Report - Singapore supply Quote#142574RWD Co, LTD.xll

Generic Malware Malicious Library UPX PE64 PE File OS Processor Check DLL
ScreenShot
Created 2021.10.25 17:33 Machine s1_win7_x6403
Filename Singapore supply Quote#142574RWD Co, LTD.xll
Type PE32+ executable (DLL) (GUI) x86-64, for MS Windows
AI Score
2
Behavior Score
1.0
ZERO API file : clean
VT API (file) 4 detected (Malware@#zwccpt07b3xx, ASMalwS, DOTHETUK, 59xMQMvn7qc)
md5 b649cfb75c80a2007de27dfa415ec12e
sha256 2cbcfdf0d8239ed8393f3d4c9f9641bf03aa786a4f7814dcf62bdd8633f75bbf
ssdeep 12288:Qn/zDvGHAykHSzLW/4+8bzbBSreMdVLOZBVCjeEQGW9qsVK1vzJTwHEmGiQttB5o:CzbGHAzHAjX1T35VP
imphash a31761b5a590c4c499d5f4a347d75c12
impfuzzy 48:aY9xOEttoXyzGpc+pEmM3ij//gja/wTHQL:aY/pttoXyzGpc+pEeVwrQL
  Network IP location

Signature (4cnts)

Level Description
notice File has been identified by 4 AntiVirus engines on VirusTotal as malicious
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The file contains an unknown PE resource name possibly indicative of a packer
info This executable has a PDB path

Rules (7cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsDLL (no description) binaries (upload)
info IsPE64 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids



Similarity measure (PE file only) - Checking for service failure