Summary | ZeroBOX

chaosgroup.v-ray.4.00.02.sketchup.activate.2015-2019.exe

Process Kill CryptGenKey FindFirstVolume PE File Device_File_Check OS Processor Check PE32
Category Machine Started Completed
FILE s1_win7_x6402 June 24, 2021, 7:30 p.m. June 24, 2021, 8:04 p.m.
Size 1.2MB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 8aa62ed37255b651a55ede3bad34e4f8
SHA256 3f11bad14437faae83c0acab00f66cd04e85a61b53c309d63e7aeeb7aed63755
CRC32 CD17CA81
ssdeep 24576:uAHnh+eWsN3skA4RV1Hom2KXMmHaKva9h7yFVgfHic9skg5:Zh+ZkldoPK8YaKvaPqV8H3s5
Yara
  • PE_Header_Zero - PE File Signature
  • CryptGenKey_Zero - CryptGenKey Zero
  • OS_Processor_Check_Zero - OS Processor Check
  • Device_Check_Zero - Device Check Zero
  • IsPE32 - (no description)
  • FindFirstVolume_Zero - FindFirstVolume Zero
  • Process_Snapshot_Kill_Zero - Process Kill Zero

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
172.217.25.14 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 812
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x73772000
process_handle: 0xffffffff
1 0 0
section {u'size_of_data': u'0x0005f000', u'virtual_address': u'0x000c8000', u'entropy': 7.901331413938724, u'name': u'.rsrc', u'virtual_size': u'0x0005ef50'} entropy 7.90133141394 description A section with a high entropy has been found
entropy 0.31973075305 description Overall entropy of this PE file is high
host 172.217.25.14
CyrenCloud W32/Autoit.G.gen!Eldorado
Bkav W32.AIDetect.malware1
FireEye Generic.mg.8aa62ed37255b651
CAT-QuickHeal Trojan.AgentSM.S6640043
Sangfor Trojan.Win32.Save.a
F-Prot W32/Autoit.G.gen!Eldorado
APEX Malicious
Paloalto generic.ml
Sophos Generic ML PUA (PUA)
Cyren W32/Autoit.G.gen!Eldorado
eGambit Unsafe.AI_Score_99%
Gridinsoft Trojan.Win32.Downloader.sa
Cynet Malicious (score: 100)
Malwarebytes Malware.AI.4189888653
MaxSecure Trojan.Malware.300983.susgen
Fortinet PossibleThreat.RF
CrowdStrike win/malicious_confidence_90% (W)