Summary | ZeroBOX

ypqhgl.exe

UPX PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6401 Sept. 22, 2024, 5:19 p.m. Sept. 22, 2024, 5:26 p.m.
Size 326.0KB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 990ddf57779c6d17b6885dab3f5c3494
SHA256 c260ed4b2144fa321b1353511d8ed78cb30e5e4856cce42c766fa0fad7e9bc1f
CRC32 EFAAA024
ssdeep 6144:RP5irYuB5ZuZAGW6fIdnum2vKU7fKrILt4FtDyNe6FVX17fET8ijBBvSzHBi20iA:RRnuB5ZuVCPDy4MA9ErEGXG/zrKwUrO
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
45.33.6.223 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

host 45.33.6.223
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.LummaStealer.4!c
Cynet Malicious (score: 100)
Skyhigh BehavesLike.Win32.Generic.fh
Cylance Unsafe
VIPRE Gen:Heur.Mint.Zard.25
Sangfor Spyware.Win32.Lummastealer.V4ew
BitDefender Gen:Heur.Mint.Zard.25
K7GW Spyware ( 005b29001 )
K7AntiVirus Spyware ( 005b29001 )
Arcabit Trojan.Mint.Zard.25
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Spy.LummaStealer.G
APEX Malicious
Avast Win32:Evo-gen [Trj]
ClamAV Win.Packed.Zard-10035522-0
Alibaba TrojanPSW:Win32/Lumma.4b4ec2e5
NANO-Antivirus Virus.Win32.Gen.ccmw
MicroWorld-eScan Gen:Heur.Mint.Zard.25
Rising Spyware.LummaStealer!8.1A464 (TFE:5:xBA9tH1EnUP)
Emsisoft Gen:Heur.Mint.Zard.25 (B)
F-Secure Trojan.TR/Redcap.zcrqc
TrendMicro TrojanSpy.Win32.LUMMASTEALER.YXEIUZ
McAfeeD Real Protect-LS!990DDF57779C
Trapmine malicious.high.ml.score
CTX exe.trojan.lummastealer
Sophos Mal/Generic-S
FireEye Generic.mg.990ddf57779c6d17
Webroot W32.Trojan.Gen
Google Detected
Avira TR/Redcap.zcrqc
Antiy-AVL Trojan/Win32.Phonzy
Kingsoft malware.kb.a.994
Gridinsoft Ransom.Win32.Sabsik.sa
Microsoft Trojan:Win32/Wacatac.B!ml
GData Gen:Heur.Mint.Zard.25
AhnLab-V3 Trojan/Win.Generic.C5669971
McAfee Artemis!990DDF57779C
DeepInstinct MALICIOUS
VBA32 BScope.TrojanPSW.Lumma
Malwarebytes Malware.AI.4169542726
Ikarus Trojan-Spy.Win32.LummaStealer
Panda Trj/Genetic.gen
TrendMicro-HouseCall TrojanSpy.Win32.LUMMASTEALER.YXEIUZ
Tencent Win32.Trojan-QQPass.QQRob.Wylw
huorong TrojanSpy/LummaStealer.g
MaxSecure Trojan.Malware.281541855.susgen
AVG Win32:Evo-gen [Trj]
Paloalto generic.ml