Summary | ZeroBOX

qbittorrent.exe

Gen1 UPX Malicious Library Malicious Packer Anti_VM PE64 PE File OS Processor Check
Category Machine Started Completed
FILE s1_win7_x6401 March 13, 2023, 9:55 a.m. March 13, 2023, 9:57 a.m.
Size 28.3MB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 cb03a80bc17d2d81fd34aab4341e89eb
SHA256 8e6af6cbd3765b8d8c1dd553354a0d4ff9f7fc2eb293704845af7e66a9ccdb0a
CRC32 E576120E
ssdeep 393216:keHUAF/9iRC0o+9xU+q7WndIFdU5cqyRZUSfruM4Jsv6tWKFdu9CCoR1:keHUwy9y9Wn+FK5cbfrVor
PDB Path qbittorrent.pdb
Yara
  • UPX_Zero - UPX packed file
  • Malicious_Library_Zero - Malicious_Library
  • Win32_Trojan_Gen_2_0904B0_Zero - Win32 Trojan Gen
  • OS_Processor_Check_Zero - OS Processor Check
  • Win32_Trojan_Gen_1_0904B0_Zero - Win32 Trojan Emotet
  • anti_vm_detect - Possibly employs anti-virtualization techniques
  • IsPE64 - (no description)
  • Malicious_Packer_Zero - Malicious Packer
  • PE_Header_Zero - PE File Signature

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid
pdb_path qbittorrent.pdb
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section _RDATA
section .qtmetad
section .qtmimed
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 2656
region_size: 65536
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0000000002450000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0xffffffffffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2656
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000000007304c000
process_handle: 0xffffffffffffffff
1 0 0
Paloalto generic.ml
section {u'size_of_data': u'0x00b06800', u'virtual_address': u'0x00f96000', u'entropy': 7.463488289899328, u'name': u'.rdata', u'virtual_size': u'0x00b067a6'} entropy 7.4634882899 description A section with a high entropy has been found
section {u'size_of_data': u'0x0004ee00', u'virtual_address': u'0x01be3000', u'entropy': 7.998000978505574, u'name': u'.qtmimed', u'virtual_size': u'0x0004ece5'} entropy 7.99800097851 description A section with a high entropy has been found
entropy 0.400168956778 description Overall entropy of this PE file is high
file C:\Users\test22\AppData\Roaming\qBittorrent\qBittorrent_new.ini.lock