Summary | ZeroBOX

md7_7dfj.exe

PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6402 Oct. 7, 2021, 6:07 p.m. Oct. 7, 2021, 6:11 p.m.
Size 2.1MB
Type PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed
MD5 0122c6b7f2509a0eec1b39c8689bee86
SHA256 9f72ad74c30a5ea4ead990fc8d9e395178a3c100dc5bcc098991fe3b23b02273
CRC32 D36E9A1E
ssdeep 49152:pwcOZfYiqG4rT1/0jyh1KsyYL0XnvSX3l:p+jqG4N/0jUKiL0XqX3l
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)

Name Response Post-Analysis Lookup
iplogger.org 88.99.66.31
IP Address Status Action
164.124.101.2 Active Moloch
186.2.171.3 Active Moloch
88.99.66.31 Active Moloch

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.102:49165 -> 88.99.66.31:443 906200056 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.102:49165
88.99.66.31:443
C=GB, ST=Greater Manchester, L=Salford, O=Sectigo Limited, CN=Sectigo RSA Domain Validation Secure Server CA CN=*.iplogger.org 55:1e:13:99:46:1c:67:40:a3:48:7f:38:0d:16:e7:51:f4:c4:43:cb

Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
packer PECompact 2.xx --> BitSum Technologies
resource name PNG
resource name STYLE_XML
resource name None
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa1 ntdll+0x39ed2 @ 0x77b19ed2
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xce ntdll+0x39ea5 @ 0x77b19ea5

exception.instruction_r: 89 08 50 45 43 6f 6d 70 61 63 74 32 00 59 79 3b
exception.symbol: md7_7dfj+0x1016
exception.instruction: mov dword ptr [eax], ecx
exception.module: md7_7dfj.exe
exception.exception_code: 0xc0000005
exception.offset: 4118
exception.address: 0xc51016
registers.esp: 3210860
registers.edi: 0
registers.eax: 0
registers.ebp: 3210876
registers.edx: 12914688
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
1 0 0
suspicious_features Connection to IP address suspicious_request GET http://186.2.171.3/seemorebty/il.php?e=md7_7dfj
request GET http://186.2.171.3/seemorebty/il.php?e=md7_7dfj
request GET https://iplogger.org/ZlbB4
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 1092
region_size: 12288
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00320000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Default\Cookies
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
name PNG language LANG_CHINESE filetype empty sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x004e53c0 size 0x00001623
section {u'size_of_data': u'0x001f7600', u'virtual_address': u'0x00001000', u'entropy': 7.999886661787159, u'name': u'.text', u'virtual_size': u'0x00581000'} entropy 7.99988666179 description A section with a high entropy has been found
entropy 0.925534359917 description Overall entropy of this PE file is high
host 186.2.171.3
Time & API Arguments Status Return Repeated

RegSetValueExA

key_handle: 0x00000548
regkey_r: ProxyEnable
reg_type: 4 (REG_DWORD)
value: 0
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable
1 0 0
Bkav W32.AIDetect.malware2
McAfee Artemis!0122C6B7F250
Cylance Unsafe
Sangfor Riskware.Win32.Agent.ky
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/PSW.Agent.OHG
APEX Malicious
Paloalto generic.ml
Kaspersky UDS:Trojan-Banker.Win32.Passteal.gen
DrWeb Trojan.DownLoader43.36535
McAfee-GW-Edition BehavesLike.Win32.Generic.vc
Microsoft Trojan:Script/Phonzy.B!ml
GData Win32.Trojan-Stealer.Predator.6C8JSB
AhnLab-V3 Trojan/Win.Generic.C4645045
BitDefenderTheta Gen:NN.ZexaF.34170.io0aaqYZPJm
Fortinet W32/Agent.OLG!tr.pws
AVG Win32:TrojanX-gen [Trj]
Avast Win32:TrojanX-gen [Trj]
Time & API Arguments Status Return Repeated

RegSetValueExA

key_handle: 0x00000548
regkey_r: ProxyOverride
reg_type: 1 (REG_SZ)
value: 127.0.0.1:16107;
regkey: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyOverride
1 0 0