Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | April 29, 2025, 10:24 a.m. | April 29, 2025, 10:38 a.m. |
-
csr.bin "C:\Users\test22\AppData\Local\Temp\csr.bin"
2556
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
section | CODE |
section | DATA |
packer | UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser |
resource name | TEXTINCLUDE |
name | TEXTINCLUDE | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x000fdb28 | size | 0x00000151 | ||||||||||||||||||
name | TEXTINCLUDE | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x000fdb28 | size | 0x00000151 | ||||||||||||||||||
name | TEXTINCLUDE | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x000fdb28 | size | 0x00000151 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x000ff7b8 | size | 0x000000b4 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x000ff7b8 | size | 0x000000b4 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x000ff7b8 | size | 0x000000b4 | ||||||||||||||||||
name | RT_CURSOR | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x000ff7b8 | size | 0x000000b4 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00100190 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00100190 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00100190 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00100190 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00100190 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00100190 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00100190 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00100190 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00100190 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00100190 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00100190 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00100190 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00100190 | size | 0x00000144 | ||||||||||||||||||
name | RT_BITMAP | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00100190 | size | 0x00000144 | ||||||||||||||||||
name | RT_MENU | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x000ff158 | size | 0x00000284 | ||||||||||||||||||
name | RT_MENU | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x000ff158 | size | 0x00000284 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x000feca0 | size | 0x0000018c | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x000feca0 | size | 0x0000018c | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x000feca0 | size | 0x0000018c | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x000feca0 | size | 0x0000018c | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x000feca0 | size | 0x0000018c | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x000feca0 | size | 0x0000018c | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x000feca0 | size | 0x0000018c | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x000feca0 | size | 0x0000018c | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x000feca0 | size | 0x0000018c | ||||||||||||||||||
name | RT_DIALOG | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x000feca0 | size | 0x0000018c | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00100ba8 | size | 0x00000024 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00100ba8 | size | 0x00000024 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00100ba8 | size | 0x00000024 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00100ba8 | size | 0x00000024 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00100ba8 | size | 0x00000024 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00100ba8 | size | 0x00000024 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00100ba8 | size | 0x00000024 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00100ba8 | size | 0x00000024 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00100ba8 | size | 0x00000024 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00100ba8 | size | 0x00000024 | ||||||||||||||||||
name | RT_STRING | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x00100ba8 | size | 0x00000024 | ||||||||||||||||||
name | RT_GROUP_CURSOR | language | LANG_CHINESE | filetype | PGP\011Secret Sub-key - | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x000ff870 | size | 0x00000022 | ||||||||||||||||||
name | RT_GROUP_CURSOR | language | LANG_CHINESE | filetype | PGP\011Secret Sub-key - | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x000ff870 | size | 0x00000022 | ||||||||||||||||||
name | RT_GROUP_CURSOR | language | LANG_CHINESE | filetype | PGP\011Secret Sub-key - | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x000ff870 | size | 0x00000022 | ||||||||||||||||||
name | RT_GROUP_ICON | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0011b1d8 | size | 0x00000014 | ||||||||||||||||||
name | RT_GROUP_ICON | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0011b1d8 | size | 0x00000014 | ||||||||||||||||||
name | RT_GROUP_ICON | language | LANG_CHINESE | filetype | data | sublanguage | SUBLANG_CHINESE_SIMPLIFIED | offset | 0x0011b1d8 | size | 0x00000014 |
file | C:\Users\test22\AppData\Local\Temp\25261765\TemporaryFile\TemporaryFile |
section | {u'size_of_data': u'0x00057600', u'virtual_address': u'0x000b7000', u'entropy': 7.925992429736249, u'name': u'DATA', u'virtual_size': u'0x00058000'} | entropy | 7.92599242974 | description | A section with a high entropy has been found | |||||||||
entropy | 0.874843554443 | description | Overall entropy of this PE file is high |
reg_key | HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\systeamst | reg_value | C:\Users\test22\AppData\Local\Temp\csr.bin |
Bkav | W32.AIDetectMalware |
Lionic | Trojan.Multi.Generic.mE1c |
Cynet | Malicious (score: 100) |
CAT-QuickHeal | Trojan.Ghanarava.17444789249334dc |
Skyhigh | BehavesLike.Win32.Generic.gc |
ALYac | Gen:Variant.Barys.59148 |
Cylance | Unsafe |
VIPRE | Gen:Variant.Barys.59148 |
Sangfor | Trojan.Win32.Save.a |
CrowdStrike | win/malicious_confidence_70% (W) |
BitDefender | Gen:Variant.Barys.59148 |
K7GW | Trojan ( 005246d51 ) |
K7AntiVirus | Trojan ( 005246d51 ) |
Arcabit | Trojan.Barys.DE70C |
Symantec | ML.Attribute.HighConfidence |
Elastic | malicious (high confidence) |
ESET-NOD32 | a variant of Win32/FlyStudio.ORN |
APEX | Malicious |
Avast | MalwareX-gen [Misc] |
ClamAV | Win.Malware.Babar-10034117-0 |
Kaspersky | HEUR:Trojan-Downloader.Win32.Agent.gen |
Alibaba | TrojanDownloader:Win32/FlyStudio.09f20e8e |
NANO-Antivirus | Trojan.Win32.BlackHole.hqumcr |
MicroWorld-eScan | Gen:Variant.Barys.59148 |
Rising | Trojan.Occamy!8.F1CD (TFE:5:lbQiteBw5lK) |
Emsisoft | Gen:Variant.Barys.59148 (B) |
F-Secure | Trojan.TR/ATRAPS.Gen |
DrWeb | Trojan.Siggen31.11387 |
McAfeeD | Real Protect-LS!B2A7F546295D |
Trapmine | malicious.high.ml.score |
CTX | exe.trojan.flystudio |
Sophos | Mal/Generic-S |
SentinelOne | Static AI - Suspicious PE |
Detected | |
Avira | TR/ATRAPS.Gen |
Antiy-AVL | Trojan[Packed]/Win32.FlyStudio |
Gridinsoft | Trojan.Win32.Agent.sa |
Xcitium | TrojWare.Win32.TrojanSpy.Banker.OV@6e1pyh |
Microsoft | Trojan:Win32/Wacatac.B!ml |
ViRobot | Trojan.Win.Z.Barys.410112 |
GData | Gen:Variant.Barys.59148 |
Varist | W32/S-776111c5!Eldorado |
McAfee | Artemis!B2A7F546295D |
DeepInstinct | MALICIOUS |
VBA32 | BScope.Trojan.Wacatac |
Malwarebytes | MachineLearning/Anomalous.100% |
Ikarus | PUA.BlackMoon |
TrendMicro-HouseCall | TROJ_GEN.R002H09DC25 |
Tencent | Win32.Trojan-Downloader.Agent.Jajl |
Yandex | Trojan.GenAsa!zBP+1MxmcWM |