Summary | ZeroBOX

act.ocx

VMProtect Malicious Library PE64 PE File
Category Machine Started Completed
FILE s1_win7_x6401 March 17, 2023, 9:42 a.m. March 17, 2023, 10 a.m.
Size 233.0KB
Type PE32+ executable (console) x86-64, for MS Windows
MD5 214aa1ab355e70aefadf701a32fecb36
SHA256 063f644e6268c9909b5ce4fcd9eb400c6d4e32aea4ae7ebc913f047019f6ccdc
CRC32 8C45F0FB
ssdeep 6144:DQKvfCy8WTIyNL3zlbln5LgBK7gj1b6cS:DQIr8gfXlbxabb6c
Yara
  • Malicious_Library_Zero - Malicious_Library
  • IsPE64 - (no description)
  • PE_Header_Zero - PE File Signature
  • VMProtect_Zero - VMProtect packed file

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0
section .vmp0
section .vmp1
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2560
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 90112
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000000013f2d1000
process_handle: 0xffffffffffffffff
1 0 0
section {u'size_of_data': u'0x00039c00', u'virtual_address': u'0x00047000', u'entropy': 7.889530640349294, u'name': u'.vmp1', u'virtual_size': u'0x00039ba0'} entropy 7.88953064035 description A section with a high entropy has been found
entropy 0.995689655172 description Overall entropy of this PE file is high
section .vmp0 description Section name indicates VMProtect
section .vmp1 description Section name indicates VMProtect
FireEye Generic.mg.214aa1ab355e70ae
Cylance unsafe
K7AntiVirus Trojan ( 7000001d1 )
K7GW Trojan ( 7000001d1 )
CrowdStrike win/malicious_confidence_70% (D)
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Packed.VMProtect.ABO
APEX Malicious
Cynet Malicious (score: 100)
Avast Win64:MalwareX-gen [Trj]
Tencent Win32.Trojan.Black.Qzfl
Sophos Mal/VMProtBad-A
Trapmine malicious.moderate.ml.score
SentinelOne Static AI - Suspicious PE
Avira TR/Black.Gen2
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Google Detected
Yandex Trojan.GenAsa!MCKN04f+JBc
Ikarus Trojan.Win32.VMProtect
AVG Win64:MalwareX-gen [Trj]