Summary | ZeroBOX

setup.exe

Malicious Library ASPack UPX Malicious Packer PE64 PE File OS Processor Check
Category Machine Started Completed
FILE s1_win7_x6403_us June 24, 2024, 7:35 a.m. June 24, 2024, 7:40 a.m.
Size 32.6MB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 b6698d4058a87ffcd7bfd86ed09860af
SHA256 b7abc68b15241dcc425b41e48adab590155a5c4825ccfe761903f6a689a8dc17
CRC32 C1491E12
ssdeep 393216:whImijFjJ3D7uSHhtyWcBN3MjyQhlktqYGGCVPpjSBibscqvWsWithg:whUF5D0WqNcxhYqRGCtpjSQvg
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • ASPack_Zero - ASPack packed file
  • Malicious_Packer_Zero - Malicious Packer
  • IsPE64 - (no description)
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section .buildid
section {u'size_of_data': u'0x012fce00', u'virtual_address': u'0x00afd000', u'entropy': 7.880348157757867, u'name': u'.rdata', u'virtual_size': u'0x012fcdfc'} entropy 7.88034815776 description A section with a high entropy has been found
entropy 0.582698993047 description Overall entropy of this PE file is high