active Moloch
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0
section text
section data
section .inidata
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 1204
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00000000735bc000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 204
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00000000735bc000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2100
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00000000735bc000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1016
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00000000735bc000
process_handle: 0xffffffffffffffff
1 0 0
name RT_CURSOR language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021dbec size 0x00000134
name RT_CURSOR language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021dbec size 0x00000134
name RT_CURSOR language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021dbec size 0x00000134
name RT_CURSOR language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021dbec size 0x00000134
name RT_CURSOR language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021dbec size 0x00000134
name RT_CURSOR language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021dbec size 0x00000134
name RT_CURSOR language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021dbec size 0x00000134
name RT_CURSOR language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021dbec size 0x00000134
name RT_CURSOR language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021dbec size 0x00000134
name RT_CURSOR language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021dbec size 0x00000134
name RT_CURSOR language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021dbec size 0x00000134
name RT_CURSOR language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021dbec size 0x00000134
name RT_CURSOR language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021dbec size 0x00000134
name RT_CURSOR language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021dbec size 0x00000134
name RT_CURSOR language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021dbec size 0x00000134
name RT_CURSOR language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021dbec size 0x00000134
name RT_BITMAP language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021ddd8 size 0x00000144
name RT_BITMAP language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021ddd8 size 0x00000144
name RT_DIALOG language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021e000 size 0x00000034
name RT_DIALOG language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021e000 size 0x00000034
name RT_STRING language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021e920 size 0x000001a6
name RT_STRING language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021e920 size 0x000001a6
name RT_STRING language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021e920 size 0x000001a6
name RT_STRING language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021e920 size 0x000001a6
name RT_STRING language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021e920 size 0x000001a6
name RT_STRING language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021e920 size 0x000001a6
name RT_STRING language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021e920 size 0x000001a6
name RT_STRING language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021e920 size 0x000001a6
name RT_STRING language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021e920 size 0x000001a6
name RT_STRING language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021e920 size 0x000001a6
name RT_STRING language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021e920 size 0x000001a6
name RT_STRING language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021e920 size 0x000001a6
name RT_STRING language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021e920 size 0x000001a6
name RT_GROUP_CURSOR language LANG_CHINESE filetype Lotus unknown worksheet or configuration, revision 0x1 sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021ebf0 size 0x00000014
name RT_GROUP_CURSOR language LANG_CHINESE filetype Lotus unknown worksheet or configuration, revision 0x1 sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021ebf0 size 0x00000014
name RT_GROUP_CURSOR language LANG_CHINESE filetype Lotus unknown worksheet or configuration, revision 0x1 sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021ebf0 size 0x00000014
name RT_GROUP_CURSOR language LANG_CHINESE filetype Lotus unknown worksheet or configuration, revision 0x1 sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021ebf0 size 0x00000014
name RT_GROUP_CURSOR language LANG_CHINESE filetype Lotus unknown worksheet or configuration, revision 0x1 sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021ebf0 size 0x00000014
name RT_GROUP_CURSOR language LANG_CHINESE filetype Lotus unknown worksheet or configuration, revision 0x1 sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021ebf0 size 0x00000014
name RT_GROUP_CURSOR language LANG_CHINESE filetype Lotus unknown worksheet or configuration, revision 0x1 sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021ebf0 size 0x00000014
name RT_GROUP_CURSOR language LANG_CHINESE filetype Lotus unknown worksheet or configuration, revision 0x1 sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021ebf0 size 0x00000014
name RT_GROUP_CURSOR language LANG_CHINESE filetype Lotus unknown worksheet or configuration, revision 0x1 sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021ebf0 size 0x00000014
name RT_GROUP_CURSOR language LANG_CHINESE filetype Lotus unknown worksheet or configuration, revision 0x1 sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021ebf0 size 0x00000014
name RT_GROUP_CURSOR language LANG_CHINESE filetype Lotus unknown worksheet or configuration, revision 0x1 sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021ebf0 size 0x00000014
name RT_GROUP_CURSOR language LANG_CHINESE filetype Lotus unknown worksheet or configuration, revision 0x1 sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021ebf0 size 0x00000014
name RT_GROUP_CURSOR language LANG_CHINESE filetype Lotus unknown worksheet or configuration, revision 0x1 sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021ebf0 size 0x00000014
name RT_GROUP_CURSOR language LANG_CHINESE filetype Lotus unknown worksheet or configuration, revision 0x1 sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021ebf0 size 0x00000014
name RT_GROUP_CURSOR language LANG_CHINESE filetype Lotus unknown worksheet or configuration, revision 0x1 sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021ebf0 size 0x00000014
name RT_VERSION language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021ec04 size 0x000002e4
name RT_HTML language LANG_CHINESE filetype PE32+ executable (native) x86-64, for MS Windows sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0021eee8 size 0x00097fc0
section {u'size_of_data': u'0x0009b200', u'virtual_address': u'0x0021c000', u'entropy': 7.949038353567183, u'name': u'.rsrc', u'virtual_size': u'0x0009b108'} entropy 7.94903835357 description A section with a high entropy has been found
section {u'size_of_data': u'0x00080800', u'virtual_address': u'0x002b8000', u'entropy': 7.823758239666046, u'name': u'.reloc', u'virtual_size': u'0x0019e000'} entropy 7.82375823967 description A section with a high entropy has been found
entropy 0.35151045701 description Overall entropy of this PE file is high
host 123.57.142.8
Time & API Arguments Status Return Repeated

