Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | June 24, 2021, 7:29 p.m. | June 24, 2021, 8:30 p.m. |
-
partsoffer.exe "C:\Users\test22\AppData\Local\Temp\partsoffer.exe"
3972
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
172.217.25.14 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
section | CODE |
section | DATA |
section | BSS |
section | .aspack |
section | .adata |
packer | ASPack v2.12 -> Alexey Solodovnikov |
name | RT_ICON | language | LANG_KOREAN | filetype | dBase III DBT, version number 0, next free block index 40 | sublanguage | SUBLANG_KOREAN | offset | 0x004f87cc | size | 0x00010828 | ||||||||||||||||||
name | RT_GROUP_ICON | language | LANG_KOREAN | filetype | data | sublanguage | SUBLANG_KOREAN | offset | 0x004f87b8 | size | 0x00000014 |
section | {u'size_of_data': u'0x00107400', u'virtual_address': u'0x00001000', u'entropy': 7.9997649240178434, u'name': u'CODE', u'virtual_size': u'0x00360000'} | entropy | 7.99976492402 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00002400', u'virtual_address': u'0x00361000', u'entropy': 7.846572829406638, u'name': u'DATA', u'virtual_size': u'0x00006000'} | entropy | 7.84657282941 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00001400', u'virtual_address': u'0x00369000', u'entropy': 7.835266058429392, u'name': u'.idata', u'virtual_size': u'0x00004000'} | entropy | 7.83526605843 | description | A section with a high entropy has been found | |||||||||
section | {u'size_of_data': u'0x00032400', u'virtual_address': u'0x003a5000', u'entropy': 7.851095973449192, u'name': u'.rsrc', u'virtual_size': u'0x00152000'} | entropy | 7.85109597345 | description | A section with a high entropy has been found | |||||||||
entropy | 0.945915703096 | description | Overall entropy of this PE file is high |
host | 172.217.25.14 |
MicroWorld-eScan | Trojan.GenericKD.37141407 |
FireEye | Trojan.GenericKD.37141407 |
McAfee | Artemis!E15787EA22A7 |
Sangfor | Suspicious.Win32.Artemis.E15787EA22A7 |
Avast | Win32:Malware-gen |
BitDefender | Trojan.GenericKD.37141407 |
Ad-Aware | Trojan.GenericKD.37141407 |
Emsisoft | Trojan.GenericKD.37141407 (B) |
Zillya | Trojan.Generic.Win32.1403548 |
McAfee-GW-Edition | Artemis!Trojan |
Jiangmin | Trojan.Generic.gwuym |
MAX | malware (ai score=80) |
Antiy-AVL | Trojan/Generic.ASMalwS.3381206 |
Gridinsoft | Trojan.Win32.AI.oa |
GData | Trojan.GenericKD.37141407 |
VBA32 | TScope.Trojan.Delf |
Malwarebytes | Malware.AI.1655360805 |
Yandex | Trojan.GenAsa!O5kSGRR64q8 |
eGambit | Unsafe.AI_Score_99% |
AVG | Win32:Malware-gen |