Summary | ZeroBOX

dl2.exe

Category Machine Started Completed
FILE s1_win7_x6402 April 28, 2021, 9:22 a.m. April 28, 2021, 9:29 a.m.
Size 414.0KB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 c4539adb4566822ab8dfe45aa3d5ca63
SHA256 665d2cbbe026c961b1506f5d45205959c817c7b69af4106a40e74186cee6eb94
CRC32 B5820791
ssdeep 12288:E1czBBLUkiKyuQlgX9XfzI4JQnawQU3xHFNTDU8EBW:7yu6gX9X7IUwQUpFxA
Yara
  • IsPE64 - (no description)
  • IsWindowsGUI - (no description)
  • IsPacked - Entropy Check
  • HasDebugData - DebugData Check
  • HasRichSignature - Rich Signature Check
  • PE_Header_Zero - PE File Signature Zero
  • OS_Processor_Check_Zero - OS Processor Check Signature Zero
  • win_files_operation - Affect private profile

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
172.217.25.14 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section .vtbs
section .gfids
resource name AFX_DIALOG_LAYOUT
McAfee Artemis!C4539ADB4566
CrowdStrike win/malicious_confidence_90% (W)
ESET-NOD32 a variant of Win64/GenKryptik.FEGA
APEX Malicious
McAfee-GW-Edition BehavesLike.Win64.Generic.gc
FireEye Generic.mg.c4539adb4566822a
Gridinsoft Trojan.Heur!.02092023
section {u'size_of_data': u'0x00048200', u'virtual_address': u'0x00001000', u'entropy': 6.83182538136574, u'name': u'.text', u'virtual_size': u'0x000480a0'} entropy 6.83182538137 description A section with a high entropy has been found
section {u'size_of_data': u'0x00009c00', u'virtual_address': u'0x0005c000', u'entropy': 7.8227568742560685, u'name': u'.data', u'virtual_size': u'0x0000adc0'} entropy 7.82275687426 description A section with a high entropy has been found
section {u'size_of_data': u'0x00001c00', u'virtual_address': u'0x00069000', u'entropy': 7.919721807206859, u'name': u'.vtbs', u'virtual_size': u'0x00001b80'} entropy 7.91972180721 description A section with a high entropy has been found
entropy 0.809927360775 description Overall entropy of this PE file is high
host 172.217.25.14