Report - e8084ec4de8c64eabd3169cee9ac27bc.exe

Malicious Library UPX PE File OS Processor Check PE32
ScreenShot
Created 2021.10.18 09:53 Machine s1_win7_x6401
Filename e8084ec4de8c64eabd3169cee9ac27bc.exe
Type PE32 executable (console) Intel 80386, for MS Windows
AI Score
2
Behavior Score
2.0
ZERO API file : clean
VT API (file) 29 detected (GenericKD, Unsafe, Mokes, AGen, TrojanX, GenericUHMLFNG, Score, Redcap, hcbfx, ai score=81, kcloud, Tnega, Malicious, BScope, Dzki, PossibleThreat, GdSda)
md5 1c58be0a33997195e1e9dbc5b9298ec6
sha256 88e993e9749fc01b654faadb511143d5f6530496ac1013d075342a053d64bb2f
ssdeep 1536:q+T6H2NTQCqdNeTOG/Yyz17QmSYYIKgD3DDO7y8VNCYX/isWcgIcdnws8nBs0HWm:q+JTqPatQy57QGYFq3Dy7yKCS6JnNwWm
imphash 2b20eeb6148aabd0fc53f3237cfb9a38
impfuzzy 24:FXlEubD3HMUsviucH4GcStIS18YbJh9roHOovbOuqNy3T3wxCEYBqEEQm:h9H6EcStIS1RDZB3dnHYC9
  Network IP location

Signature (5cnts)

Level Description
warning File has been identified by 29 AntiVirus engines on VirusTotal as malicious
notice Checks adapter addresses which can be used to detect virtual network interfaces
notice Performs some HTTP requests
info Checks amount of memory in system
info The executable contains unknown PE section names indicative of a packer (could be a false positive)

Rules (5cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (5cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://apps.identrust.com/roots/dstrootcax3.p7c KR Korea Telecom 222.122.182.200 clean
apps.identrust.com KR Korea Telecom 222.122.182.200 clean
t.gogamec.com US CLOUDFLARENET 172.67.204.112 clean
172.67.204.112 US CLOUDFLARENET 172.67.204.112 clean
121.254.136.57 KR LG DACOM Corporation 121.254.136.57 clean

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.dll
 0x40f000 WriteFile
 0x40f004 InterlockedDecrement
 0x40f008 InitializeCriticalSectionAndSpinCount
 0x40f00c CreateFileW
 0x40f010 GetLastError
 0x40f014 RaiseException
 0x40f018 DecodePointer
 0x40f01c GetProcAddress
 0x40f020 DeleteCriticalSection
 0x40f024 GetModuleHandleW
 0x40f028 WriteConsoleW
 0x40f02c SetFilePointerEx
 0x40f030 GetConsoleMode
 0x40f034 GetConsoleCP
 0x40f038 FlushFileBuffers
 0x40f03c GetStringTypeW
 0x40f040 SetStdHandle
 0x40f044 CloseHandle
 0x40f048 GetFileType
 0x40f04c GetProcessHeap
 0x40f050 SetEnvironmentVariableA
 0x40f054 FreeEnvironmentStringsW
 0x40f058 GetEnvironmentStringsW
 0x40f05c GetCPInfo
 0x40f060 IsDebuggerPresent
 0x40f064 OutputDebugStringW
 0x40f068 EnterCriticalSection
 0x40f06c LeaveCriticalSection
 0x40f070 MultiByteToWideChar
 0x40f074 WideCharToMultiByte
 0x40f078 LocalFree
 0x40f07c UnhandledExceptionFilter
 0x40f080 SetUnhandledExceptionFilter
 0x40f084 GetCurrentProcess
 0x40f088 TerminateProcess
 0x40f08c IsProcessorFeaturePresent
 0x40f090 GetStartupInfoW
 0x40f094 QueryPerformanceCounter
 0x40f098 GetCurrentProcessId
 0x40f09c GetCurrentThreadId
 0x40f0a0 GetSystemTimeAsFileTime
 0x40f0a4 InitializeSListHead
 0x40f0a8 EncodePointer
 0x40f0ac RtlUnwind
 0x40f0b0 SetLastError
 0x40f0b4 TlsAlloc
 0x40f0b8 TlsGetValue
 0x40f0bc TlsSetValue
 0x40f0c0 TlsFree
 0x40f0c4 FreeLibrary
 0x40f0c8 LoadLibraryExW
 0x40f0cc ExitProcess
 0x40f0d0 GetModuleHandleExW
 0x40f0d4 GetModuleFileNameA
 0x40f0d8 GetStdHandle
 0x40f0dc GetCommandLineA
 0x40f0e0 GetCommandLineW
 0x40f0e4 GetACP
 0x40f0e8 HeapFree
 0x40f0ec HeapAlloc
 0x40f0f0 HeapSize
 0x40f0f4 HeapReAlloc
 0x40f0f8 CompareStringW
 0x40f0fc LCMapStringW
 0x40f100 FindClose
 0x40f104 FindFirstFileExA
 0x40f108 FindNextFileA
 0x40f10c IsValidCodePage
 0x40f110 GetOEMCP
ole32.dll
 0x40f14c CoInitializeSecurity
 0x40f150 CoSetProxyBlanket
 0x40f154 CoCreateInstance
OLEAUT32.dll
 0x40f118 SafeArrayGetDim
 0x40f11c VariantInit
 0x40f120 SafeArrayGetUBound
 0x40f124 SafeArrayGetLBound
 0x40f128 SysFreeString
 0x40f12c SysStringByteLen
 0x40f130 SysAllocStringByteLen
 0x40f134 SysAllocString
 0x40f138 SafeArrayUnaccessData
 0x40f13c SafeArrayAccessData
 0x40f140 VariantClear
 0x40f144 GetErrorInfo

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure