Summary | ZeroBOX

sc.exe

Malicious Packer UPX Malicious Library PE64 PE File
Category Machine Started Completed
FILE s1_win7_x6403_us June 16, 2024, 9:53 a.m. June 16, 2024, 9:57 a.m.
Size 2.1MB
Type PE32+ executable (console) x86-64, for MS Windows
MD5 1c7ce77089b1bc88099485ff0c30a928
SHA256 db74c9cf550a01d6961af9d5155a93d926484b7d7b255a1a2f2ba74d33d77717
CRC32 6B744C3E
ssdeep 24576:OPtYRHuLzYT4a+LTHgBPpgWU4sfvSH7WBUCXTZXTTV5reBBPb:iqRHKzYRI34sCbWBvD9V5rOPb
Yara
  • Malicious_Packer_Zero - Malicious Packer
  • Malicious_Library_Zero - Malicious_Library
  • IsPE64 - (no description)
  • PE_Header_Zero - PE File Signature
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section .symtab
section {u'size_of_data': u'0x00022c00', u'virtual_address': u'0x001ef000', u'entropy': 7.99237141357897, u'name': u'/19', u'virtual_size': u'0x00022ab3'} entropy 7.99237141358 description A section with a high entropy has been found
section {u'size_of_data': u'0x00006e00', u'virtual_address': u'0x00212000', u'entropy': 7.926354215612744, u'name': u'/32', u'virtual_size': u'0x00006da6'} entropy 7.92635421561 description A section with a high entropy has been found
section {u'size_of_data': u'0x00040c00', u'virtual_address': u'0x0021a000', u'entropy': 7.996818822441904, u'name': u'/65', u'virtual_size': u'0x00040a8e'} entropy 7.99681882244 description A section with a high entropy has been found
section {u'size_of_data': u'0x00021a00', u'virtual_address': u'0x0025b000', u'entropy': 7.988523630315708, u'name': u'/78', u'virtual_size': u'0x00021957'} entropy 7.98852363032 description A section with a high entropy has been found
section {u'size_of_data': u'0x0000ca00', u'virtual_address': u'0x0027d000', u'entropy': 7.795503173172705, u'name': u'/90', u'virtual_size': u'0x0000c952'} entropy 7.79550317317 description A section with a high entropy has been found
entropy 0.286956521739 description Overall entropy of this PE file is high