CreateServiceW

service_start_name:
start_type: 3
password:
display_name: Display_DD94687
filepath: C:\DD94687.sys
service_name: DD94687
filepath_r: C:\DD94687.sys
desired_access: 983551
service_handle: 0x0000000000000000
error_control: 1
service_type: 1
service_manager_handle: 0x00000000002240f0
0 0

CreateServiceW

service_start_name:
start_type: 3
password:
display_name: Display_DD94687
filepath: C:\DD94687.sys
service_name: DD94687
filepath_r: C:\DD94687.sys
desired_access: 983551
service_handle: 0x0000000000000000
error_control: 1
service_type: 1
service_manager_handle: 0x00000000003d40c0
0 0

CreateServiceW

service_start_name:
start_type: 3
password:
display_name: Display_DD94687
filepath: C:\DD94687.sys
service_name: DD94687
filepath_r: C:\DD94687.sys
desired_access: 983551
service_handle: 0x0000000000000000
error_control: 1
service_type: 1
service_manager_handle: 0x00000000003340c0
0 0

CreateServiceW

service_start_name:
start_type: 3
password:
display_name: Display_DD94687
filepath: C:\DD94687.sys
service_name: DD94687
filepath_r: C:\DD94687.sys
desired_access: 983551
service_handle: 0x0000000000000000
error_control: 1
service_type: 1
service_manager_handle: 0x00000000003540c0
0 0

CreateServiceW

service_start_name:
start_type: 3
password:
display_name: Display_DD94687
filepath: C:\DD94687.sys
service_name: DD94687
filepath_r: C:\DD94687.sys
desired_access: 983551
service_handle: 0x00000000003240f0
error_control: 1
service_type: 1
service_manager_handle: 0x00000000003240c0
1 3293424 0

CreateServiceW

service_start_name:
start_type: 3
password:
display_name: Display_DD94687
filepath: C:\DD94687.sys
service_name: DD94687
filepath_r: C:\DD94687.sys
desired_access: 983551
service_handle: 0x0000000000000000
error_control: 1
service_type: 1
service_manager_handle: 0x00000000000c40c0
0 0

CreateServiceW

service_start_name:
start_type: 3
password:
display_name: Display_DD94687
filepath: C:\DD94687.sys
service_name: DD94687
filepath_r: C:\DD94687.sys
desired_access: 983551
service_handle: 0x0000000000000000
error_control: 1
service_type: 1
service_manager_handle: 0x00000000001d40c0
0 0

CreateServiceW

service_start_name:
start_type: 3
password:
display_name: Display_DD94687
filepath: C:\DD94687.sys
service_name: DD94687
filepath_r: C:\DD94687.sys
desired_access: 983551
service_handle: 0x0000000000000000
error_control: 1
service_type: 1
service_manager_handle: 0x00000000004040c0
0 0