Summary | ZeroBOX

rust.exe

Malicious Library PE64 PE File
Category Machine Started Completed
FILE s1_win7_x6402 Sept. 16, 2021, 6:30 p.m. Sept. 16, 2021, 6:33 p.m.
Size 7.9MB
Type PE32+ executable (console) x86-64, for MS Windows
MD5 bb7a55020d96e929f6c92ddd42e54c18
SHA256 70c64a3f46820c47b44e30d3925165340735c7ce62ad124268820335ecc808be
CRC32 D1643987
ssdeep 196608:KnqgDu1Vqje+OIso69vlq1z7MRci6i/W+lQc:KnqgDiUjUIJ6w3ur7/nQc
Yara
  • IsPE64 - (no description)
  • PE_Header_Zero - PE File Signature
  • Malicious_Library_Zero - Malicious_Library

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section ^r(dKW;O
section ulh.I_/q
section iaM[z-t6
section c!6tgk05
section eZ7*_/NG
section g!!naD^0
section %X9!tPd$
FireEye Generic.mg.bb7a55020d96e929
Cylance Unsafe
APEX Malicious
Sophos Generic ML PUA (PUA)
McAfee-GW-Edition BehavesLike.Win64.Generic.wc
SentinelOne Static AI - Malicious PE
Gridinsoft Trojan.Heur!.02296023
Microsoft Trojan:Win32/Wacatac.B!ml
Cynet Malicious (score: 100)
section {u'size_of_data': u'0x007d9e00', u'virtual_address': u'0x0063e000', u'entropy': 7.947284054172802, u'name': u'g!!naD^0', u'virtual_size': u'0x007d9d60'} entropy 7.94728405417 description A section with a high entropy has been found
entropy 0.999937810945 description Overall entropy of this PE file is high