Summary | ZeroBOX

66d1b31955f50_SunshineSolving.exe

Generic Malware Malicious Library UPX ftp PE File OS Processor Check PE32
Category Machine Started Completed
FILE s1_win7_x6403_us Sept. 2, 2024, 10:11 a.m. Sept. 2, 2024, 10:18 a.m.
Size 1.7MB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 0a34380175bb4da2cce136e0cb3d3e04
SHA256 1ef7ccb345b2132b8e1a38bdef87dd47a0a0588603703ee63a201a9a8b5ba51d
CRC32 A5646B75
ssdeep 24576:w92WI6QAqC7rFYDkW/rdEGMcDqDc21uOGF7h/baPqprTKRpm5WfKR6bnKkXbESI9:wQDLDDkw1McDqDRuOGF9Sw5WC0zH
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

WriteConsoleW

buffer: 1 file(s) moved.
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Set
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Freight=5
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: dAStating
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Opinions Yale Confident Alberta Green Fridge Believes Awarded
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'dAStating' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: MMSer
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Victoria
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'MMSer' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: xTMZFormal
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Burner Enhancements Put Related Thrown Statewide Muslim
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'xTMZFormal' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: oCcGsm
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Nato Basket Simpson Cabin Merger
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'oCcGsm' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: ssSingle
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'ssSingle' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Set
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Biol=Y
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: qvEvent
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Moderate Losing Bless Kathy Lately
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'qvEvent' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: ngmBMainland
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Analyzed Conservation Exercises Nature
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'ngmBMainland' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: aSECommitment
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Quizzes Mardi Agricultural Addressed Junction Off
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'aSECommitment' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: IRoUWhale
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Testimonials Involve Tour Benjamin Gothic Feat Sport
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'IRoUWhale' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: NRBacking
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Oops Runner Girls Speakers Passive Mostly At
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'NRBacking' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: xQCKen
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Convicted Subtle Lloyd Southampton
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'xQCKen' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section .ndata
file C:\Users\test22\AppData\Local\Temp\800157\Tapes.pif
cmdline "C:\Windows\System32\cmd.exe" /k move Tb Tb.bat & Tb.bat & exit
file C:\Users\test22\AppData\Local\Temp\800157\Tapes.pif
file C:\Users\test22\AppData\Local\Temp\800157\Tapes.pif
wmi SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Time & API Arguments Status Return Repeated

ShellExecuteExW

show_type: 0
filepath_r: cmd
parameters: /k move Tb Tb.bat & Tb.bat & exit
filepath: cmd
1 1 0
section {u'size_of_data': u'0x00003400', u'virtual_address': u'0x004b4000', u'entropy': 7.936259531347089, u'name': u'.reloc', u'virtual_size': u'0x0000320e'} entropy 7.93625953135 description A section with a high entropy has been found
Time & API Arguments Status Return Repeated

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0
cmdline "C:\Windows\System32\cmd.exe" /k move Tb Tb.bat & Tb.bat & exit
cmdline tasklist
cmdline cmd /k move Tb Tb.bat & Tb.bat & exit
cmdline cmd /c copy /b ..\Rt + ..\Core + ..\Created + ..\Reg + ..\Aa + ..\Toe + ..\Interested + ..\Opera + ..\Instant + ..\Findings + ..\Gave + ..\Hk + ..\Pollution m
Bkav W32.AIDetectMalware
Elastic malicious (high confidence)
Cylance Unsafe
tehtris Generic.Malware
Kaspersky HEUR:Backdoor.Win32.Agent.gen
McAfeeD ti!1EF7CCB345B2
Sophos Mal/Generic-S
Kingsoft Win32.Troj.Unknown.a
Microsoft Trojan:Win32/Casdet!rfn
ZoneAlarm HEUR:Backdoor.Win32.Agent.gen
DeepInstinct MALICIOUS
huorong Trojan/BAT.Agent.cv
MaxSecure Trojan.Malware.121218.susgen
CrowdStrike win/grayware_confidence_100% (D)
Process injection Process 2160 resumed a thread in remote process 2676
Time & API Arguments Status Return Repeated

NtResumeThread

thread_handle: 0x00000084
suspend_count: 0
process_identifier: 2676
1 0 0