Summary | ZeroBOX

joffer2.exe

Generic Malware Admin Tool (Sysinternals etc ...) UPX PE File DLL PE32
Category Machine Started Completed
FILE s1_win7_x6403_us Sept. 2, 2024, 9:52 a.m. Sept. 2, 2024, 9:59 a.m.
Size 6.3MB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 4386df2790a9752e9cf0424dca91ad15
SHA256 e2f0e525c66dba847bedf887398405348159ce607bc6cc826bef73651fd7135d
CRC32 11308678
ssdeep 49152:B0QJDHck3aW3sg1Kptd473sgCMMqfHFIUYIIKdkiT1dEKIOLxlbid:B9JLckf31QtG3sghMqfH+V81ddLxl+d
Yara
  • Admin_Tool_IN_Zero - Admin Tool Sysinternals
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • Generic_Malware_Zero - Generic Malware
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
sevxv17pt.top 195.133.13.230
IP Address Status Action
164.124.101.2 Active Moloch
195.133.13.230 Active Moloch

suspicious_features POST method with no referer header suspicious_request POST http://sevxv17pt.top/v1/upload.php
request POST http://sevxv17pt.top/v1/upload.php
request POST http://sevxv17pt.top/v1/upload.php
domain sevxv17pt.top description Generic top level domain TLD
file C:\Users\test22\AppData\Local\Temp\BawuYOCdGNZiqevXAMeS.dll
file C:\Users\test22\AppData\Local\Temp\service123.exe
section {u'size_of_data': u'0x000e2400', u'virtual_address': u'0x00b39000', u'entropy': 6.841635613240144, u'name': u'.reloc', u'virtual_size': u'0x000e22dc'} entropy 6.84163561324 description A section with a high entropy has been found
Elastic malicious (high confidence)
ALYac Generic.Dacic.3683.930236D9
VIPRE Generic.Dacic.3683.930236D9
K7AntiVirus Password-Stealer ( 0054cf561 )
BitDefender Generic.Dacic.3683.930236D9
K7GW Password-Stealer ( 0054cf561 )
Arcabit Generic.Dacic.3683.930236D9
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/PSW.Agent.OGR
APEX Malicious
Avast Win32:Evo-gen [Trj]
ClamAV Win.Malware.Barys-10032866-0
Kaspersky VHO:Trojan-PSW.Win32.Stealer.gen
MicroWorld-eScan Generic.Dacic.3683.930236D9
Rising Trojan.CryptBot!8.19865 (TFE:5:du8Y4XG1zuF)
Emsisoft Generic.Dacic.3683.930236D9 (B)
FireEye Generic.Dacic.3683.930236D9
Google Detected
MAX malware (ai score=88)
Microsoft Trojan:Win32/CryptBot.CCJD!MTB
ZoneAlarm VHO:Trojan-PSW.Win32.Stealer.gen
GData Win32.Trojan.PSE.1D64ECY
AhnLab-V3 Trojan/Win.CryptBot.C5659071
BitDefenderTheta Gen:NN.ZexaF.36812.@@Z@aCOEHzb
Malwarebytes Spyware.Stealer
Ikarus Trojan-PSW.Agent
Panda Trj/Genetic.gen
Fortinet W32/Agent.OGR!tr
AVG Win32:Evo-gen [Trj]
CrowdStrike win/malicious_confidence_70% (D)