Summary | ZeroBOX

spphost.exe

Generic Malware Malicious Library UPX PE64 PE File OS Processor Check
Category Machine Started Completed
FILE s1_win7_x6401 June 20, 2024, 7:31 p.m. June 20, 2024, 7:31 p.m.
Size 134.6KB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 358f68588c7f515fcf638b0141fea937
SHA256 19e2639a1a919aad17700a903d31930f6ff6c3ca2d850999f613504a554b729b
CRC32 02F097ED
ssdeep 3072:70VPJwm17dkYntPisvVMQrfctQZE0RbrfHMoNpmWo8qxU/RFVxsnDT:70VPJwmgYntPisNdXZEOHHrpm1XUZLxo
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE64 - (no description)
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section .00cfg
section .retplne
Bkav W64.AIDetectMalware
DeepInstinct MALICIOUS
MaxSecure Win.MxResIcn.Heur.Gen
section {u'size_of_data': u'0x00012600', u'virtual_address': u'0x00012000', u'entropy': 7.216979168604809, u'name': u'.rsrc', u'virtual_size': u'0x00012468'} entropy 7.2169791686 description A section with a high entropy has been found
entropy 0.581027667984 description Overall entropy of this PE file is high