Summary | ZeroBOX

umciavi32.exe

Malicious Packer Malicious Library PE64 PE File
Category Machine Started Completed
FILE s1_win7_x6403_us Dec. 10, 2022, 3:03 p.m. Dec. 10, 2022, 3:05 p.m.
Size 7.2MB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 19d3006a093ae7f7dddd0f0fb812bbc3
SHA256 821784f00f563c345d56b28f5ac31321e3d63fa193fcaeaa24ff1c5f5799938e
CRC32 9EE687EB
ssdeep 196608:KCC0/Okh6p9cl7V6fiHMwwilE/G3icjzThvk:Kb0/LvpIi9wilMG3icz
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE64 - (no description)
  • Malicious_Packer_Zero - Malicious Packer

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section C1aJ5ApM
section \RPN\q`@
section o(Mo6,GK
section _?i`!m?Y
section wov<xmg1
section 52FZy>L#
section _Mg(F-,0
section -x&@99zw
section nCk39'8\
section 0`p)Yb2J
section 5&zT1E_"
section i4KfTz'o
section ^lh%B-yO
section rH_N@Ea+
section {u'size_of_data': u'0x00736800', u'virtual_address': u'0x00590000', u'entropy': 7.94267944436541, u'name': u"i4KfTz'o", u'virtual_size': u'0x007367e8'} entropy 7.94267944437 description A section with a high entropy has been found
entropy 0.99878296146 description Overall entropy of this PE file is high