Summary | ZeroBOX

svhost.exe

Generic Malware UPX OS Processor Check PE64 PE File
Category Machine Started Completed
FILE s1_win7_x6403_us Jan. 10, 2025, 4:46 p.m. Jan. 10, 2025, 4:48 p.m.
Size 6.7MB
Type PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows
MD5 6b3b2c4cdcc210e868ca4c3dee9584e5
SHA256 5422a959db0ae7deadab5898df05405af64a12e3eacd0419644fd3078989f620
CRC32 4E054C76
ssdeep 98304:Vm/6cbaX5jpmODW4pkIYbt9zWPlRcRE4DxMpGCEuP+OCN0x2qx+cOOXk2MokrMxg:4/v45DdyM35XkBfDn
Yara
  • PE_Header_Zero - PE File Signature
  • IsPE64 - (no description)
  • Generic_Malware_Zero - Generic Malware
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
Skyhigh Artemis!Trojan
Cylance Unsafe
ESET-NOD32 a variant of Win64/CoinMiner.UG potentially unwanted
Avast Win64:MalwareX-gen [Trj]
MicroWorld-eScan Gen:Variant.Tedy.676713
Rising PUA.CoinMiner!8.4639 (CLOUD)
F-Secure Trojan.TR/AVI.Agent.soicu
Avira TR/AVI.Agent.soicu
McAfee Artemis!6B3B2C4CDCC2
TrendMicro-HouseCall TROJ_GEN.R002H09LB24
MaxSecure Trojan.Malware.316833894.susgen
AVG Win64:MalwareX-gen [Trj]
alibabacloud Trojan:Win/Tedy.Gen