Summary | ZeroBOX

BandiCut.exe

Suspicious_Script_Bin Generic Malware UPX Malicious Library PE File OS Processor Check PE32
Category Machine Started Completed
FILE s1_win7_x6403_us Oct. 30, 2024, 9:19 a.m. Oct. 30, 2024, 9:21 a.m.
Size 3.0MB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 649673218a19e8fd278c99d1355949f4
SHA256 7a2c1437ed5ff19adf078f17881fc836a4b08d3eaaff243d5ca77577f5880169
CRC32 26CC8A49
ssdeep 24576:1az71UBrCXaw68FowF0vkf2fkAJzGthOXUKqx3Weeg:szRUDyFMPsAB0OXAV
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

WriteConsoleW

buffer: 1 file(s) copied.
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Set
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Expanding=6
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: FiDh-Component-Tracks-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'FiDh-Component-Tracks-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: opTvcom-Lowest-Outline-Democrat-Raid-Directly-Vertical-Backgrounds-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'opTvcom-Lowest-Outline-Democrat-Raid-Directly-Vertical-Backgrounds-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: KCrAud-Impact-Styles-Wild-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'KCrAud-Impact-Styles-Wild-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: TQAChase-Associates-Madrid-Invite-Nutrition-Pleased-Tyler-Replace-Admitted-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'TQAChase-Associates-Madrid-Invite-Nutrition-Pleased-Tyler-Replace-Admitted-' is not recognized as an internal or external command, operable program or batch f
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: ile.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: BedNa-Fingers-Recording-Chelsea-Van-Kick-Ill-Stated-Lions-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'BedNa-Fingers-Recording-Chelsea-Van-Kick-Ill-Stated-Lions-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: MhQUnauthorized-Nitrogen-Ee-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'MhQUnauthorized-Nitrogen-Ee-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: zWzProvides-Devoted-Pay-Dublin-Cb-Nowhere-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'zWzProvides-Devoted-Pay-Dublin-Cb-Nowhere-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: iCaNDocuments-Overnight-Probe-Questionnaire-Sunset-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'iCaNDocuments-Overnight-Probe-Questionnaire-Sunset-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Set
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Lodging=G
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: QkISupreme-Shed-Initial-Folding-Example-Attractive-Improved-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'QkISupreme-Shed-Initial-Folding-Example-Attractive-Improved-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: wSDemocratic-Financing-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'wSDemocratic-Financing-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: WcHThereby-Most-Geology-Guru-Infrastructure-Alphabetical-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'WcHThereby-Most-Geology-Guru-Infrastructure-Alphabetical-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: zoIRCount-Mcdonald-Motels-Calgary-Newsletters-Justice-Ahead-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'zoIRCount-Mcdonald-Motels-Calgary-Newsletters-Justice-Ahead-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: fcfTicket-Welsh-Resorts-Bm-Compilation-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'fcfTicket-Welsh-Resorts-Bm-Compilation-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: VdSlBeen-Friendship-Invoice-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'VdSlBeen-Friendship-Invoice-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section .ndata
file C:\Users\test22\AppData\Local\Temp\438799\Dump.pif
cmdline "C:\Windows\System32\cmd.exe" /c copy Highlighted Highlighted.bat & Highlighted.bat
file C:\Users\test22\AppData\Local\Temp\438799\Dump.pif
file C:\Users\test22\AppData\Local\Temp\438799\Dump.pif
wmi SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Time & API Arguments Status Return Repeated

ShellExecuteExW

show_type: 0
filepath_r: cmd
parameters: /c copy Highlighted Highlighted.bat & Highlighted.bat
filepath: cmd
1 1 0
section {u'size_of_data': u'0x00020e00', u'virtual_address': u'0x000f4000', u'entropy': 7.853116998357046, u'name': u'.rsrc', u'virtual_size': u'0x00020d4a'} entropy 7.85311699836 description A section with a high entropy has been found
entropy 0.753581661891 description Overall entropy of this PE file is high
Time & API Arguments Status Return Repeated

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0
cmdline tasklist
cmdline cmd /c copy Highlighted Highlighted.bat & Highlighted.bat
cmdline "C:\Windows\System32\cmd.exe" /c copy Highlighted Highlighted.bat & Highlighted.bat
Process injection Process 2096 resumed a thread in remote process 2596
Time & API Arguments Status Return Repeated

NtResumeThread

thread_handle: 0x00000084
suspend_count: 0
process_identifier: 2596
1 0 0
Bkav W32.AIDetectMalware
tehtris Generic.Malware
Skyhigh BehavesLike.Win32.Generic.wm
Cylance Unsafe
CrowdStrike win/malicious_confidence_60% (D)
Elastic malicious (high confidence)
ESET-NOD32 NSIS/Runner.CR
Kaspersky UDS:DangerousObject.Multi.Generic
Rising Trojan.Runner/NSIS!1.104E6 (CLASSIC)
DrWeb Trojan.MulDrop28.35217
McAfeeD ti!7A2C1437ED5F
CTX exe.trojan.runner
Sophos Generic ML PUA (PUA)
Antiy-AVL Trojan/Win32.Runner.bq
Kingsoft Win32.Trojan.Autoit.gen
ZoneAlarm UDS:DangerousObject.Multi.Generic
McAfee Artemis!649673218A19
DeepInstinct MALICIOUS
huorong Trojan/Runner.bn
Paloalto generic.ml