Summary | ZeroBOX

Setup.7z

Generic Malware
Category Machine Started Completed
FILE s1_win7_x6403_us Sept. 14, 2024, 9:42 a.m. Sept. 14, 2024, 9:47 a.m.
Size 13.5MB
Type 7-zip archive data, version 0.4
MD5 4d9ad7c00699115a773f8ad0f2df7a17
SHA256 f1197d378546d5c5c2fd88c0b08a16ef30dbad4b21a5c52ea6fc3f525878ac2e
CRC32 2B2851D1
ssdeep 393216:ORc/IKa0RnnHcXP82IV3t2AjDxSHlr4NQxaFQMg4H:yKrnnHc/NM3tdDeKNQxYH
Yara None matched

  • chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" C:\Users\test22\AppData\Local\Temp\Setup.7z

    1540
    • chrome.exe "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=86.0.4240.111 --initial-client-data=0xb0,0xb4,0xb8,0x84,0xbc,0x7fef3f36e00,0x7fef3f36e10,0x7fef3f36e20

      2140

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0
registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid
file C:\Program Files (x86)\Google\Chrome\Application\86.0.4240.111\Locales
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0xf7
registers.r14: 242742200
registers.r15: 82945712
registers.rcx: 1344
registers.rsi: 17302540
registers.r10: 0
registers.rbx: 242741456
registers.rsp: 242741160
registers.r11: 242745072
registers.r8: 2004779404
registers.r9: 0
registers.rdx: 1392
registers.r12: 242741816
registers.rbp: 242741312
registers.rdi: 83486816
registers.rax: 11010048
registers.r13: 83119712
1 0 0
Application Crash Process chrome.exe with pid 1540 crashed
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7
0xf7

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0xf7
registers.r14: 242742200
registers.r15: 82945712
registers.rcx: 1344
registers.rsi: 17302540
registers.r10: 0
registers.rbx: 242741456
registers.rsp: 242741160
registers.r11: 242745072
registers.r8: 2004779404
registers.r9: 0
registers.rdx: 1392
registers.r12: 242741816
registers.rbp: 242741312
registers.rdi: 83486816
registers.rax: 11010048
registers.r13: 83119712
1 0 0
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-66E55125-604.pma
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_0
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Last Version
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\CrashpadMetrics-spare.pma
file C:\Users\test22\AppData\Local\Google\Chrome\User Data
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\CrashpadMetrics-active.pma
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Local State
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\reports\d7e978ea-fc15-4253-83ab-aa4ba359c1b7.dmp
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_2
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\CrashpadMetrics.pma
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\First Run
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\reports
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad\metadata
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\index
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_1
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\BrowserMetrics-spare.pma
file C:\Users\test22\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_3
Time & API Arguments Status Return Repeated

NtTerminateProcess

status_code: 0xc0000005
process_identifier: 1540
process_handle: 0x00000000000000bc
0 0

NtTerminateProcess

status_code: 0xc0000005
process_identifier: 1540
process_handle: 0x00000000000000bc
1 0 0
parent_process chrome.exe martian_process "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=836,6058740302610574607,1866156677204497404,131072 --gpu-preferences=MAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAQAAAAAAAAAAAAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAA= --use-gl=swiftshader-webgl --mojo-platform-channel-handle=1044 /prefetch:2
parent_process chrome.exe martian_process "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\test22\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\test22\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=86.0.4240.111 --initial-client-data=0xb0,0xb4,0xb8,0x84,0xbc,0x7fef3f36e00,0x7fef3f36e10,0x7fef3f36e20
Process injection Process 2140 resumed a thread in remote process 1540
Time & API Arguments Status Return Repeated

NtResumeThread

thread_handle: 0x0000000000000118
suspend_count: 2
process_identifier: 1540
1 0 0

NtResumeThread

thread_handle: 0x0000000000000118
suspend_count: 2
process_identifier: 1540
1 0 0

NtResumeThread

thread_handle: 0x0000000000000118
suspend_count: 2
process_identifier: 1540
1 0 0

NtResumeThread

thread_handle: 0x0000000000000118
suspend_count: 2
process_identifier: 1540
1 0 0

NtResumeThread

thread_handle: 0x0000000000000118
suspend_count: 2
process_identifier: 1540
1 0 0

NtResumeThread

thread_handle: 0x0000000000000118
suspend_count: 2
process_identifier: 1540
1 0 0

NtResumeThread

thread_handle: 0x0000000000000118
suspend_count: 2
process_identifier: 1540
1 0 0

NtResumeThread

thread_handle: 0x0000000000000118
suspend_count: 2
process_identifier: 1540
1 0 0

NtResumeThread

thread_handle: 0x0000000000000118
suspend_count: 2
process_identifier: 1540
1 0 0

NtResumeThread

thread_handle: 0x0000000000000118
suspend_count: 2
process_identifier: 1540
1 0 0

NtResumeThread

thread_handle: 0x0000000000000118
suspend_count: 2
process_identifier: 1540
1 0 0

NtResumeThread

thread_handle: 0x0000000000000118
suspend_count: 2
process_identifier: 1540
1 0 0

NtResumeThread

thread_handle: 0x0000000000000118
suspend_count: 2
process_identifier: 1540
1 0 0

NtResumeThread

thread_handle: 0x0000000000000118
suspend_count: 2
process_identifier: 1540
1 0 0

NtResumeThread

thread_handle: 0x0000000000000118
suspend_count: 2
process_identifier: 1540
1 0 0

NtResumeThread

thread_handle: 0x0000000000000118
suspend_count: 2
process_identifier: 1540
1 0 0

NtResumeThread

thread_handle: 0x0000000000000118
suspend_count: 2
process_identifier: 1540
1 0 0

NtResumeThread

thread_handle: 0x0000000000000118
suspend_count: 2
process_identifier: 1540
1 0 0

NtResumeThread

thread_handle: 0x0000000000000118
suspend_count: 2
process_identifier: 1540
1 0 0

NtResumeThread

thread_handle: 0x0000000000000118
suspend_count: 2
process_identifier: 1540
1 0 0

NtResumeThread

thread_handle: 0x0000000000000118
suspend_count: 2
process_identifier: 1540
1 0 0