One or more potentially interesting buffers were extracted, these generally contain injected code, configuration data, etc.
Performs some HTTP requests
(3 个事件)
request |
GET http://stat.zvu.com/installer.html?param=ed84ff5985ee5d78424e538c61f439342a2ea9ef4c840fd09add337d57cf62a5ee9e318e63af818a08cbdf4f1f24e7a877e435c9ae5a52a5726be07d0018fc5d89805a30c33a071d9a7d1512dd1dfecf368f09a84e1ccdf6431183acb4644e5ae068ac60eafa0cf3d8902b78a82856b25436b441585c9a752eb5ccbb51144243d628788f7c8c9767840fd440af392fc53f397a7514e4d2c00e1d5c0fd15ebddb43d2d59d6a33b73150849cdd29b5cc56425928b4bd26587261162b41fef204f5256dbbb92ccb2a59b3cc0fb98c142e3480b08f218a6eba58cb69809d3c0770b3a973d4a72d91bfb61df93fe2ca116750449057f6a172514545ac5a5445580a19ffd387c19984a37d1eeeec689373139e |
request |
GET http://zvu.com/img/no-cover.jpg |
request |
GET http://dl.zvu.com/dl/zvu-18.0.1.ru.win7_32.installer.exe |
Queries the disk size which could be used to detect virtual machine with small fixed size or dynamic allocation
(1 个事件)
Time & API |
Arguments |
Status |
Return |
Repeated |
1621008621.913999
GetDiskFreeSpaceExW
|
root_path:
C:\
free_bytes_available:
19611471872
total_number_of_free_bytes:
19611471872
total_number_of_bytes:
34252779520
|
success
|
1 |
0
|
Creates executable files on the filesystem
(2 个事件)
file |
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\ZvuInstaller.exe |
file |
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\hd.vbs |
Drops an executable to the user AppData folder
(1 个事件)
file |
C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\ZvuInstaller.exe |
Executes one or more WMI queries
(1 个事件)
wmi |
Select * from Win32_DiskDrive |
Checks adapter addresses which can be used to detect virtual network interfaces
(1 个事件)
Time & API |
Arguments |
Status |
Return |
Repeated |
1621008629.647999
GetAdaptersAddresses
|
flags:
0
family:
0
|
failed
|
111 |
0
|
An executable file was downloaded by the process d751d9e784a2f5ae4d1771caec8fff4d.exe
(1 个事件)
Time & API |
Arguments |
