Summary | ZeroBOX

Dtrade_v1.3.6.exe

Malicious Library UPX Malicious Packer PE64 PE File OS Processor Check
Category Machine Started Completed
FILE s1_win7_x6401 Aug. 21, 2024, 1:28 p.m. Aug. 21, 2024, 1:53 p.m.
Size 16.4MB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 1f6c6f36d126cd027ded1915e321c693
SHA256 cc3557f4fdaad9aa47bf46dce4f0a8e0a45d7e81084962a54b67b4f55f8bf64c
CRC32 A387860E
ssdeep 98304:8WJWZ3fhw2RuB0yZ8KhBc18zCEy5h3RUcNikFElaeDiyilOIN+gkypKuZ8U:ZWfhwH0L18zPy1Nik+RmJkhypn
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer
  • IsPE64 - (no description)
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section .symtab
Bkav W64.AIDetectMalware
Google Detected
Microsoft Program:Win32/Wacapew.C!ml
Ikarus Trojan.WinGo.Merlin
Fortinet PossibleThreat.PALLAS.H
CrowdStrike win/malicious_confidence_70% (D)
section {u'size_of_data': u'0x0009a600', u'virtual_address': u'0x00d8d000', u'entropy': 7.996475840887054, u'name': u'/19', u'virtual_size': u'0x0009a59e'} entropy 7.99647584089 description A section with a high entropy has been found
section {u'size_of_data': u'0x0001f200', u'virtual_address': u'0x00e28000', u'entropy': 7.939610498307072, u'name': u'/32', u'virtual_size': u'0x0001f1fd'} entropy 7.93961049831 description A section with a high entropy has been found
section {u'size_of_data': u'0x00119400', u'virtual_address': u'0x00e49000', u'entropy': 7.998070062333371, u'name': u'/65', u'virtual_size': u'0x0011923e'} entropy 7.99807006233 description A section with a high entropy has been found
section {u'size_of_data': u'0x000bd000', u'virtual_address': u'0x00f63000', u'entropy': 7.995872520834671, u'name': u'/78', u'virtual_size': u'0x000bce75'} entropy 7.99587252083 description A section with a high entropy has been found
section {u'size_of_data': u'0x00037a00', u'virtual_address': u'0x01020000', u'entropy': 7.827606429153707, u'name': u'/90', u'virtual_size': u'0x0003791a'} entropy 7.82760642915 description A section with a high entropy has been found