Summary | ZeroBOX

aaa.exe

Gen1 Malicious Library UPX Malicious Packer PE File PE32 DLL
Category Machine Started Completed
FILE s1_win7_x6403_us Sept. 23, 2022, 5:40 p.m. Sept. 23, 2022, 5:42 p.m.
Size 1.7MB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 7b74e4fb9a95f41d5d9b4a71a5fe40b9
SHA256 0ec87a7f943ab72d08aeb957d33dd348ab7cf45052ab7a31bcce33ff7a095837
CRC32 A6D662D7
ssdeep 12288:cbVyGrARa7TAPZfMiuU9YAioFOVdgnFoA7aXKPXPiXuHNHGb6bH/zx/GCLW/nh/B:cb8BwmZ33qAioFmymA7yEpGLm+FFaO
Yara
  • IsPE32 - (no description)
  • Win32_Trojan_Gen_2_0904B0_Zero - Win32 Trojan Gen
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section .ndata
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
0x1ddb497b
Int64Op+0x12e0 system+0x2c59 @ 0x73bc2c59

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x458d0040
registers.esp: 1634356
registers.edi: 16
registers.eax: 0
registers.ebp: 1635788
registers.edx: 0
registers.ebx: 0
registers.esi: 16
registers.ecx: 500913640
1 0 0
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2352
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x73bc5000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2688
region_size: 1376256
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x020e0000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2688
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x021f0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2688
region_size: 16384
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x021f1000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2688
region_size: 69632
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x021f5000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2688
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02206000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2688
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02207000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2688
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7734f000
process_handle: 0xffffffff
1 0 0
file C:\Users\test22\AppData\Local\Temp\nsl97CC.tmp\System.dll
file C:\Users\test22\AppData\Local\Temp\nsl97CC.tmp\System.dll
buffer Buffer with sha1: 41fa5aebc149d9c428b34b4ba11b2772c7440d4d
Process injection Process 2352 called NtSetContextThread to modify thread in remote process 2688
Time & API Arguments Status Return Repeated

NtSetContextThread

registers.eip: 1999372740
registers.esp: 1638384
registers.edi: 0
registers.eax: 4297839
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
thread_handle: 0x000001e8
process_identifier: 2688
1 0 0
Lionic Trojan.Win32.Agent.Y!c
MicroWorld-eScan Gen:Variant.Nemesis.10729
McAfee Artemis!7B74E4FB9A95
Cylance Unsafe
Sangfor Trojan.Win32.Agent.V1tr
BitDefender Gen:Variant.Nemesis.10729
Arcabit Trojan.Nemesis.D29E9
Symantec Downloader
Elastic malicious (high confidence)
Cynet Malicious (score: 99)
APEX Malicious
Paloalto generic.ml
Kaspersky HEUR:Trojan-Dropper.Win32.Agent.gen
Avast FileRepMalware [Ransom]
Tencent Win32.Trojan-Dropper.Agent.Ddhl
Emsisoft Gen:Variant.Nemesis.10729 (B)
F-Secure Heuristic.HEUR/AGEN.1252584
VIPRE Gen:Variant.Nemesis.10729
McAfee-GW-Edition BehavesLike.Win32.Generic.tm
FireEye Gen:Variant.Nemesis.10729
Avira HEUR/AGEN.1252584
Microsoft Trojan:Win32/Sabsik.FL.B!ml
GData Gen:Variant.Nemesis.10729
ALYac Gen:Variant.Nemesis.10729
MAX malware (ai score=88)
TrendMicro-HouseCall TROJ_GEN.R002H07IN22
Rising Trojan.Injector/NSIS!1.BFBB (CLASSIC)
Fortinet NSIS/Injector.AOW!tr
AVG FileRepMalware [Ransom]
CrowdStrike win/malicious_confidence_60% (W)