Summary | ZeroBOX

ss35.exe

Gen1 UPX Malicious Library Malicious Packer PE64 PE File
Category Machine Started Completed
FILE s1_win7_x6401 March 9, 2023, 9:52 a.m. March 9, 2023, 10:03 a.m.
Size 212.5KB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 8c88de3d340307ef3994e4d42b988b27
SHA256 c0e65f9b50c5bcd97ced63cab1f3d3194473a6e81f26436c88af9d7c2622809f
CRC32 A5961730
ssdeep 3072:xVFE/ZYueQ6059PKEywh8QzEfae1NJLgf7nDVF6PUp1Yo3ICgC:MYue05FhyI8wEHN5gfzDVlVXg
PDB Path notepad.pdb
Yara
  • UPX_Zero - UPX packed file
  • Malicious_Library_Zero - Malicious_Library
  • Win32_Trojan_Gen_2_0904B0_Zero - Win32 Trojan Gen
  • Malicious_Packer_Zero - Malicious Packer
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
  • PE_Header_Zero - PE File Signature
  • IsPE64 - (no description)

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

pdb_path notepad.pdb
resource name MUI
McAfee Artemis!8C88DE3D3403
Elastic malicious (moderate confidence)
APEX Malicious
Kaspersky UDS:DangerousObject.Multi.Generic
McAfee-GW-Edition Artemis!Trojan
Microsoft Trojan:Script/Wacatac.H!ml
AhnLab-V3 Trojan/Win.Generic.C5392277
section {u'size_of_data': u'0x00019c00', u'virtual_address': u'0x0001f000', u'entropy': 7.370268553909843, u'name': u'.rsrc', u'virtual_size': u'0x00019af0'} entropy 7.37026855391 description A section with a high entropy has been found
entropy 0.486997635934 description Overall entropy of this PE file is high