Summary | ZeroBOX

njhor.exe

backdoor njRAT Generic Malware Antivirus PE File PE32 .NET EXE PowerShell
Category Machine Started Completed
FILE s1_win7_x6401 April 3, 2024, 7:19 a.m. April 3, 2024, 7:39 a.m.
Size 197.0KB
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 20d4f344fa2a4ad4cb48d90abfbab41f
SHA256 8c3b889f84864da05897622f9e90a1a860d9587296ae37daba5bf0394a5283fe
CRC32 13D2C742
ssdeep 3072:p/W1v3s+XvNby4I81B3pmL49sO13ENzB6dZ4ydThn6Yb4reE8xdoY92XF:p/uxXHZhswENB6k8v4rv87r921
Yara
  • PE_Header_Zero - PE File Signature
  • Is_DotNET_EXE - (no description)
  • IsPE32 - (no description)
  • Win_Backdoor_njRAT_Zero - Win Backdoor njRAT

IP Address Status Action
104.20.67.143 Active Moloch
164.124.101.2 Active Moloch
3.127.181.115 Active Moloch
3.67.62.142 Active Moloch

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49175 -> 104.20.67.143:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined
UDP 192.168.56.101:54148 -> 164.124.101.2:53 2022642 ET INFO DNS Query to a *.ngrok domain (ngrok.io) Misc activity
UDP 192.168.56.101:53004 -> 164.124.101.2:53 2022642 ET INFO DNS Query to a *.ngrok domain (ngrok.io) Misc activity

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49175
104.20.67.143:443
C=US, O=Cloudflare, Inc., CN=Cloudflare Inc RSA CA-2 C=US, ST=California, L=San Francisco, O=Cloudflare, Inc., CN=sni.cloudflaressl.com c7:af:cc:81:4d:27:d1:4c:7c:f4:bf:5d:55:9d:80:50:3b:6f:6c:cd

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameA

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

WriteConsoleW

buffer: The term 'Set-MpPreference' is not recognized as the name of a cmdlet, function
console_handle: 0x00000023
1 1 0

WriteConsoleW

buffer: , script file, or operable program. Check the spelling of the name, or if a pat
console_handle: 0x0000002f
1 1 0

WriteConsoleW

buffer: h was included, verify that the path is correct and try again.
console_handle: 0x0000003b
1 1 0

WriteConsoleW

buffer: At line:1 char:17
console_handle: 0x00000047
1 1 0

WriteConsoleW

buffer: + Set-MpPreference <<<< -DisableRealtimeMonitoring $true
console_handle: 0x00000053
1 1 0

WriteConsoleW

buffer: + CategoryInfo : ObjectNotFound: (Set-MpPreference:String) [], Co
console_handle: 0x0000005f
1 1 0

WriteConsoleW

buffer: mmandNotFoundException
console_handle: 0x0000006b
1 1 0

WriteConsoleW

buffer: + FullyQualifiedErrorId : CommandNotFoundException
console_handle: 0x00000077
1 1 0

WriteConsoleW

buffer: SERVICE_NAME: windefend TYPE : 20 WIN32_SHARE_PROCESS STATE : 1 STOPPED WIN32_EXIT_CODE : 1077 (0x435) SERVICE_EXIT_CODE : 0 (0x0) CHECKPOINT : 0x0 WAIT_HINT : 0x0
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: [SC] ControlService FAILED 1062: The service has not been started.
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: [SC] DeleteService SUCCESS
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: The operation completed successfully.
console_handle: 0x00000007
1 1 0
Time & API Arguments Status Return Repeated

