Report - 1.dll

PWS Loki[b] Loki[m] Kpot stealer Malicious Library PE File DLL PE32
ScreenShot
Created 2021.08.02 10:26 Machine s1_win7_x6402
Filename 1.dll
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
AI Score
6
Behavior Score
2.0
ZERO API file : clean
VT API (file) 46 detected (malicious, high confidence, Ursu, Trojanpws, Kpot, Generic PWS, Unsafe, TrojanPSW, Tiggre, confidence, 100%, ZedlaF, jm4@aayQqrk, RFSX, Attribute, HighConfidence, Malware@#17ov49eddpq4r, R002C0PGQ21, rtyvq, PSWTroj, kcloud, score, ai score=82, Gozi, Generic@ML, RDMK, Y9FH508plRniVLZcWQpIMQ, ua8HUFS3s, susgen, GdSda, HygBueAA)
md5 1ea7d46d94299fa8bad4043c13100df0
sha256 12f790d9a0775b5e62effc6ea9e55bbef345fffbfb2f671f85098c4f7661dd0f
ssdeep 3072:duNxJ3d1L5Evs7bV+odOqAfS0OZ7shc6U85lplnizXz4Ls9kmh3:duNxX1L5EvUModfX0OWhc6F4zqs9kA
imphash 536a622ab5c7198822e97fa200e881b1
impfuzzy 3:sU9KnJ6gPnXI4MKLF7Mzt4IOEVMGW3EmELVKJ8n:HUP/MKBoZrVQEzVKJ8
  Network IP location

Signature (4cnts)

Level Description
danger File has been identified by 46 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
info Checks amount of memory in system
info Checks if process is being debugged by a debugger

Rules (6cnts)

Level Name Description Collection
danger Kpot_stealer_IN Kpot Stealer binaries (upload)
danger Win32_PWS_Loki_Zero Win32 PWS Loki binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
info IsDLL (no description) binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (2cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
donattelli.com ES Soluciones web on line s.l. 185.92.244.225 clean
185.92.244.225 ES Soluciones web on line s.l. 185.92.244.225 clean

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.dll
 0x10001014 GetProcessHeap
ADVAPI32.dll
 0x10001000 LsaQueryInformationPolicy
 0x10001004 LsaFreeMemory
 0x10001008 LsaClose
 0x1000100c LsaOpenPolicy

EAT(Export Address Table) Library

0x10021209 Install
0x1002121f __DllMainCRTStartup@12


Similarity measure (PE file only) - Checking for service failure