Summary | ZeroBOX

file.exe

Generic Malware Malicious Library UPX Malicious Packer PE File OS Processor Check PE32
Category Machine Started Completed
FILE s1_win7_x6403_us Aug. 10, 2024, 12:26 p.m. Aug. 10, 2024, 12:28 p.m.
Size 13.1MB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 364045dcd335ffd17f48a8cf5f816a01
SHA256 dc5b6ebcf502935ed2c0b4258eb13ff403efc8b97fe562e96a3dc1c7451db76b
CRC32 9830A54F
ssdeep 196608:t1cCA+KNn9QK7FQZDJLla35CKFdu9CwJsv6t0KAnag:t1cDPQca1JA3YKFdu9CwJsv6ti1
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • Generic_Malware_Zero - Generic Malware
  • OS_Processor_Check_Zero - OS Processor Check

IP Address Status Action
164.124.101.2 Active Moloch
195.154.81.43 Active Moloch
23.41.113.9 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

Flow Issuer Subject Fingerprint
TLS 1.3
192.168.56.103:49166
195.154.81.43:443
None None None
TLS 1.3
192.168.56.103:49167
195.154.81.43:443
None None None
TLS 1.3
192.168.56.103:49163
195.154.81.43:443
None None None

Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section .qtmetad
section .qtmimed
request GET http://x1.i.lencr.org/
Time & API Arguments Status Return Repeated

GetAdaptersAddresses

flags: 15
family: 0
111 0
section {u'size_of_data': u'0x00051800', u'virtual_address': u'0x00c6c000', u'entropy': 7.99756120407481, u'name': u'.qtmimed', u'virtual_size': u'0x000517ca'} entropy 7.99756120407 description A section with a high entropy has been found
registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\F81F111D0E5AB58D396F7BF525577FD30FDC95AA\Blob
Lionic Adware.Win32.OpenSUpdater.2!c
ALYac Application.OpenSUpdater.AJ
VIPRE Application.OpenSUpdater.AJ
BitDefender Application.OpenSUpdater.AJ
Cybereason malicious.cd335f
Arcabit Application.OpenSUpdater.AJ
Symantec ML.Attribute.HighConfidence
McAfee Artemis!364045DCD335
Avast Win32:AdwareX-gen [Adw]
Kaspersky UDS:DangerousObject.Multi.Generic
MicroWorld-eScan Application.OpenSUpdater.AJ
Rising Adware.OpenSUpdater!8.C9C (CLOUD)
Emsisoft Application.OpenSUpdater.AJ (B)
McAfeeD ti!DC5B6EBCF502
FireEye Application.OpenSUpdater.AJ
Sophos Generic Reputation PUA (PUA)
Antiy-AVL GrayWare[AdWare]/Win32.OpenSUpdater
GData Application.OpenSUpdater.AJ
DeepInstinct MALICIOUS
Malwarebytes Adware.SpecialSearchOffer
Ikarus PUA.OpenSUpdater
Fortinet Riskware/Application
AVG Win32:AdwareX-gen [Adw]