Summary | ZeroBOX

client.exe

.NET framework(MSIL) Malicious Library UPX PE File OS Processor Check PE32 .NET EXE
Category Machine Started Completed
FILE s1_win7_x6401 Oct. 17, 2024, 2:39 p.m. Oct. 17, 2024, 2:39 p.m.
Size 3.1MB
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 29de30606fa3cd9024d87066016d0351
SHA256 56a35f9bcb582449d44a4bed4fa36dcb140f04961f0f1fec1d96385569f72cac
CRC32 17E73302
ssdeep 49152:KvyI22SsaNYfdPBldt698dBcjHwCV1JupoGdaELTHHB72eh2NT:Kvf22SsaNYfdPBldt6+dBcjHwC8
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Is_DotNET_EXE - (no description)
  • Win32_Trojan_PWS_Net_1_Zero - Win32 Trojan PWS .NET Azorult
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Bkav W32.AIDetectMalware.CS
Elastic Windows.Generic.Threat
CAT-QuickHeal Trojan.Generic.TRFH927
Skyhigh BehavesLike.Win32.Generic.wh
ALYac Generic.MSIL.PasswordStealerA.4CA5C56B
Cylance Unsafe
VIPRE Generic.MSIL.PasswordStealerA.4CA5C56B
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005b1c021 )
BitDefender Generic.MSIL.PasswordStealerA.4CA5C56B
K7GW Trojan ( 005690671 )
Cybereason malicious.06fa3c
Arcabit Generic.MSIL.PasswordStealerA.4CA5C56B
VirIT Trojan.Win32.MSIL.MJ
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Agent.CLQ
APEX Malicious
McAfee GenericRXMC-UD!29DE30606FA3
Avast MSIL:Quasar-A [Rat]
ClamAV Win.Malware.Generic-9883083-0
Kaspersky HEUR:Trojan.MSIL.Quasar.gen
MicroWorld-eScan Generic.MSIL.PasswordStealerA.4CA5C56B
Rising Backdoor.Quasar!1.E5F1 (CLASSIC)
Emsisoft Trojan.Agent (A)
F-Secure Heuristic.HEUR/AGEN.1365341
DrWeb BackDoor.QuasarNET.3
Zillya Trojan.Agent.Win32.3282583
McAfeeD ti!56A35F9BCB58
FireEye Generic.mg.29de30606fa3cd90
Sophos Troj/Quasar-AF
Ikarus Trojan-Spy.Agent
Jiangmin Trojan.MSIL.aogzw
Webroot W32.Trojan.Quasar
Google Detected
Avira HEUR/AGEN.1365341
MAX malware (ai score=84)
Antiy-AVL Trojan/MSIL.Quasar
Kingsoft malware.kb.c.963
Gridinsoft Spy.Win32.Keylogger.dd!n
Microsoft Backdoor:MSIL/Quasar!atmn
ZoneAlarm HEUR:Trojan.MSIL.Quasar.gen
GData MSIL.Backdoor.Quasar.A
Varist W32/MSIL_Troj.BTX.gen!Eldorado
AhnLab-V3 Backdoor/Win32.QuasarRAT.R341693
BitDefenderTheta Gen:NN.ZemsilF.36808.hp0@aGyvMr
DeepInstinct MALICIOUS
VBA32 Trojan.MSIL.Quasar.Heur
Malwarebytes Generic.Malware.AI.DDS
Tencent Trojan.MSIL.Quasar.ka
SentinelOne Static AI - Malicious PE