Summary | ZeroBOX

PowderGpl.exe

Generic Malware Malicious Library UPX PE File OS Processor Check PE32
Category Machine Started Completed
FILE s1_win7_x6403_us Nov. 13, 2024, 2:07 p.m. Nov. 13, 2024, 2:17 p.m.
Size 1.0MB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 bf265e0055178b2aa642fc6df2ae5f40
SHA256 9b0021640b636a39ab43bfff88e5dca26161e8cd4da26596f0c3068fb7659642
CRC32 24136809
ssdeep 12288:BCQdkpj9XCQR9Fo+lSEr/CAcHqpxr0H8totz8LfAz1uviBCGG4HgoKQJZNL:BVdujt9pAE0+rMN8LYzcyTAqJZNL
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

WriteConsoleW

buffer: 1 file(s) copied.
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Set
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Door=o
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: RJPrince-Mastercard-Horses-Pac-What-Charity-Silence-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'RJPrince-Mastercard-Horses-Pac-What-Charity-Silence-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: IUXdExercise-Supply-Sound-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'IUXdExercise-Supply-Sound-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: ByEarlier-Vary-Recipes-Latest-Carmen-France-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'ByEarlier-Vary-Recipes-Latest-Carmen-France-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: ZgpGovernment-Rev-Meanwhile-Algebra-Accessible-Lambda-Acquisition-Ask-Cest-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'ZgpGovernment-Rev-Meanwhile-Algebra-Accessible-Lambda-Acquisition-Ask-Cest-' is not recognized as an internal or external command, operable program or batch f
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: ile.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: PrhDifferential-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'PrhDifferential-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: WppuRecommended-Apollo-Gone-Removed-Simpsons-Trucks-Lamp-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'WppuRecommended-Apollo-Gone-Removed-Simpsons-Trucks-Lamp-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Set
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Lined=S
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: fLVAnalyses-Trailers-Lows-Earth-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'fLVAnalyses-Trailers-Lows-Earth-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: aITalk-Measured-Warcraft-Translate-Ourselves-Thomson-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'aITalk-Measured-Warcraft-Translate-Ourselves-Thomson-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: DoViolations-Employment-Clan-Resident-Priorities-Reset-Easily-Last-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'DoViolations-Employment-Clan-Resident-Priorities-Reset-Easily-Last-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: lcOr-Relate-This-Valuable-Possession-Guess-Talk-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'lcOr-Relate-This-Valuable-Possession-Guess-Talk-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: RbmSubsidiaries-Dozens-Lounge-Electronic-Examining-Mystery-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'RbmSubsidiaries-Dozens-Lounge-Electronic-Examining-Mystery-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: LxvOhio-Discussing-Dynamics-Crossing-Salaries-Zshops-Maintaining-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'LxvOhio-Discussing-Dynamics-Crossing-Salaries-Zshops-Maintaining-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Set
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: Goes=G
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp>
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: jGWarren-Admitted-Thats-Bicycle-
console_handle: 0x00000007
1 1 0

WriteConsoleW

buffer: 'jGWarren-Admitted-Thats-Bicycle-' is not recognized as an internal or external command, operable program or batch file.
console_handle: 0x0000000b
1 1 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section .ndata
file C:\Users\test22\AppData\Local\Temp\609587\Horizon.pif
cmdline "C:\Windows\System32\cmd.exe" /c copy Dragon Dragon.bat & Dragon.bat
file C:\Users\test22\AppData\Local\Temp\609587\Horizon.pif
file C:\Users\test22\AppData\Local\Temp\609587\Horizon.pif
wmi SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Time & API Arguments Status Return Repeated

ShellExecuteExW

show_type: 0
filepath_r: cmd
parameters: /c copy Dragon Dragon.bat & Dragon.bat
filepath: cmd
1 1 0
Time & API Arguments Status Return Repeated

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0
cmdline cmd /c copy Dragon Dragon.bat & Dragon.bat
cmdline tasklist
cmdline "C:\Windows\System32\cmd.exe" /c copy Dragon Dragon.bat & Dragon.bat
file C:\mIRC\mirc.ini
Process injection Process 2168 resumed a thread in remote process 2632
Time & API Arguments Status Return Repeated

NtResumeThread

thread_handle: 0x00000084
suspend_count: 0
process_identifier: 2632
1 0 0