Summary | ZeroBOX

pic2.jpg.exe

UPX PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6401 July 2, 2024, 10:26 a.m. July 2, 2024, 10:28 a.m.
Size 6.3MB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 bd2eac64cbded877608468d86786594a
SHA256 cae992788853230af91501546f6ead07cfd767cb8429c98a273093a90bbcb5ad
CRC32 BBA76196
ssdeep 98304:LqhZ67opwYckx35SF2XKgxVvHuCPU8GSbO3JAXV1LrA+ZlL9CxpzTp2:LgErupSgKORuCT43JeV1LE+/s3p
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section .vmpL\xc2\xa7p
section {u'size_of_data': u'0x005de400', u'virtual_address': u'0x00335000', u'entropy': 7.881816676779664, u'name': u'.vmpL\\xc2\\xa7p', u'virtual_size': u'0x005de290'} entropy 7.88181667678 description A section with a high entropy has been found
entropy 0.926528409529 description Overall entropy of this PE file is high
section .vmpL\xc2\xa7p description Section name indicates VMProtect
section .vmpL\xc2\xa7p description Section name indicates VMProtect
section .vmpL\xc2\xa7p description Section name indicates VMProtect
Bkav W32.AIDetectMalware
Elastic malicious (high confidence)
Skyhigh BehavesLike.Win32.Generic.vc
ALYac Trojan.GenericKD.73323652
Cylance Unsafe
VIPRE Trojan.GenericKD.73323652
Sangfor Suspicious.Win32.Save.a
BitDefender Trojan.GenericKD.73323652
Arcabit Trojan.Generic.D45ED484
VirIT Trojan.Win32.Genus.VYR
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Spy.LummaStealer.B
APEX Malicious
Avast Win32:MalwareX-gen [Trj]
MicroWorld-eScan Trojan.GenericKD.73323652
Rising Spyware.LummaStealer!8.1A464 (CLOUD)
Emsisoft Trojan.GenericKD.73323652 (B)
F-Secure Trojan.TR/AVI.Agent.wkgdl
TrendMicro Trojan.Win32.SMOKELOADER.YXEF4Z
McAfeeD ti!CAE992788853
Trapmine malicious.moderate.ml.score
FireEye Generic.mg.bd2eac64cbded877
Sophos Mal/Generic-S
Ikarus Trojan-Spy.Win32.LummaStealer
Google Detected
Avira TR/AVI.Agent.wkgdl
MAX malware (ai score=84)
Gridinsoft Spy.Win32.Gen.tr
Microsoft Trojan:Win32/LummaStealer.MWW!MTB
GData Trojan.GenericKD.73323652
Varist W32/ABTrojan.BATW-1424
BitDefenderTheta Gen:NN.ZexaF.36808.@J0@aeZYSJai
DeepInstinct MALICIOUS
VBA32 SScope.TrojanDropper.Hider
Malwarebytes Neshta.Virus.FileInfector.DDS
TrendMicro-HouseCall Trojan.Win32.SMOKELOADER.YXEF4Z
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/LummaStealer.B!tr.spy
AVG Win32:MalwareX-gen [Trj]
Paloalto generic.ml
CrowdStrike win/malicious_confidence_100% (W)