Summary | ZeroBOX

plink.exe

Malicious Library PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6403_us Nov. 5, 2023, 12:30 p.m. Nov. 5, 2023, 12:33 p.m.
Size 312.5KB
Type PE32 executable (console) Intel 80386, for MS Windows
MD5 7e559dc4e162f6aaee6a034fa2d9c838
SHA256 4c2e05acad9e625ba60ca90fa7cce6a1b11a147e00f43e0f29225faeff6b54aa
CRC32 68CD2745
ssdeep 6144:jU+kZmuBc5tF/LdiZ/xCJkQbvy5XVkmZyTJS1xvnLgmbEB968oET0WoABqzMoRXq:jUBZmewtxLE/kJkcvxEtzyB968hTEFZ
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
5.148.32.222 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

WriteConsoleA

buffer: PuTTY Link: command-line connection utility
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: Release 0.63
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: Usage: plink [options] [user@]host [command]
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: ("host" can also be a PuTTY saved session name)
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: Options:
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -V print version information and exit
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -pgpfp print PGP key fingerprints and exit
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -v show verbose messages
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: force use of a particular protocol
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -P port connect to specified port
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -l user connect with specified username
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -batch disable all interactive prompts
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: The following options only apply to SSH connections:
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -pw passw login with specified password
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -D [listen-IP:]listen-port
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: Dynamic SOCKS-based port forwarding
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -L [listen-IP:]listen-port:host:port
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: Forward local port to remote address
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -R [listen-IP:]listen-port:host:port
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: Forward remote port to local address
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -X -x enable / disable X11 forwarding
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -A -a enable / disable agent forwarding
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -t -T enable / disable pty allocation
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -1 -2 force use of particular protocol version
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -4 -6 force use of IPv4 or IPv6
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -C enable compression
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -i key private key file for authentication
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -noagent disable use of Pageant
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -agent enable use of Pageant
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -m file read remote command(s) from file
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -s remote command is an SSH subsystem (SSH-2 only)
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -N don't start a shell/command (SSH-2 only)
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -nc host:port
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: open tunnel in place of session (SSH-2 only)
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -sercfg configuration-string (e.g. 19200,8,n,1,X)
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: Specify the serial configuration (serial only)
console_handle: 0x00000007
1 1 0
host 5.148.32.222
registry HKEY_CURRENT_USER\Software\SimonTatham\PuTTY\Sessions