ScreenShot
Created | 2021.10.18 09:53 | Machine | s1_win7_x6401 |
Filename | e8084ec4de8c64eabd3169cee9ac27bc.exe | ||
Type | PE32 executable (console) Intel 80386, for MS Windows | ||
AI Score |
|
Behavior Score |
|
ZERO API | file : clean | ||
VT API (file) | 29 detected (GenericKD, Unsafe, Mokes, AGen, TrojanX, GenericUHMLFNG, Score, Redcap, hcbfx, ai score=81, kcloud, Tnega, Malicious, BScope, Dzki, PossibleThreat, GdSda) | ||
md5 | 1c58be0a33997195e1e9dbc5b9298ec6 | ||
sha256 | 88e993e9749fc01b654faadb511143d5f6530496ac1013d075342a053d64bb2f | ||
ssdeep | 1536:q+T6H2NTQCqdNeTOG/Yyz17QmSYYIKgD3DDO7y8VNCYX/isWcgIcdnws8nBs0HWm:q+JTqPatQy57QGYFq3Dy7yKCS6JnNwWm | ||
imphash | 2b20eeb6148aabd0fc53f3237cfb9a38 | ||
impfuzzy | 24:FXlEubD3HMUsviucH4GcStIS18YbJh9roHOovbOuqNy3T3wxCEYBqEEQm:h9H6EcStIS1RDZB3dnHYC9 |
Network IP location
Signature (5cnts)
Level | Description |
---|---|
warning | File has been identified by 29 AntiVirus engines on VirusTotal as malicious |
notice | Checks adapter addresses which can be used to detect virtual network interfaces |
notice | Performs some HTTP requests |
info | Checks amount of memory in system |
info | The executable contains unknown PE section names indicative of a packer (could be a false positive) |
Rules (5cnts)
Level | Name | Description | Collection |
---|---|---|---|
watch | Malicious_Library_Zero | Malicious_Library | binaries (upload) |
watch | UPX_Zero | UPX packed file | binaries (upload) |
info | IsPE32 | (no description) | binaries (upload) |
info | OS_Processor_Check_Zero | OS Processor Check | binaries (upload) |
info | PE_Header_Zero | PE File Signature | binaries (upload) |
Network (5cnts) ?
Suricata ids
SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee)
PE API
IAT(Import Address Table) Library
KERNEL32.dll
0x40f000 WriteFile
0x40f004 InterlockedDecrement
0x40f008 InitializeCriticalSectionAndSpinCount
0x40f00c CreateFileW
0x40f010 GetLastError
0x40f014 RaiseException
0x40f018 DecodePointer
0x40f01c GetProcAddress
0x40f020 DeleteCriticalSection
0x40f024 GetModuleHandleW
0x40f028 WriteConsoleW
0x40f02c SetFilePointerEx
0x40f030 GetConsoleMode
0x40f034 GetConsoleCP
0x40f038 FlushFileBuffers
0x40f03c GetStringTypeW
0x40f040 SetStdHandle
0x40f044 CloseHandle
0x40f048 GetFileType
0x40f04c GetProcessHeap
0x40f050 SetEnvironmentVariableA
0x40f054 FreeEnvironmentStringsW
0x40f058 GetEnvironmentStringsW
0x40f05c GetCPInfo
0x40f060 IsDebuggerPresent
0x40f064 OutputDebugStringW
0x40f068 EnterCriticalSection
0x40f06c LeaveCriticalSection
0x40f070 MultiByteToWideChar
0x40f074 WideCharToMultiByte
0x40f078 LocalFree
0x40f07c UnhandledExceptionFilter
0x40f080 SetUnhandledExceptionFilter
0x40f084 GetCurrentProcess
0x40f088 TerminateProcess
0x40f08c IsProcessorFeaturePresent
0x40f090 GetStartupInfoW
0x40f094 QueryPerformanceCounter
0x40f098 GetCurrentProcessId
0x40f09c GetCurrentThreadId
0x40f0a0 GetSystemTimeAsFileTime
0x40f0a4 InitializeSListHead
0x40f0a8 EncodePointer
0x40f0ac RtlUnwind
0x40f0b0 SetLastError
0x40f0b4 TlsAlloc
0x40f0b8 TlsGetValue
0x40f0bc TlsSetValue
0x40f0c0 TlsFree
