Summary | ZeroBOX

pic2.exe

UPX PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6401 June 25, 2024, 7:53 a.m. June 25, 2024, 7:55 a.m.
Size 2.7MB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 5f9be6e22310cc089a32fac1d037ced4
SHA256 e03ad208cd03d80ab4c684abc5be5cc4bd492021288de2742a875c6e8f2e85fa
CRC32 48FD8F2B
ssdeep 49152:95Ar0ZH/UbYLC+qsqaep9g7fjtSnXkiO08llBenVAJhv17/9EaRq1/SoCJ0k1yn:cIhJLya6IKnX8MnVGd15Eao/lA
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section .vmp\xc2\x9dt\xc3
section {u'size_of_data': u'0x00271c00', u'virtual_address': u'0x00158000', u'entropy': 7.971632567843599, u'name': u'.vmp\\xc2\\x9dt\\xc3', u'virtual_size': u'0x00271b50'} entropy 7.97163256784 description A section with a high entropy has been found
entropy 0.910844250364 description Overall entropy of this PE file is high
section .vmp\xc2\x9dt\xc3 description Section name indicates VMProtect
section .vmp\xc2\x9dt\xc3 description Section name indicates VMProtect
section .vmp\xc2\x9dt\xc3 description Section name indicates VMProtect
Bkav W32.AIDetectMalware
Elastic malicious (high confidence)
Cynet Malicious (score: 100)
Cylance Unsafe
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Packed.VMProtect.BG suspicious
Kaspersky VHO:Trojan.Win32.Sdum.gen
Rising Trojan.Generic@AI.97 (RDMK:cmRtazqNwNER12ofNRXvtXBxQRjY)
McAfeeD ti!E03AD208CD03
Trapmine malicious.high.ml.score
Gridinsoft Trojan.Heur!.00210281
Microsoft Trojan:Win32/Wacatac.B!ml
ZoneAlarm VHO:Trojan.Win32.Sdum.gen
AhnLab-V3 Suspicious/Win.MalPe.X2200
BitDefenderTheta Gen:NN.ZexaF.36808.TI2@ayuRDF
DeepInstinct MALICIOUS
VBA32 BScope.TrojanSpy.LClipper
MaxSecure Trojan.Malware.300983.susgen