Summary | ZeroBOX

svhost.exe

UPX PE64 PE File
Category Machine Started Completed
FILE s1_win7_x6401 Sept. 30, 2024, 11:25 a.m. Sept. 30, 2024, 11:29 a.m.
Size 829.0KB
Type PE32+ executable (console) x86-64, for MS Windows
MD5 b58c2506b40b7c00bb2e7a6651bfc9a9
SHA256 d955ee0453b19363773ff5bae57335f2a7e4c2c5af0c3c0227a570b349137630
CRC32 B2352D71
ssdeep 12288:08VSH0eAHnKp8i+3Rlh5AyRq3p/QpSJFbfyNulbAi/9w9ropx:vV9S+BlIgq5TDqi/9+rG
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE64 - (no description)
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section .symtab
Bkav W64.AIDetectMalware
Skyhigh BehavesLike.Win64.TrojanWinCosmu.ch
CrowdStrike win/malicious_confidence_60% (W)
Trapmine malicious.high.ml.score
Webroot W32.Malware.Gen
Google Detected
Antiy-AVL GrayWare/Win32.Wacapew
McAfee Artemis!B58C2506B40B
Ikarus Trojan.WinGo.Rozena