Summary | ZeroBOX

qwe.exe

UPX Malicious Library OS Processor Check PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6401 Nov. 7, 2021, 10:14 a.m. Nov. 7, 2021, 10:16 a.m.
Size 358.9KB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 85ec477462d743926f740b17c40b323a
SHA256 90aed2bc654014fa0706c10df251d4ccec94a1e06b9c0b15ec7b4f938fc18696
CRC32 2C0020A0
ssdeep 6144:9h3Bc5UiD5uUnQhfrWuaoMgGaHtH9FStwG7+erf1:9h3wUa5rnQFrxaoMgGaHteprf1
PDB Path C:\sejihifizex34 humugaz.pdb
Yara
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE32 - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

pdb_path C:\sejihifizex34 humugaz.pdb
section .cod
resource name CIDAFICUDUROSOTAROM
resource name VESURAGOSAG
resource name YONAMIKORUFENI
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2772
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 81920
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00a9e000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2772
region_size: 135168
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00320000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0
section {u'size_of_data': u'0x00041800', u'virtual_address': u'0x00001000', u'entropy': 7.031228466374225, u'name': u'.text', u'virtual_size': u'0x00041610'} entropy 7.03122846637 description A section with a high entropy has been found
entropy 0.742209631728 description Overall entropy of this PE file is high
Lionic Trojan.Win32.Strab.4!c
Elastic malicious (high confidence)
FireEye Generic.mg.85ec477462d74392
Cylance Unsafe
CrowdStrike win/malicious_confidence_80% (W)
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Kryptik.HNFE
Paloalto generic.ml
Kaspersky UDS:Trojan.Win32.Strab.gen
Sophos Mal/Generic-S
Baidu Win32.Trojan.Kryptik.jm
McAfee-GW-Edition Artemis!Trojan
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Trojan.Heur!.00812031
Microsoft Ransom:Win32/StopCrypt.SL!MTB
Cynet Malicious (score: 100)
Acronis suspicious
McAfee RDN/Strab
VBA32 BScope.Trojan.Sabsik.FL
Malwarebytes Trojan.MalPack.GS
Ikarus Trojan.Agent
eGambit PE.Heur.InvalidSig
Fortinet PossibleThreat.PALLAS.H