Summary | ZeroBOX

setup%E7%9B%AE%E5%BD%95%E8%A1%A8%E6%A0%BC%E5%90%8D%E5%8D%956001.exe

Malicious Library PE64 PE File
Category Machine Started Completed
FILE s1_win7_x6401 June 14, 2024, 9:15 a.m. June 14, 2024, 9:17 a.m.
Size 185.0KB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 7fbc6a95fc41c5bb0fecdd659d641ae9
SHA256 6f230022e87603e77015b30bf28f3a18fb668c290d79a797c5fcb1ba667b6bcf
CRC32 E8735D45
ssdeep 3072:1sTFNXXCODoKGDCEywH4/vikDv24LFYjRPOghNrXA4O8JHtiEIV98HegZUv/+X:aTzSeGDP54/vz0RPOghNrXATQgEIb8sv
Yara
  • IsPE64 - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
8.138.14.211 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Elastic malicious (high confidence)
Kaspersky VHO:Trojan.Win32.Injuke.gen
Trapmine malicious.moderate.ml.score
Microsoft Trojan:Win32/Sabsik.RD.A!ml
ZoneAlarm VHO:Trojan.Win32.Injuke.gen
MaxSecure Trojan.Malware.300983.susgen
section {u'size_of_data': u'0x00013600', u'virtual_address': u'0x00020000', u'entropy': 7.962624758446382, u'name': u'.rsrc', u'virtual_size': u'0x000135b0'} entropy 7.96262475845 description A section with a high entropy has been found
entropy 0.421195652174 description Overall entropy of this PE file is high
host 8.138.14.211
dead_host 8.138.14.211:80