Summary | ZeroBOX

Adobe.exe

NSIS Generic Malware Malicious Library ASPack Antivirus UPX Malicious Packer Anti_VM dll BMP Format PE File ftp PE64 PNG Format DLL OS Processor Check PE32 ZIP Format JPEG Format DllRegisterServer
Category Machine Started Completed
FILE s1_win7_x6401 Nov. 9, 2023, 7:59 a.m. Nov. 9, 2023, 8:05 a.m.
Size 14.1MB
Type PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5 be4bbdb604b6c6e5f6975c050d00ce53
SHA256 164b37e53edc820539aa8f9daa5bb4846447f05e451eab8466306b6b1d1927b8
CRC32 25DDD85E
ssdeep 393216:hUDC+UzXnsCmmG0M8e5O7sNp3tHRs5wwahCAPc:hUDC3jndmmYNH2OwHz
Yara
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
  • PE_Header_Zero - PE File Signature
  • NSIS_Installer - Null Soft Installer
  • IsPE32 - (no description)

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
121.254.136.9 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section .ndata
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2552
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x732a2000
process_handle: 0xffffffff
1 0 0
file C:\Users\test22\AppData\Local\Applications\lib\win32com\test\testPyScriptlet.js
file C:\Users\test22\AppData\Local\Applications\lib\win32com\test\testInterp.vbs
file C:\Users\test22\AppData\Local\Applications\lib\pip\_vendor\distlib\t32.exe
file C:\Users\test22\AppData\Local\Applications\python3.dll
file C:\Users\test22\AppData\Local\Applications\lib\pip\_vendor\distlib\t64.exe
file C:\Users\test22\AppData\Local\Applications\lib\libssl-1_1.dll
file C:\Users\test22\AppData\Local\Applications\putti.exe
file C:\Users\test22\AppData\Local\Applications\lib\win32com\test\testDictionary.vbs
file C:\Users\test22\AppData\Local\Applications\lib\pip\_vendor\distlib\w64.exe
file C:\Users\test22\AppData\Local\Applications\lib\libcrypto-1_1.dll
file C:\Users\test22\AppData\Local\Applications\lib\pywintypes310.dll
file C:\Users\test22\AppData\Local\Applications\lib\test\empty.vbs
file C:\Users\test22\AppData\Local\Applications\lib\pythoncom310.dll
file C:\Users\test22\AppData\Local\Applications\lib\ctypes\macholib\fetch_macholib.bat
file C:\Users\test22\AppData\Local\Applications\lib\win32com\test\testxslt.js
file C:\Users\test22\AppData\Local\Applications\lib\libffi-7.dll
file C:\Users\test22\AppData\Local\Applications\lib\pip\_vendor\distlib\w32.exe
file C:\Users\test22\AppData\Local\Applications\lib\pywin32_system32\pythoncom310.dll
file C:\Users\test22\AppData\Local\Applications\lib\sqlite3.dll
file C:\Users\test22\AppData\Local\Applications\python310.dll
file C:\Users\test22\AppData\Local\Applications\lib\pywin32_system32\pywintypes310.dll
file C:\Users\test22\AppData\Local\Applications\lib\pip\_vendor\distlib\t32.exe
file C:\Users\test22\AppData\Local\Applications\lib\pip\_vendor\distlib\w32.exe
host 121.254.136.9
file C:\Users\test22\AppData\Local\Applications\lib\pip\_internal\vcs\mercurial.pyc
file C:\Users\test22\AppData\Local\Applications\lib\encodings\iso8859_9.pyc
file C:\Users\test22\AppData\Local\Applications\lib\pip\_vendor\packaging\requirements.pyc
file C:\Users\test22\AppData\Local\Applications\lib\unittest\loader.pyc
file C:\Users\test22\AppData\Local\Applications\lib\Crypto\Math\Primality.pyc
file C:\Users\test22\AppData\Local\Applications\lib\importlib\readers.pyc
file C:\Users\test22\AppData\Local\Applications\lib\pip\_internal\utils\misc.pyc
file C:\Users\test22\AppData\Local\Applications\lib\pip\_vendor\urllib3\util\proxy.pyc
