Summary | ZeroBOX

dwm.exe

Gen1 Malicious Library UPX Malicious Packer PE64 PE File OS Processor Check
Category Machine Started Completed
FILE s1_win7_x6401 Nov. 18, 2021, 10:28 p.m. Nov. 18, 2021, 10:28 p.m.
Size 92.5KB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 5c27608411832c5b39ba04e33d53536c
SHA256 0ac827c9e35cdaa492ddd435079415805dcc276352112b040bcd34ef122cf565
CRC32 50F82EE5
ssdeep 1536:aN5PiWRvy0kAfaccAAwrtG5rthFk3RFGJpbz/KGAmrEKRrJecva/:ekAfRgla8pbziGACE6Je0a/
PDB Path dwm.pdb
Yara
  • Malicious_Packer_Zero - Malicious Packer
  • IsPE64 - (no description)
  • PE_Header_Zero - PE File Signature
  • OS_Processor_Check_Zero - OS Processor Check
  • Win32_Trojan_Gen_2_0904B0_Zero - Win32 Trojan Gen
  • Malicious_Library_Zero - Malicious_Library
  • UPX_Zero - UPX packed file
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS