Summary | ZeroBOX

Security.exe

Vidar Generic Malware Malicious Library Antivirus UPX Malicious Packer PE64 PE File .NET DLL DLL OS Processor Check PE32 .NET EXE
Category Machine Started Completed
FILE s1_win7_x6403_us Oct. 27, 2024, 11:46 a.m. Oct. 27, 2024, 11:50 a.m.
Size 488.0KB
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 f8862a71544afeafbd2ed09e19e33b50
SHA256 d3ddea55a7fdb26efcf9d220940191fa07ed291d1b7dce2c7f6f157575886ebb
CRC32 9F976879
ssdeep 12288:SgFYH9GgqEyGocGjPrW/XbQaqK3FDRlSU3zf90v:gHogRy9cGe/XZbCazf
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Is_DotNET_EXE - (no description)
  • IsPE32 - (no description)

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

WriteConsoleW

buffer: SUCCESS: The scheduled task "$77Security" has successfully been created.
console_handle: 0x0000000000000007
1 1 0
Time & API Arguments Status Return Repeated

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00000000005e1540
flags: 0
crypto_export_handle: 0x0000000000000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00000000005e1690
flags: 0
crypto_export_handle: 0x0000000000000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00000000005e1690
flags: 0
crypto_export_handle: 0x0000000000000000
blob_type: 6
1 1 0
registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 1880
region_size: 917504
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00000000007d0000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffffffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1880
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0000000000830000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1880
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fef3641000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1880
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fef3cdb000
process_handle: 0xffffffffffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1880
region_size: 1638400
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0000000002240000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffffffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1880
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0000000002350000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1880
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fef3642000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1880
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fef3642000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1880
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fef3642000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1880
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fef3642000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1880
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fef3642000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1880
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fef3642000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1880
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fef3642000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1880
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fef3642000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1880
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fef3642000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1880
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fef3642000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1880
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fef3642000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1880
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fef3644000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1880
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fef3644000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1880
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fef3644000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 1880
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fef3644000
process_handle: 0xffffffffffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1880
region_size: 655360
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fffff10000
allocation_type: 1056768 (MEM_RESERVE|MEM_TOP_DOWN)
process_handle: 0xffffffffffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1880
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fffff10000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffffffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1880
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fffff10000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffffffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1880
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fffff20000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffffffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1880
region_size: 65536
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fffff00000
allocation_type: 1056768 (MEM_RESERVE|MEM_TOP_DOWN)
process_handle: 0xffffffffffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1880
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fffff00000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffffffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1880
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fe93eba000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffffffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1880
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fe93f6c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffffffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1880
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fe93f96000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffffffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1880
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fe93f70000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffffffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1880
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fe93ecc000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffffffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1880
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fe93fe0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffffffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1880
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fe93ebb000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffffffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1880
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fe93edb000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffffffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1880
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fe93f0c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffffffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1880
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fe93edd000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffffffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1880
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fe93fe1000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffffffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1880
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fe93ebc000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffffffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1880
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fe93eca000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffffffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1880
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fe93eb2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffffffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 1880
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fe94020000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffffffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2460
region_size: 524288
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0000000000480000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffffffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2460
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0000000000480000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2460
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fef3641000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2460
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fef3cdb000
process_handle: 0xffffffffffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2460
region_size: 1048576
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0000000000a20000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffffffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2460
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0000000000aa0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2460
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fef3642000
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2460
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000007fef3642000
process_handle: 0xffffffffffffffff
1 0 0
description $77Security.exe tried to sleep 149 seconds, actually delayed analysis time by 149 seconds
Time & API Arguments Status Return Repeated

