Summary | ZeroBOX

random.exe

UPX Anti_VM PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6401 April 12, 2024, 8:40 a.m. April 12, 2024, 8:40 a.m.
Size 2.2MB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 04444d22b3bfefd4ea745d46267a9690
SHA256 2d155276d6678839354259ccd3958c96160064e13baa76674ced32aaa32891f0
CRC32 9218F74A
ssdeep 49152:ds9NRR5MmyC8+CLH9+9GZwh+lDZ13KMm2EBEnCIJBAu+:dQNRG3LiGbZJKMoynbC3
Yara
  • PE_Header_Zero - PE File Signature
  • anti_vm_detect - Possibly employs anti-virtualization techniques
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section \x00
section .idata
section
section dtrnuynz
section xanfxued
section {u'size_of_data': u'0x00093e00', u'virtual_address': u'0x00001000', u'entropy': 7.928340859424422, u'name': u' \\x00 ', u'virtual_size': u'0x00144000'} entropy 7.92834085942 description A section with a high entropy has been found
section {u'size_of_data': u'0x00000c00', u'virtual_address': u'0x00145000', u'entropy': 7.552732691461608, u'name': u'.rsrc', u'virtual_size': u'0x00002e50'} entropy 7.55273269146 description A section with a high entropy has been found
section {u'size_of_data': u'0x00191e00', u'virtual_address': u'0x003f0000', u'entropy': 7.949478729447231, u'name': u'dtrnuynz', u'virtual_size': u'0x00192000'} entropy 7.94947872945 description A section with a high entropy has been found
entropy 0.999319264806 description Overall entropy of this PE file is high