Summary | ZeroBOX

C++%20Dropper.exe

Category Machine Started Completed
FILE s1_win7_x6401 April 13, 2021, 9:57 a.m. April 13, 2021, 10:24 a.m.
Size 18.0KB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 356dc1680475998c7c23e199f2c2e9ca
SHA256 e5990480cda6207bf008957ae5a3fa3debe6303fd19c3babc3f2223bf769479c
CRC32 01A0BCA7
ssdeep 384:XbRIvCAcTljSxyW79lxqZQC7ZHLh2jSVe0J7OseTe:3jSxykxqhZHLZVnJ7OxTe
PDB Path C:\Users\Test\source\repos\C++ Dropper\Release\C++ Dropper.pdb
Yara
  • network_dropper - File downloader/dropper
  • PE_Header_Zero - PE File Signature Zero
  • OS_Processor_Check_Zero - OS Processor Check Signature Zero
  • IsPE32 - (no description)
  • IsWindowsGUI - (no description)
  • HasDebugData - DebugData Check
  • HasRichSignature - Rich Signature Check

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

pdb_path C:\Users\Test\source\repos\C++ Dropper\Release\C++ Dropper.pdb
Bkav W32.AIDetect.malware2
FireEye Generic.mg.356dc1680475998c
McAfee GenericRXOF-PV!356DC1680475
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
Sangfor Trojan.Win32.Wacatac.B
CrowdStrike win/malicious_confidence_90% (W)
BitDefender Trojan.GenericKD.36687042
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Generik.DNATVJ
APEX Malicious
Avast Win32:Trojan-gen
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan.Win32.Bsymem.gen
AegisLab Trojan.Win32.Bsymem.4!c
MicroWorld-eScan Trojan.GenericKD.36687042
Rising Trojan.Bsymem!8.FAE7 (CLOUD)
Ad-Aware Trojan.GenericKD.36687042
Sophos Mal/Generic-S
DrWeb Trojan.Siggen13.6107
McAfee-GW-Edition Artemis!Trojan
Emsisoft Trojan.GenericKD.36687042 (B)
GData Trojan.GenericKD.36687042
MAX malware (ai score=100)
Kingsoft Win32.Heur.KVMH017.a.(kcloud)
Gridinsoft Trojan.Win32.Agent.oa
Arcabit Trojan.Generic.D22FCCC2
Microsoft Trojan:Win32/Wacatac.B!ml
ALYac Trojan.Agent.Bsymem
Panda Trj/GdSda.A
Ikarus Win32.Outbreak
Fortinet W32/Bsymem.DNATVJ!tr
AVG Win32:Trojan-gen
Paloalto generic.ml
Qihoo-360 Win32/Trojan.Bsymem.HgIASSkA