Summary | ZeroBOX

setup.exe

Generic Malware Malicious Library Admin Tool (Sysinternals etc ...) UPX Malicious Packer PE File DLL OS Processor Check PE32
Category Machine Started Completed
FILE s1_win7_x6401 Nov. 18, 2021, 7:44 a.m. Nov. 18, 2021, 8:13 a.m.
Size 1.9MB
Type PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5 682d741260d7a77643182eb40000ca92
SHA256 7f57705a95aea58f631f0d287cf0e6d380fa5c13bc95021997d1bb1d2940534f
CRC32 7ADED0CC
ssdeep 49152:eKzaWct2mph4nm83MsWpErDZ4rgNvFeBIDOeP:BGpt/ph4n9B4rgxk0P
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
91.243.59.61 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section .ndata
file C:\Users\test22\AppData\Local\Temp\nsbE11A.tmp\nsExec.dll
file C:\Windows\Client.exe
file C:\Users\test22\AppData\Local\Temp\nsbE11A.tmp\nsProcess.dll
Time & API Arguments Status Return Repeated

CreateServiceW

service_start_name:
start_type: 2
password:
display_name: MiningeService
filepath: C:\Windows\Client.exe
service_name: MiningeService
filepath_r: C:\Windows\Client.exe
desired_access: 983551
service_handle: 0x0051b888
error_control: 1
service_type: 16
service_manager_handle: 0x0051b928
1 5355656 0
cmdline C:\Windows\system32\cmd.exe /C sc description MiningeService ServiceManagerForMiner
cmdline C:\Windows\system32\cmd.exe /C Sc delete MiningeService
cmdline C:\Windows\system32\cmd.exe /C net stop MiningeService
cmdline C:\Windows\system32\cmd.exe /C net start MiningeService
cmdline C:\Windows\system32\cmd.exe /C Sc create MiningeService binpath= C:\Windows\Client.exe start= auto DisplayName= MiningeService
file C:\Users\test22\AppData\Local\Temp\nsbE11A.tmp\nsExec.dll
file C:\Users\test22\AppData\Local\Temp\nsbE11A.tmp\nsProcess.dll
cmdline net start MiningeService
cmdline C:\Windows\system32\cmd.exe /C sc description MiningeService ServiceManagerForMiner
cmdline Sc delete MiningeService
cmdline Sc create MiningeService binpath= C:\Windows\Client.exe start= auto DisplayName= MiningeService
cmdline net stop MiningeService
cmdline sc description MiningeService ServiceManagerForMiner
cmdline C:\Windows\system32\cmd.exe /C Sc delete MiningeService
cmdline C:\Windows\system32\cmd.exe /C net stop MiningeService
cmdline C:\Windows\system32\cmd.exe /C net start MiningeService
cmdline C:\Windows\system32\cmd.exe /C Sc create MiningeService binpath= C:\Windows\Client.exe start= auto DisplayName= MiningeService
host 91.243.59.61
service_name MiningeService service_path C:\Windows\Client.exe