Summary | ZeroBOX

EDge.exe

Malicious Library UPX Malicious Packer PE64 PE File OS Processor Check
Category Machine Started Completed
FILE s1_win7_x6403_us Oct. 29, 2024, 5:09 p.m. Oct. 29, 2024, 5:12 p.m.
Size 2.4MB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 f01ed03b7a786c24ebd92eab9b441b9d
SHA256 6dc5fcbd3d05cb11dc4731aea996c7cbc213253c4d4b119799c5ddedebe537fb
CRC32 B1B2C436
ssdeep 24576:VmbfFJN3P6yM97l2cMPdjjy/ZIbRCTtM+UcI6TRq3jUN6DMhQKjyJ9IFz1uXy:k7N3P6ykZ2cmjjalM+E3SMQJW
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer
  • IsPE64 - (no description)
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section .symtab
Bkav W64.AIDetectMalware
Lionic Trojan.Win32.ShellcodeRunner.4!c
Cynet Malicious (score: 100)
Cylance Unsafe
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_90% (D)
BitDefender Trojan.Autoruns.GenericKD.150
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of WinGo/ShellcodeRunner.UG
APEX Malicious
Avast FileRepMalware [Drp]
Kaspersky Trojan.Win64.Shellcode.auz
MicroWorld-eScan Trojan.Autoruns.GenericKD.150
Emsisoft Trojan.Autoruns.GenericKD.150 (B)
F-Secure Dropper.DR/AVI.Agent.utbzo
TrendMicro Trojan.Win64.AMADEY.YXEJ3Z
McAfeeD ti!6DC5FCBD3D05
CTX exe.trojan.shellcoderunner
Sophos Mal/Generic-S
SentinelOne Static AI - Suspicious PE
Google Detected
Avira DR/AVI.Agent.utbzo
Antiy-AVL Trojan/Win32.ShellcodeRunner
Kingsoft Win32.Troj.Unknown.a
Microsoft Trojan:Win64/Androm
ZoneAlarm UDS:DangerousObject.Multi.Generic
GData Win32.Malware.Donut.1515V3
Varist W64/ABTrojan.OPWA-8597
AhnLab-V3 Trojan/Win.Donut.C5688175
McAfee Artemis!F01ED03B7A78
DeepInstinct MALICIOUS
Malwarebytes Malware.AI.3996307552
Ikarus Trojan.WinGo.Agent
Panda Trj/Chgt.AD
TrendMicro-HouseCall Trojan.Win64.AMADEY.YXEJ3Z
Tencent Win64.Trojan.Shellcode.Ekjl
Fortinet W32/ShellcodeRunner.UG!tr
AVG FileRepMalware [Drp]
Paloalto generic.ml
alibabacloud Trojan:Multi/ShellcodeRunner.UU