Summary | ZeroBOX

44264.7304233796.dat.exe

Category Machine Started Completed
FILE s1_win7_x6401 March 10, 2021, 2:28 p.m. March 10, 2021, 2:28 p.m.
Size 770.9KB
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5 84fee4e2242a993c51dc2c2310726694
SHA256 74a6c59a693f0dce653ea08d05e5f7570912c3f0e4a8307db36c0ed7dbdb5fc2
CRC32 3ACAE39A
ssdeep 12288:UlTxdlYUTXacR/927cw6nlsL8IQayFihyGgBfMdK6Uwh1/6aMCxtd:YFgkau97wUsTsFicGEfUK4Lx
Yara
  • IsPE32 - (no description)
  • IsDLL - (no description)
  • IsWindowsGUI - (no description)
  • HasOverlay - Overlay Check
  • HasDigitalSignature - DigitalSignature Check
  • borland_delphi_dll - Borland Delphi DLL
  • screenshot - Take screenshot
  • keylogger - Run a keylogger
  • win_registry - Affect system registries
  • win_files_operation - Affect private profile
  • PE_Header_Zero - PE File Signature Zero

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section CODE
section DATA
section BSS
resource name None
section {u'size_of_data': u'0x00051000', u'virtual_address': u'0x00072000', u'entropy': 6.9258747569183585, u'name': u'.rsrc', u'virtual_size': u'0x00051000'} entropy 6.92587475692 description A section with a high entropy has been found
entropy 0.424083769634 description Overall entropy of this PE file is high