Summary | ZeroBOX

mysq1.exe

Malicious Packer UPX Malicious Library PE64 PE File
Category Machine Started Completed
FILE s1_win7_x6403_us Oct. 22, 2024, 9:53 a.m. Oct. 22, 2024, 9:57 a.m.
Size 2.9MB
Type PE32+ executable (console) x86-64, for MS Windows
MD5 fa2efb3b704384a5fe40b382738657c1
SHA256 2457a3241ec13c77b4132d6c5923e63b51a4d05a96dc0ae249c92a43ed9c7c04
CRC32 A2877BE9
ssdeep 49152:xwQXmaTqC3awgEdhUTQvHr4uuGxM/QBzv3MF9:7PFBHcuujQBzv8b
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer
  • IsPE64 - (no description)
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section .symtab
Time & API Arguments Status Return Repeated

__exception__

stacktrace:

        
      
      
      
exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.r14: 6214336
registers.r15: 0
registers.rcx: -1
registers.rsi: 2292481
registers.r10: 0
registers.rbx: -10000
registers.rsp: 2292760
registers.r11: 582
registers.r8: 2292800
registers.r9: 2292528
registers.rdx: 0
registers.r12: 2293320
registers.rbp: 2292816
registers.rdi: 4431968
registers.rax: 0
registers.r13: 0
1 0 0
section {u'size_of_data': u'0x0002dc00', u'virtual_address': u'0x0024e000', u'entropy': 7.994326966224088, u'name': u'/19', u'virtual_size': u'0x0002da86'} entropy 7.99432696622 description A section with a high entropy has been found
section {u'size_of_data': u'0x00009c00', u'virtual_address': u'0x0027c000', u'entropy': 7.922978029130276, u'name': u'/32', u'virtual_size': u'0x00009ac1'} entropy 7.92297802913 description A section with a high entropy has been found
section {u'size_of_data': u'0x00054400', u'virtual_address': u'0x00287000', u'entropy': 7.9963400040838275, u'name': u'/65', u'virtual_size': u'0x000543e1'} entropy 7.99634000408 description A section with a high entropy has been found
section {u'size_of_data': u'0x00031a00', u'virtual_address': u'0x002dc000', u'entropy': 7.992076088574316, u'name': u'/78', u'virtual_size': u'0x000319e4'} entropy 7.99207608857 description A section with a high entropy has been found
section {u'size_of_data': u'0x00010200', u'virtual_address': u'0x0030e000', u'entropy': 7.798389225928946, u'name': u'/90', u'virtual_size': u'0x00010177'} entropy 7.79838922593 description A section with a high entropy has been found
entropy 0.277374725831 description Overall entropy of this PE file is high
Bkav W64.AIDetectMalware
Skyhigh BehavesLike.Win64.Generic.vh
Kaspersky not-a-virus:HEUR:Server-Proxy.Win64.Iox.gen
McAfeeD ti!2457A3241EC1
Jiangmin Backdoor.Lotok.bws
Google Detected
ZoneAlarm not-a-virus:HEUR:Server-Proxy.Win64.Iox.gen
DeepInstinct MALICIOUS
Ikarus Win32.Outbreak
Fortinet PossibleThreat.DU
alibabacloud ProxyTool:Win/Iox.gyf