Summary | ZeroBOX

Athens.dll

VMProtect Malicious Library PE64 PE File DLL
Category Machine Started Completed
FILE s1_win7_x6402 Jan. 18, 2022, 2:05 p.m. Jan. 18, 2022, 2:06 p.m.
Size 8.3MB
Type PE32+ executable (DLL) (GUI) x86-64, for MS Windows
MD5 61295ca80fbecf05b60915d8f6ce8c31
SHA256 ce7be5bfe8fc4c8439cda750f20e37439ff9a2fb2aeac4a967e4bf6e916d9dac
CRC32 3F06053B
ssdeep 196608:osnnFLF9PGTv7L5WdpCibQUy8G3LfUOQSVrs:oyZqAdrpG3AB
Yara
  • IsPE64 - (no description)
  • VMProtect_Zero - VMProtect packed file
  • PE_Header_Zero - PE File Signature
  • Malicious_Library_Zero - Malicious_Library
  • IsDLL - (no description)

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section .vmp0
section .vmp1
section {u'size_of_data': u'0x0084aa00', u'virtual_address': u'0x0069c000', u'entropy': 7.9538210088986006, u'name': u'.vmp1', u'virtual_size': u'0x0084a9ec'} entropy 7.9538210089 description A section with a high entropy has been found
entropy 0.999882235176 description Overall entropy of this PE file is high
section .vmp0 description Section name indicates VMProtect
section .vmp1 description Section name indicates VMProtect
FireEye Generic.mg.61295ca80fbecf05
Cylance Unsafe
CrowdStrike win/malicious_confidence_90% (W)
APEX Malicious
Sophos ML/PE-A
McAfee-GW-Edition BehavesLike.Win64.Generic.rc
SentinelOne Static AI - Suspicious PE
Microsoft Trojan:Win32/Wacatac.DC!ml
Cynet Malicious (score: 100)
McAfee Artemis!61295CA80FBE
Qihoo-360 Win64/Heur.Generic.H8sAavcA