Summary | ZeroBOX

CheatWiz.exe

Emotet Gen1 Generic Malware Malicious Library ASPack UPX Malicious Packer dll PE64 PE File OS Processor Check ZIP Format DLL DllRegisterServer
Category Machine Started Completed
FILE s1_win7_x6401 Nov. 17, 2023, 7:50 a.m. Nov. 17, 2023, 7:52 a.m.
Size 19.8MB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 cee8be42d8a32ec2c409c34df0158e19
SHA256 b9deb45546b62402b05c68ffa7e404cc77e6048da90e3f9303a6089a45966327
CRC32 6E74A380
ssdeep 393216:UqPnLFXlrCIxBZgQpDOEffGCKgZ3LqvE4TKv/0oHX2:1PLFXNPyQoNenr/nH
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE64 - (no description)
  • ASPack_Zero - ASPack packed file
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section _RDATA
file C:\Users\test22\AppData\Local\Temp\_MEI26482\VCRUNTIME140.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26482\mfc140u.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26482\python3.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26482\pywintypes310.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26482\libffi-7.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26482\python310.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26482\libcrypto-1_1.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26482\pythoncom310.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26482\libssl-1_1.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26482\VCRUNTIME140_1.dll
section {u'size_of_data': u'0x0000f600', u'virtual_address': u'0x00052000', u'entropy': 7.555572206814071, u'name': u'.rsrc', u'virtual_size': u'0x0000f498'} entropy 7.55557220681 description A section with a high entropy has been found
file C:\Users\test22\AppData\Local\Temp\_MEI26482\Crypto\PublicKey\_ec_ws.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26482\_overlapped.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26482\pywintypes310.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26482\altgraph-0.17.4.dist-info\LICENSE
file C:\Users\test22\AppData\Local\Temp\_MEI26482\select.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26482\Crypto\Cipher\_ARC4.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26482\setuptools-65.5.0.dist-info\WHEEL
file C:\Users\test22\AppData\Local\Temp\_MEI26482\cryptography-41.0.5.dist-info\WHEEL
file C:\Users\test22\AppData\Local\Temp\_MEI26482\Crypto\PublicKey\_ed448.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26482\altgraph-0.17.4.dist-info\RECORD
file C:\Users\test22\AppData\Local\Temp\_MEI26482\PIL\_webp.cp310-win_amd64.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26482\altgraph-0.17.4.dist-info\METADATA
file C:\Users\test22\AppData\Local\Temp\_MEI26482\_queue.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26482\cryptography-41.0.5.dist-info\RECORD
file C:\Users\test22\AppData\Local\Temp\_MEI26482\altgraph-0.17.4.dist-info\INSTALLER
file C:\Users\test22\AppData\Local\Temp\_MEI26482\PIL\_imagingcms.cp310-win_amd64.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26482\pyinstaller-5.1.dist-info\WHEEL
file C:\Users\test22\AppData\Local\Temp\_MEI26482\Crypto\Hash\_SHA1.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26482\Crypto\Math\_modexp.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26482\_uuid.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26482\cryptography-41.0.5.dist-info\INSTALLER
file C:\Users\test22\AppData\Local\Temp\_MEI26482\cryptography-41.0.5.dist-info\REQUESTED
file C:\Users\test22\AppData\Local\Temp\_MEI26482\_hashlib.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26482\Crypto\Cipher\_raw_blowfish.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26482\_win32sysloader.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26482\Crypto\Hash\_SHA384.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26482\pyinstaller-5.1.dist-info\direct_url.json
file C:\Users\test22\AppData\Local\Temp\_MEI26482\libffi-7.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26482\pyinstaller-5.1.dist-info\COPYING.txt
file C:\Users\test22\AppData\Local\Temp\_MEI26482\attrs-23.1.0.dist-info\WHEEL
file C:\Users\test22\AppData\Local\Temp\_MEI26482\setuptools-65.5.0.dist-info\LICENSE
file C:\Users\test22\AppData\Local\Temp\_MEI26482\mfc140u.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26482\Crypto\Cipher\_raw_des3.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26482\Crypto\Cipher\_raw_eksblowfish.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26482\Crypto\Cipher\_raw_aesni.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26482\python3.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26482\charset_normalizer\md__mypyc.cp310-win_amd64.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26482\attrs-23.1.0.dist-info\RECORD
file C:\Users\test22\AppData\Local\Temp\_MEI26482\setuptools-65.5.0.dist-info\top_level.txt
file C:\Users\test22\AppData\Local\Temp\_MEI26482\attrs-23.1.0.dist-info\licenses\LICENSE
file C:\Users\test22\AppData\Local\Temp\_MEI26482\Crypto\Hash\_keccak.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26482\_decimal.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26482\altgraph-0.17.4.dist-info\zip-safe
file C:\Users\test22\AppData\Local\Temp\_MEI26482\pyinstaller-5.1.dist-info\entry_points.txt
file C:\Users\test22\AppData\Local\Temp\_MEI26482\cryptography-41.0.5.dist-info\LICENSE
file C:\Users\test22\AppData\Local\Temp\_MEI26482\PIL\_imagingtk.cp310-win_amd64.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26482\Crypto\Hash\_MD2.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26482\pyinstaller-5.1.dist-info\REQUESTED
file C:\Users\test22\AppData\Local\Temp\_MEI26482\Crypto\Protocol\_scrypt.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26482\Crypto\Hash\_poly1305.pyd