Summary | ZeroBOX

az.exe

Malicious Library UPX Malicious Packer PE File OS Processor Check PE32
Category Machine Started Completed
FILE s1_win7_x6401 Aug. 7, 2024, 9:57 a.m. Aug. 7, 2024, 10:08 a.m.
Size 422.5KB
Type PE32 executable (console) Intel 80386, for MS Windows
MD5 b9fcbae32e294854e2507179d4acef1c
SHA256 5ee6cfb7dd10f7fecf03d515c60c8e319920ec1b99e9835f4fbcba8caa4b924c
CRC32 D36385D8
ssdeep 6144:EQEPWO/7+Ugo33uIH7/hjOlqkDVmaxR3psGoyj0mBZ0gTzzh6lOUepHiPVn5lXwM:EHv3LVOAkDVmaxR5sGb0KZ0e4
PDB Path I:\我的项目\GGENET\Release\ggeserver.pdb
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

pdb_path I:\我的项目\GGENET\Release\ggeserver.pdb
resource name GGE
name RT_VERSION language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x000696e4 size 0x000002c8
section {u'size_of_data': u'0x0005bc00', u'virtual_address': u'0x0000e000', u'entropy': 7.5349019023842665, u'name': u'.rsrc', u'virtual_size': u'0x0005bb08'} entropy 7.53490190238 description A section with a high entropy has been found
entropy 0.870699881376 description Overall entropy of this PE file is high
Bkav W32.AIDetectMalware
Elastic malicious (moderate confidence)
Skyhigh GenericRXNY-CE!B9FCBAE32E29
Sangfor Trojan.Win32.Agent.Vi6m
APEX Malicious
McAfee GenericRXNY-CE!B9FCBAE32E29
Avast Win32:TrojanX-gen [Trj]
McAfeeD ti!5EE6CFB7DD10
FireEye Generic.mg.b9fcbae32e294854
Ikarus Trojan.Win32.Agent
Google Detected
Antiy-AVL Trojan/Win32.Generic
Gridinsoft Malware.Win32.Uwamson.oa!s1
DeepInstinct MALICIOUS
VBA32 Trojan.Zpevdo
Malwarebytes Wapomi.Virus.FileInfector.DDS
AVG Win32:TrojanX-gen [Trj]