Summary | ZeroBOX

Sli.ps1

Generic Malware Antivirus
Category Machine Started Completed
FILE s1_win7_x6402 Aug. 10, 2024, 5:38 p.m. Aug. 10, 2024, 5:40 p.m.
Size 4.8KB
Type ASCII text, with very long lines, with CRLF line terminators
MD5 a93c2401d4ef1d66c9ddf7c16d27ba8d
SHA256 cca080b0f9eba9f904059b3f6b70c72dc6091b875bd4432eac53b0c318e5fe58
CRC32 971BA557
ssdeep 96:GS8b0rVBH0PTGjwFnFXeFe/FTRFGFjF7OgPmHAkY1HlL7:Q0BVsGo5KOQUY3
Yara None matched

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

WriteConsoleW

buffer: Exception calling "FromBase64String" with "1" argument(s): "Invalid character i
console_handle: 0x00000023
1 1 0

WriteConsoleW

buffer: n a Base-64 string."
console_handle: 0x0000002f
1 1 0

WriteConsoleW

buffer: At C:\Users\test22\AppData\Local\Temp\Sli.ps1:7 char:136
console_handle: 0x0000003b
1 1 0

WriteConsoleW

buffer: + $s6nGAALtcr38JlHHPHVgg8kTr7nPLkOEtvdHz8z9UIYoBsVsn2q8UxVUm4O2NvhsdYeNHzHg
console_handle: 0x00000047
1 1 0

WriteConsoleW

buffer: HnW8JvRzLu2itfkw8TU4T7VZ05Ld = [Convert]::FromBase64String <<<< ($8i2yj2qiGvo4f
console_handle: 0x00000053
1 1 0

WriteConsoleW

buffer: DvHt0vO8JzjQx8KHaKiV4LnwbMxI0VfYcuqGCv8nkPZiihmtfb6kGHKsHKROyFHnTWdChDEfcvbPlEO
console_handle: 0x0000005f
1 1 0

WriteConsoleW

buffer: tZD2pqvS)
console_handle: 0x0000006b
1 1 0

WriteConsoleW

buffer: + CategoryInfo : NotSpecified: (:) [], MethodInvocationException
console_handle: 0x00000077
1 1 0

WriteConsoleW

buffer: + FullyQualifiedErrorId : DotNetMethodException
console_handle: 0x00000083
1 1 0

WriteConsoleW

buffer: Exception setting "Key": "Value cannot be null.
console_handle: 0x000000a3
1 1 0

WriteConsoleW

buffer: Parameter name: value"
console_handle: 0x000000af
1 1 0

WriteConsoleW

buffer: At C:\Users\test22\AppData\Local\Temp\Sli.ps1:11 char:107
console_handle: 0x000000bb
1 1 0

WriteConsoleW

buffer: + $Mk54c5IIweLJZdAFQEbN5AXxH5ZkkKggnG7NMIQBqgnLv6sP3ygnRiXLX8XHGXXly4VTGmsI
console_handle: 0x000000c7
1 1 0

WriteConsoleW

buffer: oaXoMLCadJRl4sZEjWqekJv3TCM0. <<<< Key = $s6nGAALtcr38JlHHPHVgg8kTr7nPLkOEtvdHz
console_handle: 0x000000d3
1 1 0

WriteConsoleW

buffer: 8z9UIYoBsVsn2q8UxVUm4O2NvhsdYeNHzHgHnW8JvRzLu2itfkw8TU4T7VZ05Ld
console_handle: 0x000000df
1 1 0

WriteConsoleW

buffer: + CategoryInfo : InvalidOperation: (:) [], RuntimeException
console_handle: 0x000000eb
1 1 0

WriteConsoleW

buffer: + FullyQualifiedErrorId : PropertyAssignmentException
console_handle: 0x000000f7
1 1 0

WriteConsoleW

buffer: Exception calling "ReadToEnd" with "0" argument(s): "Padding is invalid and can
console_handle: 0x00000117
1 1 0

WriteConsoleW

buffer: not be removed."
console_handle: 0x00000123
1 1 0

WriteConsoleW

buffer: At C:\Users\test22\AppData\Local\Temp\Sli.ps1:18 char:220
console_handle: 0x0000012f
1 1 0

WriteConsoleW

buffer: + $nnk1vzyCe7SOSS6cMI5qLdSi5ogUoh4yTiJq6Uj16hEwjHWmv9fx46RJ4CwGSdNwCTu9IgFr
console_handle: 0x0000013b
1 1 0

WriteConsoleW

buffer: YDU39VyY2uYPC74n1AV4YcIs3It0 = $KTCYZgCqHbfSZDGbH0D03tZ8IOmDCMQkwcSQIWdEqsviVKa
console_handle: 0x00000147
1 1 0

WriteConsoleW

buffer: 5RYllBNIQu4QLtynvWuVnkq2mnz9aygLxeRme04ji4BWeF2LrFzX2.ReadToEnd <<<< ()
console_handle: 0x00000153
1 1 0

WriteConsoleW

buffer: + CategoryInfo : NotSpecified: (:) [], MethodInvocationException
console_handle: 0x0000015f
1 1 0

