Summary | ZeroBOX

skin.exe

Admin Tool (Sysinternals etc ...) ASPack Malicious Library PE File OS Processor Check PE32
Category Machine Started Completed
FILE s1_win7_x6401 Aug. 20, 2021, 11:42 a.m. Aug. 20, 2021, 11:43 a.m.
Size 444.0KB
Type PE32 executable (console) Intel 80386, for MS Windows
MD5 35d246695f2bca9c07c187a2b41ca7e3
SHA256 69747996584aba2690d04958b5e2d6446107ae702a0053fd28c8073b4d7c8ad5
CRC32 EF58EA59
ssdeep 6144:UcaJPbmXH5F2pO8z4kf+uy4Ln1QiBSTfMoPXD2u20/7AZRnLIuLenLfHv:U96XTwUYNb1VoTfMoPX6U/7AZZDLeLf
PDB Path C:\code\16\cal-2\Release\cal-2.pdb
Yara
  • PE_Header_Zero - PE File Signature
  • Admin_Tool_IN_Zero - Admin Tool Sysinternals
  • OS_Processor_Check_Zero - OS Processor Check
  • Malicious_Library_Zero - Malicious_Library
  • IsPE32 - (no description)
  • ASPack_Zero - ASPack packed file

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

pdb_path C:\code\16\cal-2\Release\cal-2.pdb
section {u'size_of_data': u'0x0006a000', u'virtual_address': u'0x00005000', u'entropy': 7.7008741606250855, u'name': u'.data', u'virtual_size': u'0x0006a1e8'} entropy 7.70087416063 description A section with a high entropy has been found
entropy 0.957110609481 description Overall entropy of this PE file is high
Bkav W32.AIDetect.malware1
Lionic Trojan.Win32.Noon.l!c
Elastic malicious (high confidence)
FireEye Generic.mg.35d246695f2bca9c
McAfee Artemis!35D246695F2B
Malwarebytes Malware.AI.1850730742
BitDefenderTheta Gen:NN.ZexaF.34088.BuW@amaxdHhO
Cyren W32/FakeDoc.BZ.gen!Eldorado
APEX Malicious
Paloalto generic.ml
Kaspersky UDS:Trojan-Spy.Win32.Noon.gen
Avast FileRepMetagen [Malware]
Rising Trojan.Kryptik!1.D6EE (CLASSIC)
Comodo TrojWare.Win32.Agent.ponco@0
Ikarus Trojan.Inject
Kingsoft Win32.Troj.Undef.(kcloud)
Microsoft Trojan:Win32/Wacatac.B!ml
AhnLab-V3 Trojan/Win.FormBook.R437881
Acronis suspicious
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Webroot W32.Trojan.Gen
AVG FileRepMetagen [Malware]
CrowdStrike win/malicious_confidence_100% (W)