Hostile 100% pe-machine-learning-dataset Download

49131

UPX packed PE with evasion

UPX decompression failed: IO error: Permission denied (os error 13)Entry point in writable scrambled UPX section
SHA-25683e071e33af7e6e9b74d3abff7c4cd6a069ea0073eabc87eba4d29d2bb4beb3c

Evidence

Entry point in writable scrambled UPX section 0x0–0x40
0x04d5a90000300000004000000ffff0000MZ..............
0x10b8000000000000004000000000000000........@.......
0x2000000000000000000000000000000000................
0x30000000000000000000000000e0000000................
0x400e1fba ...
UPX packer marker string 0x1c8–0x218
0x1c800000000000000000000000000000000................
0x1d8555058300000000000c0650000100000UPX0......e.....
0x1e800000000000400000000000000000000................
0x1f800000000800000e05550583100000000........UPX1....
0x2080050000000d065000048000000040000.P....e..H......
0x218000000000000000000000000 ............
WSOCK32 Winsock DLL import 0x4cad–0x4cfd
0x4cad0000004b45524e454c33322e444c4c00...KERNEL32.DLL.
0x4cbd47444933322e646c6c004d5356435254GDI32.dll.MSVCRT
0x4ccd2e646c6c005553455233322e646c6c00.dll.USER32.dll.
0x4cdd57534f434b33322e646c6c00004c6f61WSOCK32.dll..Loa
0x4ced644c6962726172794100004765745072dLibraryA..GetPr
0x4cfd6f63416464726573730000 ocAddress..

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.