Summary | ZeroBOX

ScholarshipHamilton.exe

Malicious Library UPX Malicious Packer PE File OS Processor Check PE32
Category Machine Started Completed
FILE s1_win7_x6401 Jan. 11, 2024, 7:34 a.m. Jan. 11, 2024, 7:37 a.m.
Size 857.8KB
Type PE32 executable (console) Intel 80386, for MS Windows
MD5 f48ff00102947acd17461bd8cbca9b71
SHA256 9594160451608088b8e987328f0b13fb77d59bc99d27c4faad97e2ad834c5a65
CRC32 CB97FFE1
ssdeep 24576:mD3s67DbEXHWA8u5Hhfyip26+rVgINQu1I/N:4X7cXHOM+rKINQlN
PDB Path Z:\7zsfxmm-51139022f6d790da60884077b63b2f265052be0b\Output\Win32\7ZSfxMod.pdb
Yara
  • Malicious_Library_Zero - Malicious_Library
  • IsPE32 - (no description)
  • Malicious_Packer_Zero - Malicious Packer
  • PE_Header_Zero - PE File Signature
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

pdb_path Z:\7zsfxmm-51139022f6d790da60884077b63b2f265052be0b\Output\Win32\7ZSfxMod.pdb
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2636
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 876544
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x76f20000
process_handle: 0xffffffff
1 0 0
Time & API Arguments Status Return Repeated

GetDiskFreeSpaceExW

total_number_of_free_bytes: 0
free_bytes_available: 13324423168
root_path: C:\Users\test22\AppData\Local\Temp\7ZipSfx.000
total_number_of_bytes: 0
1 1 0
Bkav W32.Common.0A6B76D1
Lionic Trojan.Win32.Crysan.m!c
DrWeb Trojan.MulDrop24.46494
Skyhigh Artemis!Trojan
McAfee Artemis!F48FF0010294
Cylance unsafe
Sangfor Backdoor.Win32.Crysan.Vfum
K7AntiVirus Trojan ( 005b04371 )
Alibaba Backdoor:MSIL/Crysan.5942f9d6
K7GW Trojan ( 005b04371 )
Symantec Trojan.Gen.MBT
Elastic malicious (moderate confidence)
ESET-NOD32 a variant of Win32/Packed.7zip.DB suspicious
Avast Win32:DropperX-gen [Drp]
Kaspersky Backdoor.MSIL.Crysan.icw
NANO-Antivirus Trojan.Win32.Crysan.kgugbu
Tencent Win32.Trojan.FalseSign.Fkjl
F-Secure Trojan.TR/AD.Nekark.ubnth
Sophos Mal/Generic-S
Webroot W32.Malware.Gen
Google Detected
Avira TR/AD.Nekark.ubnth
Varist W32/ABRisk.NMPL-7894
Kingsoft Win32.Hack.Undef.a
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Gridinsoft Trojan.Win32.Packed.cl
ZoneAlarm Backdoor.MSIL.Crysan.icw
GData Win32.Trojan.Agent.K83VAF
Cynet Malicious (score: 99)
AhnLab-V3 Malware/Win.Generic.R630773
Panda Trj/Chgt.AD
Fortinet Malicious_Behavior.SB
AVG Win32:DropperX-gen [Drp]
DeepInstinct MALICIOUS