Summary | ZeroBOX

66f2966e903c0_AntiLogger.exe

Generic Malware Malicious Library UPX Malicious Packer PE64 PE File dll OS Processor Check DllRegisterServer
Category Machine Started Completed
FILE s1_win7_x6401 Sept. 25, 2024, 10:33 a.m. Sept. 25, 2024, 11:17 a.m.
Size 5.1MB
Type PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
MD5 93848befe2685e3de677ef88df8081d7
SHA256 3b563d19a0a77bf36e498433380333d1d686494e51e3d9acf150e0260c212053
CRC32 70BDDB3D
ssdeep 49152:EeIkDMh/s7Ywp1lMkobIJPaKDNCjFEi2xpoj+5ETbiUjwq0Mm9roTmAc62lYb:3us00Ck9DNCeETmnq0MmqTmd6L
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer
  • IsPE64 - (no description)
  • DllRegisterServer_Zero - execute regsvr32.exe
  • Generic_Malware_Zero - Generic Malware
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Bkav W64.AIDetectMalware
Cynet Malicious (score: 99)
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of WinGo/TrojanDropper.Agent.DS
Rising Trojan.Agent!1.F9CC (CLASSIC)
F-Secure Heuristic.HEUR/AGEN.1376933
Google Detected
Avira HEUR/AGEN.1376933
Microsoft Trojan:Win32/Sabsik.FL.A!ml
Varist W64/Agent.IKW.gen!Eldorado
Ikarus Trojan.WinGo.Agent
huorong Trojan/Injector.btl