Summary | ZeroBOX

Builder.exe

UPX Malicious Library Malicious Packer PE64 PE File OS Processor Check
Category Machine Started Completed
FILE s1_win7_x6401 May 31, 2023, 12:25 a.m. May 31, 2023, 12:26 a.m.
Size 145.5KB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 1866f69cfaeeda3915074a0aab36717a
SHA256 b17d9682fd03dc7d18fb141718d6fc90b59e76ee6b8f39f2ace385600fad7c68
CRC32 A9037D52
ssdeep 3072:qguAgTsGLYEZl70PsLko1Gs2T/0oim/JbRZzlZ2pJqq:q5twsLko1Gs2T/pPlZ2fq
PDB Path D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb
Yara
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
  • Malicious_Library_Zero - Malicious_Library
  • IsPE64 - (no description)
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GetComputerNameA

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
pdb_path D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section _RDATA