Report - updatewin-21H2.exe

RAT Generic Malware PE64 PE File
ScreenShot
Created 2021.10.14 09:32 Machine s1_win7_x6402
Filename updatewin-21H2.exe
Type PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
AI Score
3
Behavior Score
2.6
ZERO API file : clean
VT API (file) 3 detected (Malicious, Seraph, Sabsik)
md5 1c978ed3ed7b3f6c428792697d5fade4
sha256 0dba0627fcf1b3a0c754c2e0a71cd15a73705719729a53feaa676bae9fb3fc23
ssdeep 192:CtwlMr8MIhI1SLj4+kFrtRoCKoCW0hyY8PGCz9QwAOWgSr/GQyBbd2/0rfwOzqN7:SW6FIK1SL34BrVyOzhVWpAY
imphash
impfuzzy 3::
  Network IP location

Signature (8cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice Checks adapter addresses which can be used to detect virtual network interfaces
notice File has been identified by 3 AntiVirus engines on VirusTotal as malicious
notice One or more potentially interesting buffers were extracted
notice Performs some HTTP requests
info Checks amount of memory in system
info Checks if process is being debugged by a debugger
info Collects information to fingerprint the system (MachineGuid

Rules (4cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (upload)
info IsPE64 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)
info Win_Backdoor_AsyncRAT_Zero Win Backdoor AsyncRAT binaries (upload)

Network (5cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://apps.identrust.com/roots/dstrootcax3.p7c US Akamai International B.V. 96.16.99.43 clean
apps.identrust.com US Akamai International B.V. 96.16.99.43 clean
store2.gofile.io Unknown 31.14.69.10 mailcious
61.111.58.34 KR LG DACOM Corporation 61.111.58.34 malware
31.14.69.10 Unknown 31.14.69.10 mailcious

Suricata ids

PE API

IAT(Import Address Table) is none

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure