Summary | ZeroBOX

mobiletrans.exe

Generic Malware Malicious Library UPX Malicious Packer Anti_VM PE64 PE File dll OS Processor Check DllRegisterServer
Category Machine Started Completed
FILE s1_win7_x6403_us Aug. 17, 2024, 10:10 p.m. Aug. 17, 2024, 10:32 p.m.
Size 20.3MB
Type PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
MD5 c8af5b81b11f3db6cb5b7efab33d11ef
SHA256 2a627e55b12be1b4521658c25d2d46d38b87442f648070311cad06e4995a5304
CRC32 91FAE990
ssdeep 98304:xW+Gcm43XnW2C4/YzHVx4Bu+UxPi+YrmJihOeFXEQp3Bf0n+KXhX38XCaxpmMqmH:oiXy4/YzHVOuBi+YaJZQ3I+KRX38M
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer
  • IsPE64 - (no description)
  • DllRegisterServer_Zero - execute regsvr32.exe
  • anti_vm_detect - Possibly employs anti-virtualization techniques
  • Generic_Malware_Zero - Generic Malware
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

Flow SID Signature Category
TCP 45.89.247.19:34587 -> 192.168.56.103:49162 2400003 ET DROP Spamhaus DROP Listed Traffic Inbound group 4 Misc Attack

Suricata TLS

No Suricata TLS

Bkav W64.AIDetectMalware
Elastic malicious (high confidence)
Cynet Malicious (score: 99)
Sangfor Trojan.Win32.Agent.Vmfw
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of WinGo/Agent.XQ
Avast Win64:Malware-gen
Kaspersky Trojan.MSIL.Agent.qwiuxl
F-Secure Dropper.DR/AVI.Wingo.opply
TrendMicro Trojan.Win64.AMADEY.YXEHOZ
Google Detected
Avira DR/AVI.Wingo.opply
Antiy-AVL Trojan/Win32.Wacatac
Kingsoft MSIL.Trojan.Agent.qwiuxl
Gridinsoft Ransom.Win64.Wacatac.cl
Microsoft Trojan:Win32/Caynamer.A!ml
ZoneAlarm Trojan.MSIL.Agent.qwiuxl
GData Win64.Trojan.Agent.MAN206
Varist W64/Agent.IKW.gen!Eldorado
DeepInstinct MALICIOUS
Ikarus Trojan.WinGo.Agent
TrendMicro-HouseCall Trojan.Win64.AMADEY.YXEHOZ
Tencent Msil.Trojan.Agent.Rwhl
Fortinet W64/Agent.VY!tr
AVG Win64:Malware-gen
alibabacloud Trojan:Multi/Wacatac.B9nj