Report - hak.exe

Formbook PE File PE32
ScreenShot
Created 2021.09.28 16:16 Machine s1_win7_x6402
Filename hak.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
9
Behavior Score
3.2
ZERO API file : malware
VT API (file) 43 detected (AIDetect, malware1, malicious, high confidence, Razy, GenericRXLS, Unsafe, Formbook, Eldorado, ccmw, Siggen9, A + Troj, ZPACK, ai score=85, score, BScope, TrojanPSW, Generic@ML, RDML, mAbFVIx0MKNPsSp0, 0mlww, Static AI, Malicious PE, GenKryptik, AYEB, confidence)
md5 3b710cc2fd2ed7c2c71e88b128cb1297
sha256 0c22acaa973cbb781aea92dc1fb5a8c7cc1fd2abd403f2a6b9703f8f1e1c8657
ssdeep 3072:QspeY2fikqwsoKMDwDNBit6hFEYtLXq4lyQaZ:QRnz27MDkXit6hFEQq4lyQ0
imphash
impfuzzy 3::
  Network IP location

Signature (6cnts)

Level Description
danger File has been identified by 43 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Checks for the Locally Unique Identifier on the system for a suspicious privilege
notice HTTP traffic contains suspicious features which may be indicative of malware related traffic
notice Performs some HTTP requests
notice The binary likely contains encrypted or compressed data indicative of a packer

Rules (3cnts)

Level Name Description Collection
danger Win_Trojan_Formbook_Zero Used Formbook binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (40cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://www.socialmediaplugin.com/mjyv/?uTuD=OU27+ysrGKu/jK/yOqR5sqFza95Uvw+WRzi5j7TKNAgvfz99QkpIgkjRoF2Ht6HwV+67RAOW&Kj6dY=ATxxQ4G DE AMAZON-02 52.58.78.16 clean
http://www.calmingscience.com/mjyv/?uTuD=88UrMb6q8kEA6d0RMNJBQg7TjSnN5axFSt02V9alnUE8WVXARanhd7Zn9ZpbXjvnPJPP0laE&Kj6dY=ATxxQ4G US CLOUDFLARENET 172.67.215.123 clean
http://www.upgradepklohb.xyz/mjyv/?uTuD=9dnvdWURialXEyaz2ywPsOoM6gGuiR5AxFBltEEFKs81axtXl2dPjYUDr1hLwXJCVRBcbtND&Kj6dY=ATxxQ4G US NAMECHEAP-NET 198.54.117.216 clean
http://www.bjjinmei.com/mjyv/?uTuD=tK48cpNOceqqCiIAD7hTSWdfMm0U+M5ICQ0DMQW4dcqulfLFmq83X0mVZBBYriEB2HGVoedd&Kj6dY=ATxxQ4G US IKGUL-26484 154.205.217.133 clean
http://www.healthylifefit.com/mjyv/?uTuD=wu4G29Df/3jk6rtufY07T1aH5SRRTSPupQ0Am8+JIxBphBMLoCuvIjFknaaw90h7xGBdC+KC&Kj6dY=ATxxQ4G US CLOUDFLARENET 104.16.13.194 clean
http://www.volteraenergy.net/mjyv/?uTuD=6GSsGhXNJ4X+IglcYBeGMK5UD+vC/aYPjEqHkj3TutxRiNJSuqpeM1lWW/9MfcCLuZzXea82&Kj6dY=ATxxQ4G US GOOGLE 34.102.136.180 clean
http://www.chatcure.com/mjyv/?uTuD=Q1v42zleUYIi8flkghcQmr8tAyGjsl4sXlxb78q+SjvyPDjFfh7215Q2cKPJE2klAkGZe5l7&Kj6dY=ATxxQ4G US AMAZON-AES 52.20.84.62 clean
http://www.single-on-purpose.com/mjyv/?uTuD=Q7OMrrO86y0JqdY0g4bf91NmCgnX6BTekei23iJFdfIv5eDZ2hVr8AZAqZJxsWpRuuzn5HXG&Kj6dY=ATxxQ4G US AUTOMATTIC 192.0.78.24 clean
http://www.simpeltattofor.men/mjyv/?uTuD=YF19YjsW8YJ3UOve4Qb3KBW5CTiNCbLMIoRIqgRYw5C7pHv6F5Yv7+2MVeO4kquiRvNeMbg8&Kj6dY=ATxxQ4G AU Trellian Pty. Limited 103.224.182.210 clean
http://www.ziototoristorante.com/mjyv/?uTuD=BGF3MaDqcKXz2+ypQpBN49HcofQtIb5uumrf5yGZXgK71e6jsOADztt5ugiiGjAz+eZLHYvw&Kj6dY=ATxxQ4G US BODIS-NJ 199.59.242.153 clean
http://www.murdabudz.com/mjyv/?uTuD=hg13/nVpXa7sw8wTOoVMHFZDgDUsR9Gv/arf8487HKoYm/D9BgH6B8HPQM6vzvqD84xy947Y&Kj6dY=ATxxQ4G SG AS-26496-GO-DADDY-COM-LLC 182.50.132.242 clean
http://www.welcome-sber.store/mjyv/?uTuD=Kv+/SJ7M/lzJbcaI/wLw7bttHXU14P8fHaqyHUXbe+/kB7RUPLEP6r3tla+4qncMfsOmfoJX&Kj6dY=ATxxQ4G RU Beget LLC 87.236.16.91 clean
www.socialmediaplugin.com DE AMAZON-02 52.58.78.16 clean
www.wenyuexuan.com Unknown clean
www.simpeltattofor.men AU Trellian Pty. Limited 103.224.182.210 clean
www.single-on-purpose.com US AUTOMATTIC 192.0.78.24 clean
www.reemletenleafy.com Unknown clean
www.ziototoristorante.com US BODIS-NJ 199.59.242.153 clean
www.ventasdecasasylotes.xyz Unknown clean
www.murdabudz.com SG AS-26496-GO-DADDY-COM-LLC 182.50.132.242 clean
www.chatcure.com US AMAZON-AES 52.20.84.62 clean
www.welcome-sber.store RU Beget LLC 87.236.16.91 clean
www.calmingscience.com US CLOUDFLARENET 104.21.51.3 clean
www.bjjinmei.com US IKGUL-26484 154.205.217.133 clean
www.miyonbuilding.com Unknown clean
www.healthylifefit.com US CLOUDFLARENET 104.16.13.194 clean
www.volteraenergy.net US GOOGLE 34.102.136.180 clean
www.upgradepklohb.xyz US NAMECHEAP-NET 198.54.117.216 clean
87.236.16.91 RU Beget LLC 87.236.16.91 mailcious
52.20.84.62 US AMAZON-AES 52.20.84.62 mailcious
154.205.217.133 US IKGUL-26484 154.205.217.133 clean
52.58.78.16 DE AMAZON-02 52.58.78.16 mailcious
34.102.136.180 US GOOGLE 34.102.136.180 mailcious
199.59.242.153 US BODIS-NJ 199.59.242.153 mailcious
104.21.51.3 US CLOUDFLARENET 104.21.51.3 clean
103.224.182.210 AU Trellian Pty. Limited 103.224.182.210 phishing
198.54.117.210 US NAMECHEAP-NET 198.54.117.210 mailcious
192.0.78.24 US AUTOMATTIC 192.0.78.24 mailcious
182.50.132.242 SG AS-26496-GO-DADDY-COM-LLC 182.50.132.242 mailcious
104.16.14.194 US CLOUDFLARENET 104.16.14.194 clean

Suricata ids

PE API

IAT(Import Address Table) is none

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure