Report - oqibxmsfz.zip

ScreenShot
Created 2021.04.01 09:28 Machine s1_win7_x6402
Filename oqibxmsfz.zip
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
AI Score
2
Behavior Score
3.4
ZERO API file : malware
VT API (file) 7 detected (AIDetect, malware2, Malicious, Roxer, Wacapew, score)
md5 d29310c232038a6dd1f2b8749be5619e
sha256 bb56d5afc7d00cb06990a05455fdaffd42f98f2b86fba71a282df8d0195ff674
ssdeep 6144:n6vYH/guLTgCb1oFtIaJmGDtDplcJqiD4IU2fQ/TxH+GtrHayYm:n6vYouLTgC5oFt/hRDfkL1U2Y/TxeGtn
imphash 02e581d639f814ba43d9c6c8be6f316e
impfuzzy 48:RUKtMS17Mbc+ppXr36cLE6x9j/11t9oGAi:RVtMS17Mbc+ppXdxZ
  Network IP location

Signature (9cnts)

Level Description
watch Communicates with host for which no DNS query was performed
notice Allocates read-write-execute memory (usually to unpack itself)
notice File has been identified by 7 AntiVirus engines on VirusTotal as malicious
notice HTTP traffic contains suspicious features which may be indicative of malware related traffic
notice Performs some HTTP requests
notice Sends data using the HTTP POST Method
notice The binary likely contains encrypted or compressed data indicative of a packer
info One or more processes crashed
info This executable has a PDB path

Rules (8cnts)

Level Name Description Collection
info IsDLL (no description) binaries (upload)
info IsPE32 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check Signature Zero binaries (upload)
info PE_Header_Zero PE File Signature Zero binaries (upload)
info HasDebugData DebugData Check binaries (upload)
info HasRichSignature Rich Signature Check binaries (upload)
info IsWindowsGUI (no description) binaries (upload)
info win_files_operation Affect private profile binaries (upload)

Network (7cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://r3---sn-3u-bh26.gvt1.com/edgedl/release2/update2/ALmnr7lDhOvozdF08iOk7Ks_1.3.36.72/GoogleUpdateSetup.exe?cms_redirect=yes&mh=pH&mip=175.208.134.150&mm=28&mn=sn-3u-bh26&ms=nvh&mt=1617236418&mv=m&mvi=3&pl=18&shardbypass=yes KR Korea Telecom 59.18.44.14 clean
http://redirector.gvt1.com/edgedl/release2/update2/ALmnr7lDhOvozdF08iOk7Ks_1.3.36.72/GoogleUpdateSetup.exe US GOOGLE 172.217.25.206 clean
https://update.googleapis.com/service/update2?cup2key=10:1131089239&cup2hreq=b1fbf598cff2d879a4bf382cc07193d04fcb89cdad69ea0b0d44ceb3cb86d922 US GOOGLE 142.250.66.67 clean
r3---sn-3u-bh26.gvt1.com KR Korea Telecom 59.18.44.14 clean
142.250.199.78 US GOOGLE 142.250.199.78 clean
59.18.44.14 KR Korea Telecom 59.18.44.14 clean
142.250.66.67 US GOOGLE 142.250.66.67 clean

Suricata ids



Similarity measure (PE file only) - Checking for service failure