ScreenShot
Created | 2021.07.22 13:11 | Machine | s1_win7_x6403 |
Filename | MfbNKrx.png | ||
Type | PE32 executable (DLL) (GUI) Intel 80386, for MS Windows | ||
AI Score |
|
Behavior Score |
|
ZERO API | file : malware | ||
VT API (file) | 20 detected (AIDetect, malware2, Save, malicious, confidence, 100%, ZedlaF, lu8@ayNMVSni, Attribute, HighConfidence, ccmw, TrojanX, Generic@ML, RDML, mN2jEGaWcnNH, 2b8sEuZ4g, Drixed, Unsafe, Score, Emotet, Artemis, Static AI, Suspicious PE) | ||
md5 | aae1e725e2dbfd91213be22e857f9d02 | ||
sha256 | 3cba24dba02d5817a029caee6eadf1b3b4eb75ff861c62df3e4d4fbde1c349c2 | ||
ssdeep | 3072:TVadvfvemTEtQ9yoZPW/k/nklVtu77wBeZUCEQZRpdBDp57WQhdIif4:4DTyJWPd/nkdqw4/HdB77WQhdIu | ||
imphash | 458d7355fbf070054838e3593829db8d | ||
impfuzzy | 6:ZKUHXQ1bXhrV92VUI579ym1XYBVoXCwUcrMAdvX6n:ZtAHp92VT579ym1XY3D4rxvX6 |
Network IP location
Signature (2cnts)
Level | Description |
---|---|
warning | File has been identified by 20 AntiVirus engines on VirusTotal as malicious |
notice | The binary likely contains encrypted or compressed data indicative of a packer |
Rules (4cnts)
Level | Name | Description | Collection |
---|---|---|---|
danger | Win32_Trojan_Dridex_Gene_Zero | Win32 Trojan Dridex Gene | binaries (upload) |
info | IsDLL | (no description) | binaries (upload) |
info | IsPE32 | (no description) | binaries (upload) |
info | PE_Header_Zero | PE File Signature | binaries (upload) |
Network (0cnts) ?
Request | CC | ASN Co | IP4 | Rule ? | ZERO ? |
---|
Suricata ids
PE API
IAT(Import Address Table) Library
USER32.dll
0x10008030 TranslateMessage
0x10008034 GetWindowThreadProcessId
0x10008038 FindWindowExA
WS2_32.dll
0x10008040 accept
msvcrt.dll
0x10008048 memset
ADVAPI32.dll
0x10008000 AddUsersToEncryptedFile
0x10008004 RegOverridePredefKey
MPRAPI.dll
0x10008020 MprInfoDelete
SHLWAPI.dll
0x10008028 PathRemoveBlanksA
KERNEL32.dll
0x1000800c GlobalSize
0x10008010 CloseHandle
0x10008014 GetModuleFileNameA
0x10008018 OutputDebugStringA
EAT(Export Address Table) is none
USER32.dll
0x10008030 TranslateMessage
0x10008034 GetWindowThreadProcessId
0x10008038 FindWindowExA
WS2_32.dll
0x10008040 accept
msvcrt.dll
0x10008048 memset
ADVAPI32.dll
0x10008000 AddUsersToEncryptedFile
0x10008004 RegOverridePredefKey
MPRAPI.dll
0x10008020 MprInfoDelete
SHLWAPI.dll
0x10008028 PathRemoveBlanksA
KERNEL32.dll
0x1000800c GlobalSize
0x10008010 CloseHandle
0x10008014 GetModuleFileNameA
0x10008018 OutputDebugStringA
EAT(Export Address Table) is none