ScreenShot
Created | 2021.08.09 20:46 | Machine | s1_win7_x6401 |
Filename | dcj83r7fy7328.exe | ||
Type | PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows | ||
AI Score |
|
Behavior Score |
|
ZERO API | file : malware | ||
VT API (file) | 44 detected (malicious, high confidence, GenericKD, Artemis, Unsafe, tetqvx, GoCLR, a variant of WinGo, Bulz, HackTool, CLASSIC, R002C0WH621, CobaltStrike, Score, 100%, AGEN, Mamson, R426638, ai score=83, zJ+7ehHYawY, susgen, confidence, H8oADAcA) | ||
md5 | 86178014e457120d9dc6f6e27453338c | ||
sha256 | d541b9ff1fd68818abd9d0f70966e97beaab82dd6bb32d66566fbd6d657fbfd8 | ||
ssdeep | 49152:+G6we2P/3W01/65p9CepD70BIme1AWwYg015Y5vl5zytq9oB5JSZZSYu5q01ka2i:+32P/d/s | ||
imphash | 4035d2883e01d64f3e7a9dccb1d63af5 | ||
impfuzzy | 24:UbVjhN5O+VuT2oLtXOr6kwmDruMztxdEr6UP:K5O+VAXOmGx0nP |
Network IP location
Signature (3cnts)
Level | Description |
---|---|
danger | File has been identified by 44 AntiVirus engines on VirusTotal as malicious |
watch | Detects the presence of Wine emulator |
info | The executable contains unknown PE section names indicative of a packer (could be a false positive) |
Rules (8cnts)
Level | Name | Description | Collection |
---|---|---|---|
danger | NPKI_Zero | File included NPKI | binaries (upload) |
warning | Generic_Malware_Zero | Generic Malware | binaries (upload) |
watch | Malicious_Library_Zero | Malicious_Library | binaries (upload) |
watch | Malicious_Packer_Zero | Malicious Packer | binaries (upload) |
watch | UPX_Zero | UPX packed file | binaries (upload) |
notice | anti_vm_detect | Possibly employs anti-virtualization techniques | binaries (upload) |
info | IsPE64 | (no description) | binaries (upload) |
info | PE_Header_Zero | PE File Signature | binaries (upload) |
Network (0cnts) ?
Request | CC | ASN Co | IP4 | Rule ? | ZERO ? |
---|
Suricata ids
PE API
IAT(Import Address Table) Library
kernel32.dll
0x9ec020 WriteFile
0x9ec028 WriteConsoleW
0x9ec030 WaitForMultipleObjects
0x9ec038 WaitForSingleObject
0x9ec040 VirtualQuery
0x9ec048 VirtualFree
0x9ec050 VirtualAlloc
0x9ec058 SwitchToThread
0x9ec060 SuspendThread
0x9ec068 Sleep
0x9ec070 SetWaitableTimer
0x9ec078 SetUnhandledExceptionFilter
0x9ec080 SetProcessPriorityBoost
0x9ec088 SetEvent
0x9ec090 SetErrorMode
0x9ec098 SetConsoleCtrlHandler
0x9ec0a0 ResumeThread
0x9ec0a8 PostQueuedCompletionStatus
0x9ec0b0 LoadLibraryA
0x9ec0b8 LoadLibraryW
0x9ec0c0 SetThreadContext
0x9ec0c8 GetThreadContext
0x9ec0d0 GetSystemInfo
0x9ec0d8 GetSystemDirectoryA
0x9ec0e0 GetStdHandle
0x9ec0e8 GetQueuedCompletionStatusEx
0x9ec0f0 GetProcessAffinityMask
0x9ec0f8 GetProcAddress
0x9ec100 GetEnvironmentStringsW
0x9ec108 GetConsoleMode
0x9ec110 FreeEnvironmentStringsW
0x9ec118 ExitProcess
0x9ec120 DuplicateHandle
0x9ec128 CreateWaitableTimerExW
0x9ec130 CreateThread
0x9ec138 CreateIoCompletionPort
0x9ec140 CreateEventA
0x9ec148 CloseHandle
0x9ec150 AddVectoredExceptionHandler
EAT(Export Address Table) is none
kernel32.dll
0x9ec020 WriteFile
0x9ec028 WriteConsoleW
0x9ec030 WaitForMultipleObjects
0x9ec038 WaitForSingleObject
0x9ec040 VirtualQuery
0x9ec048 VirtualFree
0x9ec050 VirtualAlloc
0x9ec058 SwitchToThread
0x9ec060 SuspendThread
0x9ec068 Sleep
0x9ec070 SetWaitableTimer
0x9ec078 SetUnhandledExceptionFilter
0x9ec080 SetProcessPriorityBoost
0x9ec088 SetEvent
0x9ec090 SetErrorMode
0x9ec098 SetConsoleCtrlHandler
0x9ec0a0 ResumeThread
0x9ec0a8 PostQueuedCompletionStatus
0x9ec0b0 LoadLibraryA
0x9ec0b8 LoadLibraryW
0x9ec0c0 SetThreadContext
0x9ec0c8 GetThreadContext
0x9ec0d0 GetSystemInfo
0x9ec0d8 GetSystemDirectoryA
0x9ec0e0 GetStdHandle
0x9ec0e8 GetQueuedCompletionStatusEx
0x9ec0f0 GetProcessAffinityMask
0x9ec0f8 GetProcAddress
0x9ec100 GetEnvironmentStringsW
0x9ec108 GetConsoleMode
0x9ec110 FreeEnvironmentStringsW
0x9ec118 ExitProcess
0x9ec120 DuplicateHandle
0x9ec128 CreateWaitableTimerExW
0x9ec130 CreateThread
0x9ec138 CreateIoCompletionPort
0x9ec140 CreateEventA
0x9ec148 CloseHandle
0x9ec150 AddVectoredExceptionHandler
EAT(Export Address Table) is none