Summary | ZeroBOX

anydesk_resolver.exe

Gen1 Generic Malware Malicious Library Malicious Packer .NET DLL PE64 PE File OS Processor Check DLL
Category Machine Started Completed
FILE s1_win7_x6401 Sept. 15, 2021, 10:35 a.m. Sept. 15, 2021, 10:37 a.m.
Size 5.1MB
Type PE32+ executable (console) x86-64, for MS Windows
MD5 df701faf88644d68ec3e380f72f432be
SHA256 aecbf25226c2b78bec1f90d17e25c38b5ea2d72a5abd99d09a80f3708b14cb09
CRC32 82686AA2
ssdeep 98304:pleMM4CnotnbtFSur2WtdSKqgXuaLBwDhk/U94OO2QaVGetbFObISsG4zTwNJNs:pleWVBAdqd2gXuQBuiYORx1ESsFz8NHs
Yara
  • IsPE64 - (no description)
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • Malicious_Library_Zero - Malicious_Library

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section .gfids
file C:\Users\test22\AppData\Local\Temp\_MEI24442\python27.dll
file C:\Users\test22\AppData\Local\Temp\_MEI24442\msvcr90.dll
file C:\Users\test22\AppData\Local\Temp\_MEI24442\msvcm90.dll
file C:\Users\test22\AppData\Local\Temp\_MEI24442\msvcp90.dll
APEX Malicious
McAfee-GW-Edition BehavesLike.Win64.HToolLazagne.tc
section {u'size_of_data': u'0x0000ec00', u'virtual_address': u'0x00046000', u'entropy': 7.297139614323312, u'name': u'.rsrc', u'virtual_size': u'0x0000ea38'} entropy 7.29713961432 description A section with a high entropy has been found
entropy 0.221804511278 description Overall entropy of this PE file is high
Time & API Arguments Status Return Repeated

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0
process audiodg.exe
Time & API Arguments Status Return Repeated

NtQuerySystemInformation

information_class: 8 (SystemProcessorPerformanceInformation)
1 0 0