Summary | ZeroBOX

newpy.exe

Gen1 UPX Malicious Library Anti_VM PE64 PE File OS Processor Check ZIP Format DLL
Category Machine Started Completed
FILE s1_win7_x6403_us July 10, 2023, 7:48 a.m. July 10, 2023, 7:51 a.m.
Size 7.5MB
Type PE32+ executable (console) x86-64, for MS Windows
MD5 b28167faf2bcf0150d5e816346abb42d
SHA256 c416d6ca4ee95a6647cc4357ba51a5e04a956b5a4ceaa74ad768fe544d706f48
CRC32 EB56BA69
ssdeep 196608:IpY3avuuDfyGR21X5Sp6GemDMPwuW23vYPGshGRx:uY3aJDfDspfaMP5z
Yara
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE64 - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
141.95.16.111 Active Moloch
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section _RDATA
file C:\Users\test22\AppData\Local\Temp\_MEI20682\libcrypto-1_1.dll
file C:\Users\test22\AppData\Local\Temp\_MEI20682\python311.dll
file C:\Users\test22\AppData\Local\Temp\_MEI20682\VCRUNTIME140.dll
file C:\Users\test22\AppData\Local\Temp\_MEI20682\libssl-1_1.dll
file C:\Users\test22\AppData\Local\Temp\_MEI20682\libffi-8.dll
host 141.95.16.111
MicroWorld-eScan Gen:Variant.Tedy.362136
ALYac Gen:Variant.Tedy.362136
Cylance unsafe
Sangfor Trojan.Win32.Agent.Vvvi
CrowdStrike win/malicious_confidence_60% (D)
Symantec Trojan Horse
APEX Malicious
Cynet Malicious (score: 100)
Kaspersky Trojan.Win32.Bsymem.amyi
BitDefender Gen:Variant.Tedy.362136
Emsisoft Gen:Variant.Tedy.362136 (B)
VIPRE Gen:Variant.Tedy.362136
McAfee-GW-Edition BehavesLike.Win64.TrojanCoinMiner.wc
FireEye Generic.mg.b28167faf2bcf015
Sophos Mal/Generic-S
GData Gen:Variant.Tedy.362136
Gridinsoft Trojan.Win64.Remcos.bot
Arcabit Trojan.Tedy.D58698
ZoneAlarm Trojan.Win32.Bsymem.amyi
Microsoft Trojan:Win64/Malagent!MSR
McAfee Artemis!B28167FAF2BC
MAX malware (ai score=85)
Panda Trj/Chgt.AD
TrendMicro-HouseCall TROJ_GEN.R002H09G823
Fortinet Malicious_Behavior.SB
DeepInstinct MALICIOUS