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00411d40
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004122c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004122c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004122c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00411e40
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00411e40
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00411e40
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00411e40
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00411e40
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00411e40
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00411900
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00411900
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00411900
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004122c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004122c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004122c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004121c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004122c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004122c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004122c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004122c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004122c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004122c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004122c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00411a40
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00411a40
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00411a40
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00411a40
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00411a40
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00411a40
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00411a40
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00411a40
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00411a40
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00411a40
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00411a40
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00411a40
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00411a40
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00411a40
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004126c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004126c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004126c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004126c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004126c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004126c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004126c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004126c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section .sdata
suspicious_features GET method with no useragent header suspicious_request GET https://pastebin.com/raw/g96Z0CYj
request GET https://pastebin.com/raw/g96Z0CYj
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 2552
region_size: 2228224
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00890000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2552
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00a70000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2552
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72891000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2552
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0047a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2552
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72892000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2552
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00472000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2552
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00482000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2552
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00483000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2552
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x004bb000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2552
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x004b7000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2552
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0048c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2552
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04520000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2552
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x004aa000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2552
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x004a2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2552
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00484000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2552
region_size: 24576
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04521000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2552
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0048a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2552
region_size: 12288
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04527000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2552
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0452a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2552
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00485000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2552
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00486000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2552
region_size: 12288
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0452b000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2552
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0452e000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2552
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00496000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2552
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0049a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2552
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00497000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2552
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00487000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2552
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0452f000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2552
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04c90000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2552
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0047b000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2552
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00489000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2552
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04c91000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2936
region_size: 655360
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02770000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2936
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x027d0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2936
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x722e1000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2936
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x021aa000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2936
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x722e2000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2936
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x021a2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2936
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x021f2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2936
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x027d1000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2936
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x027d2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2936
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0221a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2936
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x021f3000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2936
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x021f4000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2936
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0222b000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2936
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02227000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2936
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x021ab000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2936
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02212000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2936
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02225000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2936
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x021f5000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0
file C:\Users\test22\AppData\Local\Temp\dllhost.exe
file C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk
cmdline powershell Set-MpPreference -DisableRealtimeMonitoring $true
file C:\Users\test22\AppData\Local\Temp\dllhost.exe
file C:\Users\test22\AppData\Local\Temp\dllhost.exe
Time & API Arguments Status Return Repeated

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0
cmdline reg ADD HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System /v EnableLUA /t REG_DWORD /d 0 /f
cmdline sc delete windefend
cmdline sc stop windefend
cmdline sc query windefend
Time & API Arguments Status Return Repeated

ControlService

service_handle: 0x0042b730
service_name: windefend
control_code: 1
0 0
Time & API Arguments Status Return Repeated

NtQuerySystemInformation

information_class: 8 (SystemProcessorPerformanceInformation)
1 0 0
description njhor.exe tried to sleep 2728177 seconds, actually delayed analysis time by 2728177 seconds
Process injection Process 2552 injected into non-child 2552
Time & API Arguments Status Return Repeated

WriteProcessMemory

buffer: N8&((*
base_address: 0x00402060
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: :8&
base_address: 0x00402074
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: F8&þ ( *
base_address: 0x00402084
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: &8&
base_address: 0x00402098
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: &8&
base_address: 0x004020a4
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: N8&( ( *
base_address: 0x004020b8
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: :8&
base_address: 0x004020cc
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: F8&þ ( *
base_address: 0x004020dc
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: &8&
base_address: 0x004020f0
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: &8&
base_address: 0x004020fc
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: J8&~o *
base_address: 0x004021dc
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: J8&~o *
base_address: 0x004021f0
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: J8&~o *
base_address: 0x00402204
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: J8&~o *
base_address: 0x00402218
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: :8&
base_address: 0x0040222c
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: &8&
base_address: 0x0040223c
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: &8&
base_address: 0x00402248
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: R8&((
base_address: 0x00402254
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: :8&
base_address: 0x0040226c
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: ^8& (#($
base_address: 0x0040227c
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: :8&
base_address: 0x00402294
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: 0!8&
base_address: 0x004022a4
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: >8&
base_address: 0x004022d4
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: N8&(&('*
base_address: 0x004022e4
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: J8&þ ( *
base_address: 0x004022f8
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: V8&þ þ (
base_address: 0x0040230c
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: &8&
base_address: 0x00402324
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: &8&
base_address: 0x00402330
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: F8&þ ( *
base_address: 0x0040233c
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: J8&þ
base_address: 0x00402350
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: J8&þ ( *
base_address: 0x00402364
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: F8&þ ( *
base_address: 0x00402378
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: :8&
base_address: 0x0040238c
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: F8&þ ( *
base_address: 0x0040239c
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: š8&~ Œ:
base_address: 0x004023d0
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: N8&(ª( *
base_address: 0x004023f8
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: &8&
base_address: 0x0040240c
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: &8&
base_address: 0x00402418
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: N8&(2(5*
base_address: 0x00402444
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: 0{ 8&
base_address: 0x00402458
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: 0³8&
base_address: 0x00402ee0
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: :8&
base_address: 0x00402fa0
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: &8&
base_address: 0x00402fb0
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: &8&
base_address: 0x00402fbc
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: F8&þ ( *
base_address: 0x00402fc8
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: J8&þ (" *
base_address: 0x00402fdc
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: :8&
base_address: 0x00402ff0
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: V8&þ þ o$
base_address: 0x00403000
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: V8&þ þ o%
base_address: 0x00403018
process_identifier: 2552
process_handle: 0x000001d8
1 1 0
file C:\Windows\System32\ie4uinit.exe
file C:\Program Files\Windows Sidebar\sidebar.exe
file C:\Windows\System32\WindowsAnytimeUpgradeUI.exe
file C:\Windows\System32\xpsrchvw.exe
file C:\Windows\System32\displayswitch.exe
file C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe
file C:\Windows\System32\mblctr.exe
file C:\Windows\System32\mstsc.exe
file C:\Windows\System32\SnippingTool.exe
file C:\Windows\System32\SoundRecorder.exe
file C:\Windows\System32\dfrgui.exe
file C:\Windows\System32\msinfo32.exe
file C:\Windows\System32\rstrui.exe
file C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe
file C:\Program Files\Windows Journal\Journal.exe
file C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
file C:\Windows\System32\MdSched.exe
file C:\Windows\System32\msconfig.exe
file C:\Windows\System32\recdisc.exe
file C:\Windows\System32\msra.exe
description attempts to disable user access control registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA
Time & API Arguments Status Return Repeated

