Summary | ZeroBOX

anquangou.exe

Generic Malware Malicious Library UPX Malicious Packer PE64 PE File OS Processor Check
Category Machine Started Completed
FILE s1_win7_x6403_us Sept. 30, 2024, 9:25 a.m. Sept. 30, 2024, 9:27 a.m.
Size 683.5KB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 cff6ea5599ff3ea5f354be57be8b7a9e
SHA256 c07c5149e870e626647a458db02b62a1c6ce3def73dc079bd71bd2ddc01b3339
CRC32 B8A0B488
ssdeep 6144:Xck5ByBAYD75tiLAMYsrjRIKZhqsUMILZ6rcWH6h+Q8GPs+UTq/Fb2ZWPGDKS1qL:XxoNf0FIMQsUMI/WHQ82kOGx
PDB Path project.pdb
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer
  • IsPE64 - (no description)
  • Generic_Malware_Zero - Generic Malware
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

pdb_path project.pdb
section {u'size_of_data': u'0x00056000', u'virtual_address': u'0x0002f000', u'entropy': 7.446788772615981, u'name': u'.rdata', u'virtual_size': u'0x00055e02'} entropy 7.44678877262 description A section with a high entropy has been found
entropy 0.504029304029 description Overall entropy of this PE file is high
Lionic Trojan.Win32.Generic.4!c
Cynet Malicious (score: 99)
CTX exe.trojan.johnnie
ALYac Gen:Variant.Adware.Johnnie.273941
Cylance Unsafe
VIPRE Gen:Variant.Adware.Johnnie.273941
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_70% (D)
Alibaba Trojan:Win64/MalwareX.c8aa0744
K7GW Trojan ( 005b86721 )
K7AntiVirus Trojan ( 005b86721 )
Arcabit Trojan.Adware.Johnnie.D42E15
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win64/Agent.EFI
APEX Malicious
Paloalto generic.ml
BitDefender Gen:Variant.Adware.Johnnie.273941
MicroWorld-eScan Gen:Variant.Adware.Johnnie.273941
Rising Trojan.ShellCodeRunner/x64!1.102DF (CLASSIC)
Emsisoft Gen:Variant.Adware.Johnnie.273941 (B)
F-Secure Trojan.TR/Agent.wjghd
McAfeeD ti!C07C5149E870
Sophos Mal/Generic-S
SentinelOne Static AI - Suspicious PE
FireEye Gen:Variant.Adware.Johnnie.273941
Webroot W32.Adware.Gen
Google Detected
Avira TR/Agent.wjghd
Antiy-AVL Trojan/Win64.Agent
Kingsoft Win32.Troj.Unknown.a
Microsoft Program:Win32/Wacapew.C!ml
GData Gen:Variant.Adware.Johnnie.273941
AhnLab-V3 Adware/Win.Johnnie.R663399
McAfee Artemis!CFF6EA5599FF
DeepInstinct MALICIOUS
Malwarebytes Malware.AI.922230826
Ikarus Win32.Outbreak
TrendMicro-HouseCall TROJ_GEN.R002H09HV24
Tencent Trojan.Win64.Agent.cgq
MaxSecure Trojan.Malware.300983.susgen
Fortinet Adware/Agent
alibabacloud Backdoor:Multi/RustShellloader