Summary | ZeroBOX

cp.exe

UPX PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6403_us Dec. 4, 2023, 3:38 p.m. Dec. 4, 2023, 3:39 p.m.
Size 5.6MB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 67c91a40f9550dca6e0caf57325b9a10
SHA256 b3210c2edf5c7692385406495e2745e108e404bbcab374c0ec2902bf7cb1e371
CRC32 0AFB7FFB
ssdeep 98304:kt8mEfgml7ba8CeEKpo4//jnDQSYrvD8oudALqV6BC2gxSCIwTNMTxn+OCWk:kvEfgqkezO4jnDQSIBudAWV6BC2nCIOj
Yara
  • IsPE32 - (no description)
  • PE_Header_Zero - PE File Signature
  • UPX_Zero - UPX packed file
  • themida_packer - themida packer

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section
section .imports
section \xc2\xba\xc2\xba\xc2\xba\xc2\xbb
section .themida
section .boot
section .vmp\xc6\x92\xc2\xa4
section {u'size_of_data': u'0x00551a00', u'virtual_address': u'0x00835000', u'entropy': 7.9944891531264926, u'name': u'.vmp\\xc6\\x92\\xc2\\xa4', u'virtual_size': u'0x00551960'} entropy 7.99448915313 description A section with a high entropy has been found
entropy 0.949694856146 description Overall entropy of this PE file is high
section .vmp\xc6\x92\xc2\xa4 description Section name indicates VMProtect
section .vmp\xc6\x92\xc2\xa4 description Section name indicates VMProtect
section .vmp\xc6\x92\xc2\xa4 description Section name indicates VMProtect