ScreenShot
Created | 2021.06.15 11:09 | Machine | s1_win7_x6401 |
Filename | VOKLIGHT.exe | ||
Type | PE32 executable (GUI) Intel 80386, for MS Windows | ||
AI Score |
|
Behavior Score |
|
ZERO API | file : malware | ||
VT API (file) | 13 detected (AIDetect, malware1, Unsafe, Malicious, Generic ML PUA, Score, ZexaF, @t0@augQkak, ET#93%, RDMK, cmRtazqB, qih59iLEZ29TSng2w7x, Static AI, Malicious PE, susgen) | ||
md5 | 9a86329fb7bd48fc778676e664d3d0be | ||
sha256 | 648071554a71aeab1671abf122cdd67da6f356853ae322534394de276b10034d | ||
ssdeep | 98304:t9pAo0zb3cdttpGl4/zgNb8Qn0NbsuO1XeK39NNXH+tCNSZ:t4o03Mdzc4/8Nb8k0V1EXeK3pul | ||
imphash | 9dd8c0ff4fc84287e5b766563240f983 | ||
impfuzzy | 24:gdqnuDoDyBNYnbrJOovS2cfEt4UjMAH/J3KyvbaFQHOTqlnpCwuC8ERaTCEQDR4S:gQ8NIb4QcfEt4ITbuWlpC4RaTHq4ud |
Network IP location
Signature (9cnts)
Level | Description |
---|---|
watch | File has been identified by 13 AntiVirus engines on VirusTotal as malicious |
notice | Allocates read-write-execute memory (usually to unpack itself) |
notice | Checks for the Locally Unique Identifier on the system for a suspicious privilege |
notice | The binary likely contains encrypted or compressed data indicative of a packer |
info | Checks amount of memory in system |
info | Checks if process is being debugged by a debugger |
info | One or more processes crashed |
info | This executable has a PDB path |
info | Uses Windows APIs to generate a cryptographic key |
Rules (5cnts)
Level | Name | Description | Collection |
---|---|---|---|
danger | NPKI_Zero | File included NPKI | binaries (upload) |
warning | UltraVNC_Zero | UltraVNC | binaries (upload) |
info | IsPE32 | (no description) | binaries (upload) |
info | OS_Processor_Check_Zero | OS Processor Check | binaries (upload) |
info | PE_Header_Zero | PE File Signature | binaries (upload) |
Network (0cnts) ?
Request | CC | ASN Co | IP4 | Rule ? | ZERO ? |
---|
Suricata ids
PE API
IAT(Import Address Table) Library
KERNEL32.dll
0x41b000 RaiseException
0x41b004 GetLastError
0x41b008 MultiByteToWideChar
0x41b00c lstrlenA
0x41b010 InterlockedDecrement
0x41b014 GetProcAddress
0x41b018 LoadLibraryA
0x41b01c FreeResource
0x41b020 SizeofResource
0x41b024 LockResource
0x41b028 LoadResource
0x41b02c FindResourceA
0x41b030 GetModuleHandleA
0x41b034 Module32Next
0x41b038 CloseHandle
0x41b03c Module32First
0x41b040 CreateToolhelp32Snapshot
0x41b044 GetCurrentProcessId
0x41b048 SetEndOfFile
0x41b04c GetStringTypeW
0x41b050 GetStringTypeA
0x41b054 LCMapStringW
0x41b058 LCMapStringA
0x41b05c GetLocaleInfoA
0x41b060 CreateFileA
0x41b064 HeapFree
0x41b068 GetProcessHeap
0x41b06c HeapAlloc
0x41b070 GetCommandLineA
0x41b074 HeapCreate
0x41b078 VirtualFree
0x41b07c DeleteCriticalSection
0x41b080 LeaveCriticalSection
0x41b084 EnterCriticalSection
0x41b088 VirtualAlloc
0x41b08c HeapReAlloc
0x41b090 HeapSize
0x41b094 TerminateProcess
0x41b098 GetCurrentProcess
0x41b09c UnhandledExceptionFilter
0x41b0a0 SetUnhandledExceptionFilter
0x41b0a4 IsDebuggerPresent
0x41b0a8 GetModuleHandleW
0x41b0ac Sleep
0x41b0b0 ExitProcess
0x41b0b4 WriteFile
0x41b0b8 GetStdHandle
0x41b0bc GetModuleFileNameA
0x41b0c0 WideCharToMultiByte
0x41b0c4 GetConsoleCP
0x41b0c8 GetConsoleMode
0x41b0cc ReadFile
0x41b0d0 TlsGetValue
0x41b0d4 TlsAlloc
0x41b0d8 TlsSetValue
0x41b0dc TlsFree
0x41b0e0 InterlockedIncrement
0x41b0e4 SetLastError
0x41b0e8 GetCurrentThreadId
0x41b0ec FlushFileBuffers
