Summary | ZeroBOX

clp6.exe

Malicious Library UPX OS Processor Check PE64 PE File
Category Machine Started Completed
FILE s1_win7_x6401 May 30, 2023, 9:31 a.m. May 30, 2023, 9:35 a.m.
Size 7.1MB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 d6c0b5e502d7816fa0eb105b10dfa481
SHA256 f66b8ab3449dd88d3abd537fa6bd5595a6f499248bb83ee27d05487d254d4867
CRC32 F6B2E7B3
ssdeep 98304:xniYKBKcQH0BcNgrGAFcznoomNJVNWG7lw5rxdIMaD5yMpGV3Usq8D:xnix1QH07rpFcdOh7yr7aD5yMsSz8
Yara
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
  • Malicious_Library_Zero - Malicious_Library
  • IsPE64 - (no description)
  • PE_Header_Zero - PE File Signature

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch
194.50.153.131 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section _RDATA
section U0APIFLU
section .0Dev
section {u'size_of_data': u'0x00031000', u'virtual_address': u'0x002e0000', u'entropy': 6.98302107901811, u'name': u'.rdata', u'virtual_size': u'0x00030e4c'} entropy 6.98302107902 description A section with a high entropy has been found
section {u'size_of_data': u'0x00003200', u'virtual_address': u'0x0032a000', u'entropy': 7.859922961901827, u'name': u'.pdata', u'virtual_size': u'0x00003168'} entropy 7.8599229619 description A section with a high entropy has been found
section {u'size_of_data': u'0x00000600', u'virtual_address': u'0x0032f000', u'entropy': 7.148182169980113, u'name': u'U0APIFLU', u'virtual_size': u'0x00000480'} entropy 7.14818216998 description A section with a high entropy has been found
section {u'size_of_data': u'0x00000c00', u'virtual_address': u'0x00330000', u'entropy': 7.353872356849237, u'name': u'U0APIFLU', u'virtual_size': u'0x00000a7c'} entropy 7.35387235685 description A section with a high entropy has been found
section {u'size_of_data': u'0x00194c00', u'virtual_address': u'0x003f4000', u'entropy': 7.774925162095149, u'name': u'U0APIFLU', u'virtual_size': u'0x00194a87'} entropy 7.7749251621 description A section with a high entropy has been found
section {u'size_of_data': u'0x0018aa00', u'virtual_address': u'0x0058a000', u'entropy': 7.8541526589908015, u'name': u'U0APIFLU', u'virtual_size': u'0x0018a908'} entropy 7.85415265899 description A section with a high entropy has been found
entropy 0.471812962579 description Overall entropy of this PE file is high
host 194.50.153.131
dead_host 192.168.56.101:49169