Summary | ZeroBOX

s5.exe

Malicious Library PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6401 Sept. 2, 2023, 6:33 p.m. Sept. 2, 2023, 6:40 p.m.
Size 450.0KB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 6d23627f776c90f686e5768774aad09f
SHA256 cddf2ab61b0857d22423a4eef6ab476831209e7dd096776f284125d9b3162e9f
CRC32 84CE90D8
ssdeep 6144:a+RNrHv44H2i+SAWU52gqZer/7IhLgLUebH/:a+RNrHNH2is/wJZW7igLUeL/
PDB Path C:\wadepar.pdb
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

pdb_path C:\wadepar.pdb
resource name AFX_DIALOG_LAYOUT
section {u'size_of_data': u'0x0003c400', u'virtual_address': u'0x00001000', u'entropy': 7.6453125318522135, u'name': u'.text', u'virtual_size': u'0x0003c36c'} entropy 7.64531253185 description A section with a high entropy has been found
entropy 0.536748329621 description Overall entropy of this PE file is high