Windows
Analysis Report
TDL7Z3zNPD.exe
Overview
General Information
Sample name: | TDL7Z3zNPD.exerenamed because original name is a hash value |
Original sample name: | a82c5abfc976b78a19020e690992a803fae267080d1e3fb30dff552a0ddf73b1.exe |
Analysis ID: | 1670877 |
MD5: | ccb993b425257228bd48c0aac20d5027 |
SHA1: | 20c2350d5dee7c06dfcd9d182bfa87a02ad8e275 |
SHA256: | a82c5abfc976b78a19020e690992a803fae267080d1e3fb30dff552a0ddf73b1 |
Tags: | cactusexeransomwareuser-TheRavenFile |
Infos: | |
Detection
Score: | 64 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
TDL7Z3zNPD.exe (PID: 7592 cmdline:
"C:\Users\ user\Deskt op\TDL7Z3z NPD.exe" MD5: CCB993B425257228BD48C0AAC20D5027) conhost.exe (PID: 7600 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Babuk | Babuk Ransomware is a sophisticated ransomware compiled for several platforms. Windows and ARM for Linux are the most used compiled versions, but ESX and a 32bit old PE executable were observed over time. as well It uses an Elliptic Curve Algorithm (Montgomery Algorithm) to build the encryption keys. | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_babuk | Yara detected Babuk Ransomware | Joe Security | ||
JoeSecurity_babuk | Yara detected Babuk Ransomware | Joe Security | ||
JoeSecurity_babuk | Yara detected Babuk Ransomware | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_babuk | Yara detected Babuk Ransomware | Joe Security | ||
JoeSecurity_babuk | Yara detected Babuk Ransomware | Joe Security |
Click to jump to signature section
AV Detection |
---|
Source: | Virustotal: | Perma Link |
Source: | Static PE information: |
Networking |
---|
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Binary or memory string: |
Source: | Classification label: |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Process created: | ||
Source: | Process created: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Binary or memory string: |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 2 Command and Scripting Interpreter | 1 Bootkit | 1 Process Injection | 1 Bootkit | OS Credential Dumping | 1 System Information Discovery | Remote Services | Data from Local System | 1 Proxy | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 DLL Side-Loading | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 File Deletion | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
64% | Virustotal | Browse |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1670877 |
Start date and time: | 2025-04-22 09:05:36 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 5s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 11 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Power Change |
Sample name: | TDL7Z3zNPD.exerenamed because original name is a hash value |
Original Sample Name: | a82c5abfc976b78a19020e690992a803fae267080d1e3fb30dff552a0ddf73b1.exe |
Detection: | MAL |
Classification: | mal64.rans.evad.winEXE@2/0@0/0 |
EGA Information: | Failed |
HCA Information: | Failed |
Cookbook Comments: |
|
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, W MIADAP.exe, SIHClient.exe, Sgr mBroker.exe, conhost.exe, svch ost.exe - Excluded IPs from analysis (wh
itelisted): 184.29.183.29, 4.2 45.163.56, 150.171.27.254 - Excluded domains from analysis
(whitelisted): c2a9c95e369881 c67228a6591cac2686.clo.footpri ntdns.com, ax-ring.msedge.net, fs.microsoft.com, slscr.updat e.microsoft.com, ctldl.windows update.com, c.pki.goog, fe3cr. delivery.mp.microsoft.com - Execution Graph export aborted
for target TDL7Z3zNPD.exe, PI D 7592 because it is empty - Not all processes where analyz
ed, report is missing behavior information
File type: | |
Entropy (8bit): | 6.418676674278581 |
TrID: |
|
File name: | TDL7Z3zNPD.exe |
File size: | 9'222'026 bytes |
