Summary | ZeroBOX

dby33.exe

Malicious Packer PWS PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6402 Oct. 20, 2021, 11:27 a.m. Oct. 20, 2021, 11:27 a.m.
Size 104.0KB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 d576c9dc10e4705d5ee7a2d75349f45e
SHA256 bf0db2eda1cc6923349fc6510a00d443e0f1fe3618acc9d46aefc2392c02aeda
CRC32 39A72676
ssdeep 1536:czvQSZpGS4/31A6mQgL2eYCGDwRcMkVQd8YhY0/EqfIzmd:nSHIG6mQwGmfOQd8YhY0/EqUG
Yara
  • Malicious_Packer_Zero - Malicious Packer
  • Win32_PWS_Loki_Zero - Win32 PWS Loki
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section .x
Bkav W32.AIDetect.malware1
Elastic malicious (high confidence)
DrWeb Trojan.PWS.Siggen2.59088
MicroWorld-eScan Trojan.PWS.ZKD
FireEye Generic.mg.d576c9dc10e4705d
CAT-QuickHeal Trojan.Mauvaise.SL1
McAfee LokiBot!D576C9DC10E4
Cylance Unsafe
Zillya Trojan.naKocTb.Win32.12
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Password-Stealer ( 004d88671 )
K7GW Password-Stealer ( 004d88671 )
Cybereason malicious.c10e47
Arcabit Trojan.PWS.ZKD
BitDefenderTheta Gen:NN.ZexaF.34218.gqW@aOzWOyp
Cyren W32/S-f2ff7de9!Eldorado
Symantec Infostealer.Lokibot!gm
ESET-NOD32 Win32/PSW.Fareit.L
APEX Malicious
ClamAV Win.Trojan.Autoit-7057849-0
Kaspersky Trojan.Win32.Agentb.bvrg
BitDefender Trojan.PWS.ZKD
NANO-Antivirus Trojan.Win32.Stealer.eshrhl
SUPERAntiSpyware Trojan.Agent/Gen-PasswordStealer
Avast Win32:LokiBot-A [Trj]
Tencent Malware.Win32.Gencirc.10b3c757
Ad-Aware Trojan.PWS.ZKD
Emsisoft Trojan-PSW.Fareit (A)
Comodo TrojWare.Win32.Fareit.LB@7pzcfo
TrendMicro TSPY_LOKI.SMA
McAfee-GW-Edition BehavesLike.Win32.Generic.ch
Sophos ML/PE-A + Troj/Fareit-CHG
SentinelOne Static AI - Malicious PE
Jiangmin Trojan.naKocTb.l
eGambit Unsafe.AI_Score_99%
Avira TR/Crypt.XPACK.Gen
MAX malware (ai score=87)
Antiy-AVL Trojan/Generic.ASMalwS.1B6B4C6
Gridinsoft Malware.Win32.Gen.bot!se39734
Microsoft PWS:Win32/PrimaryPass.AD!MTB
ViRobot Trojan.Win32.Agent.106496.HD
ZoneAlarm HEUR:Trojan-PSW.Win32.Tepfer.gen
GData Trojan.PWS.ZKD
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win32.Lokibot.R270234
Acronis suspicious
VBA32 BScope.Trojan.Agentb
ALYac Trojan.PWS.ZKD
TACHYON Trojan/W32.naKocTb.106496
Malwarebytes Spyware.LokiBot