Summary | ZeroBOX

SoftShipment.exe

Generic Malware Malicious Library UPX PE File OS Processor Check PE32
Category Machine Started Completed
FILE s1_win7_x6403_us Sept. 26, 2024, 12:04 p.m. Sept. 26, 2024, 12:06 p.m.
Size 1.0MB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 88f2f4df57c115ab7062c7a2a23e454a
SHA256 08f30ece5f7e77a69e58a970b3684c2a0eba1aa203ac97836dad32fc10a15e90
CRC32 E4786E8F
ssdeep 24576:T97KLeYdCBMGq8TBUfnrO/E7Bup/884hvndKzVDDuy3ent:TUXfEBUvyj884uzxDqt
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

WriteConsoleW

buffer: 1 file(s) moved.
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Set
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Witnesses=d
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: pMWDownloadcom
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Arm
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'pMWDownloadcom' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: gGjSubcommittee
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Mate Onion
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'gGjSubcommittee' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: KIAging
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Tricks
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'KIAging' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: IUArrived
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Completion Toilet Safety Diary Questions Defense Lounge Mobiles
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'IUArrived' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: obPromise
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Senator Mozambique Boy Rg
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'obPromise' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: WcFacilities
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'WcFacilities' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: BbtjSterling
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Co Losses
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'BbtjSterling' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: wytiAdvert
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Titans Accused Searched Eco Drain
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'wytiAdvert' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: OpXIma
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Sierra Intensity
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'OpXIma' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Set
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Detective=P
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: fCAeWill
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Tag Na Enzyme Farm
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'fCAeWill' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: vJAReleased
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Finishing Diego Long Dialogue Controllers
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'vJAReleased' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section .ndata
file C:\Users\test22\AppData\Local\Temp\10518\Voyuer.pif
cmdline "C:\Windows\System32\cmd.exe" /c move Killing Killing.bat & Killing.bat
file C:\Users\test22\AppData\Local\Temp\10518\Voyuer.pif
file C:\Users\test22\AppData\Local\Temp\10518\Voyuer.pif
wmi SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Time & API Arguments Status Return Repeated

ShellExecuteExW

show_type: 0
filepath_r: cmd
parameters: /c move Killing Killing.bat & Killing.bat
filepath: cmd
1 1 0
Time & API Arguments Status Return Repeated

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0
cmdline "C:\Windows\System32\cmd.exe" /c move Killing Killing.bat & Killing.bat
cmdline tasklist
cmdline cmd /c move Killing Killing.bat & Killing.bat
file C:\mIRC\mirc.ini
Process injection Process 2164 resumed a thread in remote process 2636
Time & API Arguments Status Return Repeated

NtResumeThread

thread_handle: 0x00000084
suspend_count: 0
process_identifier: 2636
1 0 0
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Runner.4!c
Cynet Malicious (score: 99)
ALYac Gen:Variant.Autoruns.Nemesis.16
Cylance Unsafe
VIPRE Gen:Variant.Autoruns.Nemesis.16
Sangfor Trojan.Win32.Runner.V7s2
CrowdStrike win/grayware_confidence_60% (D)
BitDefender Gen:Variant.Autoruns.Nemesis.16
K7GW Trojan ( 005bad8e1 )
K7AntiVirus Trojan ( 005bad8e1 )
Arcabit Trojan.Autoruns.Nemesis.16
VirIT Trojan.Win32.NSISDrp.HHH
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 NSIS/Runner.BP
APEX Malicious
Avast Win32:Malware-gen
MicroWorld-eScan Gen:Variant.Autoruns.Nemesis.16
Emsisoft Gen:Variant.Autoruns.Nemesis.16 (B)
F-Secure Trojan.TR/AVI.Agent.bgfwt
DrWeb Trojan.Siggen29.42523
McAfeeD ti!08F30ECE5F7E
CTX exe.trojan.runner
Sophos Mal/Generic-S
FireEye Generic.mg.88f2f4df57c115ab
Webroot W32.Malware.Gen
Google Detected
Avira TR/AVI.Agent.bgfwt
Antiy-AVL Trojan/Win32.AdLoad.bh
Kingsoft Win32.Trojan.Autoit.gen
Gridinsoft Ransom.Win32.Wacatac.cl
Microsoft Trojan:Win32/Conteban.A!ml
GData Gen:Variant.Autoruns.Nemesis.16
Varist W32/ABTrojan.HHTL-2825
McAfee Artemis!88F2F4DF57C1
DeepInstinct MALICIOUS
Malwarebytes Malware.AI.4248437397
Ikarus Trojan.NSIS.Runner
Panda Trj/Chgt.AD
Tencent Win32.Trojan.Autoit.Szfl
huorong HEUR:Trojan/Runner.b
MaxSecure Trojan.Malware.121218.susgen
Fortinet NSIS/Runner.K!tr
AVG Win32:Malware-gen
Paloalto generic.ml
alibabacloud Trojan:Win/Runner.BT