Summary | ZeroBOX

ActiveMQ-RCE.exe

Malicious Packer UPX Malicious Library PE64 PE File
Category Machine Started Completed
FILE s1_win7_x6403_us Aug. 11, 2024, 2:25 p.m. Aug. 11, 2024, 3:23 p.m.
Size 5.3MB
Type PE32+ executable (console) x86-64, for MS Windows
MD5 4ba8f3acf74baeaf5db40372f0c70e9d
SHA256 7ddbd321db79dc901f4da4a2307b89f182a37c7c93f5e9d7da50a695673fa5ea
CRC32 BFE304DD
ssdeep 98304:LXTREiuLEdWfUWQxSHI8VZIByEjpzTSmQH:LjGiuYdN2ZFEF0
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer
  • IsPE64 - (no description)
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section .symtab
Bkav W64.AIDetectMalware
Google Detected
Microsoft Program:Win32/Wacapew.C!ml
DeepInstinct MALICIOUS
Ikarus Trojan.WinGo.Rozena
section {u'size_of_data': u'0x0004f600', u'virtual_address': u'0x0042f000', u'entropy': 7.995058486893925, u'name': u'/19', u'virtual_size': u'0x0004f5f9'} entropy 7.99505848689 description A section with a high entropy has been found
section {u'size_of_data': u'0x00010200', u'virtual_address': u'0x0047f000', u'entropy': 7.937296838607071, u'name': u'/32', u'virtual_size': u'0x000101fc'} entropy 7.93729683861 description A section with a high entropy has been found
section {u'size_of_data': u'0x0008c800', u'virtual_address': u'0x00491000', u'entropy': 7.997713961139183, u'name': u'/65', u'virtual_size': u'0x0008c63e'} entropy 7.99771396114 description A section with a high entropy has been found
section {u'size_of_data': u'0x00065a00', u'virtual_address': u'0x0051e000', u'entropy': 7.9950670973644, u'name': u'/78', u'virtual_size': u'0x00065966'} entropy 7.99506709736 description A section with a high entropy has been found
section {u'size_of_data': u'0x0001de00', u'virtual_address': u'0x00584000', u'entropy': 7.813016057412364, u'name': u'/90', u'virtual_size': u'0x0001ddb8'} entropy 7.81301605741 description A section with a high entropy has been found
entropy 0.269873324766 description Overall entropy of this PE file is high