MD5: | ccb993b425257228bd48c0aac20d5027 |
SHA1: | 20c2350d5dee7c06dfcd9d182bfa87a02ad8e275 |
SHA256: | a82c5abfc976b78a19020e690992a803fae267080d1e3fb30dff552a0ddf73b1 |
SHA512: | b0da5aa97c9605ea59374bc44bb2b207f3f928813c29d26a1b4d51dc87d6a58d20d6050b23631acda28d78ef4ca2219cb507fbdd14fd861bd333ab2fb719e62b |
SSDEEP: | 98304:spDzj18PqRj6+eK+3gp53LuGnLYrfJ40YeeWB9OutOUHu345hsMXWruB0W2:ej1/N+6obZOutOUHk |
TLSH: | FE965B5365AB0CEDDDDA67B492D76336A734FD218A792F3B6604C6302D139C06E2BB10 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....ze..d.......&....(.0@..&S..>.............@.............................Pi...........`... ............................ |
Icon Hash: | 90cececece8e8eb0 |
Entrypoint: | 0x1400013f0 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x140000000 |
Subsystem: | windows cui |
Image File Characteristics: | EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LARGE_ADDRESS_AWARE |
DLL Characteristics: | HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT |
Time Stamp: | 0x657AEE8C [Thu Dec 14 12:01:16 2023 UTC] |
TLS Callbacks: | 0x4032b460, 0x1, 0x4032b430, 0x1, 0x4033fa20, 0x1 |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | 2db53f4954708699a2b0e735b5b59251 |
Instruction |
---|
dec eax |
sub esp, 28h |
dec eax |
mov eax, dword ptr [004BE4A5h] |
mov dword ptr [eax], 00000000h |
call 00007FB5310D6A3Fh |
nop |
nop |
dec eax |
add esp, 28h |
ret |
nop dword ptr [eax] |
dec eax |
sub esp, 28h |
call 00007FB5314124A4h |
dec eax |
cmp eax, 01h |
sbb eax, eax |
dec eax |
add esp, 28h |
ret |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
dec eax |
lea ecx, dword ptr [00000009h] |
jmp 00007FB5310D6C99h |
nop dword ptr [eax+00h] |
ret |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
push ebp |
dec eax |
mov ebp, esp |
dec eax |
sub esp, 00000090h |
dec eax |
mov eax, dword ptr [0056B806h] |
call eax |
dec eax |
mov dword ptr [ebp-08h], eax |
mov ecx, 00000008h |
call 00007FB531412603h |
dec eax |
mov dword ptr [ebp-10h], eax |
mov edx, 00000028h |
mov ecx, 00000040h |
dec eax |
mov eax, dword ptr [0056B941h] |
call eax |
dec eax |
mov dword ptr [ebp-18h], eax |
dec eax |
mov eax, dword ptr [ebp-10h] |
inc ecx |
mov eax, 00000004h |
mov edx, 00000008h |
dec eax |
mov ecx, eax |
dec eax |
mov eax, dword ptr [0056B682h] |
call eax |
mov dword ptr [ebp-26h], 00000000h |
mov word ptr [ebp-22h], 0100h |
dec eax |
lea eax, dword ptr [ebp+00h] |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x56c000 | 0x2cf4 | .idata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x571000 | 0x4e8 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x4d6000 | 0x27948 | .pdata |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x572000 | 0x9f38 | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x4bd9a0 | 0x28 | .rdata |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x402e50 | 0x403000 | deafb4fd12cde2c1b60860c86c787133 | unknown | unknown | unknown | unknown | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.data | 0x404000 | 0x5120 | 0x5200 | e706e7a92dccbaef2b9fe1e975b26c2f | False | 0.13724275914634146 | data | 2.1655766071634344 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rdata | 0x40a000 | 0xcb020 | 0xcb200 | d5be3237699f56612e4f798a600fe652 | False | 0.29029447115384616 | data | 5.093957452695144 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.pdata | 0x4d6000 | 0x27948 | 0x27a00 | 757379b8151dd98e75a12e66dd817d18 | False | 0.5116386533911672 | data | 6.275470632316642 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.xdata | 0x4fe000 | 0x29fdc | 0x2a000 | 0f438f4829e223726847696e9d64bc78 | False | 0.17568824404761904 | data | 4.694062618150425 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.bss | 0x528000 | 0x43c90 | 0x0 | d41d8cd98f00b204e9800998ecf8427e | False | 0 | empty | 0.0 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.idata | 0x56c000 | 0x2cf4 | 0x2e00 | ea1eb029fff0efb3b71bb519b00ac913 | False | 0.2398947010869565 | data | 4.167456177867594 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.CRT | 0x56f000 | 0x68 | 0x200 | dc8f96afaaaa9a9fed2fff837af96d94 | False | 0.078125 | data | 0.40665232183492983 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.tls | 0x570000 | 0x10 | 0x200 | bf619eac0cdf3f68d496ea9344137e8b | False | 0.02734375 | data | 0.0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x571000 | 0x4e8 | 0x600 | 7bb75ff0b08b50c6eac14449d8033074 | False | 0.333984375 | data | 4.7823913622889584 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.reloc | 0x572000 | 0x9f38 | 0xa000 | d0cc4b10f9af6f3dfa642555d038f338 | False | 0.2810546875 | data | 5.446935941478724 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
/4 | 0x57c000 | 0x2310 | 0x2400 | 0ab170630d5c1d65c2ba5fd2b0d70eff | False | 0.22916666666666666 | data | 2.4703200594587593 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
/19 | 0x57f000 | 0xc53c8 | 0xc5400 | f5df15a06dd374a96fc720b34eb0a7dc | False | 0.2963638208967047 | data | 5.996197696654939 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
/31 | 0x645000 | 0xc32f | 0xc400 | e7a4f9dd50bb9932ce36da7e3ec8a189 | False | 0.23487324617346939 | data | 4.949123208937445 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
/45 | 0x652000 | 0x19a3f | 0x19c00 | 2a79bc905498eac4acf836fd67a9f74b | False | 0.4298202366504854 | data | 5.223030067952597 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
/57 | 0x66c000 | 0x7dd8 | 0x7e00 | 868dc9d2b12f48322b1c95a7d252c136 | False | 0.2058531746031746 | data | 4.586168864864171 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
/70 | 0x674000 | 0x2bca | 0x2c00 | 97f29411b63f8b434953d3282e700b41 | False | 0.2785866477272727 | data | 4.556736428924381 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
/81 | 0x677000 | 0x6de4 | 0x6e00 | 150ad6da94159883ba875b75f701a1bb | False | 0.11502130681818182 | data | 5.043777069233123 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
/97 | 0x67e000 | 0x14aab | 0x14c00 | c0a706b5601bed235c043a076c82c150 | False | 0.5041650978915663 | data | 5.968165520201052 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
/113 | 0x693000 | 0x1b3c | 0x1c00 | 8e215c8a2e918815f7923dcc518f0095 | False | 0.5439453125 | data | 5.4694387933596875 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_MANIFEST | 0x571058 | 0x48f | XML 1.0 document, ASCII text | 0.40102827763496146 |
DLL | Import |
---|---|
KERNEL32.DLL | AcquireSRWLockExclusive, AcquireSRWLockShared, AddVectoredExceptionHandler, CloseHandle, ConvertFiberToThread, ConvertThreadToFiberEx, CopyFileW, CreateDirectoryW, CreateEventA, CreateFiberEx, CreateFileW, CreateHardLinkW, CreateMutexW, CreateProcessW, CreateSemaphoreA, CreateToolhelp32Snapshot, DeleteCriticalSection, DeleteFiber, DeleteFileW, DuplicateHandle, EnterCriticalSection, FindClose, FindFirstFileW, FindFirstVolumeW, FindNextFileW, FindNextVolumeW, FindVolumeClose, FormatMessageA, FormatMessageW, FreeLibrary, GetACP, GetConsoleMode, GetConsoleWindow, GetCurrentProcess, GetCurrentProcessId, GetCurrentThread, GetCurrentThreadId, GetDiskFreeSpaceExW, GetDriveTypeW, GetEnvironmentVariableW, GetFileAttributesW, GetFileInformationByHandle, GetFileSizeEx, GetFileType, GetFullPathNameW, GetHandleInformation, GetLastError, GetLogicalDriveStringsW, GetModuleFileNameA, GetModuleFileNameW, GetModuleHandleExA, GetModuleHandleExW, GetModuleHandleW, GetProcAddress, GetProcessAffinityMask, GetProcessHeap, GetProcessId, GetStdHandle, GetSystemDirectoryA, GetSystemInfo, GetSystemTimeAsFileTime