Summary | ZeroBOX

wmiexec.exe

Gen1 Generic Malware Malicious Library UPX Anti_VM ftp PE64 PE File OS Processor Check ZIP Format DLL
Category Machine Started Completed
FILE s1_win7_x6403_us Aug. 5, 2024, 10:35 a.m. Aug. 5, 2024, 10:40 a.m.
Size 10.6MB
Type PE32+ executable (console) x86-64, for MS Windows
MD5 e3e29ce5e9af4e3b0452b79bad2a31ac
SHA256 68ca7bcfb1ce73da7e17e22a93752f0925776581238c4569c0c0057946fce9e0
CRC32 D6F410DD
ssdeep 196608:DYs+UGFLOtEp6dQmRJ8dA6lwkaqdVTeby0NWMxWn8woTXA:z+UwatddQuslwwdUbyXMS81TX
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE64 - (no description)
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section _RDATA
file C:\Users\test22\AppData\Local\Temp\_MEI16642\python310.dll
file C:\Users\test22\AppData\Local\Temp\_MEI16642\VCRUNTIME140.dll
file C:\Users\test22\AppData\Local\Temp\_MEI16642\libcrypto-1_1.dll
file C:\Users\test22\AppData\Local\Temp\_MEI16642\libssl-1_1.dll
file C:\Users\test22\AppData\Local\Temp\_MEI16642\libffi-7.dll
section {u'size_of_data': u'0x0000f200', u'virtual_address': u'0x00052000', u'entropy': 7.356255504376821, u'name': u'.rsrc', u'virtual_size': u'0x0000f008'} entropy 7.35625550438 description A section with a high entropy has been found
Bkav W64.AIDetectMalware
Lionic Trojan.Win32.Tiny.tsdM
Cylance Unsafe
Sangfor Riskware.Python.Impacket.Velz
Symantec Trojan.Gen.MBT
ESET-NOD32 Python/Riskware.WMIExec.B
APEX Malicious
McAfee Artemis!E3E29CE5E9AF
Avast Python:Agent-RT [Trj]
Kaspersky HEUR:HackTool.Python.Impacket.gen
Alibaba HackTool:Application/Impacket.2981a292
McAfeeD ti!68CA7BCFB1CE
Sophos Mal/Generic-S
Google Detected
Kingsoft Win32.Troj.Unknown.a
ZoneAlarm HEUR:HackTool.Python.Impacket.gen
Varist W64/ABApplication.WYJN-1131
DeepInstinct MALICIOUS
Panda Trj/CI.A
Tencent Win32.Hacktool.Impacket.Ugil
MaxSecure Trojan.Malware.184314475.susgen
Fortinet Riskware/WMIEXEC
AVG Python:Agent-RT [Trj]
Paloalto generic.ml
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Exploit:Win/MS17-010.E