Summary | ZeroBOX

Regnator.exe

PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6401 June 24, 2021, 7:04 p.m. June 24, 2021, 7:26 p.m.
Size 5.2MB
Type MS-DOS executable, MZ for MS-DOS
MD5 da1beec86fb22f7e885ce7d96704998a
SHA256 16f2eb22571035050b2a31f1e5061777845a311c690aff9076c8e4249ab45a5f
CRC32 652EA1F9
ssdeep 98304:GpWR17HfgQF1jn9nDwYlepHBltorSvP6icsTNzv2RHmtDRDUGI4tTX6UuO1GYKVf:Gp41UI1jndwdHJsGP6iTR/tDRDUiOdWM
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section .MPRESS1
section .MPRESS2
resource name AFX_DIALOG_LAYOUT
resource name TEXTFILE
resource name None
section {u'size_of_data': u'0x0048b200', u'virtual_address': u'0x00001000', u'entropy': 7.999960076044649, u'name': u'.MPRESS1', u'virtual_size': u'0x01d9c000'} entropy 7.99996007604 description A section with a high entropy has been found
entropy 0.865984178688 description Overall entropy of this PE file is high
Bkav W32.AIDetect.malware2
FireEye Generic.mg.da1beec86fb22f7e
Cylance Unsafe
Symantec ML.Attribute.HighConfidence
APEX Malicious
Microsoft Program:Win32/Wacapew.C!ml
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Generic.R424526
Malwarebytes Malware.AI.938839829
Rising Malware.Heuristic!ET#92% (RDMK:cmRtazp43aroHneaFtEoveIlCN9w)
eGambit Unsafe.AI_Score_100%