Summary | ZeroBOX

w-12.exe

PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6401 Oct. 10, 2023, 4:57 p.m. Oct. 10, 2023, 5:02 p.m.
Size 3.3MB
Type PE32 executable (console) Intel 80386, for MS Windows, UPX compressed
MD5 0cb677593212bc9f636c778bd6333b3a
SHA256 80cb07c7e1d7f14d45d879b80e3d9664eb7b1252217d03d1569c2653c10fd821
CRC32 0C90A092
ssdeep 49152:yZGup0+G/KKEl7rFxhfpHv8KSjGHkLwyfcazlqh7mWTfCZnYXAJU2QqdhQvh:8Gc+8zHv8zl0ecai7bHWU2pdh
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

WriteConsoleA

buffer: fatal error:
console_handle: 0x0000000b
1 1 0

WriteConsoleA

buffer: kernel32.dll not found
console_handle: 0x0000000b
1 1 0

WriteConsoleA

buffer: runtime: panic before malloc heap initialized
console_handle: 0x0000000b
1 1 0
packer UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser
Time & API Arguments Status Return Repeated

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.esp: 4192476
registers.edi: 18748048
registers.eax: 0
registers.ebp: 4192480
registers.edx: 4294967295
registers.ebx: 4192492
registers.esi: 4192408
registers.ecx: 0
1 0 0
section {u'size_of_data': u'0x00351400', u'virtual_address': u'0x005f8000', u'entropy': 7.886656281072496, u'name': u'UPX1', u'virtual_size': u'0x00352000'} entropy 7.88665628107 description A section with a high entropy has been found
entropy 0.999852832965 description Overall entropy of this PE file is high
section UPX0 description Section name indicates UPX
section UPX1 description Section name indicates UPX
section UPX2 description Section name indicates UPX
Bkav W32.AIDetectMalware
Elastic malicious (moderate confidence)
Skyhigh BehavesLike.Win32.Generic.wc
McAfee Artemis!0CB677593212
Sangfor Trojan.Win32.Save.a
Alibaba Trojan:Win32/Windigo.b3862a64
CrowdStrike win/malicious_confidence_70% (W)
BitDefenderTheta Gen:NN.ZexaF.36738.upGfa4D27Al
Symantec ML.Attribute.HighConfidence
Cynet Malicious (score: 100)
APEX Malicious
Kaspersky Trojan-Proxy.Win32.Windigo.axz
Trapmine malicious.high.ml.score
Webroot W32.Trojan.Gen
Antiy-AVL GrayWare/Win32.Kryptik.ffp
Gridinsoft Trojan.Win32.Kryptik.sa
ZoneAlarm Trojan-Proxy.Win32.Windigo.axz
Google Detected
Rising Trojan.Generic@AI.96 (RDML:JETLrtUwq2gL1qzQhMNicg)
Ikarus Trojan.WinGo.Shellcoderunner
MaxSecure Trojan.Malware.300983.susgen
DeepInstinct MALICIOUS