Summary | ZeroBOX

zpeu.exe

Suspicious_Script_Bin NSIS UPX Malicious Library .NET DLL PE File DLL PE32
Category Machine Started Completed
FILE s1_win7_x6403_us June 1, 2023, 7:37 p.m. June 1, 2023, 7:39 p.m.
Size 336.6KB
Type PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5 9dca43cb15d97693d2de73683804c5c7
SHA256 c3ac750a23fb48eee9e1ce2d9bd59aadbc190a1dd36afbdc9f5c39eeb7f87756
CRC32 49D4383F
ssdeep 6144:bmOPbtybqh+/fDv9vE520B36t/21/F99OjpiN6:ft2W+nz9s520j999OS6
Yara
  • UPX_Zero - UPX packed file
  • Malicious_Library_Zero - Malicious_Library
  • NSIS_Installer - Null Soft Installer
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section .ndata
file C:\Users\test22\AppData\Local\Temp\nsc6921.tmp\System.dll
file C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\spilplatform\Thenceforth\Troubleshooting\Egueiite240\SharpDX.DXGI.dll
Bkav W32.AIDetectMalware
Elastic malicious (high confidence)
APEX Malicious
Cynet Malicious (score: 100)
Cylance unsafe
CrowdStrike win/malicious_confidence_70% (W)