Summary | ZeroBOX

doh.exe

Generic Malware Malicious Library UPX Malicious Packer PE64 PE File
Category Machine Started Completed
FILE s1_win7_x6403_us July 11, 2024, 1:22 p.m. July 11, 2024, 2:05 p.m.
Size 5.6MB
Type PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
MD5 820562b1432bd540f32b277ce5e6f749
SHA256 4b8235e2898b9c65dd767b1d8bd3ffd20bab614c5eadcf586fc8f28593793f5c
CRC32 C2017CA9
ssdeep 98304:6gcKKE5jT3QDvt9yU/Za3GeZ+jEMy6GYmX7WUK87JJSpPAwXeARo8:tcbVgU/Z/3TGX7WbYJSpPAieARB
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer
  • IsPE64 - (no description)
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 17836000
registers.r15: 0
registers.rcx: -1
registers.rsi: 2422552
registers.r10: 3221225485
registers.rbx: -10000
registers.rsp: 2422216
registers.r11: 2
registers.r8: 2422256
registers.r9: 360
registers.rdx: 0
registers.r12: 2422776
registers.rbp: 2422280
registers.rdi: 12201024
registers.rax: 0
registers.r13: 8
1 0 0
section {u'size_of_data': u'0x00453800', u'virtual_address': u'0x00094000', u'entropy': 7.988966321152739, u'name': u'.data', u'virtual_size': u'0x004536c0'} entropy 7.98896632115 description A section with a high entropy has been found
entropy 0.775831873905 description Overall entropy of this PE file is high
Bkav W64.AIDetectMalware
Lionic Trojan.Win32.Generic.4!c
Elastic malicious (high confidence)
Cynet Malicious (score: 100)
Skyhigh BehavesLike.Win64.Generic.tc
Cylance Unsafe
Sangfor Trojan.Win32.Save.a
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Packed.GoLang_AGen.G suspicious
APEX Malicious
Avast FileRepMalware [Misc]
Kaspersky UDS:DangerousObject.Multi.Generic
McAfeeD ti!4B8235E2898B
Trapmine suspicious.low.ml.score
FireEye Generic.mg.820562b1432bd540
Sophos Mal/Generic-S
Ikarus Trojan.WinGo.Shellcoderunner
Google Detected
Microsoft Program:Win32/Wacapew.C!ml
ZoneAlarm UDS:DangerousObject.Multi.Generic
GData Win64.Trojan.Agent.P0B1IP
DeepInstinct MALICIOUS
Malwarebytes Generic.Malware.AI.DDS
Fortinet Riskware/Application
AVG FileRepMalware [Misc]
CrowdStrike win/malicious_confidence_90% (D)
alibabacloud VirTool:Win/Packed.GoLang_AGen.G