Summary | ZeroBOX

72345877550736152487.bin

Malicious Library UPX OS Processor Check PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6403_us May 26, 2023, 9:13 a.m. May 26, 2023, 9:32 a.m.
Size 3.9MB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 34a210904bca96c8fa9e37255211463a
SHA256 54744988f152233722b2e866c66c6f3ee3c215cdedce36ec17270e63353df738
CRC32 09AFE139
ssdeep 98304:OKeb41herumoa987/Po7YgFVP9ZbIGbAeJ8rF5GvuJLfhPEc:Okgu/Kp7YgLlZ5tqHGvulhPH
Yara
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch
77.91.68.62 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section .lol0
section .lol1
section .lol2
section {u'size_of_data': u'0x00607400', u'virtual_address': u'0x00360000', u'entropy': 7.9615645106856565, u'name': u'.lol2', u'virtual_size': u'0x00607210'} entropy 7.96156451069 description A section with a high entropy has been found
entropy 0.99959517448 description Overall entropy of this PE file is high
host 77.91.68.62
dead_host 192.168.56.103:49180