file C:\Users\test22\AppData\Local\Applications\lib\charset_normalizer\version.pyc
file C:\Users\test22\AppData\Local\Applications\lib\Crypto\Cipher\DES3.pyc
file C:\Users\test22\AppData\Local\Applications\lib\pip\_internal\utils\wheel.pyc
file C:\Users\test22\AppData\Local\Applications\lib\Crypto\SelfTest\Cipher\test_SIV.pyc
file C:\Users\test22\AppData\Local\Applications\lib\http\server.pyc
file C:\Users\test22\AppData\Local\Applications\lib\ctypes\test\test_values.pyc
file C:\Users\test22\AppData\Local\Applications\lib\encodings\big5hkscs.pyc
file C:\Users\test22\AppData\Local\Applications\lib\collections\__init__.pyc
file C:\Users\test22\AppData\Local\Applications\lib\Crypto\SelfTest\Cipher\test_OCB.pyc
file C:\Users\test22\AppData\Local\Applications\lib\pip\_vendor\urllib3\contrib\__init__.pyc
file C:\Users\test22\AppData\Local\Applications\lib\ctypes\test\test_macholib.pyc
file C:\Users\test22\AppData\Local\Applications\lib\sqlite3\dump.pyc
file C:\Users\test22\AppData\Local\Applications\lib\logging\__init__.pyc
file C:\Users\test22\AppData\Local\Applications\lib\ctypes\test\test_init.pyc
file C:\Users\test22\AppData\Local\Applications\lib\encodings\euc_jp.pyc
file C:\Users\test22\AppData\Local\Applications\lib\encodings\cp1006.pyc
file C:\Users\test22\AppData\Local\Applications\lib\Crypto\SelfTest\Cipher\common.pyc
file C:\Users\test22\AppData\Local\Applications\lib\xml\sax\_exceptions.pyc
file C:\Users\test22\AppData\Local\Applications\lib\encodings\iso2022_jp.pyc
file C:\Users\test22\AppData\Local\Applications\lib\asyncio\proactor_events.pyc
file C:\Users\test22\AppData\Local\Applications\lib\pip\_vendor\html5lib\treewalkers\dom.pyc
file C:\Users\test22\AppData\Local\Applications\lib\encodings\cp855.pyc
file C:\Users\test22\AppData\Local\Applications\lib\pip\_internal\operations\__init__.pyc
file C:\Users\test22\AppData\Local\Applications\lib\pip\_vendor\distlib\scripts.pyc
file C:\Users\test22\AppData\Local\Applications\lib\encodings\iso8859_2.pyc
file C:\Users\test22\AppData\Local\Applications\lib\xml\dom\NodeFilter.pyc
file C:\Users\test22\AppData\Local\Applications\lib\pip\_vendor\requests\cookies.pyc
file C:\Users\test22\AppData\Local\Applications\lib\pip\_vendor\cachecontrol\filewrapper.pyc
file C:\Users\test22\AppData\Local\Applications\lib\Crypto\Protocol\KDF.pyc
file C:\Users\test22\AppData\Local\Applications\lib\pip\_vendor\html5lib\treewalkers\etree.pyc
file C:\Users\test22\AppData\Local\Applications\lib\ctypes\test\test_repr.pyc
file C:\Users\test22\AppData\Local\Applications\lib\ctypes\macholib\__init__.pyc
file C:\Users\test22\AppData\Local\Applications\lib\charset_normalizer\models.pyc
file C:\Users\test22\AppData\Local\Applications\lib\Crypto\SelfTest\Signature\test_pkcs1_15.pyc
file C:\Users\test22\AppData\Local\Applications\lib\ctypes\test\test_anon.pyc
file C:\Users\test22\AppData\Local\Applications\lib\asyncio\queues.pyc
file C:\Users\test22\AppData\Local\Applications\lib\charset_normalizer\utils.pyc
file C:\Users\test22\AppData\Local\Applications\lib\pip\_vendor\urllib3\packages\ssl_match_hostname\__init__.pyc
file C:\Users\test22\AppData\Local\Applications\lib\xml\dom\expatbuilder.pyc
file C:\Users\test22\AppData\Local\Applications\lib\xml\parsers\expat.pyc
file C:\Users\test22\AppData\Local\Applications\lib\test\test_importlib\data01\binary.file
file C:\Users\test22\AppData\Local\Applications\lib\encodings\cp850.pyc