Summary | ZeroBOX

file22.exe

PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6401 June 8, 2021, 10:46 a.m. June 8, 2021, 10:49 a.m.
Size 1.1MB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 4b7f05a9dc569f83f9a2aed17d165e29
SHA256 67a3f3fde86611605ca136cb40e1ac6d2ac2459d8ba8d5452c0cf601adc86749
CRC32 7F0CBDA6
ssdeep 24576:0mmSOqlDkOkFWrvv4n2zjP/zRSp1jP6xl:0mmDQIVWLRP/zRSpm
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section CODE
section DATA
section BSS
packer BobSoft Mini Delphi -> BoB / BobSoft
resource name S2
resource name SS
name S2 language LANG_RUSSIAN filetype data sublanguage SUBLANG_ARABIC_SYRIA offset 0x00073078 size 0x000186a0
name SS language LANG_RUSSIAN filetype data sublanguage SUBLANG_ARABIC_SYRIA offset 0x0008b718 size 0x00090404
section {u'size_of_data': u'0x000b0600', u'virtual_address': u'0x00072000', u'entropy': 7.191296515001334, u'name': u'.rsrc', u'virtual_size': u'0x000b0600'} entropy 7.191296515 description A section with a high entropy has been found
entropy 0.619675010979 description Overall entropy of this PE file is high