Summary | ZeroBOX

main.exe

Gen1 Generic Malware Malicious Library ASPack UPX Malicious Packer Anti_VM ftp MSOffice File PE64 ELF PE File OS Processor Check PE32 ZIP Format DLL
Category Machine Started Completed
FILE s1_win7_x6401 Oct. 21, 2024, 1:39 p.m. Oct. 21, 2024, 1:46 p.m.
Size 11.9MB
Type PE32+ executable (console) x86-64, for MS Windows
MD5 2e25791fd09060fec2d4650c9872056b
SHA256 5e710e7f5f14a4e4fbc0b8a2d2845742f3272b38437d7789e53327ec34e7bd25
CRC32 EA0E382E
ssdeep 196608:sosFymvdsBcs4njQthsiHzy7kZCCQHZcuZeaTB3ukzVm8AbrHoOXLPmxrMiFenEd:EnvaBcNnKhs57R59sw3n48A4oLKMiFeg
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • ASPack_Zero - ASPack packed file
  • IsPE64 - (no description)
  • Generic_Malware_Zero - Generic Malware
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section _RDATA
file C:\Users\test22\AppData\Local\Temp\_MEI26522\libssl-1_1.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\python310.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\selenium\webdriver\remote\getAttribute.js
file C:\Users\test22\AppData\Local\Temp\_MEI26522\VCRUNTIME140.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\selenium\webdriver\remote\findElements.js
file C:\Users\test22\AppData\Local\Temp\_MEI26522\selenium\webdriver\common\mutation-listener.js
file C:\Users\test22\AppData\Local\Temp\_MEI26522\libcrypto-1_1.dll
file C:\Users\test22\AppData\Local\Temp\_MEI26522\selenium\webdriver\remote\isDisplayed.js
file C:\Users\test22\AppData\Local\Temp\_MEI26522\selenium\webdriver\common\windows\selenium-manager.exe
file C:\Users\test22\AppData\Local\Temp\_MEI26522\selenium\webdriver\common\windows\selenium-manager.exe
Bkav W64.AIDetectMalware
Skyhigh BehavesLike.Win64.Dropper.wc
APEX Malicious
section {u'size_of_data': u'0x0000f200', u'virtual_address': u'0x00052000', u'entropy': 7.356245303547822, u'name': u'.rsrc', u'virtual_size': u'0x0000f008'} entropy 7.35624530355 description A section with a high entropy has been found