Summary | ZeroBOX

InstallSetup.exe

Suspicious_Script_Bin Generic Malware UPX Malicious Library PE File OS Processor Check PE32
Category Machine Started Completed
FILE s1_win7_x6403_us Oct. 10, 2024, 10:56 a.m. Oct. 10, 2024, 11 a.m.
Size 1.2MB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 e6dd6a25125edd4c21fe5cf7bafcd2bb
SHA256 523cd90154c376b7f6953f1e825eb467b231b3fffe30ab321c1a69da22cb1148
CRC32 B9A215C8
ssdeep 24576:5ACy4Y4Q1jqxeColSZkrmiZM/z+KpN/6xwA1u3l5y98IOyxa/VvEW:iF7NeY34+iNyxwg2vy9DOyWj
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

WriteConsoleW

buffer: 1 file(s) moved.
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Set
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Baptist=f
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: ljFwd-Lead-Strike-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'ljFwd-Lead-Strike-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: RcVwColleges-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'RcVwColleges-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: VsReduce-Ns-Attachments-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'VsReduce-Ns-Attachments-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: jZbPackard-Ferrari-Guarantee-Finally-Solved-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'jZbPackard-Ferrari-Guarantee-Finally-Solved-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: rhWiPreviews-Thousands-Loving-Camp-Thinkpad-Semiconductor-Xanax-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'rhWiPreviews-Thousands-Loving-Camp-Thinkpad-Semiconductor-Xanax-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: KUgVDensity-Remains-Aberdeen-Periodic-Maiden-S-Vista-Dicks-Rolling-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'KUgVDensity-Remains-Aberdeen-Periodic-Maiden-S-Vista-Dicks-Rolling-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: TAfmCharts-Welsh-Secret-Describes-Titanium-Consequently-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'TAfmCharts-Welsh-Secret-Describes-Titanium-Consequently-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: slnPractitioner-Diesel-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'slnPractitioner-Diesel-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Set
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Allowing=8
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: qYejLolita-Options-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'qYejLolita-Options-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: HYPMerchandise-Originally-Native-Flexible-Troy-Wma-Health-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'HYPMerchandise-Originally-Native-Flexible-Troy-Wma-Health-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: lyForget-Favourites-Situated-Crap-Manchester-Ge-Investment-Tapes-Fall-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'lyForget-Favourites-Situated-Crap-Manchester-Ge-Investment-Tapes-Fall-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: tUENTrusts-Manuals-Told-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'tUENTrusts-Manuals-Told-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: iAPerceived-Share-Nhl-Training-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'iAPerceived-Share-Nhl-Training-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: UYtRiver-Thus-Acknowledge-Positions-Threesome-Functional-Erik-Bedford-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'UYtRiver-Thus-Acknowledge-Positions-Threesome-Functional-Erik-Bedford-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section .ndata
file C:\Users\test22\AppData\Local\Temp\773416\Welding.pif
cmdline "C:\Windows\System32\cmd.exe" /c move Halo Halo.bat & Halo.bat
file C:\Users\test22\AppData\Local\Temp\773416\Welding.pif
file C:\Users\test22\AppData\Local\Temp\773416\Welding.pif
wmi SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Time & API Arguments Status Return Repeated

ShellExecuteExW

show_type: 0
filepath_r: cmd
parameters: /c move Halo Halo.bat & Halo.bat
filepath: cmd
1 1 0
Time & API Arguments Status Return Repeated

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0
cmdline tasklist
cmdline cmd /c move Halo Halo.bat & Halo.bat
cmdline "C:\Windows\System32\cmd.exe" /c move Halo Halo.bat & Halo.bat
file C:\mIRC\mirc.ini
Process injection Process 2152 resumed a thread in remote process 2656
Time & API Arguments Status Return Repeated

NtResumeThread

thread_handle: 0x00000084
suspend_count: 0
process_identifier: 2656
1 0 0