Summary | ZeroBOX

vbc.bin

UPX PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6401 Aug. 25, 2021, 11 p.m. Aug. 25, 2021, 11 p.m.
Size 368.0KB
Type PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5 24c4788a737cda143d0edac9c711994d
SHA256 bb025003b58ee61c3d6805cd3974844ca21224c8fd64c0678b19864453137a58
CRC32 7A0C3169
ssdeep 6144:l4XrK9PX7Fp6Gh2wWRGl0EDDf1PisZQ5rAGQwg1QtP1f4paaYlsdcaMJEdbI0Pzs:eXe9PPlowWX0t6mOQwg1Qd15CcYk0We8
Yara
  • PE_Header_Zero - PE File Signature
  • UPX_Zero - UPX packed file
  • IsPE32 - (no description)

Name Response Post-Analysis Lookup
a.uguu.se 144.76.201.136
IP Address Status Action
144.76.201.136 Active Moloch
164.124.101.2 Active Moloch

Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2216
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72a62000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2216
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02af0000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0xffffffff
1 0 0
section {u'size_of_data': u'0x00054200', u'virtual_address': u'0x0008c000', u'entropy': 7.937159861876598, u'name': u'UPX1', u'virtual_size': u'0x00055000'} entropy 7.93715986188 description A section with a high entropy has been found
entropy 0.91689373297 description Overall entropy of this PE file is high
section UPX0 description Section name indicates UPX
section UPX1 description Section name indicates UPX
Bkav W32.AIDetect.malware2
Elastic malicious (high confidence)
FireEye Generic.mg.24c4788a737cda14
Cylance Unsafe
Sangfor Trojan.Win32.Save.a
Cyren W32/AutoIt.TA.gen!Eldorado
APEX Malicious
Kaspersky UDS:DangerousObject.Multi.Generic
McAfee-GW-Edition BehavesLike.Win32.Generic.fc
Sophos Generic ML PUA (PUA)
eGambit Unsafe.AI_Score_99%
ZoneAlarm UDS:DangerousObject.Multi.Generic
Cynet Malicious (score: 100)
Malwarebytes Malware.Heuristic.1003
MaxSecure Trojan.Malware.300983.susgen
Webroot Pua.Yukleyici
Cybereason malicious.c300fc