Summary | ZeroBOX

windows_update.exe

UPX PE64 PE File
Category Machine Started Completed
FILE s1_win7_x6401 July 8, 2024, 9:40 a.m. July 8, 2024, 9:43 a.m.
Size 5.7MB
Type PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows
MD5 14129aa32bbd6bf03d3cde8837119e2a
SHA256 a14cf7fe50d04752115b10db3af584676082152adae4295b44c1aefd2074fbf4
CRC32 32E05F25
ssdeep 98304:5QuBuV9L1VPDnK/oW1DNk0gH4cz7dp4kQDn8n/VJo+n6Ffh68lLdN5ij6rmZdQKt:5QuBuVx1VT4d5NG42d+InHl6FfhJlr5g
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE64 - (no description)
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section {u'size_of_data': u'0x005a9c00', u'virtual_address': u'0x00a7a000', u'entropy': 7.892057871610188, u'name': u'UPX1', u'virtual_size': u'0x005aa000'} entropy 7.89205787161 description A section with a high entropy has been found
entropy 0.999913785671 description Overall entropy of this PE file is high
section UPX0 description Section name indicates UPX
section UPX1 description Section name indicates UPX
section UPX2 description Section name indicates UPX
Time & API Arguments Status Return Repeated

LdrGetProcedureAddress

ordinal: 0
function_address: 0x000007fefd6b7a50
function_name: wine_get_version
module: ntdll
module_address: 0x0000000076d30000
-1073741511 0
Bkav W64.AIDetectMalware
Lionic Trojan.Win32.Generic.4!c
Cynet Malicious (score: 100)
Cylance Unsafe
Sangfor Trojan.Win32.Save.a
Symantec ML.Attribute.HighConfidence
Elastic malicious (moderate confidence)
ESET-NOD32 a variant of WinGo/Kryptik.FF
APEX Malicious
Paloalto generic.ml
Rising Trojan.Kryptik!8.8 (CLOUD)
DrWeb Trojan.Siggen29.1328
McAfeeD ti!A14CF7FE50D0
Sophos Mal/Generic-S
Ikarus Trojan.WinGo.Injector
Webroot W32.Eb.Gen
Avira TR/AVI.Agent.monnt
Antiy-AVL GrayWare/Win32.Kryptik.ffp
Kingsoft Win32.Troj.Unknown.a
Gridinsoft Trojan.Win64.Kryptik.sa
ZoneAlarm Backdoor.Win64.Supershell.cd
Google Detected
DeepInstinct MALICIOUS
Malwarebytes Malware.AI.3056318976
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Kryptik.FF!tr
alibabacloud Trojan:Multi/Kryptik.F#