Summary | ZeroBOX

MpgRat.exe

Generic Malware Malicious Library UPX PE File OS Processor Check PE32
Category Machine Started Completed
FILE s1_win7_x6403_us Oct. 6, 2024, 6:39 p.m. Oct. 6, 2024, 6:42 p.m.
Size 1.3MB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 2a051b9aa77beac67746c61354d7db3a
SHA256 c4436ad3fc46d26c9c066489d3a04665589104813524f24352b063d21d3c8d3c
CRC32 FC63EEAF
ssdeep 24576:CHKgAPnJ2/jQPgamwcGSVZ6rtZMufRSSRYFD6BfntvnQTTj6U1jw69J/aXgt3ccS:rgAPJ2bQ4vWSVovUS069ntATj6q9glZ
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

WriteConsoleW

buffer: 1 file(s) moved.
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Set
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Discover=A
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: tyGMistake-Prevent-Oem-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'tyGMistake-Prevent-Oem-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: KqWage-Dressed-Thousands-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'KqWage-Dressed-Thousands-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: dQfEThorough-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'dQfEThorough-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: TRcVeterans-Hq-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'TRcVeterans-Hq-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: OxPMQuarter-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'OxPMQuarter-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: UMbLOpportunities-Numerous-Insider-Futures-Rates-Carbon-Substantial-Renew-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'UMbLOpportunities-Numerous-Insider-Futures-Rates-Carbon-Substantial-Renew-' is not recognized as an internal or external command, operable program or batch fi
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: le.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: wFTar-Img-Mileage-Def-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'wFTar-Img-Mileage-Def-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: RxMpTouring-Nos-Lease-Dawn-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'RxMpTouring-Nos-Lease-Dawn-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: pUBases-Stones-Stress-Does-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'pUBases-Stones-Stress-Does-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: VcPostal-Annually-Besides-Powerseller-Producer-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'VcPostal-Annually-Besides-Powerseller-Producer-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Set
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Surgeons=N
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: tuMConversations-Battery-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'tuMConversations-Battery-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: PgcICompute-Tower-Anyway-Gen-Respective-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'PgcICompute-Tower-Anyway-Gen-Respective-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: xcLXSome-Thank-Approx-Sql-Grammar-Girl-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'xcLXSome-Thank-Approx-Sql-Grammar-Girl-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: VzKiss-Representatives-Disable-Greater-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'VzKiss-Representatives-Disable-Greater-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section .ndata
file C:\Users\test22\AppData\Local\Temp\233773\Ranch.pif
cmdline "C:\Windows\System32\cmd.exe" /c move Runtime Runtime.bat & Runtime.bat
file C:\Users\test22\AppData\Local\Temp\233773\Ranch.pif
file C:\Users\test22\AppData\Local\Temp\233773\Ranch.pif
wmi SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Time & API Arguments Status Return Repeated

ShellExecuteExW

show_type: 0
filepath_r: cmd
parameters: /c move Runtime Runtime.bat & Runtime.bat
filepath: cmd
1 1 0
Time & API Arguments Status Return Repeated

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0
cmdline tasklist
cmdline cmd /c move Runtime Runtime.bat & Runtime.bat
cmdline "C:\Windows\System32\cmd.exe" /c move Runtime Runtime.bat & Runtime.bat
Bkav W32.AIDetectMalware
CrowdStrike win/grayware_confidence_60% (D)
Elastic malicious (high confidence)
Kaspersky HEUR:Backdoor.Win32.Agent.gen
McAfeeD ti!C4436AD3FC46
Sophos Mal/Generic-S
Kingsoft Win32.Hack.Agent.gen
Microsoft Trojan:Win32/Sonbokli.A!cl
ZoneAlarm HEUR:Backdoor.Win32.Agent.gen
McAfee Artemis!2A051B9AA77B
Panda Trj/Chgt.AD
huorong Trojan/BAT.Agent.cv
Paloalto generic.ml
file C:\mIRC\mirc.ini
Process injection Process 2084 resumed a thread in remote process 2628
Time & API Arguments Status Return Repeated

NtResumeThread

thread_handle: 0x00000084
suspend_count: 0
process_identifier: 2628
1 0 0