Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | March 17, 2024, 10:03 a.m. | March 17, 2024, 10:12 a.m. |
-
Xzserver.exe "C:\Users\test22\AppData\Local\Temp\Xzserver.exe"
1460
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
1.92.90.232 | Active | Moloch |
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.103:49161 -> 1.92.90.232:8000 | 2013214 | ET MALWARE Gh0st Remote Access Trojan Encrypted Session To CnC Server | Malware Command and Control Activity Detected |
TCP 192.168.56.103:49161 -> 1.92.90.232:8000 | 2016922 | ET MALWARE Backdoor family PCRat/Gh0st CnC traffic | Malware Command and Control Activity Detected |
TCP 192.168.56.103:49161 -> 1.92.90.232:8000 | 2021716 | ET MALWARE Backdoor family PCRat/Gh0st CnC traffic (OUTBOUND) 102 | Malware Command and Control Activity Detected |
TCP 1.92.90.232:8000 -> 192.168.56.103:49161 | 2048478 | ET MALWARE [ANY.RUN] Win32/Gh0stRat Keep-Alive | A Network Trojan was detected |
Suricata TLS
No Suricata TLS
packer | InstallShield 2000 |
resource name | 00526EC220243100352 |
resource name | 085513A620243100353 |
resource name | 7BFA3F1B20243100353 |
resource name | CE16F6A220243100352 |
resource name | FC0E79B320243100352 |
resource name | HOST |
resource name | SCR |
resource name | SYS |
description | Xzserver.exe tried to sleep 159 seconds, actually delayed analysis time by 159 seconds |
name | SCR | language | LANG_CHINESE | filetype | PE32 executable (GUI) Intel 80386, for MS Windows | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00059d30 | size | 0x0001d03d | ||||||||||||||||||
name | SYS | language | LANG_CHINESE | filetype | DOS executable (COM) | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00076d70 | size | 0x00008b40 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008df48 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008df48 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008df48 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008df48 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008df48 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008df48 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008df48 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008df48 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008df48 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008df48 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008df48 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008df48 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008df48 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008df48 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008df48 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008df48 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008df48 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008df48 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008df48 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008df48 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008df48 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008df48 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008df48 | size | 0x00000468 | ||||||||||||||||||
name | RT_ICON | language | LANG_CHINESE | filetype | GLS_BINARY_LSB_FIRST | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008df48 | size | 0x00000468 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008e998 | size | 0x00000134 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008e998 | size | 0x00000134 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008e998 | size | 0x00000134 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008e998 | size | 0x00000134 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008e998 | size | 0x00000134 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008e998 | size | 0x00000134 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008e998 | size | 0x00000134 | ||||||||||||||||||
name | RT_GROUP_ICON | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008ebac | size | 0x00000084 | ||||||||||||||||||
name | RT_GROUP_ICON | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008ebac | size | 0x00000084 | ||||||||||||||||||
name | RT_GROUP_ICON | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008ebac | size | 0x00000084 | ||||||||||||||||||
name | RT_VERSION | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0008ec30 | size | 0x00000398 |
section | {u'size_of_data': u'0x00031000', u'virtual_address': u'0x00025000', u'entropy': 6.916460607775499, u'name': u'.data', u'virtual_size': u'0x00032988'} | entropy | 6.91646060778 | description | A section with a high entropy has been found | |||||||||
entropy | 0.345070422535 | description | Overall entropy of this PE file is high |
process | xzserver.exe |
host | 1.92.90.232 |
reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\XXXXXX4FBB9E52 | reg_value | C:\Windows\XXXXXX4FBB9E52\svchsot.exe |
mutex | AAAAAArr2msb2mr72xsLGpp6+vr58= |
Bkav | W32.AIDetectMalware |
Lionic | Trojan.Win32.Generic.lNr1 |
Elastic | malicious (high confidence) |
Cynet | Malicious (score: 100) |
CAT-QuickHeal | Trojan.Aksula.A |
Skyhigh | GenericRXER-EK!6A7DBF9CF7F2 |
ALYac | Gen:Trojan.Redosdru.!o!.1 |
Cylance | unsafe |
VIPRE | Gen:Trojan.Redosdru.!o!.1 |
Sangfor | Suspicious.Win32.Save.ins |
K7AntiVirus | Trojan ( 0055e3e41 ) |
BitDefender | Gen:Trojan.Redosdru.!o!.1 |
K7GW | Trojan ( 0055e3e41 ) |
Cybereason | malicious.cf7f21 |
Arcabit | Trojan.Redosdru.!o!.1 |
Baidu | Win32.Trojan.Dialer.a |
VirIT | Backdoor.Win32.Generic.BAA |
Symantec | SMG.Heur!gen |
tehtris | Generic.Malware |
ESET-NOD32 | a variant of Win32/Farfli.XB |
APEX | Malicious |
McAfee | GenericRXER-EK!6A7DBF9CF7F2 |
Avast | Win32:Dropper-JQQ [Drp] |
ClamAV | Win.Malware.Generickdz-6957625-0 |
Kaspersky | Trojan-Spy.Win32.Agent.cdfh |
Alibaba | TrojanDownloader:Win32/Farfli.add155f9 |
NANO-Antivirus | Trojan.Win32.Dwn.rkaxu |
MicroWorld-eScan | Gen:Trojan.Redosdru.!o!.1 |
Rising | Backdoor.Zegost!1.9CDE (CLASSIC) |
Emsisoft | Gen:Trojan.Redosdru.!o!.1 (B) |
F-Secure | Backdoor.BDS/Zegost.bmnya |
DrWeb | Trojan.DownLoader5.49351 |
Zillya | Trojan.Dialer.Win32.12199 |
TrendMicro | BKDR_ZEGOST.SM34 |
Trapmine | malicious.high.ml.score |
FireEye | Generic.mg.6a7dbf9cf7f21fd9 |
Sophos | Mal/Generic-S |
Ikarus | Trojan.Win32.Dialer |
Jiangmin | TrojanSpy.Agent.tst |
Webroot | W32.Trojan.Gen |
Detected | |
Avira | BDS/Zegost.bmnya |
MAX | malware (ai score=85) |
Antiy-AVL | Trojan[Spy]/Win32.Agent.cdfh |
Kingsoft | malware.kb.a.1000 |
Gridinsoft | Trojan.Win32.Gen.tr |
Xcitium | TrojWare.Win32.Kryptik.BHFS@56cp6y |
Microsoft | Backdoor:Win32/Farfli!pz |
ViRobot | Trojan.Win32.A.Agent.430080.A |
ZoneAlarm | Trojan-Spy.Win32.Agent.cdfh |