Summary | ZeroBOX

setup%E4%B8%8B%E8%BD%BD%E5%90%8D%E5%8D%95%E7%9B%AE%E5%BD%956056.exe

Malicious Library PE64 PE File
Category Machine Started Completed
FILE s1_win7_x6401 June 14, 2024, 9:17 a.m. June 14, 2024, 9:28 a.m.
Size 205.1KB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 2b2690881f0030510504113baf20831b
SHA256 c2ffdc8abad170351313c2cf2dc4f6ef3f9c320543f0608a37dbf75da2e2b539
CRC32 89FCF8A6
ssdeep 6144:jPTc+NurrbUTp1YC+P6PPPTP2PdN2WHPPjLB:jYpUDYCu
Yara
  • IsPE64 - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
8.138.0.158 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

name RT_VERSION language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x00033cc0 size 0x00000294
host 8.138.0.158
dead_host 8.138.0.158:80
Bkav W32.Common.4999DDF8
Lionic Trojan.Win32.Agent.Y!c
Elastic malicious (high confidence)
ALYac Trojan.GenericKDZ.106434
Cylance Unsafe
VIPRE Trojan.GenericKDZ.106434
Sangfor Downloader.Win32.Agent.Vvbv
K7AntiVirus Trojan-Downloader ( 005b4a5f1 )
BitDefender Trojan.GenericKDZ.106434
K7GW Trojan-Downloader ( 005b4a5f1 )
Cybereason malicious.81f003
Arcabit Trojan.Generic.D19FC2
Symantec Trojan.Gen.MBT
ESET-NOD32 a variant of Win64/TrojanDownloader.Agent.ASS
Avast Win64:Evo-gen [Trj]
Kaspersky Trojan-Downloader.Win32.Agent.xycsah
Alibaba TrojanDownloader:Win64/Genric.981c426f
MicroWorld-eScan Trojan.GenericKDZ.106434
Rising Downloader.Agent!8.B23 (TFE:5:cg4jjrc1DLF)
Emsisoft Trojan.GenericKDZ.106434 (B)
F-Secure Trojan.TR/Dldr.Agent.lhkgd
Zillya Downloader.Agent.Win64.6281
TrendMicro TROJ_GEN.R03BC0XDT24
McAfeeD ti!C2FFDC8ABAD1
FireEye Generic.mg.2b2690881f003051
Sophos Mal/Generic-S
Ikarus Trojan-Downloader.Win64.Agent
Google Detected
Avira TR/Dldr.Agent.lhkgd
MAX malware (ai score=86)
Antiy-AVL GrayWare[AdWare]/Win32.Caypnamer
Kingsoft Win32.Trojan-Downloader.Agent.xycsah
Microsoft Trojan:Win32/Casdet!rfn
ZoneAlarm Trojan-Downloader.Win32.Agent.xycsah
GData Trojan.GenericKDZ.106434
Varist W64/ABDownloader.PGBU-6144
AhnLab-V3 Trojan/Win.Generic.R646446
DeepInstinct MALICIOUS
Malwarebytes Neshta.Virus.FileInfector.DDS
TrendMicro-HouseCall TROJ_GEN.R03BC0XDT24
Tencent Backdoor.Win32.Downloader_l.16001170
MaxSecure Trojan.Malware.242543320.susgen
Fortinet W64/Agent.ASS!tr.dldr
AVG Win64:Evo-gen [Trj]
Paloalto generic.ml
CrowdStrike win/malicious_confidence_70% (W)
alibabacloud Trojan[downloader]:Win/Agent.ABK