Summary | ZeroBOX

Client_zffz.exe

Malicious Library UPX PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6403_us Dec. 15, 2022, 5:40 p.m. Dec. 15, 2022, 5:46 p.m.
Size 660.3KB
Type PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5 9a3e1eee1cc88d5e7955f8a42f9cce61
SHA256 f450e7ab58e7ec8298127012ccc234e08f52fa004f579ab44459dcf081862824
CRC32 37F1E2E1
ssdeep 12288:8HLUMuiv9RgfSjAzRty26xGJeMTE3Z2ap4srKWLZ6JCtXZYJfme:WtARD6EAMC41o6Jfme
Yara
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
210.34.80.129 Active Moloch

Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
packer UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser
suspicious_features Connection to IP address suspicious_request GET http://210.34.80.129/wbwj/fjafusoft/setup_zffz.txt
suspicious_features Connection to IP address suspicious_request GET http://210.34.80.129/wbwj/fjafusoft/mobel_zffz/Setup_Mobel.txt
suspicious_features Connection to IP address suspicious_request GET http://210.34.80.129/wbwj/fjafusoft/mobel_zffz/zypgmb_zffz.txt
request GET http://210.34.80.129/wbwj/fjafusoft/setup_zffz.txt
request GET http://210.34.80.129/wbwj/fjafusoft/mobel_zffz/Setup_Mobel.txt
request GET http://210.34.80.129/wbwj/fjafusoft/mobel_zffz/zypgmb_zffz.txt
description Client_zffz.exe tried to sleep 130 seconds, actually delayed analysis time by 130 seconds
file C:\Users\test22\AppData\Local\Temp\rar.exe
file C:\Users\test22\AppData\Local\Temp\rar.exe
Elastic malicious (moderate confidence)
CrowdStrike win/malicious_confidence_60% (W)
TrendMicro-HouseCall TROJ_GEN.R002H06K721
McAfee-GW-Edition BehavesLike.Win32.Spyware.jc
AhnLab-V3 Malware/Gen.Generic.C3572474
McAfee RDN/Generic.grp
APEX Malicious
MaxSecure Worm.Win32.AutoIt.QN
section {u'size_of_data': u'0x0003f400', u'virtual_address': u'0x0006c000', u'entropy': 7.926569849329228, u'name': u'UPX1', u'virtual_size': u'0x00040000'} entropy 7.92656984933 description A section with a high entropy has been found
entropy 0.947565543071 description Overall entropy of this PE file is high
section UPX0 description Section name indicates UPX
section UPX1 description Section name indicates UPX
host 210.34.80.129