Summary | ZeroBOX

c7499e41-0a58-4589-a6f7-c5f82d04abc3

Malicious Library UPX Malicious Packer PE64 PE File OS Processor Check
Category Machine Started Completed
FILE s1_win7_x6403_us May 4, 2025, 12:43 p.m. May 4, 2025, 1:08 p.m.
Size 11.8MB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 8577579101b3c5418eb2613dbaf51b9f
SHA256 4b1b19d1fc6290260ab1a09999fcb1bb0911c91bf576125cff43da01c3b45b80
CRC32 7A24A7E3
ssdeep 196608:NWA5RV7plITg4wUs4MQ7/iam7WVjvfcHiNCy:NWq7pOTNf76am7WKi9
Yara
  • PE_Header_Zero - PE File Signature
  • Malicious_Packer_Zero - Malicious Packer
  • IsPE64 - (no description)
  • Malicious_Library_Zero - Malicious_Library
  • OS_Processor_Check_Zero - OS Processor Check
  • UPX_Zero - UPX packed file

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section .symtab
section {u'size_of_data': u'0x000a4400', u'virtual_address': u'0x00859000', u'entropy': 7.9958549712981535, u'name': u'/19', u'virtual_size': u'0x000a433b'} entropy 7.9958549713 description A section with a high entropy has been found
section {u'size_of_data': u'0x00022c00', u'virtual_address': u'0x008fe000', u'entropy': 7.941144626494354, u'name': u'/32', u'virtual_size': u'0x00022ae8'} entropy 7.94114462649 description A section with a high entropy has been found
section {u'size_of_data': u'0x0013dc00', u'virtual_address': u'0x00922000', u'entropy': 7.99869058266867, u'name': u'/65', u'virtual_size': u'0x0013db20'} entropy 7.99869058267 description A section with a high entropy has been found
section {u'size_of_data': u'0x000dc600', u'virtual_address': u'0x00a60000', u'entropy': 7.995561871734306, u'name': u'/78', u'virtual_size': u'0x000dc420'} entropy 7.99556187173 description A section with a high entropy has been found
section {u'size_of_data': u'0x0003f600', u'virtual_address': u'0x00b3d000', u'entropy': 7.812540913535634, u'name': u'/90', u'virtual_size': u'0x0003f566'} entropy 7.81254091354 description A section with a high entropy has been found
entropy 0.265318805154 description Overall entropy of this PE file is high
Lionic Trojan.Win32.Gomal.a!c
CAT-QuickHeal Trojan.Ghanarava.1745362017f51b9f
Skyhigh Artemis!Trojan
ALYac Trojan.GenericKD.76239942
Cylance Unsafe
VIPRE Trojan.GenericKD.76239942
BitDefender Trojan.GenericKD.76239942
K7GW Trojan ( 005c55451 )
K7AntiVirus Trojan ( 005c55451 )
Arcabit Trojan.Generic.D48B5446
VirIT Trojan.Win64.Agent.IAJ
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of WinGo/Agent.AHP
Avast Win64:MalwareX-gen [Misc]
Kaspersky Trojan-Downloader.Win32.Gomal.bojd
MicroWorld-eScan Trojan.GenericKD.76239942
Emsisoft Trojan.GenericKD.76239942 (B)
F-Secure Trojan.TR/AVI.Agent.piijz
Zillya Trojan.Gomal.Win32.13
TrendMicro Trojan.Win64.AMADEY.YXFDJZ
McAfeeD ti!4B1B19D1FC62
CTX exe.trojan.gomal
Sophos Mal/Generic-S
Google Detected
Avira TR/AVI.Agent.piijz
Xcitium Malware@#3ama6vz6kd9ee
Microsoft Trojan:Win32/Egairtigado!rfn
GData Trojan.GenericKD.76239942
Varist W64/ABApplication.AQKB-0364
AhnLab-V3 Trojan/Win.Wacatac.C5754099
McAfee Artemis!8577579101B3
DeepInstinct MALICIOUS
VBA32 TrojanDownloader.Gomal
Malwarebytes Malware.AI.768108541
Ikarus Trojan.WinGo.Agent
Panda Trj/Chgt.AD
TrendMicro-HouseCall Trojan.Win64.AMADEY.YXFDJZ
Tencent Win32.Trojan-Downloader.Gomal.Kqil
MaxSecure Trojan.Malware.343215759.susgen
Fortinet W32/Agent.AHP!tr
AVG Win64:MalwareX-gen [Misc]