Summary | ZeroBOX

HZUWUM5pprq6yKV.exe

Generic Malware Downloader Admin Tool (Sysinternals etc ...) HTTP PWS Internet API Http API GIF Format .NET EXE PE File PE32 AntiVM AntiDebug
Category Machine Started Completed
FILE s1_win7_x6401 Aug. 20, 2021, 9:36 a.m. Aug. 20, 2021, 9:53 a.m.
Size 1.1MB
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 3616925290acd4f40efd5a3889f3d3f1
SHA256 1a512b670911187dd2cc6a04b8da5d96b70df6129234b4fd97e30fcda7470365
CRC32 2E3F2A6C
ssdeep 12288:wkr9OOZuOaS1Uka98Dc9F3nC0Py3gAh+4H+1pLw69t9FUfaqMhr9pasXw7t5/2fp:wkj4GR69Giz9AMw3WKx2biPrs1x2d
Yara
  • PE_Header_Zero - PE File Signature
  • Admin_Tool_IN_Zero - Admin Tool Sysinternals
  • Generic_Malware_Zero - Generic Malware
  • Is_DotNET_EXE - (no description)
  • IsPE32 - (no description)
  • Win_Backdoor_AsyncRAT_Zero - Win Backdoor AsyncRAT
  • Win32_Trojan_PWS_Net_1_Zero - Win32 Trojan PWS .NET Azorult

IP Address Status Action
104.192.141.1 Active Moloch
164.124.101.2 Active Moloch
88.99.66.31 Active Moloch

Suricata Alerts

Flow SID Signature Category
TCP 104.192.141.1:443 -> 192.168.56.101:49210 2029340 ET INFO TLS Handshake Failure Potentially Bad Traffic
TCP 192.168.56.101:49210 -> 104.192.141.1:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 192.168.56.101:49203 -> 88.99.66.31:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 104.192.141.1:443 -> 192.168.56.101:49204 2029340 ET INFO TLS Handshake Failure Potentially Bad Traffic
TCP 192.168.56.101:49204 -> 104.192.141.1:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 104.192.141.1:443 -> 192.168.56.101:49206 2029340 ET INFO TLS Handshake Failure Potentially Bad Traffic
TCP 104.192.141.1:443 -> 192.168.56.101:49207 2029340 ET INFO TLS Handshake Failure Potentially Bad Traffic
TCP 192.168.56.101:49206 -> 104.192.141.1:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 104.192.141.1:443 -> 192.168.56.101:49209 2029340 ET INFO TLS Handshake Failure Potentially Bad Traffic
TCP 192.168.56.101:49209 -> 104.192.141.1:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
TCP 104.192.141.1:443 -> 192.168.56.101:49211 2029340 ET INFO TLS Handshake Failure Potentially Bad Traffic

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49203
88.99.66.31:443
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Domain Validation Secure Server CA CN=*.iplogger.org 55:1e:13:99:46:1c:67:40:a3:48:7f:38:0d:16:e7:51:f4:c4:43:cb

Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

WriteConsoleA

buffer: failed to open: C:\ProgramData\Data\GPU.zip
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: failed to open: C:\ProgramData\Systemd\CPU.zip
console_handle: 0x00000007
1 1 0
Time & API Arguments Status Return Repeated

