Summary | ZeroBOX

proxy1.exe

Category Machine Started Completed
FILE s1_win7_x6402 March 22, 2021, 6:52 p.m. March 22, 2021, 7:38 p.m.
Size 524.0KB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 bcd2583086d55ae0e1444378c2892c1d
SHA256 e80db3924627a7961f6bbb34a4d6849546d544620ea77f12b1b3dd8ed024ef4d
CRC32 7E1FA6A8
ssdeep 12288:TDl53CNKU4kET3oPSPe6v4WgZeajrzQ1bWON2Tu:TPCNKU4f7oPodvzOrzebWm2T
Yara
  • PE_Header_Zero - PE File Signature Zero
  • OS_Processor_Check_Zero - OS Processor Check Signature Zero
  • win_files_operation - Affect private profile
  • IsPE32 - (no description)
  • IsWindowsGUI - (no description)
  • IsPacked - Entropy Check

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

section .sudohef
section .mizuzip
section .new
resource name WEXE
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 7388
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 327680
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x009cb000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 7388
region_size: 593920
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00880000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0
name WEXE language LANG_TURKISH filetype ASCII text, with very long lines, with no line terminators sublanguage SUBLANG_DEFAULT offset 0x0046fd30 size 0x00000bf7
name RT_CURSOR language LANG_TURKISH filetype data sublanguage SUBLANG_DEFAULT offset 0x00470960 size 0x00000134
name RT_ICON language LANG_TURKISH filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_DEFAULT offset 0x0046f860 size 0x00000468
name RT_ICON language LANG_TURKISH filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_DEFAULT offset 0x0046f860 size 0x00000468
name RT_ICON language LANG_TURKISH filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_DEFAULT offset 0x0046f860 size 0x00000468
name RT_ICON language LANG_TURKISH filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_DEFAULT offset 0x0046f860 size 0x00000468
name RT_ICON language LANG_TURKISH filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_DEFAULT offset 0x0046f860 size 0x00000468
name RT_ICON language LANG_TURKISH filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_DEFAULT offset 0x0046f860 size 0x00000468
name RT_ICON language LANG_TURKISH filetype GLS_BINARY_LSB_FIRST sublanguage SUBLANG_DEFAULT offset 0x0046f860 size 0x00000468
name RT_DIALOG language LANG_TURKISH filetype data sublanguage SUBLANG_DEFAULT offset 0x00470ab0 size 0x0000009e
name RT_STRING language LANG_TURKISH filetype data sublanguage SUBLANG_DEFAULT offset 0x00473a28 size 0x00000166
name RT_STRING language LANG_TURKISH filetype data sublanguage SUBLANG_DEFAULT offset 0x00473a28 size 0x00000166
name RT_STRING language LANG_TURKISH filetype data sublanguage SUBLANG_DEFAULT offset 0x00473a28 size 0x00000166
name RT_STRING language LANG_TURKISH filetype data sublanguage SUBLANG_DEFAULT offset 0x00473a28 size 0x00000166
name RT_STRING language LANG_TURKISH filetype data sublanguage SUBLANG_DEFAULT offset 0x00473a28 size 0x00000166
name RT_STRING language LANG_TURKISH filetype data sublanguage SUBLANG_DEFAULT offset 0x00473a28 size 0x00000166
name RT_STRING language LANG_TURKISH filetype data sublanguage SUBLANG_DEFAULT offset 0x00473a28 size 0x00000166
name RT_STRING language LANG_TURKISH filetype data sublanguage SUBLANG_DEFAULT offset 0x00473a28 size 0x00000166
name RT_STRING language LANG_TURKISH filetype data sublanguage SUBLANG_DEFAULT offset 0x00473a28 size 0x00000166
name RT_STRING language LANG_TURKISH filetype data sublanguage SUBLANG_DEFAULT offset 0x00473a28 size 0x00000166
name RT_STRING language LANG_TURKISH filetype data sublanguage SUBLANG_DEFAULT offset 0x00473a28 size 0x00000166
name RT_STRING language LANG_TURKISH filetype data sublanguage SUBLANG_DEFAULT offset 0x00473a28 size 0x00000166
name RT_ACCELERATOR language LANG_TURKISH filetype data sublanguage SUBLANG_DEFAULT offset 0x00470928 size 0x00000038
name RT_GROUP_CURSOR language LANG_TURKISH filetype Lotus unknown worksheet or configuration, revision 0x1 sublanguage SUBLANG_DEFAULT offset 0x00470a98 size 0x00000014
name RT_GROUP_ICON language LANG_TURKISH filetype data sublanguage SUBLANG_DEFAULT offset 0x0046fcc8 size 0x00000068
section {u'size_of_data': u'0x00073c00', u'virtual_address': u'0x00001000', u'entropy': 7.801029472968202, u'name': u'.text', u'virtual_size': u'0x00073ba0'} entropy 7.80102947297 description A section with a high entropy has been found
entropy 0.885277246654 description Overall entropy of this PE file is high