0x41b0f0 SetFilePointer
0x41b0f4 SetHandleCount
0x41b0f8 GetFileType
0x41b0fc GetStartupInfoA
0x41b100 RtlUnwind
0x41b104 FreeEnvironmentStringsA
0x41b108 GetEnvironmentStrings
0x41b10c FreeEnvironmentStringsW
0x41b110 GetEnvironmentStringsW
0x41b114 QueryPerformanceCounter
0x41b118 GetTickCount
0x41b11c GetSystemTimeAsFileTime
0x41b120 InitializeCriticalSectionAndSpinCount
0x41b124 GetCPInfo
0x41b128 GetACP
0x41b12c GetOEMCP
0x41b130 IsValidCodePage
0x41b134 CompareStringA
0x41b138 CompareStringW
0x41b13c SetEnvironmentVariableA
0x41b140 WriteConsoleA
0x41b144 GetConsoleOutputCP
0x41b148 WriteConsoleW
0x41b14c SetStdHandle
ole32.dll
0x41b184 OleInitialize
OLEAUT32.dll
0x41b154 VariantInit
0x41b158 SafeArrayCreate
0x41b15c SafeArrayAccessData
0x41b160 SafeArrayUnaccessData
0x41b164 SafeArrayDestroy
0x41b168 SafeArrayCreateVector
0x41b16c VariantClear
0x41b170 SysFreeString
0x41b174 SysAllocString
mscoree.dll
0x41b17c CorBindToRuntimeEx
EAT(Export Address Table) is none
KERNEL32.dll
0x41b000 RaiseException
0x41b004 GetLastError
0x41b008 MultiByteToWideChar
0x41b00c lstrlenA
0x41b010 InterlockedDecrement
0x41b014 GetProcAddress
0x41b018 LoadLibraryA
0x41b01c FreeResource
0x41b020 SizeofResource
0x41b024 LockResource
0x41b028 LoadResource
0x41b02c FindResourceA
0x41b030 GetModuleHandleA
0x41b034 Module32Next
0x41b038 CloseHandle
0x41b03c Module32First
0x41b040 CreateToolhelp32Snapshot
0x41b044 GetCurrentProcessId
0x41b048 SetEndOfFile
0x41b04c GetStringTypeW
0x41b050 GetStringTypeA
0x41b054 LCMapStringW
0x41b058 LCMapStringA
0x41b05c GetLocaleInfoA
0x41b060 CreateFileA
0x41b064 HeapFree
0x41b068 GetProcessHeap
0x41b06c HeapAlloc
0x41b070 GetCommandLineA
0x41b074 HeapCreate
0x41b078 VirtualFree
0x41b07c DeleteCriticalSection
0x41b080 LeaveCriticalSection
0x41b084 EnterCriticalSection
0x41b088 VirtualAlloc
0x41b08c HeapReAlloc
0x41b090 HeapSize
0x41b094 TerminateProcess
0x41b098 GetCurrentProcess
0x41b09c UnhandledExceptionFilter
0x41b0a0 SetUnhandledExceptionFilter
0x41b0a4 IsDebuggerPresent
0x41b0a8 GetModuleHandleW
0x41b0ac Sleep
0x41b0b0 ExitProcess
0x41b0b4 WriteFile
0x41b0b8 GetStdHandle
0x41b0bc GetModuleFileNameA
0x41b0c0 WideCharToMultiByte
0x41b0c4 GetConsoleCP
0x41b0c8 GetConsoleMode
0x41b0cc ReadFile
0x41b0d0 TlsGetValue
0x41b0d4 TlsAlloc
0x41b0d8 TlsSetValue
0x41b0dc TlsFree
0x41b0e0 InterlockedIncrement
0x41b0e4 SetLastError
0x41b0e8 GetCurrentThreadId
0x41b0ec FlushFileBuffers
0x41b0f0 SetFilePointer
0x41b0f4 SetHandleCount
0x41b0f8 GetFileType
0x41b0fc GetStartupInfoA
0x41b100 RtlUnwind
0x41b104 FreeEnvironmentStringsA
0x41b108 GetEnvironmentStrings
0x41b10c FreeEnvironmentStringsW
0x41b110 GetEnvironmentStringsW
0x41b114 QueryPerformanceCounter
0x41b118 GetTickCount
0x41b11c GetSystemTimeAsFileTime
0x41b120 InitializeCriticalSectionAndSpinCount
0x41b124 GetCPInfo
0x41b128 GetACP
0x41b12c GetOEMCP
0x41b130 IsValidCodePage
0x41b134 CompareStringA
0x41b138 CompareStringW
0x41b13c SetEnvironmentVariableA
0x41b140 WriteConsoleA
0x41b144 GetConsoleOutputCP
0x41b148 WriteConsoleW
0x41b14c SetStdHandle
ole32.dll
0x41b184 OleInitialize
OLEAUT32.dll
0x41b154 VariantInit
0x41b158 SafeArrayCreate
0x41b15c SafeArrayAccessData
0x41b160 SafeArrayUnaccessData
0x41b164 SafeArrayDestroy
0x41b168 SafeArrayCreateVector
0x41b16c VariantClear
0x41b170 SysFreeString
0x41b174 SysAllocString
mscoree.dll
0x41b17c CorBindToRuntimeEx
EAT(Export Address Table) is none