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004b6870
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004b6870
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004b6870
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
request GET http://iplogger.org/1bUgq7
request GET https://iplogger.org/1bUgq7
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 1179648
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00560000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00640000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2704
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72741000
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2704
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72742000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 917504
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00a60000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00b00000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00562000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00595000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0059b000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00597000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0057c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x006b0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0056a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0058a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00587000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0057a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 327680
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7ef50000
allocation_type: 1056768 (MEM_RESERVE|MEM_TOP_DOWN)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7ef50000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7ef50000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7ef58000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 65536
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7ef40000
allocation_type: 1056768 (MEM_RESERVE|MEM_TOP_DOWN)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7ef40000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00586000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x006b1000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2704
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x6dee2000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0056c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x006b3000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0057d000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0057e000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x006b4000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x006b5000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x006b6000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x006b7000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x006b8000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x006b9000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x006ba000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x006bb000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x006bc000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x006bd000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x006be000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x006bf000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05370000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2704
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05371000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0
description HZUWUM5pprq6yKV.exe tried to sleep 174 seconds, actually delayed analysis time by 174 seconds
file C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\exe.lnk
file C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\exe.lnk
file C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\exe.lnk
section {u'size_of_data': u'0x0011f200', u'virtual_address': u'0x00002000', u'entropy': 7.3553053555036865, u'name': u'.text', u'virtual_size': u'0x0011f0e0'} entropy 7.3553053555 description A section with a high entropy has been found
entropy 0.997827975673 description Overall entropy of this PE file is high
Time & API Arguments Status Return Repeated

Process32NextW

snapshot_handle: 0x0000057c
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 3060
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 3060
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0

Process32NextW

snapshot_handle: 0x000005c0
process_name: conhost.exe
process_identifier: 2440
0 0
description Communications over HTTP rule Network_HTTP
description Match Windows Inet API call rule Str_Win32_Internet_API
description Match Windows Http API call rule Str_Win32_Http_API
description File Downloader rule Network_Downloader
description (no description) rule DebuggerCheck__GlobalFlags
description (no description) rule DebuggerCheck__QueryInfo
description (no description) rule DebuggerHiding__Thread
description (no description) rule DebuggerHiding__Active
description (no description) rule ThreadControl__Context
description (no description) rule SEH__vectored
description Checks if being debugged rule anti_dbg
description Bypass DEP rule disable_dep
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 2984
region_size: 434176
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x0000026c
1 0 0
file C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\exe.lnk
Time & API Arguments Status Return Repeated

WriteProcessMemory

buffer: MZÿÿ¸@º´ Í!¸LÍ!This program cannot be run in DOS mode. $2¢ycvÃ0vÃ0vÃ0b¨1xÃ0b¨1·Ã0¬ê0uÃ0$¶1dÃ0$¶1`Ã0$¶1=Ã0 ¶1Ã0b¨1aÃ0b¨1wÃ0b¨1gÃ0vÃ0ÒÃ0ö1uÃ0ö1wÃ0RichvÃ0PELŽÀaà ت =ð@ @€„€„À0´pt+¸ÿ8ðÿ@ðP.text8×Ø `.rdataŠNðPÜ@@.data4-@ ,@À.reloct+p,L@B
base_address: 0x00400000
process_identifier: 2984
process_handle: 0x0000026c
1 1 0

WriteProcessMemory

buffer: @
base_address: 0x7efde008
process_identifier: 2984
process_handle: 0x0000026c
1 1 0
Time & API Arguments Status Return Repeated

WriteProcessMemory

buffer: MZÿÿ¸@º´ Í!¸LÍ!This program cannot be run in DOS mode. $2¢ycvÃ0vÃ0vÃ0b¨1xÃ0b¨1·Ã0¬ê0uÃ0$¶1dÃ0$¶1`Ã0$¶1=Ã0 ¶1Ã0b¨1aÃ0b¨1wÃ0b¨1gÃ0vÃ0ÒÃ0ö1uÃ0ö1wÃ0RichvÃ0PELŽÀaà ت =ð@ @€„€„À0´pt+¸ÿ8ðÿ@ðP.text8×Ø `.rdataŠNðPÜ@@.data4-@ ,@À.reloct+p,L@B
base_address: 0x00400000
process_identifier: 2984
process_handle: 0x0000026c
1 1 0
Elastic malicious (high confidence)
McAfee AgentTesla-FCTJ!3616925290AC
Cylance Unsafe
Cyren W32/MSIL_Kryptik.DVA.gen!Eldorado
Symantec Trojan.Gen.2
ESET-NOD32 a variant of MSIL/GenKryptik.FJET
APEX Malicious
Kaspersky UDS:Trojan-Downloader.MSIL.Miner.gen
Avast Win32:PWSX-gen [Trj]
McAfee-GW-Edition BehavesLike.Win32.Fareit.tc
FireEye Generic.mg.3616925290acd4f4
SentinelOne Static AI - Malicious PE
Microsoft Trojan:Win32/AgentTesla!ml
Cynet Malicious (score: 100)
VBA32 Malware-Cryptor.MSIL.AgentTesla.Heur
Malwarebytes MachineLearning/Anomalous.95%
MaxSecure Trojan.Malware.300983.susgen
AVG Win32:PWSX-gen [Trj]
Qihoo-360 HEUR/QVM03.0.5B7B.Malware.Gen
Process injection Process 2704 called NtSetContextThread to modify thread in remote process 2984
Time & API Arguments Status Return Repeated

