Summary | ZeroBOX

RE-DEMON(KFTC).exe

Category Machine Started Completed
FILE s1_win7_x6401 April 2, 2021, 9:54 a.m. April 2, 2021, 9:57 a.m.
Size 26.0KB
Type MS-DOS executable, MZ for MS-DOS
MD5 203435aeaeb39a56432d1116432ebbd4
SHA256 2f41c3335f2e387849d021932df1ab6a3f6b20ad0a36b7a96ed249d09d1e8715
CRC32 9E9191F0
ssdeep 768:/qL5jeeDoqEZ74Xug7UnZxfHrQQxn7DH67O:/qNjeD74b0Zx8Qd67O
Yara
  • PE_Header_Zero - PE File Signature Zero
  • screenshot - Take screenshot
  • IsPE32 - (no description)
  • IsWindowsGUI - (no description)
  • IsPacked - Entropy Check
  • HasModified_DOS_Message - DOS Message Check

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section .MPRESS1
section .MPRESS2
file C:\Users\test22\AppData\Local\Temp\62E9.tmp\ic.bat
Time & API Arguments Status Return Repeated

ShellExecuteExW

show_type: 0
filepath_r: C:\Users\test22\AppData\Local\Temp\62E9.tmp\ic.bat
parameters:
filepath: C:\Users\test22\AppData\Local\Temp\62E9.tmp\ic.bat
1 1 0
section {u'size_of_data': u'0x00004e00', u'virtual_address': u'0x00001000', u'entropy': 7.990990126390301, u'name': u'.MPRESS1', u'virtual_size': u'0x0000d000'} entropy 7.99099012639 description A section with a high entropy has been found
entropy 0.764705882353 description Overall entropy of this PE file is high
file C:\Users\test22\AppData\Local\Temp\62E9.tmp
file C:\Users\test22\AppData\Local\Temp\62E9.tmp\ic.bat