Summary | ZeroBOX

Log_me.exe

Gen1 UPX Malicious Library Malicious Packer PE64 PE File OS Processor Check ZIP Format DLL
Category Machine Started Completed
FILE s1_win7_x6401 June 21, 2023, 5:36 a.m. June 21, 2023, 5:40 a.m.
Size 32.7MB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 0f1fc7414dafa2f5583eb3c599509f23
SHA256 375e5ffb645a88bd6293f094dfb7c6ac4ffac46023d0a0a754b9878e18248e5a
CRC32 9C694D34
ssdeep 786432:mo3EH+rrB5SKTe3/Tux9dJtY/Y4q0ptiwHEXt8nHQQs:h3EH6jSkePCxrJcY4q0muEXuH
Yara
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
  • Malicious_Library_Zero - Malicious_Library
  • IsPE64 - (no description)
  • PE_Header_Zero - PE File Signature

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section _RDATA
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-localization-l1-2-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\plugins\imageformats\qtiff.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\bin\Qt5Widgets.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-datetime-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-debug-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-crt-process-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-file-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\plugins\generic\qtuiotouchplugin.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\libssl-1_1.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-crt-heap-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\plugins\styles\qwindowsvistastyle.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-memory-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\bin\Qt5Svg.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\bin\opengl32sw.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-console-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-synch-l1-2-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-crt-filesystem-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\VCRUNTIME140_1.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\bin\Qt5Gui.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-crt-math-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-namedpipe-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\python311.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-crt-convert-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-errorhandling-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-crt-environment-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\plugins\platforms\qwindows.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\plugins\imageformats\qjpeg.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-file-l1-2-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\plugins\iconengines\qsvgicon.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-handle-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\plugins\platforms\qminimal.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\bin\libGLESv2.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-crt-conio-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\bin\Qt5Network.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-string-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\bin\Qt5Core.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-util-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-crt-time-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\libffi-8.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\bin\MSVCP140.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-heap-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\plugins\imageformats\qwebp.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\bin\Qt5Qml.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\plugins\imageformats\qico.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\bin\MSVCP140_1.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\plugins\platforms\qoffscreen.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-crt-runtime-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\bin\Qt5WebSockets.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\VCRUNTIME140.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-timezone-l1-1-0.dll
Elastic malicious (moderate confidence)
section {u'size_of_data': u'0x0000f600', u'virtual_address': u'0x00052000', u'entropy': 7.555587253339539, u'name': u'.rsrc', u'virtual_size': u'0x0000f498'} entropy 7.55558725334 description A section with a high entropy has been found
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-crt-process-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-file-l1-2-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\plugins\generic\qtuiotouchplugin.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\translations\qtbase_ja.qm
file C:\Users\test22\AppData\Local\Temp\_MEI26522\cryptography-40.0.2.dist-info\LICENSE.APACHE
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\plugins\platforms\qwindows.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\translations\qtbase_gd.qm
file C:\Users\test22\AppData\Local\Temp\_MEI26522\cryptography-40.0.2.dist-info\LICENSE.PSF
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\translations\qtbase_pl.qm
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-crt-conio-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\bin\Qt5Network.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\cryptography-40.0.2.dist-info\INSTALLER
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-util-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-string-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\_cffi_backend.cp311-win_amd64.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\translations\qtbase_cs.qm
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\plugins\platforms\qoffscreen.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\VCRUNTIME140.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\base_library.zip
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\bin\Qt5Quick.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\charset_normalizer\md.cp311-win_amd64.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-processthreads-l1-1-1.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\bin\VCRUNTIME140_1.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\_ctypes.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-crt-locale-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-handle-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\QtWidgets.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-console-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-debug-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\translations\qtbase_ar.qm
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\plugins\styles\qwindowsvistastyle.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-memory-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-synch-l1-2-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\psutil\_psutil_windows.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-crt-filesystem-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-crt-math-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-namedpipe-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\python311.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\translations\qtbase_fr.qm
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-synch-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\plugins\iconengines\qsvgicon.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-processenvironment-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\select.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26522\cryptography\hazmat\bindings\_rust.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\bin\Qt5Core.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\certifi\py.typed
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-core-profile-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\api-ms-win-crt-time-l1-1-0.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\PyQt5\Qt5\translations\qtbase_fi.qm
file C:\Users\test22\AppData\Local\Temp\_MEI26522\_hashlib.pyd