NtResumeThread

thread_handle: 0x000000d0
suspend_count: 1
process_identifier: 2552
1 0 0

NtResumeThread

thread_handle: 0x00000160
suspend_count: 1
process_identifier: 2552
1 0 0

WriteProcessMemory

buffer: N8&((*
base_address: 0x00402060
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: :8&
base_address: 0x00402074
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: F8&þ ( *
base_address: 0x00402084
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: &8&
base_address: 0x00402098
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: &8&
base_address: 0x004020a4
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: N8&( ( *
base_address: 0x004020b8
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: :8&
base_address: 0x004020cc
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: F8&þ ( *
base_address: 0x004020dc
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: &8&
base_address: 0x004020f0
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: &8&
base_address: 0x004020fc
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: J8&~o *
base_address: 0x004021dc
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: J8&~o *
base_address: 0x004021f0
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: J8&~o *
base_address: 0x00402204
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: J8&~o *
base_address: 0x00402218
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: :8&
base_address: 0x0040222c
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: &8&
base_address: 0x0040223c
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: &8&
base_address: 0x00402248
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: R8&((
base_address: 0x00402254
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: :8&
base_address: 0x0040226c
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: ^8& (#($
base_address: 0x0040227c
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: :8&
base_address: 0x00402294
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: 0!8&
base_address: 0x004022a4
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: >8&
base_address: 0x004022d4
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: N8&(&('*
base_address: 0x004022e4
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: J8&þ ( *
base_address: 0x004022f8
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: V8&þ þ (
base_address: 0x0040230c
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: &8&
base_address: 0x00402324
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: &8&
base_address: 0x00402330
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: F8&þ ( *
base_address: 0x0040233c
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: J8&þ
base_address: 0x00402350
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: J8&þ ( *
base_address: 0x00402364
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: F8&þ ( *
base_address: 0x00402378
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: :8&
base_address: 0x0040238c
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: F8&þ ( *
base_address: 0x0040239c
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: š8&~ Œ:
base_address: 0x004023d0
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: N8&(ª( *
base_address: 0x004023f8
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: &8&
base_address: 0x0040240c
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: &8&
base_address: 0x00402418
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: N8&(2(5*
base_address: 0x00402444
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: 0{ 8&
base_address: 0x00402458
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: 0³8&
base_address: 0x00402ee0
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: :8&
base_address: 0x00402fa0
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: &8&
base_address: 0x00402fb0
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: &8&
base_address: 0x00402fbc
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: F8&þ ( *
base_address: 0x00402fc8
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: J8&þ (" *
base_address: 0x00402fdc
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: :8&
base_address: 0x00402ff0
process_identifier: 2552
process_handle: 0x000001d8
1 1 0

WriteProcessMemory

buffer: V8&þ þ o$
base_address: 0x00403000
process_identifier: 2552
process_handle: 0x000001d8
1 1 0
dead_host 192.168.56.101:49191
dead_host 3.67.62.142:13052
dead_host 192.168.56.101:49192
dead_host 192.168.56.101:49196
dead_host 192.168.56.101:49176
dead_host 192.168.56.101:49184
dead_host 192.168.56.101:49180
dead_host 192.168.56.101:49193
dead_host 192.168.56.101:49188
dead_host 192.168.56.101:49197
dead_host 192.168.56.101:49177
dead_host 192.168.56.101:49185
dead_host 192.168.56.101:49181
dead_host 192.168.56.101:49194
dead_host 192.168.56.101:49189
dead_host 192.168.56.101:49198
dead_host 192.168.56.101:49178
dead_host 192.168.56.101:49186
dead_host 192.168.56.101:49182
dead_host 192.168.56.101:49195
dead_host 3.127.181.115:13052
dead_host 192.168.56.101:49190
dead_host 192.168.56.101:49199
dead_host 192.168.56.101:49179
dead_host 192.168.56.101:49187
dead_host 192.168.56.101:49183