Summary | ZeroBOX

we.exe

PE32 PE File
Category Machine Started Completed
FILE s1_win7_x6401 Nov. 11, 2024, 10:02 a.m. Nov. 11, 2024, 10:07 a.m.
Size 53.8KB
Type PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows
MD5 d7c40c24060c5d6f38e8dc41e7490778
SHA256 a76eaabc4e8ba5d6b3747825a9fbc286d44d3981ac521119902d64ae2fdcc4b7
CRC32 83F1886D
ssdeep 768:mp+68GRK6/p+Iv26bC3NuCThUkGMi9kxiYhnRbsL:1KKYpLVbC9uCCJehn6
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

WriteConsoleA

buffer: VERSION : free 1.0
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: ./xxx ([-options] [values])*
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: options :
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: Eg: ./xxx -s ssocksd -h
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -s state setup the function.You can pick one from the
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: following options:
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: ssocksd , rcsocks , rssocks ,
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: lcx_listen , lcx_tran , lcx_slave
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -l listenport open a port for the service startup.
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -d refhost set the reflection host address.
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -e refport set the reflection port.
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -f connhost set the connect host address .
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -g connport set the connect port.
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -h help show the help text, By adding the -s parameter,
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: you can also see the more detailed help.
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -a about show the about pages
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -v version show the version.
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: -t usectime set the milliseconds for timeout. The default
console_handle: 0x00000007
1 1 0

WriteConsoleA

buffer: value is 1000
console_handle: 0x00000007
1 1 0
Bkav W32.AIDetectMalware
Lionic Hacktool.Win32.Earthworm.3!c
Cynet Malicious (score: 99)
Skyhigh Artemis!Trojan
ALYac Adware.GenericKD.61013633
Cylance Unsafe
VIPRE Adware.GenericKD.61013633
CrowdStrike win/grayware_confidence_60% (W)
BitDefender Adware.GenericKD.61013633
K7GW Hacktool ( 00561aba1 )
K7AntiVirus Hacktool ( 00561aba1 )
Arcabit Adware.Generic.D3A2FE81
Symantec Hacktool
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/HackTool.NetHacker.AC
Avast Win32:Malware-gen
ClamAV Win.Tool.Earthworm-9875816-0
Kaspersky HEUR:HackTool.Win32.Earthworm.gen
Alibaba NetTool:Application/SocksSevice.190603
NANO-Antivirus Trojan.Win32.NetHacker.icjkwq
MicroWorld-eScan Adware.GenericKD.61013633
Rising PUA.Presenoker!8.F608 (C64:YzY0OiS9Hx9Suwxm)
Emsisoft Adware.GenericKD.61013633 (B)
F-Secure Trojan.TR/NetHacker.tivyv
DrWeb Tool.Earthworm.1
Zillya Tool.NetHacker.Win32.27
TrendMicro HackTool.Win32.EarthWorm.B
McAfeeD ti!A76EAABC4E8B
CTX exe.hacktool.generic
Sophos Generic Reputation PUA (PUA)
FireEye Adware.GenericKD.61013633
Jiangmin HackTool.Earthworm.g
Google Detected
Avira TR/NetHacker.tivyv
Antiy-AVL Trojan[APT]/Win32.Earthlusca
Kingsoft Win32.HackTool.Earthworm.gen
Gridinsoft Hack.Win32.Patcher.oa!s1
Xcitium Malware@#3nay66mlwbcz5
Microsoft PUA:Win32/Ymacco
ZoneAlarm HEUR:HackTool.Win32.Earthworm.gen
GData Win32.Riskware.Earthworm.A
Varist W32/Earthworm.A.gen!Eldorado
AhnLab-V3 HackTool/Win32.Earthworm.R303865
McAfee GenericRXAA-AA!D7C40C24060C
DeepInstinct MALICIOUS
VBA32 BScope.Exploit.CVE-2020-0601
Malwarebytes RiskWare.HackTool
Ikarus PUA.Hacktool.Earthworm
Panda Trj/GdSda.A
TrendMicro-HouseCall HackTool.Win32.EarthWorm.B