GetDiskFreeSpaceExW

total_number_of_free_bytes: 9932214272
free_bytes_available: 9932214272
root_path: C:\
total_number_of_bytes: 34252779520
1 1 0
file C:\Users\test22\AppData\Local\Temp\BytecodeApi.dll
file C:\Users\test22\AppData\Local\Temp\Install.exe
file C:\Users\test22\AppData\Local\Temp\Helper64.dll
file C:\Users\test22\AppData\Local\Temp\BytecodeApi.UI.dll
file C:\Users\test22\AppData\Roaming\$77Security.exe
file C:\Users\test22\AppData\Local\Temp\Helper32.dll
file C:\Users\test22\AppData\Local\Temp\$77Security.exe
file C:\Users\test22\AppData\Local\Temp\r77-x64.dll
file C:\Users\test22\AppData\Local\Temp\r77-x86.dll
cmdline "C:\Windows\System32\schtasks.exe" /create /f /RL HIGHEST /sc minute /mo 1 /tn "$77Security" /tr "C:\Users\test22\AppData\Roaming\$77Security.exe"
cmdline schtasks.exe /create /f /RL HIGHEST /sc minute /mo 1 /tn "$77Security" /tr "C:\Users\test22\AppData\Roaming\$77Security.exe"
file C:\Users\test22\AppData\Local\Temp\Install.exe
file C:\Users\test22\AppData\Local\Temp\r77-x86.dll
file C:\Users\test22\AppData\Local\Temp\Helper32.dll
file C:\Users\test22\AppData\Local\Temp\BytecodeApi.UI.dll
file C:\Users\test22\AppData\Roaming\$77Security.exe
file C:\Users\test22\AppData\Local\Temp\Install.exe
file C:\Users\test22\AppData\Local\Temp\BytecodeApi.dll
Time & API Arguments Status Return Repeated

ShellExecuteExW

show_type: 0
filepath_r: schtasks.exe
parameters: /create /f /RL HIGHEST /sc minute /mo 1 /tn "$77Security" /tr "C:\Users\test22\AppData\Roaming\$77Security.exe"
filepath: schtasks.exe
1 1 0
section {u'size_of_data': u'0x00079600', u'virtual_address': u'0x00002000', u'entropy': 7.994700205999168, u'name': u'.text', u'virtual_size': u'0x00079554'} entropy 7.994700206 description A section with a high entropy has been found
entropy 0.995897435897 description Overall entropy of this PE file is high
Time & API Arguments Status Return Repeated

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0
cmdline "C:\Windows\System32\schtasks.exe" /create /f /RL HIGHEST /sc minute /mo 1 /tn "$77Security" /tr "C:\Users\test22\AppData\Roaming\$77Security.exe"
cmdline schtasks.exe /create /f /RL HIGHEST /sc minute /mo 1 /tn "$77Security" /tr "C:\Users\test22\AppData\Roaming\$77Security.exe"
reg_key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\$77Security reg_value C:\Users\test22\AppData\Roaming\$77Security.exe
cmdline "C:\Windows\System32\schtasks.exe" /create /f /RL HIGHEST /sc minute /mo 1 /tn "$77Security" /tr "C:\Users\test22\AppData\Roaming\$77Security.exe"
cmdline schtasks.exe /create /f /RL HIGHEST /sc minute /mo 1 /tn "$77Security" /tr "C:\Users\test22\AppData\Roaming\$77Security.exe"
Time & API Arguments Status Return Repeated

