Summary | ZeroBOX

66c2d861a5b4d_google.exe

PE64 PE File
Category Machine Started Completed
FILE s1_win7_x6403_us Aug. 20, 2024, 9:36 a.m. Aug. 20, 2024, 9:45 a.m.
Size 10.6MB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 8447dbe44aa2ede5d56341e0dc22f319
SHA256 11128e278985be292ec748d40794ed3b94392e540be7f0b3c9a718a4fb4fc177
CRC32 E38DB25D
ssdeep 196608:hdclOOMPjOF5YEbRubP8kf+43/lOBv63JYEYjen8rP9Ocx1ZNONC:POWjO89bER6lOBC3LYjen8rlh1vOI
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE64 - (no description)

Name Response Post-Analysis Lookup
pool.hashvault.pro 131.153.76.130
IP Address Status Action
131.153.76.130 Active Moloch
164.124.101.2 Active Moloch

Suricata Alerts

Flow SID Signature Category
UDP 192.168.56.103:50800 -> 164.124.101.2:53 2036289 ET COINMINER CoinMiner Domain in DNS Lookup (pool .hashvault .pro) Crypto Currency Mining Activity Detected

Suricata TLS

Flow Issuer Subject Fingerprint
TLS 1.3
192.168.56.103:49163
131.153.76.130:443
None None None

section .00cfg
section .text0
section .text1
section .text2
section {u'size_of_data': u'0x00a61400', u'virtual_address': u'0x00f4d000', u'entropy': 7.976274827641615, u'name': u'.text2', u'virtual_size': u'0x00a612a0'} entropy 7.97627482764 description A section with a high entropy has been found
entropy 0.9820752102 description Overall entropy of this PE file is high
Bkav W64.AIDetectMalware
Elastic malicious (high confidence)
Skyhigh BehavesLike.Win64.RisePro.vc
Cylance Unsafe
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win64/Packed.VMProtect.AC suspicious
APEX Malicious
Avast FileRepMalware [Trj]
Kaspersky UDS:Trojan.Win32.Miner.bfhiu
Rising Trojan.Agent!8.B1E (TFE:5:FkFUO8h2JGR)
McAfeeD Real Protect-LS!8447DBE44AA2
Trapmine malicious.moderate.ml.score
Webroot W32.Backdoor.Gen
Antiy-AVL Trojan[Packed]/Win64.VMProtect
Kingsoft Win32.Trojan.Miner.bfhiu
Microsoft Trojan:Win32/Sabsik.FL.A!ml
ZoneAlarm UDS:Trojan.Win32.Miner.bfhiu
Malwarebytes Trojan.CoinMiner
AVG FileRepMalware [Trj]
CrowdStrike win/malicious_confidence_100% (W)