NtSetContextThread

registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 4341152
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
thread_handle: 0x00000268
process_identifier: 2984
1 0 0
Process injection Process 2704 resumed a thread in remote process 2984
Time & API Arguments Status Return Repeated

NtResumeThread

thread_handle: 0x00000268
suspend_count: 1
process_identifier: 2984
1 0 0
Time & API Arguments Status Return Repeated

NtResumeThread

thread_handle: 0x000000dc
suspend_count: 1
process_identifier: 2704
1 0 0

NtResumeThread

thread_handle: 0x0000014c
suspend_count: 1
process_identifier: 2704
1 0 0

NtResumeThread

thread_handle: 0x00000188
suspend_count: 1
process_identifier: 2704
1 0 0

NtResumeThread

thread_handle: 0x00000260
suspend_count: 1
process_identifier: 2704
1 0 0

CreateProcessInternalW

thread_identifier: 2608
thread_handle: 0x00000268
process_identifier: 2984
current_directory:
filepath: C:\Users\test22\AppData\Local\Temp\HZUWUM5pprq6yKV.exe
track: 1
command_line:
filepath_r: C:\Users\test22\AppData\Local\Temp\HZUWUM5pprq6yKV.exe
stack_pivoted: 0
creation_flags: 134217732 (CREATE_NO_WINDOW|CREATE_SUSPENDED)
inherit_handles: 0
process_handle: 0x0000026c
1 1 0

NtGetContextThread

thread_handle: 0x00000268
1 0 0

NtAllocateVirtualMemory

process_identifier: 2984
region_size: 434176
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x0000026c
1 0 0

WriteProcessMemory

buffer: MZÿÿ¸@º´ Í!¸LÍ!This program cannot be run in DOS mode. $2¢ycvÃ0vÃ0vÃ0b¨1xÃ0b¨1·Ã0¬ê0uÃ0$¶1dÃ0$¶1`Ã0$¶1=Ã0 ¶1Ã0b¨1aÃ0b¨1wÃ0b¨1gÃ0vÃ0ÒÃ0ö1uÃ0ö1wÃ0RichvÃ0PELŽÀaà ت =ð@ @€„€„À0´pt+¸ÿ8ðÿ@ðP.text8×Ø `.rdataŠNðPÜ@@.data4-@ ,@À.reloct+p,L@B
base_address: 0x00400000
process_identifier: 2984
process_handle: 0x0000026c
1 1 0

WriteProcessMemory

buffer:
base_address: 0x00401000
process_identifier: 2984
process_handle: 0x0000026c
1 1 0

WriteProcessMemory

buffer:
base_address: 0x0044f000
process_identifier: 2984
process_handle: 0x0000026c
1 1 0

WriteProcessMemory

buffer:
base_address: 0x00464000
process_identifier: 2984
process_handle: 0x0000026c
1 1 0

WriteProcessMemory

buffer:
base_address: 0x00467000
process_identifier: 2984
process_handle: 0x0000026c
1 1 0