RegSetValueExW

key_handle: 0x00000094
regkey_r: $77stager
reg_type: 3 (REG_BINARY)
value: MZÿÿ¸@€º´ Í!¸LÍ!This program cannot be run in DOS mode. $PEL¹ –Ëà" 0TÎs €@  @…|sO€ `s  H.textÔS T `.reloc €V@B°sHH+h°E°-0' @ + o Žio % 0ç*0ârp(( o o  /( 3 rp(( ~ r/po rAp("((o rSp(#((o Þ , o Ü( .(%+($(( repr¥p( r½p( ( rÁp( šo (*E6{ 0;s s s (Þ ,o Üo Þ ,o Ü*  )/ 08( ŽiY  +X‘ÒaҜbc` X Ži2á*0 ã 8Ô <( X8X( X<X( XX( X( X( ( .XX( (! +XX( ("  €(  ~# ($ ,s% z( (   (& ~#  ~#  (- ~# ($ ,s% z (' (   (,8 ~# ($ -*  ("  ( (" ~# ~# (-s% z( .p+H  (  ((  ()  ( Y (* ( .+( . Ð+ Ì(( .0+ (+ rÓp(, ~# ~#  ~# ( -s% z( Z( ( .( (! + ( (" ( & (" ~#  0@( 2*~# ( 2j(- ( -s% z8 (XX(ZX((. (Y/XXX(ZX((.  ( ( ( $(/  ( Ži(. (0 jX(! Ži~# ( /s% z(0 jX(! Y.Y+ Yj(- (( -s% zXh?íþÿÿ( .( (! + ( (" %(/s% z( 3[ ¤(1 (" (' X(" (' (2 ~# ( /s% z °(' X(+ +\ ˆ(3 (! (0 jX(! (0 (4 ~# ( /s% z €(0 jX(5 %(/s% z(3s% zÞ&(6 o7 Þ&ÞÞX ?%ûÿÿ*A4Å Ò »Ä0ƒ _, @_,  €_,@* _,  @_, * _, €_, €* @_,  €_,* _,* @_,* €_,**0.( .+ [X(8 (0 YjXj[jZ(! *0T( ~# (9 97(þ(9r×p( €~# ~# ( (" (9 9ä~# ( ~# (9 9¹ ~# (~# (9 9‘{(0 <jX(! (: (0 jXjX(! (; X(< 8?(0 jXjXjX(ZjX(!   (= .@  (0 jX(! (= t@ï (0 jX(! (= e@Ô (0 jX(! (= x@¹ (0 jX(! (= t@ž (0  jX(! (:   (0 jX(! (:  (0  jX(!  n(! @ (&(0  jX(! (0  jX(!  n(! (&(0  jX(!  n(!   (&+Xh?¸þÿÿ (&(&(&Þ&Þ*APP(> *®~-rpÐ(? o@ sA €~*~*€*j(r9p~oB t*j(rEp~oB t*j(rQp~oB t*j(rep~oB t*BSJB v2.0.50727l¤ #~ à #Stringsð|#USl#GUID|ì#BlobW}¢ ú3( %_B IÛmûm’;Äüp¿p[Ï  ^?¼8 T^9¼ #{^ DÛu;)mč‚ç ôÈ ¦È'^Y ^U^•^$^ Å;¬ Ž^^ rú^i^ÀN^²^' ^^ª^H –ó!M!«!¬!”Ó!Û ¹!& ±9&eyÓ}V€ V€”„V€¨„V€*Þ肇q èP –.Š„ –~U„!‘é’è!‘ž ’,"
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\$77stager
1 0 0
Time & API Arguments Status Return Repeated

RegSetValueExW

key_handle: 0x00000094
regkey_r: $77stager
reg_type: 3 (REG_BINARY)
value: MZÿÿ¸@€º´ Í!¸LÍ!This program cannot be run in DOS mode. $PEL¹ –Ëà" 0TÎs €@  @…|sO€ `s  H.textÔS T `.reloc €V@B°sHH+h°E°-0' @ + o Žio % 0ç*0ârp(( o o  /( 3 rp(( ~ r/po rAp("((o rSp(#((o Þ , o Ü( .(%+($(( repr¥p( r½p( ( rÁp( šo (*E6{ 0;s s s (Þ ,o Üo Þ ,o Ü*  )/ 08( ŽiY  +X‘ÒaҜbc` X Ži2á*0 ã 8Ô <( X8X( X<X( XX( X( X( ( .XX( (! +XX( ("  €(  ~# ($ ,s% z( (   (& ~#  ~#  (- ~# ($ ,s% z (' (   (,8 ~# ($ -*  ("  ( (" ~# ~# (-s% z( .p+H  (  ((  ()  ( Y (* ( .+( . Ð+ Ì(( .0+ (+ rÓp(, ~# ~#  ~# ( -s% z( Z( ( .( (! + ( (" ( & (" ~#  0@( 2*~# ( 2j(- ( -s% z8 (XX(ZX((. (Y/XXX(ZX((.  ( ( ( $(/  ( Ži(. (0 jX(! Ži~# ( /s% z(0 jX(! Y.Y+ Yj(- (( -s% zXh?íþÿÿ( .( (! + ( (" %(/s% z( 3[ ¤(1 (" (' X(" (' (2 ~# ( /s% z °(' X(+ +\ ˆ(3 (! (0 jX(! (0 (4 ~# ( /s% z €(0 jX(5 %(/s% z(3s% zÞ&(6 o7 Þ&ÞÞX ?%ûÿÿ*A4Å Ò »Ä0ƒ _, @_,  €_,@* _,  @_, * _, €_, €* @_,  €_,* _,* @_,* €_,**0.( .+ [X(8 (0 YjXj[jZ(! *0T( ~# (9 97(þ(9r×p( €~# ~# ( (" (9 9ä~# ( ~# (9 9¹ ~# (~# (9 9‘{(0 <jX(! (: (0 jXjX(! (; X(< 8?(0 jXjXjX(ZjX(!   (= .@  (0 jX(! (= t@ï (0 jX(! (= e@Ô (0 jX(! (= x@¹ (0 jX(! (= t@ž (0  jX(! (:   (0 jX(! (:  (0  jX(!  n(! @ (&(0  jX(! (0  jX(!  n(! (&(0  jX(!  n(!   (&+Xh?¸þÿÿ (&(&(&Þ&Þ*APP(> *®~-rpÐ(? o@ sA €~*~*€*j(r9p~oB t*j(rEp~oB t*j(rQp~oB t*j(rep~oB t*BSJB v2.0.50727l¤ #~ à #Stringsð|#USl#GUID|ì#BlobW}¢ ú3( %_B IÛmûm’;Äüp¿p[Ï  ^?¼8 T^9¼ #{^ DÛu;)mč‚ç ôÈ ¦È'^Y ^U^•^$^ Å;¬ Ž^^ rú^i^ÀN^²^' ^^ª^H –ó!M!«!¬!”Ó!Û ¹!& ±9&eyÓ}V€ V€”„V€¨„V€*Þ肇q èP –.Š„ –~U„!‘é’è!‘ž ’,"
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\$77stager
1 0 0
Time & API Arguments Status Return Repeated

