Summary | ZeroBOX

66df4cfda9a79_software.exe

Malicious Library UPX Malicious Packer Anti_VM PE64 PE File OS Processor Check
Category Machine Started Completed
FILE s1_win7_x6403_us Sept. 10, 2024, 10:05 a.m. Sept. 10, 2024, 10:11 a.m.
Size 18.0MB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 2e4c46fcdaaaa624bd6f37075077b972
SHA256 d1dd535854368f8445b62566c7e3c8c9299df68c5e5d7813d71f90d1a6cec5ee
CRC32 52CD3541
ssdeep 196608:1ceo44mHl2/VpCKlDRoMKJkcKJJFZAhx+dpT:do44mF2/bCKlDR9KJkDnFZs
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer
  • IsPE64 - (no description)
  • anti_vm_detect - Possibly employs anti-virtualization techniques
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section .symtab
Bkav W64.AIDetectMalware
Avast FileRepMalware [Misc]
Kaspersky UDS:DangerousObject.Multi.Generic
McAfeeD ti!D1DD53585436
Ikarus PUA.Generic
Microsoft Trojan:Win32/Wacatac.B!ml
AVG FileRepMalware [Misc]
alibabacloud Proxytool:Multi/GOST.func
section {u'size_of_data': u'0x000eb200', u'virtual_address': u'0x00d39000', u'entropy': 7.997120916697474, u'name': u'/19', u'virtual_size': u'0x000eb008'} entropy 7.9971209167 description A section with a high entropy has been found
section {u'size_of_data': u'0x00035a00', u'virtual_address': u'0x00e25000', u'entropy': 7.940392232465788, u'name': u'/32', u'virtual_size': u'0x00035869'} entropy 7.94039223247 description A section with a high entropy has been found
section {u'size_of_data': u'0x001a8c00', u'virtual_address': u'0x00e5c000', u'entropy': 7.998466520789676, u'name': u'/65', u'virtual_size': u'0x001a8a93'} entropy 7.99846652079 description A section with a high entropy has been found
section {u'size_of_data': u'0x00137400', u'virtual_address': u'0x01005000', u'entropy': 7.99569210725364, u'name': u'/78', u'virtual_size': u'0x001372df'} entropy 7.99569210725 description A section with a high entropy has been found
section {u'size_of_data': u'0x00055400', u'virtual_address': u'0x0113d000', u'entropy': 7.819464157536218, u'name': u'/90', u'virtual_size': u'0x000552a7'} entropy 7.81946415754 description A section with a high entropy has been found
entropy 0.241094700261 description Overall entropy of this PE file is high