Summary | ZeroBOX

8c06e6fc9ac2823c_tmp1252549637.exe

UPX Malicious Packer PWS PE File OS Processor Check PE32 .NET EXE
Category Machine Started Completed
FILE s1_win7_x6402 Sept. 12, 2022, 3:37 p.m. Sept. 12, 2022, 3:39 p.m.
Size 85.0KB
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 6489ebd538516f3ec981a41459c7c225
SHA256 8c06e6fc9ac2823c785ca0fef922de5fe1a01331e316e4ac36cdb0f0d062cc9d
CRC32 25894E55
ssdeep 1536:Fu1aD1T3xN2pkblv8/ybypQGmy1UPd/3wDu3Y6Uk9jg+rr6GbOsKpeQiQKWfS:FuchT3xN2pkbx8Kbypd1ayDud7r6GiXe
Yara
  • IsPE32 - (no description)
  • OS_Processor_Check_Zero - OS Processor Check
  • UPX_Zero - UPX packed file
  • Win_Backdoor_AsyncRAT_Zero - Win Backdoor AsyncRAT
  • PE_Header_Zero - PE File Signature
  • Win32_Trojan_PWS_Net_1_Zero - Win32 Trojan PWS .NET Azorult
  • Is_DotNET_EXE - (no description)
  • Malicious_Packer_Zero - Malicious Packer

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section {u'size_of_data': u'0x00009e00', u'virtual_address': u'0x0000e000', u'entropy': 7.1525170788423615, u'name': u'.rsrc', u'virtual_size': u'0x00009da8'} entropy 7.15251707884 description A section with a high entropy has been found
entropy 0.467455621302 description Overall entropy of this PE file is high