Summary | ZeroBOX

Updater.exe

Antivirus UPX PE File OS Processor Check PE32 .NET EXE
Category Machine Started Completed
FILE s1_win7_x6401 Oct. 17, 2024, 2:42 p.m. Oct. 17, 2024, 2:42 p.m.
Size 85.0KB
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 2d2087b08aeb06edfb294db590374dce
SHA256 2b48ff1f162dbf58ba2a9fc4a60c0ef2f98666bf49672455da7065420bac7128
CRC32 C4BCE3F6
ssdeep 1536:Nhcbp2YNr5tt+KCNjWeLfzbeMkMpW5ZsM0+6I+CWOgmlNvwWDZ/qGA:NhclJqfzbey3MF+CWOPlxwWwGA
Yara
  • PE_Header_Zero - PE File Signature
  • Antivirus - Contains references to security software
  • Is_DotNET_EXE - (no description)
  • IsPE32 - (no description)
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Bkav W32.AIDetectMalware.CS
Elastic malicious (high confidence)
CAT-QuickHeal Worm.GenericFC.S32598663
Skyhigh BehavesLike.Win32.Trojan.mm
ALYac Gen:Variant.Jalapeno.640
Cylance Unsafe
VIPRE Gen:Variant.Jalapeno.640
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Trojan ( 005aa5f01 )
BitDefender Gen:Variant.Jalapeno.640
K7GW Trojan ( 005aa5f01 )
Cybereason malicious.08aeb0
Arcabit Trojan.Jalapeno.640
VirIT Trojan.Win32.MSIL_Heur.B
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Agent.DWN
APEX Malicious
McAfee Trojan-FVYT!2D2087B08AEB
Avast Win32:RATX-gen [Trj]
Kaspersky HEUR:Backdoor.MSIL.XWorm.gen
MicroWorld-eScan Gen:Variant.Jalapeno.640
Rising Trojan.AntiVM!1.CF63 (CLASSIC)
Emsisoft Gen:Variant.Jalapeno.640 (B)
F-Secure Trojan.TR/Spy.Gen
DrWeb BackDoor.BladabindiNET.30
McAfeeD Real Protect-LS!2D2087B08AEB
Trapmine malicious.high.ml.score
FireEye Generic.mg.2d2087b08aeb06ed
Sophos Troj/RAT-FJ
SentinelOne Static AI - Malicious PE
Google Detected
Avira TR/Spy.Gen
MAX malware (ai score=81)
Kingsoft malware.kb.c.1000
Microsoft Trojan:MSIL/AsyncRAT.R!MTB
ZoneAlarm HEUR:Backdoor.MSIL.XWorm.gen
GData MSIL.Trojan.PSE.1UMFOWG
Varist W32/MSIL_Agent.BUD.gen!Eldorado
AhnLab-V3 Backdoor/Win.AsyncRat.C5360693
DeepInstinct MALICIOUS
VBA32 Backdoor.MSIL.XWorm.gen
Malwarebytes Backdoor.XWorm.MSIL.Generic
Ikarus Win32.Outbreak
Tencent Worm.Msil.Xworm.16001238
huorong Backdoor/MSIL.DDos.b
Fortinet MSIL/Bladabindi.SSNY!tr
AVG Win32:RATX-gen [Trj]
Paloalto generic.ml
CrowdStrike win/malicious_confidence_100% (W)