Summary | ZeroBOX

2201.exe

Gen1 UPX Malicious Library Malicious Packer PE64 PE File
Category Machine Started Completed
FILE s1_win7_x6403_us March 5, 2023, 2:21 p.m. March 5, 2023, 2:42 p.m.
Size 447.0KB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 0f1f4ce03d9bacf600abf05b4c1d6817
SHA256 d82f2c9c923a145c7d4608be1f9ba982ea4ff937b145634fe4f8c338211cdb0e
CRC32 DF386952
ssdeep 6144:C8aMyDtA083XIMxEZ/mRfhTp+e5t5kkUgRGerEhgVIXFML:C5GIuEZ/mce5ZaerLIX
PDB Path StikyNot.pdb
Yara
  • Malicious_Packer_Zero - Malicious Packer
  • Win32_Trojan_Gen_2_0904B0_Zero - Win32 Trojan Gen
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
  • UPX_Zero - UPX packed file
  • PE_Header_Zero - PE File Signature
  • Malicious_Library_Zero - Malicious_Library
  • IsPE64 - (no description)

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

pdb_path StikyNot.pdb
resource name IMAGE
resource name MUI
resource name UIFILE
resource name WEVT_TEMPLATE
Elastic malicious (moderate confidence)
Alibaba TrojanDownloader:Win64/Minerva.db5621dc
ESET-NOD32 a variant of Win64/TrojanDownloader.Agent.LI
ClamAV Win.Downloader.Upatre-9880459-0
Avast FileRepMalware [Misc]
Tencent Win64.Trojan-Downloader.Oader.Yimw
F-Secure Trojan.TR/YAV.Minerva.owqit
McAfee-GW-Edition BehavesLike.Win64.Dropper.gh
Sophos Mal/Generic-S
Avira TR/YAV.Minerva.owqit
Microsoft Trojan:Win64/Fabookie!MTB
Google Detected
AhnLab-V3 Trojan/Win.Generic.C5390180
McAfee RDN/Generic Downloader.x
Rising Downloader.Agent!8.B23 (TFE:5:vBcHNCv9zaH)
Ikarus Trojan-Downloader.Win64.Agent
Fortinet W64/Agent.LI!tr.dldr
AVG FileRepMalware [Misc]