Summary | ZeroBOX

sync.exe

UPX PE64 PE File
Category Machine Started Completed
FILE s1_win7_x6401 July 8, 2024, 4:59 p.m. July 8, 2024, 5:01 p.m.
Size 5.7MB
Type PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows
MD5 69bf43760932bcccc3f1d58edc80bef9
SHA256 fbd74855722a28eced2b307c732d535ac1143e2f3f0d3e1ce0056486e883bd83
CRC32 81B88C46
ssdeep 98304:Jo0dhFxmI6kgtUa0jvKTEq5F79sJjYcF+s/XrZhz6PDdG1OLZU20dzeKMyBut:JvF564KTEKFs+s/Xrz6REkUFevyA
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE64 - (no description)
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section {u'size_of_data': u'0x005aa800', u'virtual_address': u'0x00a7b000', u'entropy': 7.892060234392221, u'name': u'UPX1', u'virtual_size': u'0x005ab000'} entropy 7.89206023439 description A section with a high entropy has been found
entropy 0.999913830246 description Overall entropy of this PE file is high
section UPX0 description Section name indicates UPX
section UPX1 description Section name indicates UPX
section UPX2 description Section name indicates UPX
Bkav W64.AIDetectMalware
Elastic malicious (moderate confidence)
Cynet Malicious (score: 100)
Skyhigh BehavesLike.Win64.Generic.tc
Cylance Unsafe
Sangfor Trojan.Win32.Save.a
ESET-NOD32 a variant of WinGo/Kryptik.FF
APEX Malicious
Kaspersky VHO:Trojan.Win32.Convagent.gen
McAfeeD ti!FBD74855722A
FireEye Generic.mg.69bf43760932bccc
Sophos CXrep/MalGo-B
Ikarus Trojan.WinGo.Injector
Google Detected
Antiy-AVL GrayWare/Win32.Kryptik.ffp
ZoneAlarm VHO:Trojan.Win32.Convagent.gen
Varist W64/Agent.FXW.gen!Eldorado
DeepInstinct MALICIOUS
MaxSecure Trojan.Malware.300983.susgen
Time & API Arguments Status Return Repeated

LdrGetProcedureAddress

ordinal: 0
function_address: 0x000007fefd6b7a50
function_name: wine_get_version
module: ntdll
module_address: 0x0000000076d30000
-1073741511 0