Summary | ZeroBOX

whoami-unencrypted.exe

Malicious Library PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6403_us Sept. 30, 2024, 11:54 a.m. Sept. 30, 2024, noon
Size 41.5KB
Type PE32 executable (console) Intel 80386, for MS Windows
MD5 29130d815c8858e5b133a2157ae90b91
SHA256 33021e02da3993c8d5f3cbddd73f10f5aac3dc29f8ca1a7d756ea2feadfe7483
CRC32 6E6CAE5C
ssdeep 768:7loK+uJzmK9+jvRpBq1RnvCKlA9idnvCKG:7eKrdmc+HB1KlAHKG
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section .fzcz
Time & API Arguments Status Return Repeated

__exception__

stacktrace:

        
      
      
      
exception.instruction_r: 00 00 41 56 49 89 e6 48 81 ec a0 01 00 00 49 89
exception.symbol: whoami-unencrypted+0xd203
exception.instruction: add byte ptr [eax], al
exception.module: whoami-unencrypted.exe
exception.exception_code: 0xc0000005
exception.offset: 53763
exception.address: 0x100d203
registers.esp: 1638272
registers.edi: 16831266
registers.eax: 1970918672
registers.ebp: 16830766
registers.edx: 16830464
registers.ebx: 16830754
registers.esi: 208229532
registers.ecx: 16830755
1 0 0
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Meterpreter.4!c
Cynet Malicious (score: 99)
Skyhigh BehavesLike.Win32.Infected.pm
Cylance Unsafe
Sangfor Trojan.Win32.Meterpreter.Veat
CrowdStrike win/malicious_confidence_100% (W)
K7GW Riskware ( 0040eff71 )
K7AntiVirus Riskware ( 0040eff71 )
Symantec Meterpreter
Elastic malicious (high confidence)
APEX Malicious
Avast Win32:MsfEncode-D [Hack]
ClamAV Win.Packed.Metasploit-9805971-0
Kaspersky HEUR:Trojan.Win32.Generic
Alibaba Trojan:Win64/Meterpreter.0f7cad13
Rising Trojan.Generic!8.C3 (CLOUD)
F-Secure Trojan.TR/Crypt.XPACK.Gen
TrendMicro TROJ_GEN.R002C0DIR24
McAfeeD ti!33021E02DA39
Trapmine suspicious.low.ml.score
CTX exe.trojan.meterpreter
Sophos ATK/Swrort-J
FireEye Generic.mg.29130d815c8858e5
Google Detected
Avira TR/Crypt.XPACK.Gen
Antiy-AVL Virus/Win32.Expiro.rsrc
Kingsoft Win32.HeurC.KVMH008.a
Microsoft Trojan:Win64/Meterpreter.B
ZoneAlarm HEUR:Trojan.Win32.Generic
GData Win32.Trojan.Agent.4GKWGU
Varist W32/Rozena.GK.gen!Eldorado
AhnLab-V3 Malware/Win32.RL_Generic.R291649
McAfee GenericRXAA-AA!29130D815C88
DeepInstinct MALICIOUS
VBA32 TScope.Malware-Cryptor.SB
Malwarebytes Generic.Malware/Suspicious
Zoner Probably Heur.ExeHeaderL
TrendMicro-HouseCall TROJ_GEN.R002C0DIR24
Tencent Malware.Win32.Gencirc.13afd544
huorong Trojan/Rozena.j
Fortinet W32/PossibleThreat
AVG Win32:MsfEncode-D [Hack]
Paloalto generic.ml
alibabacloud Exploit:Win/Agent.AM