Summary | ZeroBOX

raccon.exe

Malicious Library UPX OS Processor Check PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6401 Aug. 14, 2021, 9:36 a.m. Aug. 14, 2021, 9:45 a.m.
Size 462.0KB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 ed20a01ec2d93943bd0664fafb76daa6
SHA256 5bc02ebc009910c9625991d64f2170d0c1ddd2b403d34674e3b48e8fd0f22242
CRC32 8733EB36
ssdeep 12288:+kRfdSeBVKuvlfIGLUzA9iP+ngOu4sl4OxCDi:PfnKu9fIGYzA4PyXOAi
PDB Path C:\rozabol.pdb
Yara
  • OS_Processor_Check_Zero - OS Processor Check
  • UPX_Zero - UPX packed file
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
104.21.19.200 Active Moloch
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

pdb_path C:\rozabol.pdb
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 1108
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 327680
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ddd000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1108
region_size: 593920
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02d10000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_ICON language LANG_SERBIAN filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe200 size 0x00000468
name RT_STRING language LANG_SERBIAN filetype data sublanguage SUBLANG_ARABIC_ALGERIA offset 0x029008a0 size 0x00000198
name RT_STRING language LANG_SERBIAN filetype data sublanguage SUBLANG_ARABIC_ALGERIA offset 0x029008a0 size 0x00000198
name RT_STRING language LANG_SERBIAN filetype data sublanguage SUBLANG_ARABIC_ALGERIA offset 0x029008a0 size 0x00000198
name RT_STRING language LANG_SERBIAN filetype data sublanguage SUBLANG_ARABIC_ALGERIA offset 0x029008a0 size 0x00000198
name RT_STRING language LANG_SERBIAN filetype data sublanguage SUBLANG_ARABIC_ALGERIA offset 0x029008a0 size 0x00000198
name RT_STRING language LANG_SERBIAN filetype data sublanguage SUBLANG_ARABIC_ALGERIA offset 0x029008a0 size 0x00000198
name RT_ACCELERATOR language LANG_SERBIAN filetype data sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe708 size 0x00000028
name RT_ACCELERATOR language LANG_SERBIAN filetype data sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe708 size 0x00000028
name RT_ACCELERATOR language LANG_SERBIAN filetype data sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe708 size 0x00000028
name RT_ACCELERATOR language LANG_SERBIAN filetype data sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe708 size 0x00000028
name RT_GROUP_ICON language LANG_SERBIAN filetype data sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe668 size 0x00000068
name RT_GROUP_ICON language LANG_SERBIAN filetype data sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe668 size 0x00000068
name RT_GROUP_ICON language LANG_SERBIAN filetype data sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe668 size 0x00000068
name RT_GROUP_ICON language LANG_SERBIAN filetype data sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe668 size 0x00000068
name RT_GROUP_ICON language LANG_SERBIAN filetype data sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe668 size 0x00000068
name RT_GROUP_ICON language LANG_SERBIAN filetype data sublanguage SUBLANG_ARABIC_ALGERIA offset 0x028fe668 size 0x00000068
section {u'size_of_data': u'0x00059e00', u'virtual_address': u'0x00001000', u'entropy': 7.962424723915022, u'name': u'.text', u'virtual_size': u'0x00059c70'} entropy 7.96242472392 description A section with a high entropy has been found
entropy 0.779826464208 description Overall entropy of this PE file is high
host 104.21.19.200
Elastic malicious (high confidence)
FireEye Generic.mg.ed20a01ec2d93943
McAfee Artemis!ED20A01EC2D9
Cylance Unsafe
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0056f9be1 )
K7GW Trojan ( 0056f9be1 )
Cyren W32/Kryptik.EWJ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Kryptik.HMBY
APEX Malicious
Kaspersky UDS:Trojan.Win32.Zenpak.gen
Avast FileRepMalware
Rising Trojan.Kryptik!1.B40D (CLASSIC)
Sophos ML/PE-A
TrendMicro Mal_HPGen-50
McAfee-GW-Edition BehavesLike.Win32.Generic.gc
Ikarus Trojan-Downloader.Win32.Zurgop
Microsoft Trojan:Win32/Sabsik.TE.B!ml
Cynet Malicious (score: 100)
Acronis suspicious
BitDefenderTheta Gen:NN.ZexaF.34058.Cq0@aWGz5WcG
VBA32 BScope.Trojan.Azorult
Malwarebytes Trojan.MalPack
TrendMicro-HouseCall Mal_HPGen-50
SentinelOne Static AI - Malicious PE
eGambit Unsafe.AI_Score_95%
MaxSecure Trojan.Malware.300983.susgen
AVG FileRepMalware
CrowdStrike win/malicious_confidence_100% (D)
Qihoo-360 Win32/Heur.Generic.HwoCPh8A