Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Aug. 4, 2024, 1:23 p.m. | Aug. 4, 2024, 1:45 p.m. |
-
china.exe "C:\Users\test22\AppData\Local\Temp\china.exe"
2572
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
section | CODE |
section | DATA |
section | BSS |
file | C:\Users\test22\AppData\Local\Temp\GSED6D.tmp |
section | {u'size_of_data': u'0x0000bc00', u'virtual_address': u'0x0000a000', u'entropy': 7.5078848951348585, u'name': u'.rsrc', u'virtual_size': u'0x0000bb34'} | entropy | 7.50788489513 | description | A section with a high entropy has been found | |||||||||
entropy | 0.789915966387 | description | Overall entropy of this PE file is high |
Bkav | W32.AIDetectMalware |
Cylance | Unsafe |
APEX | Malicious |
ClamAV | Win.Trojan.Generic-9787872-0 |
Rising | Trojan.Zapchast.fx (CLASSIC) |
Zillya | Backdoor.mIRC.Win32.654 |
McAfeeD | ti!D417C5248D33 |
Trapmine | malicious.high.ml.score |
Detected | |
Microsoft | PWS:Win32/Fareit!ml |
SentinelOne | Static AI - Suspicious PE |
MaxSecure | Trojan.Malware.300983.susgen |
Paloalto | generic.ml |