Summary | ZeroBOX

asca1ex123111.exe

Malicious Library PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6403_us Oct. 7, 2023, 2:50 p.m. Oct. 7, 2023, 2:56 p.m.
Size 391.5KB
Type PE32 executable (console) Intel 80386, for MS Windows
MD5 afeaa39b474fbc97ab20f75b90b340c1
SHA256 ad809b651757ec30585845eb9acdc5c335c8b36244397c8c1a23b1bf35a9648e
CRC32 A0A2ACF8
ssdeep 12288:1kUoRUzA/vZoMecqF2ksaSwRobhNnfwBlZRvB7Kpve2Jg0YBmgMyl361+5XFWQFB:1NSJQmy36yHU9q9l
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section .ktqovk
section {u'size_of_data': u'0x00008800', u'virtual_address': u'0x00001000', u'entropy': 6.9088363436071765, u'name': u'.text', u'virtual_size': u'0x000087b4'} entropy 6.90883634361 description A section with a high entropy has been found
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Generic.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.69611557
FireEye Generic.mg.afeaa39b474fbc97
Skyhigh BehavesLike.Win32.Generic.fh
Malwarebytes Spyware.RedLineStealer
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005aba0f1 )
Alibaba Malware:Win32/km_2e924.None
K7GW Trojan ( 005aba0f1 )
CrowdStrike win/malicious_confidence_100% (W)
Arcabit Trojan.Generic.D4263025
Symantec ML.Attribute.HighConfidence
Cynet Malicious (score: 100)
APEX Malicious
BitDefender Trojan.GenericKD.69611557
NANO-Antivirus Virus.Win32.Gen.ccmw
Sophos Mal/Generic-S
TrendMicro Trojan.Win32.SMOKELOADER.YXDJFZ
Trapmine malicious.high.ml.score
Emsisoft Trojan.GenericKD.69611557 (B)
Ikarus Trojan.Agent
Webroot W32.Trojan.FL
MAX malware (ai score=81)
Kingsoft malware.kb.a.1000
Gridinsoft Ransom.Win32.Sabsik.sa
Microsoft Trojan:Win32/Casdet!rfn
GData Trojan.GenericKD.69611557
Google Detected
McAfee Artemis!AFEAA39B474F
Cylance unsafe
Zoner Probably Heur.ExeHeaderL
TrendMicro-HouseCall Trojan.Win32.SMOKELOADER.YXDJFZ
Rising Trojan.Generic@AI.98 (RDML:LJNq04NusD+EbgUoBTSNRA)
SentinelOne Static AI - Malicious PE
Fortinet PossibleThreat.PALLASNET.H
Cybereason malicious.508a18
DeepInstinct MALICIOUS