Summary | ZeroBOX

167.exe

Malicious Library UPX OS Processor Check PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6403_us Sept. 15, 2023, 7:48 a.m. Sept. 15, 2023, 7:58 a.m.
Size 246.5KB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 215db96eeac70244addf2c1578245399
SHA256 17642a0a7883905a4ce9a89e54fb01d22235625258fb3e7baeed33d2f73d9a49
CRC32 F2B674F7
ssdeep 6144:f/YzSJ2LSoTZfrVTfWe0h+Q71JEqWsT1O:fwo2HZTf0Rc5Ug
PDB Path C:\kogumu.pdb
Yara
  • UPX_Zero - UPX packed file
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • OS_Processor_Check_Zero - OS Processor Check

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

pdb_path C:\kogumu.pdb
resource name AFX_DIALOG_LAYOUT
section {u'size_of_data': u'0x0002fa00', u'virtual_address': u'0x00001000', u'entropy': 7.4388239206952855, u'name': u'.text', u'virtual_size': u'0x0002f976'} entropy 7.4388239207 description A section with a high entropy has been found
entropy 0.775967413442 description Overall entropy of this PE file is high