Summary | ZeroBOX

NewApp.exe

UPX PE64 PE File
Category Machine Started Completed
FILE s1_win7_x6403_us Dec. 31, 2024, 1:22 p.m. Dec. 31, 2024, 1:26 p.m.
Size 5.5MB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 5d1255087c4512f2121410a008218430
SHA256 c9d6ebdff127c1486e402b5f4fbcdc5fac953cdd390890a5066464261b1eef34
CRC32 862B49C5
ssdeep 98304:9Lpx43K6PrRnUzI/8/hwuXkbJs274MMckVCd4PhtjJNKML2pq6AzuFuuwy:97uK6PtSjJRyeVm4Phtj7xLyWW
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE64 - (no description)
  • UPX_Zero - UPX packed file

IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

Flow SID Signature Category
UDP 192.168.56.103:53658 -> 8.8.8.8:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:64178 -> 164.124.101.2:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:53673 -> 164.124.101.2:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:53658 -> 8.8.8.8:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:64178 -> 164.124.101.2:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:53673 -> 8.8.8.8:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:64178 -> 8.8.8.8:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:53658 -> 8.8.8.8:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:53673 -> 164.124.101.2:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:53658 -> 8.8.8.8:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:64178 -> 164.124.101.2:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:64178 -> 8.8.8.8:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:53673 -> 8.8.8.8:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:64178 -> 8.8.8.8:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:50674 -> 164.124.101.2:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:53673 -> 8.8.8.8:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:53673 -> 164.124.101.2:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:64178 -> 8.8.8.8:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:53673 -> 8.8.8.8:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:50674 -> 164.124.101.2:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:50674 -> 164.124.101.2:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:64530 -> 164.124.101.2:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:64530 -> 164.124.101.2:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:64530 -> 8.8.8.8:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:64530 -> 164.124.101.2:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:64530 -> 8.8.8.8:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:64530 -> 8.8.8.8:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:53658 -> 164.124.101.2:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:64530 -> 8.8.8.8:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:53658 -> 164.124.101.2:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:50674 -> 8.8.8.8:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:53658 -> 164.124.101.2:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:50674 -> 8.8.8.8:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:57986 -> 8.8.8.8:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:50674 -> 8.8.8.8:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:57986 -> 8.8.8.8:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:50674 -> 8.8.8.8:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation
UDP 192.168.56.103:57986 -> 164.124.101.2:53 2033268 ET POLICY Observed DNS Query to Coin Mining Domain (nanopool .org) Potential Corporate Privacy Violation

Suricata TLS

No Suricata TLS

section .00cfg
section .vmp@\xe2\xa2\xaf
resource name FLEXDL
resource name FX
resource name MUI
resource name REGISTRY
resource name TXT
resource name XMLWRITE
resource name None
section {u'size_of_data': u'0x0057ba00', u'virtual_address': u'0x005ae000', u'entropy': 7.9815832639998705, u'name': u'.vmp@\\xe2\\xa2\\xaf', u'virtual_size': u'0x0057b944'} entropy 7.981583264 description A section with a high entropy has been found
entropy 0.995920177384 description Overall entropy of this PE file is high
section .vmp@\xe2\xa2\xaf description Section name indicates VMProtect
section .vmp@\xe2\xa2\xaf description Section name indicates VMProtect
section .vmp@\xe2\xa2\xaf description Section name indicates VMProtect
Bkav W64.AIDetectMalware
Lionic Trojan.Win32.Agent.Y!c
Cynet Malicious (score: 100)
Skyhigh Artemis!Trojan
ALYac Trojan.GenericKD.75271981
Cylance Unsafe
VIPRE Trojan.GenericKD.75271981
Sangfor Trojan.Win32.Agent.Vumi
CrowdStrike win/malicious_confidence_90% (W)
BitDefender Trojan.GenericKD.75271981
Arcabit Trojan.Generic.D47C8F2D
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Generik.FOJBYDI
Avast Win64:TrojanX-gen [Trj]
Kaspersky Trojan.Win32.Agent.xbuzse
MicroWorld-eScan Trojan.GenericKD.75271981
Rising Trojan.Reflo!8.1230F (TFE:5:4KEnqrPNWbT)
Emsisoft Trojan.GenericKD.75271981 (B)
F-Secure Trojan.TR/AD.Nekark.isecy
DrWeb Trojan.Siggen30.39968
McAfeeD ti!C9D6EBDFF127
CTX exe.trojan.generic
Sophos Mal/Generic-S
SentinelOne Static AI - Suspicious PE
FireEye Generic.mg.5d1255087c4512f2
Google Detected
Avira TR/AD.Nekark.isecy
Antiy-AVL Trojan/Win32.Caynamer
Kingsoft Win32.Trojan.Agent.xbuzse
Gridinsoft Trojan.Heur!.00210203
Microsoft Trojan:Win32/Caynamer.A!ml
GData Trojan.GenericKD.75271981
Varist W64/ABRisk.YMWR-4215
McAfee Artemis!5D1255087C45
DeepInstinct MALICIOUS
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/PossibleThreat
AVG Win64:TrojanX-gen [Trj]
Paloalto generic.ml