Summary | ZeroBOX

pub3.exe

UPX Malicious Library OS Processor Check PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6401 Oct. 27, 2021, 9:56 p.m. Oct. 27, 2021, 10 p.m.
Size 320.0KB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 9d9e728b344d741f97483e7628d7bedc
SHA256 96ce9be19e849a23579c240ff16d603245df315a4868237cb05b491e3de9d674
CRC32 558B50D3
ssdeep 3072:2BND0/iEIeyMSucVqapGdWBwSjfthqhYiM5c/cRxNEgg+jTFx81jPbmJM7lgFY:KMXGUdWBwQlh8Yi0DRxNJfI1jPG
PDB Path C:\buvatimijih\xufecuromuyiz\talorodeg\padelepakar.pdb
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

pdb_path C:\buvatimijih\xufecuromuyiz\talorodeg\padelepakar.pdb
resource name None
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 732
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 65536
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00264000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 732
region_size: 36864
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02c50000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0
section {u'size_of_data': u'0x00039000', u'virtual_address': u'0x00001000', u'entropy': 6.998713709837867, u'name': u'.text', u'virtual_size': u'0x00038e58'} entropy 6.99871370984 description A section with a high entropy has been found
entropy 0.71473354232 description Overall entropy of this PE file is high
Bkav W32.AIDetect.malware2
Elastic malicious (high confidence)
FireEye Generic.mg.9d9e728b344d741f
Cylance Unsafe
Sangfor Trojan.Win32.Save.a
Cybereason malicious.494d38
Cyren W32/Kryptik.FPT.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Baidu Win32.Trojan.Kryptik.jm
APEX Malicious
ClamAV Win.Trojan.Generic-9904330-0
Kaspersky VHO:Trojan.Win32.Convagent.gen
Sophos ML/PE-A
McAfee-GW-Edition Packed-GDT!9D9E728B344D
Ikarus Trojan-Spy.Agent
GData Win32.Trojan.BSE.WS9D4D
eGambit Unsafe.AI_Score_86%
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 100)
Acronis suspicious
McAfee Packed-GDT!9D9E728B344D
Rising Malware.Heuristic!ET#83% (RDMK:cmRtazpbjprgiobiE3/yiiG3Oilk)
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
CrowdStrike win/malicious_confidence_70% (D)