Summary | ZeroBOX

index.php

NSIS Generic Malware Malicious Library UPX PE File OS Processor Check PE32
Category Machine Started Completed
FILE s1_win7_x6403_us April 30, 2024, 9:47 a.m. April 30, 2024, 9:49 a.m.
Size 654.6KB
Type PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5 87f8958f40e487f7d816cd1aaf52fa84
SHA256 546d7f26d8b2a42b4a917e3642c2fffa89a1be3a41795da4ccf8afb2e0f417e8
CRC32 C9DE7D62
ssdeep 12288:IXAx/2a0CTmgQ9AlrsgsdNUUhfjersFwz3NTwBOuCUxQQZNIuJ3M7THqAi4dD4:IXAx/2z9CrsgsTUU1ioEnuCUxQQZN9Je
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • NSIS_Installer - Null Soft Installer
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

WriteConsoleW

buffer: 1 file(s) moved.
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Set
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Colleague=9
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: cXSwap
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Availability Documentcreatetextnode
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'cXSwap' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: rOvKSubsidiary
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'rOvKSubsidiary' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: awPrecise
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'awPrecise' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: LkRDClan
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Nevertheless Latin Diameter Modifications Occur
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'LkRDClan' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: OIPQMinute
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Era German Tribunal Apt Index Invisible
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'OIPQMinute' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: xnWWInline
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Belongs
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'xnWWInline' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: vReGovernmental
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Preference Public Israeli Rocket Promising
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'vReGovernmental' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: oFWAt
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Informative Pi Ing
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'oFWAt' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Set
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Proper=7
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: JOzRPrefers
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Pharmacy
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'JOzRPrefers' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: ruBFast
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Sorts Resistant Described
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'ruBFast' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: TFChi
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Fingering Valve Enrollment Briefs Instant Booty T Jersey
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'TFChi' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files>
console_handle: 0x00000007
1 1 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section .ndata
file C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\55118595\Weblog.pif
cmdline "C:\Windows\System32\cmd.exe" /k move Eva Eva.cmd & Eva.cmd & exit
file C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\55118595\Weblog.pif
file C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\55118595\Weblog.pif
wmi SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Time & API Arguments Status Return Repeated

ShellExecuteExW

show_type: 0
filepath_r: cmd
parameters: /k move Eva Eva.cmd & Eva.cmd & exit
filepath: cmd
1 1 0
Time & API Arguments Status Return Repeated

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0
cmdline ping -n 5 127.0.0.1
cmdline tasklist
Process injection Process 2076 resumed a thread in remote process 2568
Time & API Arguments Status Return Repeated

NtResumeThread

thread_handle: 0x00000084
suspend_count: 0
process_identifier: 2568
1 0 0