Benign _unknown Download

virussign.com_ee56b164d78f1b9f7d79840624e24430.vir

Process injection targeting privileged processBatch with timeout before deletion
SHA-2560a93fdf6e214ef75ccc41d64a76f6db2a08b17fec40053179dffb36ed4fb838f

Evidence

ANSI GUI active-window probe cluster 0x248a4–0x24934
⋯3 more rows
0x248d4626a656374496e666f726d6174696f6ebjectInformation
0x248e4410000004765744c6173744163746976A...GetLastActiv
0x248f465506f70757000004765744163746976ePopup..GetActiv
0x249046557696e646f77004d65737361676542eWindow.MessageB
0x249146f7841005553455233322e444c4c0000oxA.USER32.DLL..
0x2492420436f6d706c657465204f626a656374 Complete Object
0x24934204c6f Lo
Process injection targeting privileged process 0x24ff0–0x252e0
0x24ff0a45f4200805f4200785f42006c5f4200._B.._B.x_B.l_B.
0x250005c5f4200405f4200205f4200f85e4200\_B.@_B. _B..^B.
0x25010d05e4200a85e42007c5e4200605e4200.^B..^B.|^B.`^B.
0x250203c5e4200185e4200ec5d4200c05d4200<^B..^B..]B..]B.
0x25030a45d4200ec6f42000000000000000000.]B..oB.........
0x2504000000000000000000000000000000000................
0x2505000000000000000000000000000000000................
0x2506000000000000000000000000000000000................
0x2507000000000000000000000000000000000................
0x2508000000000000000000000000000000000................
0x2509000000000000000000000000000000000................
0x250a000000000000000000000000000000000................
0x250b000000000000000000000000000000000................
0x250c000000000000000000000000000000000................
0x250d000000000000000000000000000000000................
0x250e000000000000000000000000000000000................
0x250f000000000000000000000000000000000................
0x2510000000000000000000000000000000000................
0x2511000000000000000000000000000000000................
0x2512000000000000000000000000000000000................
0x2513000000000000000002000200020002000........ . . . .
0x2514020002000200020002000280028002800 . . . . .(.(.(.
0x2515028002800200020002000200020002000(.(. . . . . . .
0x2516020002000200020002000200020002000 . . . . . . . .
⋯4 more rows
0x251b010001000100010001000810081008100................
0x251c081008100810001000100010001000100................
0x251d001000100010001000100010001000100................
0x251e001000100010001000100010001001000................
0x251f010001000100010001000820082008200................
0x2520082008200820002000200020002000200................
0x2521002000200020002000200020002000200................
0x2522002000200020002000200020002001000................
0x2523010001000100020000000000000000000...... .........
0x2524000000000000000000000000000000000................
0x2525000000000000000000000000000000000................
0x2526000000000000000000000000000000000................
0x2527000000000000000000000000000000000................
0x2528000000000000000000000000000000000................
0x2529000000000000000000000000000000000................
0x252a000000000000000000000000000000000................
0x252b000000000000000000000000000000000................
0x252c000000000000000000000000000000000................
0x252d000000000000000000000000000000000................
0x252e000000000000000000000000000000000................
PHP report endpoint 0x25c60–0x25ca0
0x25c60730069006f006e003d00250073000000s.i.o.n.=.%.s...
0x25c702f007200650070006f00720074002e00/.r.e.p.o.r.t...
0x25c807000680070003f007400790070006500p.h.p.?.t.y.p.e.
0x25c903d0063006c00690065006e0074002600=.c.l.i.e.n.t.&.
0x25ca064006100740061003d00250073 d.a.t.a.=.%.s
Batch with timeout before deletion 0x25dfb–0x25e6b
0x25dfb004700450054000000000000002f0063.G.E.T......./.c
0x25e0b002000740069006d0065006f00750074. .t.i.m.e.o.u.t
0x25e1b0020002f007400200031002000260020. ./.t. .1. .&.
0x25e2b00640065006c0020002f00510020002f.d.e.l. ./.Q. ./
0x25e3b00460020002200250073002200000000.F. .".%.s."....
0x25e4b0063006d0064002e0065007800650000.c.m.d...e.x.e..
0x25e5b006f00700065006e0000000000250078.o.p.e.n.....%.x
0x25e6b0000000000696e76 .....inv
Reads thread marker (native variant) 0x2b420–0x2b4e0
0x2b42069727475616c4d656d6f727900000000irtualMemory....
0x2b4304e74416c6c6f63617465566972747561NtAllocateVirtua
0x2b4406c4d656d6f7279004e74467265655669lMemory.NtFreeVi
0x2b450727475616c4d656d6f7279004e745072rtualMemory.NtPr
0x2b4606f746563745669727475616c4d656d6fotectVirtualMemo
0x2b470727900004e7452656164566972747561ry..NtReadVirtua
0x2b4806c4d656d6f7279004e74577269746556lMemory.NtWriteV
0x2b49069727475616c4d656d6f727900000000irtualMemory....
0x2b4a04e74476574436f6e7465787454687265NtGetContextThre
0x2b4b0616400004e74536574436f6e74657874ad..NtSetContext
0x2b4c054687265616400002e74657874000000Thread...text...
0x2b4d04b65726e656c33322e646c6c00000000Kernel32.dll....
0x2b4e0437265617465 Create

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.