Sample name: | ZaPNN51vQo.dllrenamed because original name is a hash value |
Original sample name: | f222320a45dad46987e5600556f42a49.dll |
Analysis ID: | 1579300 |
MD5: | f222320a45dad46987e5600556f42a49 |
SHA1: | 0bc94ccb35d2dd80954b6dde717bcce305597ce6 |
SHA256: | a6c578970637169d77ab319744ba4ef283bfe55816013ee2f3e5036332b3d27d |
Tags: | dllGh0stRATuser-abuse_ch |
Infos: | |
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
AV Detection |
---|
Source: |
Avira: |
Source: |
Virustotal: |
Perma Link | ||
Source: |
ReversingLabs: |
Source: |
Integrated Neural Analysis Model: |
Source: |
Joe Sandbox ML: |
Source: |
Static PE information: |
Source: |
Code function: |
3_2_0453D880 | |
Source: |
Code function: |
3_2_0453D570 | |
Source: |
Code function: |
3_2_0453D930 | |
Source: |
Code function: |
3_2_0453D120 | |
Source: |
Code function: |
3_2_0453CFA0 | |
Source: |
Code function: |
4_2_04C4D880 | |
Source: |
Code function: |
4_2_04C4CFA0 | |
Source: |
Code function: |
4_2_04C4D570 | |
Source: |
Code function: |
4_2_04C4D120 | |
Source: |
Code function: |
4_2_04C4D930 | |
Source: |
Code function: |
17_2_0321CFA0 | |
Source: |
Code function: |
17_2_0321D120 | |
Source: |
Code function: |
17_2_0321D930 | |
Source: |
Code function: |
17_2_0321D570 | |
Source: |
Code function: |
17_2_0321D880 | |
Source: |
Code function: |
18_2_0471D880 | |
Source: |
Code function: |
18_2_0471D570 | |
Source: |
Code function: |
18_2_0471D930 | |
Source: |
Code function: |
18_2_0471D120 | |
Source: |
Code function: |
18_2_0471CFA0 |
Networking |
---|
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
||
Source: |
Suricata IDS: |
Source: |
Network Connect: |
Jump to behavior |
Source: |
ASN Name: |
Source: |
UDP traffic detected without corresponding DNS query: |
Source: |
Code function: |
3_2_04541A20 |
Source: |
DNS traffic detected: |
Source: |
String found in binary or memory: |
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
||
Source: |
Network traffic detected: |
Operating System Destruction |
---|
Source: |
Code function: |
3_2_045405D0 | |
Source: |
Code function: |
4_2_04C505D0 | |
Source: |
Code function: |
17_2_032205D0 |
System Summary |
---|
Source: |
Initial file: |
Source: |
Code function: |
3_2_045405D0 |
Source: |
Code function: |
3_2_0453E730 | |
Source: |
Code function: |
4_2_04C4E730 | |
Source: |
Code function: |
17_2_0321E730 |
Source: |
File created: |
Jump to behavior |
Source: |
Code function: |
3_2_04544460 | |
Source: |
Code function: |
3_2_04545AC0 | |
Source: |
Code function: |
3_2_04541E80 | |
Source: |
Code function: |
3_2_04545540 | |
Source: |
Code function: |
3_2_04543710 | |
Source: |
Code function: |
3_2_04542D20 | |
Source: |
Code function: |
3_2_045471D0 | |
Source: |
Code function: |
3_2_04543DDD | |
Source: |
Code function: |
3_2_045431C0 | |
Source: |
Code function: |
3_2_04546190 | |
Source: |
Code function: |
3_2_04543B8E | |
Source: |
Code function: |
4_2_04C55AC0 | |
Source: |
Code function: |
4_2_04C51E80 | |
Source: |
Code function: |
4_2_04C54460 | |
Source: |
Code function: |
4_2_04C531C0 | |
Source: |
Code function: |
4_2_04C571D0 | |
Source: |
Code function: |
4_2_04C53DDD | |
Source: |
Code function: |
4_2_04C53B8E | |
Source: |
Code function: |
4_2_04C56190 | |
Source: |
Code function: |
4_2_04C55540 | |
Source: |
Code function: |
4_2_04C52D20 | |
Source: |
Code function: |
17_2_03223710 | |
Source: |
Code function: |
17_2_03223B8E | |
Source: |
Code function: |
17_2_03221E80 | |
Source: |
Code function: |
17_2_03225AC0 | |
Source: |
Code function: |
17_2_03222D20 | |
Source: |
Code function: |
17_2_03225540 | |
Source: |
Code function: |
17_2_03226190 | |
Source: |
Code function: |
17_2_032231C0 | |
Source: |
Code function: |
17_2_032271D0 | |
Source: |
Code function: |
17_2_03223DDD | |
Source: |
Code function: |
17_2_03224460 | |
Source: |
Code function: |
18_2_04724460 | |
Source: |
Code function: |
18_2_04725AC0 | |
Source: |
Code function: |
18_2_04721E80 | |
Source: |
Code function: |
18_2_04725540 | |
Source: |
Code function: |
18_2_04722D20 | |
Source: |
Code function: |
18_2_04723710 | |
Source: |
Code function: |
18_2_047271D0 | |
Source: |
Code function: |
18_2_04723DDD | |
Source: |
Code function: |
18_2_047231C0 | |
Source: |
Code function: |
18_2_04726190 | |
Source: |
Code function: |
18_2_04723B8E |
Source: |
Process created: |
Source: |
Binary or memory string: |
Source: |
Static PE information: |
Source: |
Classification label: |
Source: |
Code function: |
3_2_0453E6A0 | |
Source: |
Code function: |
4_2_04C4E6A0 | |
Source: |
Code function: |
17_2_0321E6A0 |
Source: |
Code function: |
3_2_0453CDA0 |
Source: |
Code function: |
3_2_04541760 |
Source: |
Mutant created: |
||
Source: |
Mutant created: |
||
Source: |
Mutant created: |
||
Source: |
Mutant created: |
||
Source: |
Mutant created: |
||
Source: |
Mutant created: |
Source: |
File created: |
Jump to behavior |
Source: |
Static PE information: |
Source: |
Key opened: |
Jump to behavior |
Source: |
Process created: |
Source: |
Virustotal: |
||
Source: |
ReversingLabs: |
Source: |
Process created: |
|||
Source: |
Process created: |
|||
Source: |
Process created: |
|||
Source: |
Process created: |
|||
Source: |
Process created: |
|||
Source: |
Process created: |
|||
Source: |
Process created: |
|||
Source: |
Process created: |
|||
Source: |
Process created: |
|||
Source: |
Process created: |
|||
Source: |
Process created: |
|||
Source: |
Process created: |
|||
Source: |
Process created: |
|||
Source: |
Process created: |
Jump to behavior | ||
Source: |
Process created: |
Jump to behavior | ||
Source: |
Process created: |
Jump to behavior | ||
Source: |
Process created: |
Jump to behavior | ||
Source: |
Process created: |
Jump to behavior | ||
Source: |
Process created: |
Jump to behavior |
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior | ||
Source: |
Section loaded: |
Jump to behavior |
Source: |
Code function: |