Summary | ZeroBOX

FPTool.exe

PhysicalDrive Generic Malware Malicious Library UPX PE File OS Processor Check PE32
Category Machine Started Completed
FILE s1_win7_x6401 June 5, 2024, 3:17 a.m. June 5, 2024, 3:19 a.m.
Size 2.5MB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 f421bbe1658cfb4615537c78e5311534
SHA256 1adaa5368ac2e67332d4583a6fdb82a74aea9edccd7e40465b7bfd193334a73b
CRC32 F88F9A66
ssdeep 49152:3UgNcf68UBMpt2Evzbx3Hw8CzlftN6HlXSaV7suLTGz9R:3kf68UBA2qzhHw8CzlfT6HlXSaBLTm
Yara
  • PhysicalDrive_20181001 - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section .gfids
section .giats
resource name AFX_DIALOG_LAYOUT
resource name PNG
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2556
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00b32000
process_handle: 0xffffffff
1 0 0
name AFX_DIALOG_LAYOUT language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0023d9d0 size 0x00000002
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
name PNG language LANG_CHINESE filetype PNG image data, 414 x 180, 8-bit colormap, non-interlaced sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x0025b118 size 0x00000b23
Cylance Unsafe
APEX Malicious
Rising Trojan.Generic@AI.81 (RDML:mzHnonRoTtfnHaiGsoKLqQ)
BitDefenderTheta Gen:NN.ZexaF.36806.II0@aeTXBDdj
MaxSecure Trojan.Malware.300983.susgen
section {u'size_of_data': u'0x00037200', u'virtual_address': u'0x0023c000', u'entropy': 7.336041051104075, u'name': u'.rsrc', u'virtual_size': u'0x000370d0'} entropy 7.3360410511 description A section with a high entropy has been found