WriteConsoleW

buffer: + FullyQualifiedErrorId : DotNetMethodException
console_handle: 0x0000016b
1 1 0

WriteConsoleW

buffer: Exception calling "Close" with "0" argument(s): "Padding is invalid and cannot
console_handle: 0x0000001b
1 1 0

WriteConsoleW

buffer: be removed."
console_handle: 0x00000027
1 1 0

WriteConsoleW

buffer: At C:\Users\test22\AppData\Local\Temp\Sli.ps1:19 char:112
console_handle: 0x00000033
1 1 0

WriteConsoleW

buffer: + $KTCYZgCqHbfSZDGbH0D03tZ8IOmDCMQkwcSQIWdEqsviVKa5RYllBNIQu4QLtynvWuVnkq2m
console_handle: 0x0000003f
1 1 0

WriteConsoleW

buffer: nz9aygLxeRme04ji4BWeF2LrFzX2.Close <<<< ()
console_handle: 0x0000004b
1 1 0

WriteConsoleW

buffer: + CategoryInfo : NotSpecified: (:) [], MethodInvocationException
console_handle: 0x00000057
1 1 0

WriteConsoleW

buffer: + FullyQualifiedErrorId : DotNetMethodException
console_handle: 0x00000067
1 1 0

WriteConsoleW

buffer: Exception calling "Close" with "0" argument(s): "Padding is invalid and cannot
console_handle: 0x00000087
1 1 0

WriteConsoleW

buffer: be removed."
console_handle: 0x00000093
1 1 0

WriteConsoleW

buffer: At C:\Users\test22\AppData\Local\Temp\Sli.ps1:20 char:112
console_handle: 0x0000009f
1 1 0

WriteConsoleW

buffer: + $QYgFTccLaioNHIxr07pqJk6C9dpkhmYcQY7WdEEnlguwoGDdAdB5sNE5sd5gns4oTMwjabOW
console_handle: 0x000000ab
1 1 0

WriteConsoleW

buffer: 2CF2q9O29LkDktjDUC3z8YztMFdb.Close <<<< ()
console_handle: 0x000000b7
1 1 0

WriteConsoleW

buffer: + CategoryInfo : NotSpecified: (:) [], MethodInvocationException
console_handle: 0x000000c3
1 1 0

WriteConsoleW

buffer: + FullyQualifiedErrorId : DotNetMethodException
console_handle: 0x000000cf
1 1 0

WriteConsoleW

buffer: Invoke-Expression : Cannot bind argument to parameter 'Command' because it is n
console_handle: 0x000000ef
1 1 0

WriteConsoleW

buffer: ull.
console_handle: 0x000000fb
1 1 0

WriteConsoleW

buffer: At C:\Users\test22\AppData\Local\Temp\Sli.ps1:26 char:18
console_handle: 0x00000107
1 1 0

WriteConsoleW

buffer: + Invoke-Expression <<<< $MldP3n80MnaID8eYPyu5oHIITb2mu1A028LhQIlOzEbdZO0qykd4
console_handle: 0x00000113
1 1 0

WriteConsoleW

buffer: NYbFd5wrUm5knJf4VxHGMf6k65jFKcnKo5NDwGEkMutN9qqP
console_handle: 0x0000011f
1 1 0

WriteConsoleW

buffer: + CategoryInfo : InvalidData: (:) [Invoke-Expression], ParameterB
console_handle: 0x0000012b
1 1 0

WriteConsoleW

buffer: indingValidationException
console_handle: 0x00000137
1 1 0

WriteConsoleW

buffer: + FullyQualifiedErrorId : ParameterArgumentValidationErrorNullNotAllowed,M
console_handle: 0x00000143
1 1 0

WriteConsoleW

buffer: icrosoft.PowerShell.Commands.InvokeExpressionCommand
console_handle: 0x0000014f
1 1 0
Time & API Arguments Status Return Repeated

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003cf2c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003cf2c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003cf2c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003cf2c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003cf2c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003cf2c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptGenKey

crypto_handle: 0x003cf2c0
algorithm_identifier: 0x00006610 ()
flags: 1
key: f ÎgäÜA«'¿òÏ BES¬fð1ڞ54ˆµ¹b)
provider_handle: 0x003e4508
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003cf2c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 8
1 1 0

CryptExportKey

buffer: f ÎgäÜA«'¿òÏ BES¬fð1ڞ54ˆµ¹b)
crypto_handle: 0x003cf2c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 8
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003cee80
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003cee80
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026ab000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026bf000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 1703936
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x062b0000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06410000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06411000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06412000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06413000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06414000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02689000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06150000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06152000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06153000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06154000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06155000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 16384
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06415000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 69632
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06419000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0642a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05431000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 327680
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7ef40000
allocation_type: 1056768 (MEM_RESERVE|MEM_TOP_DOWN)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7ef40000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7ef40000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 65536
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7ef30000
allocation_type: 1056768 (MEM_RESERVE|MEM_TOP_DOWN)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7ef30000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06160000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02942000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0642b000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0642c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06156000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0642d000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06157000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0642e000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0642f000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06430000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06431000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3008
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0268d000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0