Summary | ZeroBOX

4f9b33bcf1b1be488fa71c43223c2bcc1ab7b67c7276604e8078fac994495693_2668-2609adb6c0fe997b.exe_

UPX PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6401 Feb. 18, 2023, 7:54 p.m. Feb. 18, 2023, 7:56 p.m.
Size 96.0KB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 e150069a927d4d93c451de82721a0b4c
SHA256 4f9b33bcf1b1be488fa71c43223c2bcc1ab7b67c7276604e8078fac994495693
CRC32 EF419291
ssdeep 1536:7TXIPfSbS9vMBN7rQOJ7CFToTCzhcRguhwxTyPCb3lZpdym4dy7p:fYXlvq7jSP1cR2prbpdCY9
Yara
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
resource name MUI
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2636
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x733d2000
process_handle: 0xffffffff
1 0 0
section {u'size_of_data': u'0x00013800', u'virtual_address': u'0x00003000', u'entropy': 7.383961819959419, u'name': u'.rsrc', u'virtual_size': u'0x00013640'} entropy 7.38396181996 description A section with a high entropy has been found
entropy 0.935619904414 description Overall entropy of this PE file is high