CryptHashData

buffer: 127631360test22TEST22-PCMicrosoft Windows NT 6.1.7601 Service Pack 134252779520
hash_handle: 0x0000000000325460
flags: 0
1 1 0
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.Rootkit.5!c
Elastic malicious (high confidence)
Skyhigh BehavesLike.Win32.Generic.gc
ALYac Gen:Variant.Jalapeno.720
Malwarebytes Backdoor.Bladabindi
VIPRE Gen:Variant.Jalapeno.720
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Trojan ( 700000121 )
BitDefender Gen:Variant.Jalapeno.720
K7GW Trojan ( 700000121 )
Cybereason malicious.1544af
Arcabit Trojan.Jalapeno.720
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/TrojanDropper.Agent.FOV
APEX Malicious
McAfee Artemis!F8862A71544A
Avast Win32:CrypterX-gen [Trj]
Kaspersky UDS:Rootkit.Win64.Agent.gen
Alibaba Backdoor:MSIL/XWormRAT.6a3066ec
NANO-Antivirus Trojan.Win32.XWorm.kntiji
MicroWorld-eScan Gen:Variant.Jalapeno.720
Rising Malware.Obfus/MSIL@AI.83 (RDM.MSIL2:yVK96/jSafm0+Krcej0zTw)
Emsisoft Gen:Variant.Jalapeno.720 (B)
F-Secure Trojan.TR/Dropper.Gen
DrWeb Trojan.MulDropNET.65
Zillya Dropper.Agent.Win32.586117
TrendMicro Backdoor.Win32.XWORM.YXEERZ
McAfeeD Real Protect-LS!F8862A71544A
Trapmine malicious.high.ml.score
FireEye Generic.mg.f8862a71544afeaf
Sophos Troj/Mdrop-JVT
Ikarus Win32.Outbreak
Google Detected
Avira TR/Dropper.Gen
MAX malware (ai score=87)
Kingsoft malware.kb.c.1000
Gridinsoft Ransom.Win32.Bladabindi.sa
Microsoft Trojan:MSIL/XWormRAT.A!MTB
ViRobot Trojan.Win.Z.Jalapeno.499712
ZoneAlarm UDS:Rootkit.Win64.Agent.gen
GData Gen:Variant.Jalapeno.720
Varist W32/MSIL_Agent.BUD.gen!Eldorado
AhnLab-V3 Trojan/Win.Generic.C5108156
BitDefenderTheta AI:Packer.F880CA9E1F
DeepInstinct MALICIOUS
Panda Trj/GdSda.A
TrendMicro-HouseCall Backdoor.Win32.XWORM.YXEERZ
Tencent Malware.Win32.Gencirc.140c1e27
SentinelOne Static AI - Malicious PE