Summary | ZeroBOX

xwo.exe

Generic Malware Malicious Library UPX PE File OS Processor Check PE32
Category Machine Started Completed
FILE s1_win7_x6403_us Nov. 11, 2024, 10:03 a.m. Nov. 11, 2024, 10:23 a.m.
Size 189.5KB
Type PE32 executable (console) Intel 80386, for MS Windows
MD5 7949220a0b341111716a81695324be27
SHA256 a22f6db007744f7768782280e66832487b3b193ff20825203bb56210b7c4e923
CRC32 8D4EB81F
ssdeep 3072:jqWg0oaxBGieuvQTtv6c/mTRPyZqqiIdhI+czv/gJQE7zK+l+2aVtUq9JosKh:jgP8GiHvQTV+d/qi25eKfU2cDJ18
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE32 - (no description)
  • Generic_Malware_Zero - Generic Malware
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section .10cfg
section {u'size_of_data': u'0x0001de00', u'virtual_address': u'0x00001000', u'entropy': 7.0501355311619776, u'name': u'.text', u'virtual_size': u'0x0001dc9c'} entropy 7.05013553116 description A section with a high entropy has been found
section {u'size_of_data': u'0x00008c00', u'virtual_address': u'0x0002a000', u'entropy': 7.994367312530358, u'name': u'.pdata', u'virtual_size': u'0x00007c00'} entropy 7.99436731253 description A section with a high entropy has been found
entropy 0.821808510638 description Overall entropy of this PE file is high
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Stelpak.4!c
Cynet Malicious (score: 100)
Skyhigh BehavesLike.Win32.Generic.cc
ALYac Trojan.GenericKD.74670876
Cylance Unsafe
VIPRE Trojan.GenericKD.74670876
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Trojan.GenericKD.74670876
Arcabit Trojan.Generic.D473631C
VirIT Trojan.Win32.Genus.WXO
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Generik.CVFVOGF
APEX Malicious
Avast Win32:Evo-gen [Trj]
ClamAV Win.Packed.Fugrafa-10037096-0
Kaspersky HEUR:Trojan.Win32.Stelpak.gen
Alibaba Trojan:Win32/Stelpak.6ddd32d1
MicroWorld-eScan Trojan.GenericKD.74670876
Rising Trojan.Stelpak!8.1B214 (TFE:5:kcmEtnJh2FU)
Emsisoft Trojan.GenericKD.74670876 (B)
F-Secure Trojan.TR/AVI.XWorm.sphdl
DrWeb Trojan.PWS.Lumma.801
McAfeeD ti!A22F6DB00774
Trapmine suspicious.low.ml.score
CTX exe.trojan.stelpak
Sophos Mal/Generic-S
SentinelOne Static AI - Malicious PE
FireEye Generic.mg.7949220a0b341111
Google Detected
Avira TR/AVI.XWorm.sphdl
Antiy-AVL Trojan/Win32.Stelpak
Kingsoft malware.kb.a.872
Gridinsoft Malware.Win32.XWorm.tr
Xcitium Malware@#a50tfxkfr9v2
Microsoft Trojan:Win32/Wacatac.A!ml
ZoneAlarm UDS:DangerousObject.Multi.Generic
GData Trojan.GenericKD.74670876
Varist W32/Trojan.NNPM-2372
AhnLab-V3 Trojan/Win.Generic.R675910
McAfee Artemis!7949220A0B34
DeepInstinct MALICIOUS
Malwarebytes Spyware.Lumma
Ikarus Trojan.SuspectCRC
Panda Trj/Chgt.AD
Tencent Trojan.Win32.Kryptik.16001480
MaxSecure Trojan.Malware.272815677.susgen
Fortinet W32/PossibleThreat
AVG Win32:Evo-gen [Trj]