Summary | ZeroBOX

66fad551bd8fd_edgeupdater.exe

UPX ftp PE64 PE File
Category Machine Started Completed
FILE s1_win7_x6403_us Oct. 1, 2024, 4:38 p.m. Oct. 1, 2024, 4:47 p.m.
Size 8.2MB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 205eba033c31a42d83971958eee8d0eb
SHA256 ff9bc3cfec4322f8bdb6ca3c81a9e0d602e4a660a9d85aa76c76b18330515d4d
CRC32 5E6076EB
ssdeep 196608:n6DCGvmFBgqmQ5ku1eYtdCKYluttk08TaSOSff3D:n6Z0rmQ5kNY3C/uttkFTaSZX
Yara
  • PE_Header_Zero - PE File Signature
  • ftp_command - ftp command
  • IsPE64 - (no description)
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section {u'size_of_data': u'0x0083b400', u'virtual_address': u'0x00e69000', u'entropy': 7.906537326983134, u'name': u'UPX1', u'virtual_size': u'0x0083c000'} entropy 7.90653732698 description A section with a high entropy has been found
entropy 0.999940684501 description Overall entropy of this PE file is high
section UPX0 description Section name indicates UPX
section UPX1 description Section name indicates UPX
section UPX2 description Section name indicates UPX
Bkav W64.AIDetectMalware
Lionic Trojan.Win32.Generic.4!c
Skyhigh BehavesLike.Win64.LokiBot.rc
McAfee Artemis!205EBA033C31
Cylance Unsafe
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_70% (D)
Symantec ML.Attribute.HighConfidence
Elastic malicious (moderate confidence)
APEX Malicious
Avast FileRepMalware
McAfeeD Real Protect-LS!205EBA033C31
CTX exe.trojan.generic
Antiy-AVL GrayWare/Win32.Kryptik.ffp
Kingsoft Win32.Trojan.Agent.a
Microsoft Program:Win32/Wacapew.C!ml
AhnLab-V3 Malware/Win.Generic.C5677008
DeepInstinct MALICIOUS
Malwarebytes Malware.AI.4208055932
Panda Trj/Chgt.AD
MaxSecure Trojan.Malware.300983.susgen
AVG FileRepMalware