Summary | ZeroBOX

sahost.exe

Suspicious_Script_Bin NSIS Malicious Library UPX PE File DLL PE32
Category Machine Started Completed
FILE s1_win7_x6401 Aug. 13, 2024, 7:42 a.m. Aug. 13, 2024, 7:48 a.m.
Size 492.1KB
Type PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5 3264ed302538a2d29f2e48f26eff85b0
SHA256 92c7e69b6d03a37ec81009ef279a87ef62d8fa6b8d4122a005813facbed979f5
CRC32 A6EE10D2
ssdeep 12288:oYtgJpASCb8O7g2b88suVYx8ftvnt/TDq2IN1SJrx:oYerASsckVtFnTL
Yara
  • Malicious_Library_Zero - Malicious_Library
  • NSIS_Installer - Null Soft Installer
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section .ndata
file C:\Users\test22\AppData\Local\Temp\nsp5699.tmp\LangDLL.dll
file C:\Users\test22\AppData\Local\Temp\nsp5699.tmp\System.dll