Summary | ZeroBOX

coreplugin.exe

Generic Malware Malicious Library UPX PE File OS Processor Check PE32
Category Machine Started Completed
FILE s1_win7_x6401 Aug. 21, 2024, 1:24 p.m. Aug. 21, 2024, 1:28 p.m.
Size 1.1MB
Type PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5 9954f7ed32d9a20cda8545c526036143
SHA256 a221b40667002cd19eece4e45e5dbb6f3c3dc1890870cf28ebcca0e4850102f5
CRC32 074A4E4A
ssdeep 24576:VzZhl2UEVJ/TDFjNuNl0S7u3dqoIESs4OUYyPF8P7cMDeB5obaWXRWIWI:VkvbDpNuT0S7u3dtIbYUYyd8PAMC+aiB
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • Generic_Malware_Zero - Generic Malware
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

WriteConsoleW

buffer: 1 file(s) moved.
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Set
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Coins=h
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: WdVBored
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Longer Baking Abstract
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'WdVBored' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: umHsEntities
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Qualify Harbor Slut Thunder
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'umHsEntities' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: RkKinase
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Detail Ms
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'RkKinase' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: bcaCurrent
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Hypothetical Scenario Opposite Sexo
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'bcaCurrent' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: WEAViewers
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Opposed Nv Trance Likelihood Appreciation Island Withdrawal
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'WEAViewers' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: UBInstalled
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Press Publisher
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'UBInstalled' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: coAthletes
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Obtain Murder Free Mtv
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'coAthletes' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: kCLatinas
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Entity Jefferson Description Giants Confident Switching Newbie Officer
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'kCLatinas' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Set
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Momentum=m
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: ZngYoung
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Vermont White Bike Trail
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'ZngYoung' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: ZNebFunctional
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Directory Alerts
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'ZNebFunctional' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: fACSnapshot
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Heaven Efficient Terrace Distance
console_handle: 0x00000007
1 1 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section .ndata
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2080
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x732c2000
process_handle: 0xffffffff
1 0 0
file C:\Users\test22\AppData\Local\Temp\297145\Cultures.pif
cmdline "C:\Windows\System32\cmd.exe" /k move Anytime Anytime.cmd & Anytime.cmd & exit
file C:\Users\test22\AppData\Local\Temp\297145\Cultures.pif
file C:\Users\test22\AppData\Local\Temp\297145\Cultures.pif
wmi SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Time & API Arguments Status Return Repeated

ShellExecuteExW

show_type: 0
filepath_r: cmd
parameters: /k move Anytime Anytime.cmd & Anytime.cmd & exit
filepath: cmd
1 1 0
Time & API Arguments Status Return Repeated

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0
cmdline tasklist
Process injection Process 2652 resumed a thread in remote process 2080
Time & API Arguments Status Return Repeated

NtResumeThread

thread_handle: 0x00000088
suspend_count: 0
process_identifier: 2080
1 0 0
Bkav W32.Common.B12C1A3F
Lionic Trojan.Win32.Autoit.4!c
Cynet Malicious (score: 99)
Cylance Unsafe
VIPRE Trojan.GenericKD.73871457
BitDefender Trojan.GenericKD.73871457
Arcabit Trojan.Generic.D4673061
Symantec Trojan.Gen.MBT
Avast Win32:Malware-gen
Kaspersky HEUR:Trojan.Win32.Autoit.gen
MicroWorld-eScan Trojan.GenericKD.73871457
Emsisoft Trojan.GenericKD.73871457 (B)
F-Secure Trojan.TR/AutoIt.fqhae
DrWeb Trojan.Siggen29.24057
TrendMicro TrojanSpy.Win32.LUMMASTEALER.YXEHRZ
McAfeeD ti!A221B4066700
FireEye Trojan.GenericKD.73871457
Sophos Mal/Generic-S
Avira TR/AutoIt.fqhae
MAX malware (ai score=83)
Antiy-AVL Trojan/Win32.Autoit
Kingsoft Win32.Trojan.Autoit.gen
Gridinsoft Spy.Win32.Gen.tr
Microsoft Trojan:Win32/Wacatac.B!ml
ZoneAlarm HEUR:Trojan.Win32.Autoit.gen
GData Win32.Trojan.Agent.I6HNES
VBA32 TrojanPSW.Lumma
Panda Trj/Chgt.AD
TrendMicro-HouseCall TrojanSpy.Win32.LUMMASTEALER.YXEHRZ
Tencent Win32.Trojan.FalseSign.Eflw
huorong Trojan/Runner.ba
AVG Win32:Malware-gen
CrowdStrike win/malicious_confidence_90% (W)