Summary | ZeroBOX

TMS_C004.exe

Malicious Library UPX MZP Format PE File dll PE32 DllRegisterServer
Category Machine Started Completed
FILE s1_win7_x6403_us Aug. 19, 2024, 2:09 p.m. Aug. 19, 2024, 2:12 p.m.
Size 2.4MB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 5073ab7e1f6081e81b056deb0799a165
SHA256 44b84b99778fc25e9606c4c83334557b326b7a8e4e2c3a38dfe7565493bafa15
CRC32 ADBD2A85
ssdeep 24576:8MkbTpGV41y4VVqPA8g0Ny6gxUeratgoI7AU/nuYGH4UtfWX/CUY29jgyVBYn2Wd:8zYuuAN0fJgIcOtfWvvSRwKD
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • DllRegisterServer_Zero - execute regsvr32.exe
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • mzp_file_format - MZP(Delphi) file format

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section CODE
section DATA
section BSS
packer BobSoft Mini Delphi -> BoB / BobSoft
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 808
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00790000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0
name RT_ICON language LANG_CHINESE filetype dBase IV DBT of @.DBF, block length 512, next free block index 40, next free block 1717962257, next used block 12022528 sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x001d3f30 size 0x000002e8
name RT_GROUP_ICON language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x00268514 size 0x00000014
name RT_VERSION language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x00268528 size 0x00000274
ALYac Gen:Variant.Midie.150933
VIPRE Gen:Variant.Midie.150933
BitDefender Gen:Variant.Midie.150933
Cybereason malicious.e1f608
Arcabit Trojan.Generic.D4614FE5
MicroWorld-eScan Gen:Variant.Midie.150933
Emsisoft Gen:Variant.Midie.150933 (B)
FireEye Gen:Variant.Midie.150933
MAX malware (ai score=87)
GData Gen:Variant.Midie.150933