Summary | ZeroBOX

ransom.exe

Emotet Gen1 Icarus Stealer Generic Malware Malicious Library UPX Malicious Packer Admin Tool (Sysinternals etc ...) Anti_VM ftp PE64 dll PE File OS Processor Check ZIP Format DLL DllRegisterServer
Category Machine Started Completed
FILE s1_win7_x6403_us June 14, 2024, 9:22 a.m. June 14, 2024, 9:24 a.m.
Size 18.8MB
Type PE32+ executable (console) x86-64, for MS Windows
MD5 425a94ea0db7c1fb84b3abeaed25784b
SHA256 ba1d624f212e543b90ef10bf95d86063055ff7b0c7f15eb87a816212d70c6006
CRC32 A7BC16C5
ssdeep 393216:XyQtsTt9JJWQsUcR4Nzjk3me8cGfdvIqoJdUUnM4i2Z:iQtshjYQFbaW5FvI7E2LV
Yara
  • IsPE64 - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • ftp_command - ftp command
  • Icarus_Stealer - Icarus Stealer
  • UPX_Zero - UPX packed file
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch
45.33.6.223 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
file C:\Users\test22\AppData\Local\Temp\_MEI20802\python3.dll
file C:\Users\test22\AppData\Local\Temp\_MEI20802\VCRUNTIME140_1.dll
file C:\Users\test22\AppData\Local\Temp\_MEI20802\libssl-3.dll
file C:\Users\test22\AppData\Local\Temp\_MEI20802\pywin32_system32\pythoncom311.dll
file C:\Users\test22\AppData\Local\Temp\_MEI20802\libffi-8.dll
file C:\Users\test22\AppData\Local\Temp\_MEI20802\VCRUNTIME140.dll
file C:\Users\test22\AppData\Local\Temp\_MEI20802\libcrypto-3.dll
file C:\Users\test22\AppData\Local\Temp\_MEI20802\Pythonwin\mfc140u.dll
file C:\Users\test22\AppData\Local\Temp\_MEI20802\pywin32_system32\pywintypes311.dll
file C:\Users\test22\AppData\Local\Temp\_MEI20802\python311.dll
section {u'size_of_data': u'0x0000f000', u'virtual_address': u'0x00049000', u'entropy': 7.350146232003548, u'name': u'.rsrc', u'virtual_size': u'0x0000ef8c'} entropy 7.350146232 description A section with a high entropy has been found
host 45.33.6.223
file C:\Users\test22\AppData\Local\Temp\_MEI20802\pytz\zoneinfo\Asia\Yangon
file C:\Users\test22\AppData\Local\Temp\_MEI20802\pytz\zoneinfo\Australia\ACT
file C:\Users\test22\AppData\Local\Temp\_MEI20802\tzdata\zoneinfo\Pacific\Kanton
file C:\Users\test22\AppData\Local\Temp\_MEI20802\tzdata\zoneinfo\Europe\Kiev
file C:\Users\test22\AppData\Local\Temp\_MEI20802\pytz\zoneinfo\Israel
file C:\Users\test22\AppData\Local\Temp\_MEI20802\tzdata\zoneinfo\Asia\Yekaterinburg
file C:\Users\test22\AppData\Local\Temp\_MEI20802\tzdata\zoneinfo\Asia\Yerevan
file C:\Users\test22\AppData\Local\Temp\_MEI20802\tzdata\zoneinfo\America\Argentina\Tucuman
file C:\Users\test22\AppData\Local\Temp\_MEI20802\pytz\zoneinfo\Asia\Tashkent
file C:\Users\test22\AppData\Local\Temp\_MEI20802\tzdata\zoneinfo\Pacific\Galapagos
file C:\Users\test22\AppData\Local\Temp\_MEI20802\pytz\zoneinfo\US\Arizona
file C:\Users\test22\AppData\Local\Temp\_MEI20802\tzdata\zoneinfo\America\Menominee
file C:\Users\test22\AppData\Local\Temp\_MEI20802\tzdata\zoneinfo\Europe\Budapest
file C:\Users\test22\AppData\Local\Temp\_MEI20802\tzdata\zoneinfo\Pacific\Kiritimati
