Summary | ZeroBOX

auto.dll

Generic Malware PE64 PE File DLL
Category Machine Started Completed
FILE s1_win7_x6401 April 13, 2023, 4:51 p.m. April 13, 2023, 4:51 p.m.
Size 1.6MB
Type PE32+ executable (DLL) (console) x86-64 (stripped to external PDB), for MS Windows
MD5 f983bbe67c157f9debd63b5d434982a0
SHA256 f3eb93c37e708dbe46a47182b5d5f7b4b1ce49ac667405d28996c1e029761e77
CRC32 5401E1BC
ssdeep 49152:p0xMzCdy2p487NpszY17wCRB8JFOHQyvFgu:+2zHL8pqE18o8HOw
Yara
  • Generic_Malware_Zero - Generic Malware
  • IsDLL - (no description)
  • IsPE64 - (no description)
  • PE_Header_Zero - PE File Signature

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GetComputerNameA

computer_name: TEST22-PC
1 1 0
section
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2696
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x000000007304c000
process_handle: 0xffffffffffffffff
1 0 0
section {u'size_of_data': u'0x00001000', u'virtual_address': u'0x00001000', u'entropy': 7.720970914279705, u'name': u'', u'virtual_size': u'0x00002000'} entropy 7.72097091428 description A section with a high entropy has been found
section {u'size_of_data': u'0x0003ac00', u'virtual_address': u'0x00003000', u'entropy': 7.999174541699886, u'name': u'', u'virtual_size': u'0x0003b000'} entropy 7.9991745417 description A section with a high entropy has been found
section {u'size_of_data': u'0x00000200', u'virtual_address': u'0x0003e000', u'entropy': 7.5344715644251865, u'name': u'', u'virtual_size': u'0x00001000'} entropy 7.53447156443 description A section with a high entropy has been found
section {u'size_of_data': u'0x00000200', u'virtual_address': u'0x0003f000', u'entropy': 7.551313191574051, u'name': u'', u'virtual_size': u'0x00001000'} entropy 7.55131319157 description A section with a high entropy has been found
section {u'size_of_data': u'0x00000200', u'virtual_address': u'0x00040000', u'entropy': 7.495629132079966, u'name': u'', u'virtual_size': u'0x00001000'} entropy 7.49562913208 description A section with a high entropy has been found
section {u'size_of_data': u'0x00000200', u'virtual_address': u'0x00043000', u'entropy': 7.484426079276523, u'name': u'', u'virtual_size': u'0x00001000'} entropy 7.48442607928 description A section with a high entropy has been found
section {u'size_of_data': u'0x00000200', u'virtual_address': u'0x00044000', u'entropy': 7.451633347023571, u'name': u'', u'virtual_size': u'0x00001000'} entropy 7.45163334702 description A section with a high entropy has been found
section {u'size_of_data': u'0x00000200', u'virtual_address': u'0x00046000', u'entropy': 7.50661781291854, u'name': u'', u'virtual_size': u'0x00001000'} entropy 7.50661781292 description A section with a high entropy has been found
section {u'size_of_data': u'0x0003be00', u'virtual_address': u'0x00047000', u'entropy': 7.999069396565351, u'name': u'', u'virtual_size': u'0x004ba000'} entropy 7.99906939657 description A section with a high entropy has been found
section {u'size_of_data': u'0x0012c200', u'virtual_address': u'0x00501000', u'entropy': 7.981202973800225, u'name': u'', u'virtual_size': u'0x0012d000'} entropy 7.9812029738 description A section with a high entropy has been found
entropy 1.0 description Overall entropy of this PE file is high
Elastic malicious (high confidence)
FireEye Generic.mg.f983bbe67c157f9d
CrowdStrike win/malicious_confidence_90% (W)
Cynet Malicious (score: 100)
APEX Malicious
Paloalto generic.ml
ClamAV Win.Malware.Agen-7623769-0
Kaspersky UDS:DangerousObject.Multi.Generic
McAfee-GW-Edition BehavesLike.Win64.Dropper.tc
Sophos Generic ML PUA (PUA)
Webroot W32.Malware.Gen
Antiy-AVL GrayWare/Win32.Wacapew
Microsoft Trojan:Win32/Casdet!rfn
ZoneAlarm Backdoor.Win64.C4.ir
Google Detected
McAfee Artemis!F983BBE67C15
Cylance unsafe
Ikarus Win32.Outbreak
Fortinet W32/PossibleThreat