, GetTempPathW, GetThreadContext, GetThreadPriority, GetTickCount64, GetVersion, GetVolumeInformationW, HeapAlloc, HeapFree, InitializeCriticalSection, InitializeSRWLock, IsDBCSLeadByteEx, IsDebuggerPresent, IsProcessorFeaturePresent, LeaveCriticalSection, LoadLibraryA, LoadLibraryW, LocalAlloc, LocalFree, MoveFileExW, MultiByteToWideChar, OpenProcess, OutputDebugStringA, Process32NextW, RaiseException, ReadConsoleA, ReadConsoleW, ReleaseSRWLockExclusive, ReleaseSRWLockShared, ReleaseSemaphore, RemoveDirectoryW, RemoveVectoredExceptionHandler, ResetEvent, ResumeThread, RtlCaptureContext, RtlLookupFunctionEntry, RtlUnwindEx, RtlVirtualUnwind, SetConsoleMode, SetEndOfFile, SetEvent, SetFileAttributesW, SetFilePointer, SetLastError, SetProcessAffinityMask, SetThreadContext, SetThreadPriority, SetUnhandledExceptionFilter, Sleep, SuspendThread, SwitchToFiber, TerminateProcess, TlsAlloc, TlsFree, TlsGetValue, TlsSetValue, TryEnterCriticalSection, VirtualAlloc, VirtualFree, VirtualLock, VirtualProtect, VirtualQuery, WaitForMultipleObjects, WaitForSingleObject, WideCharToMultiByte, WriteFile |
ADVAPI32.dll | AddAccessDeniedAce, AllocateAndInitializeSid, CloseServiceHandle, ControlService, CryptAcquireContextW, CryptGenRandom, CryptReleaseContext, DeregisterEventSource, InitializeAcl, OpenSCManagerA, OpenServiceA, RegisterEventSourceW, ReportEventW, SetSecurityInfo |
msvcrt.dll | __C_specific_handler, ___lc_codepage_func, ___mb_cur_max_func, __getmainargs, __initenv, __iob_func, __set_app_type, __setusermatherr, _amsg_exit, _beginthreadex, _cexit, _close, _commode, _endthreadex, _errno, _exit, _fdopen, _fileno, _findclose, _fileno, _fmode, _fstat64, _get_osfhandle, _gmtime64, _initterm, _localtime64, _lock, _lseeki64, _onexit, _read, _setjmp, _setmode, _stat64, _strdup, _strdup, _strtoi64, _strtoui64, _telli64, _time64, _ultoa, _unlock, _vsnprintf, _vsnwprintf, _wchdir, _wchmod, _wfindfirst64, _wfindnext64, _wfopen, _wfullpath, _wgetcwd, _wmkdir, _wopen, _wremove, _wrename, _write, _wstat64, _wsystem, _wutime64, abort, atoi, calloc, clock, exit, fclose, feof, ferror, fflush, fgets, fopen, fprintf, fputc, fputs, fputwc, fread, free, fwprintf, fseek, ftell, fwrite, getc, getenv, isspace, iswctype, isxdigit, localeconv, longjmp, malloc, memchr, memcmp, memcpy, memmove, memset, printf, qsort, raise, rand, realloc, remove, setlocale, setvbuf, signal, sprintf, srand, strcat, strchr, strcmp, strcoll, strcpy, strcspn, strerror, strftime, strlen, strncmp, strncpy, strrchr, strspn, strstr, strtol, strtoul, strxfrm, tolower, towlower, towupper, ungetc, vfprintf, wcscat, wcscmp, wcscoll, wcscpy, wcsftime, wcslen, wcsncmp, wcsstr, wcstol, wcstombs, wcsxfrm |
PSAPI.DLL | GetProcessImageFileNameW |
RstrtMgr.DLL | RmEndSession, RmGetList, RmRegisterResources, RmShutdown, RmStartSession |
SHELL32.dll | IsUserAnAdmin, StrStrIW |
USER32.dll | GetProcessWindowStation, GetUserObjectInformationW, MessageBoxW, ShowWindow |
WS2_32.dll | gethostbyaddr, getservbyname, getservbyport, htonl, htons, inet_addr, inet_ntoa |
WSOCK32.dll | WSACleanup, WSAGetLastError, WSASetLastError, WSAStartup, accept, bind, closesocket, connect, gethostbyname, getsockname, getsockopt, ioctlsocket, listen, ntohs, recv, select, send, setsockopt, shutdown, socket |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 03:06:26 |
Start date: | 22/04/2025 |
Path: | C:\Users\user\Desktop\TDL7Z3zNPD.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff736c10000 |
File size: | 9'222'026 bytes |
MD5 hash: | CCB993B425257228BD48C0AAC20D5027 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 1 |
Start time: | 03:06:26 |
Start date: | 22/04/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7e2000000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|