Summary | ZeroBOX

6gdwwv.exe

Ficker Stealer
Category Machine Started Completed
FILE s1_win7_x6401 April 7, 2021, 7:43 a.m. April 7, 2021, 7:45 a.m.
Size 267.0KB
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5 77be0dd6570301acac3634801676b5d7
SHA256 94e60de577c84625da69f785ffe7e24c889bfa6923dc7b017c21e8a313e4e8e1
CRC32 7FC11B0F
ssdeep 6144:VMWdTMYHqhElscw4liVM1LDtG8esyh3hNn+:TdTJqWrEVcDYxN+
Yara
  • Ficker_Stealer_Zero - Ficker Stealer
  • network_tcp_listen - Listen for incoming communication
  • network_tcp_socket - Communications over RAW socket
  • network_dns - Communications use DNS
  • screenshot - Take screenshot
  • win_registry - Affect system registries
  • win_files_operation - Affect private profile
  • Str_Win32_Winsock2_Library - Match Winsock 2 API library declaration
  • PE_Header_Zero - PE File Signature Zero
  • IsPE32 - (no description)
  • IsWindowsGUI - (no description)
  • HasOverlay - Overlay Check

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

request GET http://api.ipify.org/?format=xml
domain api.ipify.org
section {u'size_of_data': u'0x00003000', u'virtual_address': u'0x00038000', u'entropy': 6.831976809981057, u'name': u'.rdata', u'virtual_size': u'0x00002e68'} entropy 6.83197680998 description A section with a high entropy has been found
Elastic malicious (high confidence)
ClamAV Win.Trojan.FickerStealer-9805476-1
ALYac Trojan.Agent.Zudochka
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
AegisLab Trojan.Win32.Zudochka.4!c
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0001555e1 )
Alibaba TrojanDownloader:Win32/Stealer.2a8ebd8c
K7GW Trojan ( 0001555e1 )
CrowdStrike win/malicious_confidence_100% (W)
Arcabit Trojan.Generic.D2B83AD4
Cyren W32/Trojan.PEUM-7292
Symantec Trojan.Gen.2
ESET-NOD32 a variant of Win32/Agent.UKB
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan.Win32.Zudochka.vho
BitDefender Trojan.GenericKD.45628116
NANO-Antivirus Trojan.Win32.Zudochka.ijmhtg
MicroWorld-eScan Trojan.GenericKD.45628116
Avast Win32:TrojanX-gen [Trj]
Tencent Malware.Win32.Gencirc.11bb269d
Ad-Aware Trojan.GenericKD.45628116
Emsisoft Trojan.Agent (A)
Comodo Malware@#30vyhmhgld3p
DrWeb Trojan.PWS.Stealer.29929
Zillya Trojan.Agent.Win32.1690805
TrendMicro TrojanSpy.Win32.FICKERSTEALER.THBAFBA
McAfee-GW-Edition BehavesLike.Win32.Generic.dh
FireEye Generic.mg.77be0dd6570301ac
Sophos Mal/Generic-R + Troj/Delp-GW
Ikarus Trojan.Win32.Agent
Jiangmin Trojan.Zudochka.kd
Webroot W32.Trojan.Gen
Avira TR/Agent.aypeq
eGambit Unsafe.AI_Score_98%
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Trojan.Win32.Agent.oa
Microsoft TrojanDownloader:Win32/Stealer.CK!MTB
ZoneAlarm HEUR:Trojan.Win32.Zudochka.vho
GData Trojan.GenericKD.45628116
AhnLab-V3 Malware/Win32.RL_Generic.R352614
McAfee GenericRXNQ-MS!77BE0DD65703
MAX malware (ai score=100)
VBA32 BScope.Trojan.Zudochka
Malwarebytes Spyware.FickerStealer
TrendMicro-HouseCall TrojanSpy.Win32.FICKERSTEALER.THBAFBA
Rising Trojan.Agent!8.B1E (CLOUD)