ScreenShot
Created | 2021.09.02 11:16 | Machine | s1_win7_x6402 |
Filename | wget.exe | ||
Type | PE32+ executable (console) x86-64, for MS Windows | ||
AI Score |
|
Behavior Score |
|
ZERO API | file : malware | ||
VT API (file) | 7 detected (malicious, confidence, score, Generic ML PUA, Trickbot, Artemis) | ||
md5 | a445cf765b601d2a815968b623823088 | ||
sha256 | 26af39550affc09be4ddb80a2b7a0ff2888227e9993751bd9ac8460656b56e85 | ||
ssdeep | 49152:ipHfJrUWHOGEm5B/1iBcXGxlIzrLxMLy//tUcgtzGRC1GbR0MNUO6KUjFHd4uY:ipHfJrfuGEmb1iBcIlSLeO/7mzGRC19O | ||
imphash | 089dfe3c8f6fb17df254dd8a884e1420 | ||
impfuzzy | 6:omRgAAKXKBJAEoZ/OEGDzyRfychbK1QtwD0:omRgAAdABZG/DzktwD0 |
Network IP location
Signature (3cnts)
Level | Description |
---|---|
notice | File has been identified by 7 AntiVirus engines on VirusTotal as malicious |
notice | The binary likely contains encrypted or compressed data indicative of a packer |
notice | The executable is compressed using UPX |
Rules (3cnts)
Level | Name | Description | Collection |
---|---|---|---|
watch | Malicious_Library_Zero | Malicious_Library | binaries (upload) |
info | IsPE64 | (no description) | binaries (upload) |
info | PE_Header_Zero | PE File Signature | binaries (upload) |
Network (0cnts) ?
Request | CC | ASN Co | IP4 | Rule ? | ZERO ? |
---|
Suricata ids
PE API
IAT(Import Address Table) Library
ADVAPI32.dll
0x8df0b4 RegCloseKey
CRYPT32.dll
0x8df0c4 CertOpenStore
KERNEL32.DLL
0x8df0d4 LoadLibraryA
0x8df0dc ExitProcess
0x8df0e4 GetProcAddress
0x8df0ec VirtualProtect
msvcrt.dll
0x8df0fc _dup
ole32.dll
0x8df10c CoInitializeEx
SHELL32.dll
0x8df11c SHGetSpecialFolderPathW
USER32.dll
0x8df12c MessageBoxA
WS2_32.dll
0x8df13c ind
EAT(Export Address Table) is none
ADVAPI32.dll
0x8df0b4 RegCloseKey
CRYPT32.dll
0x8df0c4 CertOpenStore
KERNEL32.DLL
0x8df0d4 LoadLibraryA
0x8df0dc ExitProcess
0x8df0e4 GetProcAddress
0x8df0ec VirtualProtect
msvcrt.dll
0x8df0fc _dup
ole32.dll
0x8df10c CoInitializeEx
SHELL32.dll
0x8df11c SHGetSpecialFolderPathW
USER32.dll
0x8df12c MessageBoxA
WS2_32.dll
0x8df13c ind
EAT(Export Address Table) is none