Summary | ZeroBOX

TNG.dll

Generic Malware PE32 .NET DLL PE File DLL
Category Machine Started Completed
FILE s1_win7_x6401 Sept. 28, 2021, 5:11 p.m. Sept. 28, 2021, 5:11 p.m.
Size 110.5KB
Type PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 e889031780d41c9bfad18160301aae89
SHA256 79159f5ed8d4e1f58a856943bf1c8518377ff6f3f25bcb7cedc7e84d875b40dd
CRC32 F42963E3
ssdeep 3072:vyG8fseG7hjEhex3gXqqo3vBm/0Lh+Oygy:vyGS1chw0x3gX8v0/4h+O
Yara
  • PE_Header_Zero - PE File Signature
  • Generic_Malware_Zero - Generic Malware
  • Is_DotNET_DLL - (no description)
  • IsDLL - (no description)
  • Win_Backdoor_AsyncRAT_Zero - Win Backdoor AsyncRAT
  • IsPE32 - (no description)

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section =*09-V&\x19
section .vmprote
section .Resolut
section
section {u'size_of_data': u'0x00001a00', u'virtual_address': u'0x00002000', u'entropy': 7.972640240394653, u'name': u'=*09-V&\\x19', u'virtual_size': u'0x000019e4'} entropy 7.97264024039 description A section with a high entropy has been found
section .vmprote description Section name indicates VMProtect
FireEye Generic.mg.e889031780d41c9b
Cylance Unsafe
ESET-NOD32 a variant of MSIL/Injector.VOJ
APEX Malicious
Kaspersky HEUR:Trojan.MSIL.Agentb.gen
Sophos ML/PE-A
Gridinsoft Malware.Win32.Gen.bot!se60478
ZoneAlarm HEUR:Trojan.MSIL.Agentb.gen
Cynet Malicious (score: 100)
Malwarebytes Trojan.MalPack.VMPR