Summary | ZeroBOX

doward.exe

Malicious Library UPX OS Processor Check PE64 PE File
Category Machine Started Completed
FILE s1_win7_x6403_us July 10, 2023, 10:17 a.m. July 10, 2023, 10:19 a.m.
Size 1012.5KB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 b8984fa531de29bff678fa99589dd2c0
SHA256 c9daa467a96f84c12457a5d112cf5e3e6afa80b08a2215e0886d1fc964fb5762
CRC32 6B08528E
ssdeep 24576:BmJZW2wSdIHuiCyhuGaD0y13DrmmfVpd+c2ZAa7ZRaLt:BmJZW2FIOiCIuGaD0yh/zvd+c2ZAafaL
Yara
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check
  • IsPE64 - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0
Bkav W32.Common.CCF30052
Lionic Trojan.Win32.Generic.4!c
Elastic malicious (moderate confidence)
MicroWorld-eScan Trojan.GenericKD.67828693
FireEye Generic.mg.b8984fa531de29bf
CAT-QuickHeal Trojan.Casdet
McAfee Artemis!B8984FA531DE
Malwarebytes Trojan.Crypt
VIPRE Trojan.GenericKD.67828693
Sangfor Trojan.Win32.Agent.Vff1
Cybereason malicious.a1d0a7
Arcabit Trojan.Generic.D40AFBD5
Cyren W64/ABRisk.WGRO-2730
APEX Malicious
BitDefender Trojan.GenericKD.67828693
Emsisoft Trojan.GenericKD.67828693 (B)
McAfee-GW-Edition BehavesLike.Win64.Dropper.fh
Sophos Mal/Generic-S
Webroot W32.Trojan.Gen
Xcitium Malware@#1rue3eikx763g
Microsoft Trojan:Win32/Casdet!rfn
GData Trojan.GenericKD.67828693
Google Detected
ALYac Trojan.GenericKD.67828693
MAX malware (ai score=88)
Cylance unsafe
Panda Trj/Chgt.AD
TrendMicro-HouseCall TROJ_GEN.R002H09FT23
MaxSecure Trojan.Malware.210879886.susgen
Fortinet Malicious_Behavior.SB
DeepInstinct MALICIOUS