Summary | ZeroBOX

AnneSalt.exe

Suspicious_Script_Bin Generic Malware UPX Malicious Library PE File OS Processor Check PE32
Category Machine Started Completed
FILE s1_win7_x6403_us Aug. 12, 2024, 8:50 a.m. Aug. 12, 2024, 8:56 a.m.
Size 1.7MB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 0dac2872a9c5b21289499db3dcd2f18d
SHA256 bbfda112b2d2742ec593b14cf9a0d2558cedaa24ae89d0cc9b5c94b94705c772
CRC32 90AA740E
ssdeep 49152:EzQfCT0ay5jIRZRQ+uGZU9zQfCT0ay5jIRZRQ+uGZURH9:ZNlIm2U6NlIm2URH9
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

WriteConsoleW

buffer: 1 file(s) moved.
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Set
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Responded=s
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: tlIMedication
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Student Cove Cooperative Gothic Ranging Bits Token Voices
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'tlIMedication' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: DLpTConclusions
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Paperbacks Additional Significantly Uv Permissions Handed Wma
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'DLpTConclusions' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: FyQInvestigators
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Competent Removal Man Lowest Deleted Memo Securely
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'FyQInvestigators' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: UnhxAb
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Counts Tea Brings Emotional Gray Unwrap Dancing
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'UnhxAb' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: rxLfSustained
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Objectives
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'rxLfSustained' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: gUdSa
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Triple Alternatively Compression
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'gUdSa' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: dwxNMedian
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Mattress Showcase Hampton Rotation
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'dwxNMedian' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Set
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Rack=1
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: vRjjChelsea
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Sessions Verde Harbor Treatment Complimentary Dramatic
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'vRjjChelsea' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: atCure
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Eds Stockings Tsunami
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'atCure' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: rVRMaintenance
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Sought
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'rVRMaintenance' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: nMThemselves
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'nMThemselves' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section .ndata
file C:\Users\test22\AppData\Local\Temp\79556\Boxing.pif
cmdline "C:\Windows\System32\cmd.exe" /k move Technique Technique.cmd & Technique.cmd & exit
file C:\Users\test22\AppData\Local\Temp\79556\Boxing.pif
file C:\Users\test22\AppData\Local\Temp\79556\Boxing.pif
wmi SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Time & API Arguments Status Return Repeated

ShellExecuteExW

show_type: 0
filepath_r: cmd
parameters: /k move Technique Technique.cmd & Technique.cmd & exit
filepath: cmd
1 1 0
Time & API Arguments Status Return Repeated

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0
cmdline tasklist
Process injection Process 2076 resumed a thread in remote process 2564
Time & API Arguments Status Return Repeated

NtResumeThread

thread_handle: 0x0000001c
suspend_count: 0
process_identifier: 2564
1 0 0