Summary | ZeroBOX

Voiceaibeta-5.13.exe

Gen1 Malicious Library UPX Malicious Packer Anti_VM ftp PE64 PNG Format PE File OS Processor Check ZIP Format DLL icon
Category Machine Started Completed
FILE s1_win7_x6401 Dec. 20, 2023, 7:46 a.m. Dec. 20, 2023, 7:55 a.m.
Size 15.2MB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 ce3cce902aecf173e8899da746b45dc3
SHA256 2702fea5f786abc3d72d4dfa65b26a81632a4cf82d5ee36bc5497d98180ea20c
CRC32 389B0577
ssdeep 393216:zjId074k3meXcGfd0aw2L2tbfRukW8eb08aF:fIdZat5FO2LODbW8egF
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE64 - (no description)
  • ftp_command - ftp command
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section _RDATA
file C:\Users\test22\AppData\Local\Temp\_MEI26322\libssl-3.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26322\libcrypto-3.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26322\libffi-8.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26322\VCRUNTIME140.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tk86t.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl86t.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26322\python311.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\cp863.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\tis-620.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\cp860.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\cp864.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\macRomania.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\shiftjis.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\iso8859-5.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\iso8859-10.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\cp1250.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\cp1253.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\macIceland.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\symbol.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\jis0201.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\cp850.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\macThai.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\cp1256.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\cp874.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\euc-kr.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\cp861.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\iso8859-1.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\cp852.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\cp857.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\ebcdic.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\macJapan.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\iso8859-13.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\macTurkish.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\euc-jp.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\macUkraine.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\gb2312-raw.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\cp932.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\koi8-u.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\iso2022-kr.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\iso8859-7.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\big5.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\cp437.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\macCyrillic.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\cp862.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\iso8859-4.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\macCroatian.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\iso2022.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\jis0208.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\cp775.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\koi8-r.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\cp855.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\iso8859-16.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\macRoman.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\cp1255.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\ksc5601.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\ascii.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\cp1257.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\Etc\GMT+3
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\Etc\GMT+2
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\Etc\GMT+1
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\Etc\GMT+0
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\encoding\tis-620.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\Etc\GMT+6
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\Etc\GMT+5
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\Etc\GMT+4
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\SystemV\HST10
file C:\Users\test22\AppData\Local\Temp\_MEI26322\Cryptodome\Cipher\_raw_arc2.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\Asia\Katmandu
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\Asia\Choibalsan
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\SystemV\MST7MDT
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tk\obsolete.tcl
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\America\Catamarca
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\Asia\Vladivostok
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\ROK
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\Pacific\Midway
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\Europe\Belgrade
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\Etc\GMT+7
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\Asia\Brunei
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\ROC
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\America\Iqaluit
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\Africa\Lubumbashi
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\Asia\Barnaul
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\America\Swift_Current
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\Australia\Yancowinna
file C:\Users\test22\AppData\Local\Temp\_MEI26322\Cryptodome\Cipher\_chacha20.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\America\Boise
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\Europe\Zurich
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\America\Merida
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\America\North_Dakota\Center
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\msgs\sr.msg
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\Iran
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\Atlantic\South_Georgia
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\Africa\Blantyre
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\Africa\Bangui
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\msgs\ms_my.msg
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\NZ-CHAT
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\Etc\GMT+8
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\America\Santarem
file C:\Users\test22\AppData\Local\Temp\_MEI26322\_lzma.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\Pacific\Chatham
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\Atlantic\Faeroe
file C:\Users\test22\AppData\Local\Temp\_MEI26322\_uuid.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\Africa\Douala
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\Asia\Nicosia
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\Asia\Yangon
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\msgs\zh.msg
file C:\Users\test22\AppData\Local\Temp\_MEI26322\tcl\tzdata\SystemV\PST8PDT