Summary | ZeroBOX

a.dll

Malicious Library UPX PE File DLL OS Processor Check PE32
Category Machine Started Completed
FILE s1_win7_x6401 June 24, 2024, 11:01 a.m. June 24, 2024, 11:04 a.m.
Size 464.1KB
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 e543d220625ff34807f7418a638f0775
SHA256 1403c93a5684a9e1d597d976be03df41e5cec422cd85bf2b3f726ae507467d17
CRC32 67938AF2
ssdeep 6144:2ePGSKZI3pCLkMQSWm9oseyO9jjzKf3QH5SQnYav:2euZApCLk/SWm9oseRjzKPQH3ntv
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsDLL - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

resource name WAVE
name WAVE language LANG_CHINESE filetype RIFF (little-endian) data, WAVE audio, Microsoft ADPCM, mono 22050 Hz sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x00071270 size 0x00002404
name RT_DIALOG language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x000711d0 size 0x0000009a
Lionic Trojan.Win32.Generic.4!c
Cynet Malicious (score: 85)
Sangfor Malware
F-Secure Trojan.TR/Spy.Gen
Ikarus Trojan.Spy
Avira TR/Spy.Gen
BitDefenderTheta Gen:NN.ZedlaF.34282.Dy5@aKVkFhjb