Summary | ZeroBOX

DocuSign.exe

Gen1 Generic Malware Malicious Library ASPack UPX Anti_VM PE64 PE File OS Processor Check ZIP Format JPEG Format DLL icon
Category Machine Started Completed
FILE s1_win7_x6401 Oct. 14, 2024, 10:45 a.m. Oct. 14, 2024, 10:55 a.m.
Size 13.0MB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 4a1e0a1302e5143652b8cdc7d29847a2
SHA256 d57cf90d065199dcb67b32ffd79de8df38f67888a0fcb11ddfd1089afdfb1aa8
CRC32 2F9159B3
ssdeep 393216:h9YiImIEOs0zInEroXU14S2DzqfsBlRbqQ26:h9YiIuOs0MErUjqf2Rby6
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • ASPack_Zero - ASPack packed file
  • IsPE64 - (no description)
  • Generic_Malware_Zero - Generic Malware
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section _RDATA
file C:\Users\test22\AppData\Local\Temp\_MEI26642\libssl-1_1.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tk86t.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26642\VCRUNTIME140.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26642\libffi-7.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl86t.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26642\python310.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26642\libcrypto-1_1.dll
VirIT Trojan.Win64.Genus.FYE
Elastic malicious (moderate confidence)
ESET-NOD32 a variant of Win32/GenCBL.FHT
APEX Malicious
Google Detected
Malwarebytes Agent.Spyware.Stealer.DDS
Ikarus Trojan.Win32.Generic
Fortinet W32/GenCBL.FHT!tr
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\macCroatian.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\cp850.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\ascii.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\cp932.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\ebcdic.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\koi8-u.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\iso8859-15.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\jis0212.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\cp1257.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\iso8859-9.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\iso8859-6.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\cp775.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\iso8859-3.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\macTurkish.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\cp866.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\cp861.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\ksc5601.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\cp1256.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\iso8859-4.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\iso8859-13.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\euc-kr.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\cp936.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\iso8859-5.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\iso8859-2.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\macThai.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\jis0208.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\iso2022-kr.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\symbol.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\cp862.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\macGreek.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\tis-620.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\macJapan.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\iso8859-1.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\macIceland.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\cp865.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\iso8859-16.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\gb1988.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\cp1258.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\iso8859-8.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\cp864.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\cp869.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\big5.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\cp737.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\macDingbats.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\koi8-r.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\macCentEuro.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\macRomania.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\euc-cn.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\cp852.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\jis0201.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\macCroatian.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\America\Managua
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Asia\Ulaanbaatar
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\msgs\sk.msg
file C:\Users\test22\AppData\Local\Temp\_MEI26642\Crypto\Util\_cpuid_c.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\PRC
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\msgs\es_hn.msg
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Pacific\Pago_Pago
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Asia\Chongqing
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\America\Santa_Isabel
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\UTC
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\msgs\es_bo.msg
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\America\Blanc-Sablon
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Africa\Djibouti
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Iceland
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Africa\Ouagadougou
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\GMT
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\msgs\es_gt.msg
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Europe\Busingen
file C:\Users\test22\AppData\Local\Temp\_MEI26642\Crypto\Cipher\_raw_cbc.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\iso8859-5.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\base_library.zip
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\America\Argentina\Tucuman
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\msgs\be.msg
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\msgs\es_pa.msg
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tk\unsupported.tcl
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Africa\Lagos
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\America\Ensenada
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Pacific\Saipan
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Pacific\Wake
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\msgs\de.msg
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Brazil\Acre
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\encoding\iso8859-16.enc
file C:\Users\test22\AppData\Local\Temp\_MEI26642\Crypto\PublicKey\_ec_ws.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Africa\Abidjan
file C:\Users\test22\AppData\Local\Temp\_MEI26642\_hashlib.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Turkey
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tk\dialog.tcl
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Africa\Harare
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Antarctica\Palmer
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\America\Nassau
file C:\Users\test22\AppData\Local\Temp\_MEI26642\logo.jpg
file C:\Users\test22\AppData\Local\Temp\_MEI26642\Crypto\Hash\_BLAKE2b.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26642\Crypto\Hash\_ghash_portable.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Etc\GMT+2
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Etc\GMT+3
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\msgs\es_ni.msg
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Etc\GMT+1
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\America\Port_of_Spain
file C:\Users\test22\AppData\Local\Temp\_MEI26642\tcl\tzdata\Etc\GMT+7