Summary | ZeroBOX

DefenderSecurity.exe

PE32 PE File .NET EXE
Category Machine Started Completed
FILE s1_win7_x6401 March 17, 2023, 5:30 p.m. March 17, 2023, 5:55 p.m.
Size 4.0MB
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 0fbf332153113f4b0dfd105244cba305
SHA256 39ad7e9557a8177e7c6babaef7330c2ba20345562e19624d875b15f225914731
CRC32 B70FD2CA
ssdeep 49152:ffpvN8/xMQg3Q3cX5C/wnvdAlPjcmYjoM47qN:ffpvN8/B7
Yara
  • Is_DotNET_EXE - (no description)
  • Win_Backdoor_AsyncRAT_Zero - Win Backdoor AsyncRAT
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
217.64.31.3 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

host 217.64.31.3
dead_host 217.64.31.3:9742
Bkav W32.AIDetectNet.01
Lionic Trojan.Win32.Bladabindi.4!c
MicroWorld-eScan Gen:Variant.Razy.976809
CAT-QuickHeal Backdoor.MsilFC.S20328100
McAfee GenericRXOC-UC!0FBF33215311
Malwarebytes Trojan.Crypt.MSIL
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Trojan ( 0057dd3b1 )
Alibaba Backdoor:MSIL/AsyncRAT.e8b56738
K7GW Trojan ( 0057dd3b1 )
CrowdStrike win/malicious_confidence_100% (W)
Arcabit Trojan.Razy.DEE7A9
Cyren W32/MSIL_Bladabindi.GJ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/Kryptik.ZIR
Cynet Malicious (score: 100)
APEX Malicious
Paloalto generic.ml
Kaspersky HEUR:Backdoor.MSIL.Bladabindi.gen
BitDefender Gen:Variant.Razy.976809
Avast FileRepMalware [Misc]
Tencent Msil.Backdoor.Bladabindi.Hdhl
Sophos ML/PE-A
VIPRE Gen:Variant.Razy.976809
TrendMicro Backdoor.Win32.ASYNCRAT.YXDCPZ
McAfee-GW-Edition GenericRXOC-UC!0FBF33215311
FireEye Generic.mg.0fbf332153113f4b
Emsisoft Gen:Variant.Razy.976809 (B)
SentinelOne Static AI - Suspicious PE
Avira HEUR/AGEN.1235912
MAX malware (ai score=83)
Gridinsoft Ransom.Win32.Bladabindi.sa
Microsoft Trojan:MSIL/AsyncRAT.RDSC!MTB
GData Gen:Variant.Razy.976809
Google Detected
AhnLab-V3 Malware/Gen.RL_Reputation.C4314872
Acronis suspicious
BitDefenderTheta Gen:NN.ZemsilF.36344.9p0@aKUI3Jk
ALYac Gen:Variant.Razy.976809
Cylance unsafe
Rising Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:qI07/+6TD8aFhEc+A0OLEQ)
Ikarus Trojan.MSIL.Crypt
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Kryptik.ZIT!tr
AVG FileRepMalware [Misc]
Panda Trj/GdSda.A