Summary | ZeroBOX


Category Machine Started Completed
FILE s1_win7_x6401 April 13, 2021, 9:57 a.m. April 13, 2021, 10:12 a.m.
Size 161.5KB
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 fb46d54a3b05a295269e6f9e5e4ad271
SHA256 fa72e9989d96b7b82a5b89d8897840c6f7f683ade081ceeffb1ff41d1cecae9c
CRC32 637AF4CE
ssdeep 3072:elpmktgw9IAMlZxSGg7ypZIQ404g51acpg0xZtCVxwVeXm7YP1cOPpiihEY:elo0gw4ZMypZp45g51aXotOxwVeXm7Ym
  • PE_Header_Zero - PE File Signature Zero
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • IsWindowsGUI - (no description)
  • IsPacked - Entropy Check
  • HasDebugData - DebugData Check
  • HasModified_DOS_Message - DOS Message Check
  • HasRichSignature - Rich Signature Check

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

packer Ste@lth PE 1.01 -> BGCorp
section {u'size_of_data': u'0x0001e400', u'virtual_address': u'0x0000b000', u'entropy': 7.868001620347829, u'name': u'.pdata', u'virtual_size': u'0x00020214'} entropy 7.86800162035 description A section with a high entropy has been found
entropy 0.753894080997 description Overall entropy of this PE file is high