Summary | ZeroBOX

205.exe

NPKI Emotet Malicious Library UPX Anti_VM PE File OS Processor Check PE32
Category Machine Started Completed
FILE s1_win7_x6403_us Nov. 7, 2021, 5:17 p.m. Nov. 7, 2021, 5:19 p.m.
Size 1.3MB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 64f0b1471c1d2b101f1ffec664b8397d
SHA256 a229f660be8cc3146f0f6f7ee0e020389b58384ae4b4e368395ebf43765411ea
CRC32 D042B6DD
ssdeep 24576:PFsL1ho1rU4uO4B0p+Lv3jyR4s2F6XGh3PrEooZZ/0Cab16e:mDv4uO4B023jJsO3PrE9/XaE
PDB Path wextract.pdb
Yara
  • Win32_Trojan_Emotet_RL_Gen_Zero - Win32 Trojan Emotet
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0
pdb_path wextract.pdb
resource name AVI
Time & API Arguments Status Return Repeated

GetDiskFreeSpaceW

number_of_free_clusters: 2498301
sectors_per_cluster: 8
bytes_per_sector: 512
root_path: \
total_number_of_clusters: 8362495
1 1 0

GetDiskFreeSpaceW

number_of_free_clusters: 2498301
sectors_per_cluster: 8
bytes_per_sector: 512
root_path: \
total_number_of_clusters: 8362495
1 1 0
section {u'size_of_data': u'0x00146e00', u'virtual_address': u'0x0000d000', u'entropy': 7.97231578033446, u'name': u'.rsrc', u'virtual_size': u'0x00146ddc'} entropy 7.97231578033 description A section with a high entropy has been found
entropy 0.970675575353 description Overall entropy of this PE file is high
cmdline at.exe
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce\wextract_cleanup0 reg_value rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\test22\AppData\Local\Temp\IXP000.TMP\"
McAfee Artemis!64F0B1471C1D
Cylance Unsafe
Symantec ML.Attribute.HighConfidence
APEX Malicious
Paloalto generic.ml
Kaspersky UDS:DangerousObject.Multi.Generic
DrWeb Trojan.Siggen15.36155
McAfee-GW-Edition BehavesLike.Win32.Dropper.tc
Sophos Mal/Generic-S
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 100)
SentinelOne Static AI - Suspicious PE
eGambit Unsafe.AI_Score_99%
Fortinet JS/Agent.PGK!tr
Cybereason malicious.048ff2
MaxSecure Trojan.Malware.300983.susgen