WriteProcessMemory

buffer: @
base_address: 0x7efde008
process_identifier: 2984
process_handle: 0x0000026c
1 1 0

NtSetContextThread

registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 4341152
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
thread_handle: 0x00000268
process_identifier: 2984
1 0 0

NtResumeThread

thread_handle: 0x00000268
suspend_count: 1
process_identifier: 2984
1 0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Systemd\
track: 0
command_line:
filepath_r: C:\ProgramData\Systemd\
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Data\
track: 0
command_line:
filepath_r: C:\ProgramData\Data\
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Systemd\
track: 0
command_line:
filepath_r: C:\ProgramData\Systemd\
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Data\
track: 0
command_line:
filepath_r: C:\ProgramData\Data\
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Systemd\
track: 0
command_line:
filepath_r: C:\ProgramData\Systemd\
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Data\
track: 0
command_line:
filepath_r: C:\ProgramData\Data\
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Data\install.exe
track: 0
command_line:
filepath_r: C:\ProgramData\Data\install.exe
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Data\install2.exe
track: 0
command_line:
filepath_r: C:\ProgramData\Data\install2.exe
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Data\install3.exe
track: 0
command_line:
filepath_r: C:\ProgramData\Data\install3.exe
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Data\install4.exe
track: 0
command_line:
filepath_r: C:\ProgramData\Data\install4.exe
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Data\install5.exe
track: 0
command_line:
filepath_r: C:\ProgramData\Data\install5.exe
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Systemd\
track: 0
command_line:
filepath_r: C:\ProgramData\Systemd\
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Data\
track: 0
command_line:
filepath_r: C:\ProgramData\Data\
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Systemd\
track: 0
command_line:
filepath_r: C:\ProgramData\Systemd\
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Data\
track: 0
command_line:
filepath_r: C:\ProgramData\Data\
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Systemd\
track: 0
command_line:
filepath_r: C:\ProgramData\Systemd\
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Data\
track: 0
command_line:
filepath_r: C:\ProgramData\Data\
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Systemd\
track: 0
command_line:
filepath_r: C:\ProgramData\Systemd\
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Data\
track: 0
command_line:
filepath_r: C:\ProgramData\Data\
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Systemd\
track: 0
command_line:
filepath_r: C:\ProgramData\Systemd\
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Data\
track: 0
command_line:
filepath_r: C:\ProgramData\Data\
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Systemd\
track: 0
command_line:
filepath_r: C:\ProgramData\Systemd\
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Data\
track: 0
command_line:
filepath_r: C:\ProgramData\Data\
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Systemd\
track: 0
command_line:
filepath_r: C:\ProgramData\Systemd\
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Data\
track: 0
command_line:
filepath_r: C:\ProgramData\Data\
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Systemd\
track: 0
command_line:
filepath_r: C:\ProgramData\Systemd\
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Data\
track: 0
command_line:
filepath_r: C:\ProgramData\Data\
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Systemd\
track: 0
command_line:
filepath_r: C:\ProgramData\Systemd\
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Data\
track: 0
command_line:
filepath_r: C:\ProgramData\Data\
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Systemd\
track: 0
command_line:
filepath_r: C:\ProgramData\Systemd\
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Data\
track: 0
command_line:
filepath_r: C:\ProgramData\Data\
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Systemd\
track: 0
command_line:
filepath_r: C:\ProgramData\Systemd\
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Data\
track: 0
command_line:
filepath_r: C:\ProgramData\Data\
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Systemd\
track: 0
command_line:
filepath_r: C:\ProgramData\Systemd\
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0

CreateProcessInternalW

thread_identifier: 0
thread_handle: 0x00000000
process_identifier: 0
current_directory:
filepath: C:\ProgramData\Data\
track: 0
command_line:
filepath_r: C:\ProgramData\Data\
stack_pivoted: 0
creation_flags: 8 (DETACHED_PROCESS)
inherit_handles: 0
process_handle: 0x00000000
0 0