file C:\Users\test22\AppData\Local\Temp\_MEI20802\pytz\zoneinfo\Canada\Yukon
file C:\Users\test22\AppData\Local\Temp\_MEI20802\tzdata\zoneinfo\Etc\GMT+5
file C:\Users\test22\AppData\Local\Temp\_MEI20802\tzdata\zoneinfo\Asia\Jerusalem
file C:\Users\test22\AppData\Local\Temp\_MEI20802\tzdata\zoneinfo\America\St_Vincent
file C:\Users\test22\AppData\Local\Temp\_MEI20802\pytz\zoneinfo\Pacific\Palau
file C:\Users\test22\AppData\Local\Temp\_MEI20802\tzdata\zoneinfo\ROK
file C:\Users\test22\AppData\Local\Temp\_MEI20802\setuptools-65.5.0.dist-info\METADATA
file C:\Users\test22\AppData\Local\Temp\_MEI20802\tzdata\zoneinfo\Europe\Sofia
file C:\Users\test22\AppData\Local\Temp\_MEI20802\pytz\zoneinfo\America\Santiago
file C:\Users\test22\AppData\Local\Temp\_MEI20802\pytz\zoneinfo\Europe\Budapest
file C:\Users\test22\AppData\Local\Temp\_MEI20802\pytz\zoneinfo\Africa\Gaborone
file C:\Users\test22\AppData\Local\Temp\_MEI20802\tzdata\zoneinfo\Europe\Tallinn
file C:\Users\test22\AppData\Local\Temp\_MEI20802\tzdata\zoneinfo\Australia\Lindeman
file C:\Users\test22\AppData\Local\Temp\_MEI20802\tzdata\zoneinfo\Asia\Ujung_Pandang
file C:\Users\test22\AppData\Local\Temp\_MEI20802\pytz\zoneinfo\Europe\Belfast
file C:\Users\test22\AppData\Local\Temp\_MEI20802\tzdata\zoneinfo\Asia\Tomsk
file C:\Users\test22\AppData\Local\Temp\_MEI20802\pytz\zoneinfo\zonenow.tab
file C:\Users\test22\AppData\Local\Temp\_MEI20802\tzdata\zoneinfo\Atlantic\Bermuda
file C:\Users\test22\AppData\Local\Temp\_MEI20802\tzdata\zoneinfo\Asia\Pontianak
file C:\Users\test22\AppData\Local\Temp\_MEI20802\pytz\zoneinfo\America\Vancouver
file C:\Users\test22\AppData\Local\Temp\_MEI20802\pytz\zoneinfo\Asia\Magadan
file C:\Users\test22\AppData\Local\Temp\_MEI20802\tzdata\zoneinfo\America\Caracas
file C:\Users\test22\AppData\Local\Temp\_MEI20802\tzdata\zoneinfo\Asia\Thimbu
file C:\Users\test22\AppData\Local\Temp\_MEI20802\tzdata\zoneinfo\Asia\Qyzylorda
file C:\Users\test22\AppData\Local\Temp\_MEI20802\tzdata\zoneinfo\Europe\Bucharest
file C:\Users\test22\AppData\Local\Temp\_MEI20802\pytz\zoneinfo\Asia\Hebron
file C:\Users\test22\AppData\Local\Temp\_MEI20802\tzdata\zoneinfo\Asia\Vientiane
file C:\Users\test22\AppData\Local\Temp\_MEI20802\tzdata\zoneinfo\zone1970.tab
file C:\Users\test22\AppData\Local\Temp\_MEI20802\pytz\zoneinfo\America\Argentina\Cordoba
file C:\Users\test22\AppData\Local\Temp\_MEI20802\pytz\zoneinfo\Asia\Atyrau
file C:\Users\test22\AppData\Local\Temp\_MEI20802\tzdata\zoneinfo\Europe\Ulyanovsk
file C:\Users\test22\AppData\Local\Temp\_MEI20802\tzdata\zoneinfo\America\Cuiaba
file C:\Users\test22\AppData\Local\Temp\_MEI20802\tzdata-2024.1.dist-info\METADATA
file C:\Users\test22\AppData\Local\Temp\_MEI20802\pytz\zoneinfo\America\Costa_Rica
file C:\Users\test22\AppData\Local\Temp\_MEI20802\tzdata\zoneinfo\Africa\Dar_es_Salaam
file C:\Users\test22\AppData\Local\Temp\_MEI20802\pytz\zoneinfo\Pacific\Pohnpei