Summary | ZeroBOX

LPG.txt.exe

.NET framework(MSIL) UPX Malicious Packer PE File PE32 .NET EXE
Category Machine Started Completed
FILE s1_win7_x6401 Oct. 5, 2023, 6:35 p.m. Oct. 5, 2023, 6:37 p.m.
Size 348.0KB
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 19ec1b3fe77ac2bb9b4019ecf20cfc5b
SHA256 8bbf013e1a095f5841b572e0aadc6c3929533b2332620fa470fe5e744b828b91
CRC32 02FDB3C0
ssdeep 6144:b2NHXf500M7fN3hDQorkb3aUQ0gdsx9+I6WGldC:id50xl3hcymQbsH+pWG3C
Yara
  • UPX_Zero - UPX packed file
  • Malicious_Packer_Zero - Malicious Packer
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • Is_DotNET_EXE - (no description)
  • Win32_Trojan_PWS_Net_1_Zero - Win32 Trojan PWS .NET Azorult

IP Address Status Action
164.124.101.2 Active Moloch
2.59.254.111 Active Moloch
208.95.112.1 Active Moloch

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49163 -> 208.95.112.1:80 2036383 ET MALWARE Common RAT Connectivity Check Observed A Network Trojan was detected
TCP 192.168.56.101:49163 -> 208.95.112.1:80 2022082 ET POLICY External IP Lookup ip-api.com Device Retrieving External IP Address Detected

Suricata TLS

No Suricata TLS

request GET http://ip-api.com/json/
domain ip-api.com
Lionic Trojan.MSIL.Agent.mCnJ
MicroWorld-eScan Generic.MSIL.PasswordStealerA.444DF84C
FireEye Generic.mg.19ec1b3fe77ac2bb
McAfee PWS-FCOI!19EC1B3FE77A
Malwarebytes Generic.Malware.AI.DDS
Zillya Trojan.Agent.Win32.1070552
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Trojan ( 00521dab1 )
Alibaba Backdoor:MSIL/Quasar.6d6423e0
K7GW Trojan ( 00521dab1 )
CrowdStrike win/malicious_confidence_100% (W)
Arcabit Generic.MSIL.PasswordStealerA.444DF84C
BitDefenderTheta Gen:NN.ZemsilF.36738.vm0@aa4MEzd
VirIT Trojan.Win32.Dnldr27.DKPK
Cyren W32/MSIL_Mintluks.A.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic Windows.Trojan.Quasarrat
ESET-NOD32 a variant of MSIL/Spy.Agent.AES
Cynet Malicious (score: 100)
APEX Malicious
ClamAV Win.Packed.Generic-9829635-0
Kaspersky Trojan.MSIL.Agent.foww
BitDefender Generic.MSIL.PasswordStealerA.444DF84C
SUPERAntiSpyware Trojan.Agent/Gen-PasswordStealer
Avast MSIL:Rat-B [Trj]
Tencent Trojan.Msil.Agent.zc
TACHYON Trojan/W32.DN-Agent.356352.BX
Emsisoft Trojan-Spy.Agent (A)
F-Secure Trojan:w32/QuasarRAT.A1
DrWeb Trojan.DownLoader27.59888
VIPRE Generic.MSIL.PasswordStealerA.444DF84C
TrendMicro TSPY_TINCLEX.SM1
McAfee-GW-Edition BehavesLike.Win32.Generic.fh
Trapmine suspicious.low.ml.score
Sophos ATK/Zaquar-D
Ikarus Trojan.MSIL.Agent
Jiangmin Trojan.Generic.ajfvk
Webroot W32.Malware.Gen
Avira HEUR/AGEN.1307329
Antiy-AVL Trojan/MSIL.Agent
Kingsoft malware.kb.c.1000
Gridinsoft Backdoor.Win32.Quasar.bot
Microsoft Backdoor:MSIL/Quasar.GG!MTB
ViRobot Trojan.Win32.LockBit.356352
ZoneAlarm Trojan.MSIL.Agent.foww
GData MSIL.Backdoor.Quasar.D
Google Detected
AhnLab-V3 Trojan/Win32.Subti.R285137
VBA32 Trojan.MSIL.Quasar.Heur
ALYac Generic.MSIL.PasswordStealerA.444DF84C