0x40f0c4 FreeLibrary
0x40f0c8 LoadLibraryExW
0x40f0cc ExitProcess
0x40f0d0 GetModuleHandleExW
0x40f0d4 GetModuleFileNameA
0x40f0d8 GetStdHandle
0x40f0dc GetCommandLineA
0x40f0e0 GetCommandLineW
0x40f0e4 GetACP
0x40f0e8 HeapFree
0x40f0ec HeapAlloc
0x40f0f0 HeapSize
0x40f0f4 HeapReAlloc
0x40f0f8 CompareStringW
0x40f0fc LCMapStringW
0x40f100 FindClose
0x40f104 FindFirstFileExA
0x40f108 FindNextFileA
0x40f10c IsValidCodePage
0x40f110 GetOEMCP
ole32.dll
0x40f14c CoInitializeSecurity
0x40f150 CoSetProxyBlanket
0x40f154 CoCreateInstance
OLEAUT32.dll
0x40f118 SafeArrayGetDim
0x40f11c VariantInit
0x40f120 SafeArrayGetUBound
0x40f124 SafeArrayGetLBound
0x40f128 SysFreeString
0x40f12c SysStringByteLen
0x40f130 SysAllocStringByteLen
0x40f134 SysAllocString
0x40f138 SafeArrayUnaccessData
0x40f13c SafeArrayAccessData
0x40f140 VariantClear
0x40f144 GetErrorInfo
EAT(Export Address Table) is none
KERNEL32.dll
0x40f000 WriteFile
0x40f004 InterlockedDecrement
0x40f008 InitializeCriticalSectionAndSpinCount
0x40f00c CreateFileW
0x40f010 GetLastError
0x40f014 RaiseException
0x40f018 DecodePointer
0x40f01c GetProcAddress
0x40f020 DeleteCriticalSection
0x40f024 GetModuleHandleW
0x40f028 WriteConsoleW
0x40f02c SetFilePointerEx
0x40f030 GetConsoleMode
0x40f034 GetConsoleCP
0x40f038 FlushFileBuffers
0x40f03c GetStringTypeW
0x40f040 SetStdHandle
0x40f044 CloseHandle
0x40f048 GetFileType
0x40f04c GetProcessHeap
0x40f050 SetEnvironmentVariableA
0x40f054 FreeEnvironmentStringsW
0x40f058 GetEnvironmentStringsW
0x40f05c GetCPInfo
0x40f060 IsDebuggerPresent
0x40f064 OutputDebugStringW
0x40f068 EnterCriticalSection
0x40f06c LeaveCriticalSection
0x40f070 MultiByteToWideChar
0x40f074 WideCharToMultiByte
0x40f078 LocalFree
0x40f07c UnhandledExceptionFilter
0x40f080 SetUnhandledExceptionFilter
0x40f084 GetCurrentProcess
0x40f088 TerminateProcess
0x40f08c IsProcessorFeaturePresent
0x40f090 GetStartupInfoW
0x40f094 QueryPerformanceCounter
0x40f098 GetCurrentProcessId
0x40f09c GetCurrentThreadId
0x40f0a0 GetSystemTimeAsFileTime
0x40f0a4 InitializeSListHead
0x40f0a8 EncodePointer
0x40f0ac RtlUnwind
0x40f0b0 SetLastError
0x40f0b4 TlsAlloc
0x40f0b8 TlsGetValue
0x40f0bc TlsSetValue
0x40f0c0 TlsFree
0x40f0c4 FreeLibrary
0x40f0c8 LoadLibraryExW
0x40f0cc ExitProcess
0x40f0d0 GetModuleHandleExW
0x40f0d4 GetModuleFileNameA
0x40f0d8 GetStdHandle
0x40f0dc GetCommandLineA
0x40f0e0 GetCommandLineW
0x40f0e4 GetACP
0x40f0e8 HeapFree
0x40f0ec HeapAlloc
0x40f0f0 HeapSize
0x40f0f4 HeapReAlloc
0x40f0f8 CompareStringW
0x40f0fc LCMapStringW
0x40f100 FindClose
0x40f104 FindFirstFileExA
0x40f108 FindNextFileA
0x40f10c IsValidCodePage
0x40f110 GetOEMCP
ole32.dll
0x40f14c CoInitializeSecurity
0x40f150 CoSetProxyBlanket
0x40f154 CoCreateInstance
OLEAUT32.dll
0x40f118 SafeArrayGetDim
0x40f11c VariantInit
0x40f120 SafeArrayGetUBound
0x40f124 SafeArrayGetLBound
0x40f128 SysFreeString
0x40f12c SysStringByteLen
0x40f130 SysAllocStringByteLen
0x40f134 SysAllocString
0x40f138 SafeArrayUnaccessData
0x40f13c SafeArrayAccessData
0x40f140 VariantClear
0x40f144 GetErrorInfo
EAT(Export Address Table) is none