Status |
Return |
Repeated |
1621008639.491999
InternetReadFile
|
buffer:
MZ ÿÿ ¸ @ à º ´ Í!¸LÍ!This program cannot be run in DOS mode.
$ ðHô)u´)u´)ué~·)u75{¼)ué¿)uéq¶)u´)t )uw&(¿)uë~)us/sµ)uRich´)u PE L fJâD à * ° ? @ @ P àp ªm @ ´ .text Â) * `.rdata â9 @ : . @ @.data ¤
h @ À.rsrc ªm n p @ @ VñNè* 3ÉFxNtHHHÇ@ Ç èAA ÆFhÆ^ Vñè 3ÀÇF` FTFXF\ÇFPðAA Æ^ÃVÁj3ÉZHHHPÇ BA jP$^º BA HHH Ç@øAA H,H0H4p8P(pLH@HDHHP<^ø"A èW ìô SÙVWMÐè* ÇEÐlBA E°3ÿP}ü}¬ÿ@A ÿuM¬ÆEüèW× u}ðF0;ÇÖ }jè
ÀYt` Ç \BA ðë3ö
öuètVÿPE¬jFEFEFEOÆEüMèÇ
ÀYt` ` Ç LBA Eëe E
ÀEìtPÿQÿwMÆEüÿ7VèñÊ EìMÐPèå EìÆEü
ÀtPÿQ
öÆEütVÿPÿEðEMðÇ;H01ÿÿÿð3ÿF ÿÿÿEäènþÿÿPÿÿÿÆEüèâ
ÿÿÿÆEüPVè÷
; tCP
ÿÿÿPè öØÀþÀEÈ Kxè¦ Ctst3ÿ;ÇtPÿQ>{h tAhÀ èÄ YE;ÇÆEüt Èè±e ë3ÀPÎÆEüClèÉÕ Cl;ÇtÀë3ÀCpKp ÿÿÿRÿ9}ä}ð7 3öEMð@H89
q x
g uuh8A WÆEüèP_ Àt.hx è* YEè;ÆÆEü t ÈèÊ ë3ÀPMÆEüè1Õ hHA Wè_ Àt5jèð ðYuè
öÆEü
tÎè
Ç0BA ë3öVMÆEüèïÔ 3öhhA WèÏ^ Àt+jè¬ ;ÆYtppppÇ BA ë3ÀPMè³Ô 9ut:j`è| YEè;ÆÆEütÈè:u ðë3öVMÆEüèÔ ÿuNXèvÔ 3öE;ÆM EìPÿQEìKxPÆEüè) EìÆEü;ÆtPÿQ{h tÿuKlè§h EÆEü;ÆtPÿQEÆEüé uhXA WÆEüèì] Àt.hÀ èÆ YE;ÆÆEüt Èè6 ë3ÀPMÆEüèÍÓ E;Æ EPÿQEKxPÆEüè
EÆEü;ÆtPÿQ{h tÿuKlèh EÆEü;ÆtPÿQÿEðEð;EäËýÿÿ
ÿÿÿKPè¥ Æ3ÿKpÿP9}ä}è}}ìº }EMìeð @4MF8 UðRhpHA PÆEüÿEð
Àt(Oùÿ9
ÉvQWPÿRø
ÿ
w Eð
ÀÆEütPÿQEvjMEÌè ¿BA }j|ÿÿÿÆEüèf ½|ÿÿÿÿuÌMÆEüèd£ V|ÿÿÿèX£ }
övGHMÈ|ÿÿÿPè; ÿENuåeÈ }Ì J uèO3Ò
Éâ G 90Ó BÀ;Ñ|ðéÊ MÆEü;Ît QÿPE;ÆÆEütPÿQPÿÿÿÆEüèf¢ ÿÿÿÆEüèÄ eü E°Pÿ@A M¬èô ÇEÐlBA ÇEü
ëBPÿÿÿÆEüè"¢ ÿÿÿÆEüè eü E°Pÿ@A M¬è° ÇEÐlBA ÇEü MÐè÷¡ MüÿMÐèÛ¡ ¸@ é ÂëÈÿ
À|O DÁOHë&O03Ò
É~G490tvBÀ;Ñ|ôÈÿ
À, MÁMPèð ÿEÈFEÈuè;E̹þÿÿÿuKpuìÿuVÿP|ÿÿÿÆEüèT¡ MÆEüèH¡ F;uäuìýÿÿ3ÿé: Âë
ÀÆEütPÿQPÿÿÿÆEüè¡ ÿÿÿÆEüèq eü E°Pÿ@A M¬è¡
ÇEÐlBA ÇEü ¿@ ëSEðÆEü
ÀtPÿQPÿÿÿÆEüè¹ ÿÿÿÆEüè eü E°Pÿ@A M¬èG
ÇEÐlBA ÇEü MÐè MüÿMÐèr Çé° |ÿÿÿÆEüè\ MÆEüèP PÿÿÿÆEüèA ÿÿÿÆEüè eü M¬èè ÇEÐlBA MÐÇEü è MüÿMÐè ¸@ é?
dÿÿÿ ÿÿÿPE¤P
Hÿÿÿÿ0èk {h tClM¤¼ 9}äu?PÿÿÿÆEüè¶ ÿÿÿÆEüè eü M¬è] ÇEÐlBA ÇEü 3öéµ jhÿÿÿèÏ Ç
hÿÿÿBA ÿuØhÿÿÿÆEüèÆ 3ö9}Ø~EÜhÿÿÿ°ÿ0è« F;uØ|çÿu EU¨E¨CtjWRÿuØWÿµtÿÿÿPÿQhÿÿÿðÆEüè PÿÿÿÆEü èú ÿÿÿÆEüèX eü M¬è¡ ÇEÐlBA ÇEü! MÐèÙ MüÿMÐè½ ÆMô_^[d
ÉÂ Á3ÉHHHL$HÇ tBA Â Vñè
öD$tVèù YÆ^Â UìUVW" |