Summary | ZeroBOX

psaux.exe

Malicious Packer UPX PE64 PE File
Category Machine Started Completed
FILE s1_win7_x6403_us Dec. 15, 2023, 8:25 a.m. Dec. 15, 2023, 8:41 a.m.
Size 15.1MB
Type PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
MD5 bd84bdff727b82364685f4179170d81e
SHA256 df8485aad922f0e8858f691f9b0b116c8ce1d74b1f0e7cb7128e294e879bbb1c
CRC32 A3550233
ssdeep 98304:zKaYjw5U5R5BHH6/gffAZMmuYC5es4rw2iSqsw9OE7ONkozhkrfHzF4EFEO:+VBHa/gf4ZMxYSes4rw2irsw9ra2
Yara
  • Malicious_Packer_Zero - Malicious Packer
  • PE_Header_Zero - PE File Signature
  • IsPE64 - (no description)
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
208.115.233.154 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

Flow Issuer Subject Fingerprint
TLS 1.3
192.168.56.103:49161
208.115.233.154:5443
None None None

Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0
section .symtab
Time & API Arguments Status Return Repeated

GetAdaptersAddresses

flags: 16
family: 0
1 0 0
host 208.115.233.154
Time & API Arguments Status Return Repeated

LdrGetProcedureAddress

ordinal: 0
function_address: 0x000007fefe467a50
function_name: wine_get_version
module: ntdll
module_address: 0x00000000776c0000
-1073741511 0