Report - soccer.png

PE File PE32 DLL
ScreenShot
Created 2021.11.09 10:23 Machine s1_win7_x6403
Filename soccer.png
Type PE32 executable (DLL) (native) Intel 80386, for MS Windows
AI Score
6
Behavior Score
5.4
ZERO API file : clean
VT API (file)
md5 292276fb4e37646aeca245bffb21ef21
sha256 3ebc7d218c7d0d201d79fd4dc01e42364772370b0cc5aaf93ff40fae1dd7e641
ssdeep 6144:1uNDZo15/Lb175yZhtHQqPm52aYYiHx/874uQYKJHD4YdYrde7:qDSHL575qLP0tKJHZ1
imphash 17cd9f87fbb27686b2cd8f8d33695e92
impfuzzy 6:/87mRxn5XobPbmRxGZRHmRxaj7bCmRxVUAo:kqRJJobiRgARQj7pRdo
  Network IP location

Signature (13cnts)

Level Description
danger Connects to an IP address that is no longer responding to requests (legitimate services will remain up-and-running usually)
watch Communicates with host for which no DNS query was performed
notice Allocates read-write-execute memory (usually to unpack itself)
notice Checks adapter addresses which can be used to detect virtual network interfaces
notice Checks for the Locally Unique Identifier on the system for a suspicious privilege
notice Creates a suspicious process
notice HTTP traffic contains suspicious features which may be indicative of malware related traffic
notice One or more potentially interesting buffers were extracted
notice Performs some HTTP requests
notice Terminates another process
info Checks if process is being debugged by a debugger
info One or more processes crashed
info Queries for the computername

Rules (3cnts)

Level Name Description Collection
info IsDLL (no description) binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (5cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
https://46.99.175.217/soc1/TEST22-PC_W617601.BBEDF130CF73A299F033BBC993DA0177/5/file/ AL IPKO Telecommunications LLC 46.99.175.217 5810 mailcious
216.166.148.187 US CYBERNET1 216.166.148.187 mailcious
45.36.99.184 US TWC-11426-CAROLINAS 45.36.99.184 mailcious
181.129.167.82 CO EPM Telecomunicaciones S.A. E.S.P. 181.129.167.82 mailcious
46.99.175.217 AL IPKO Telecommunications LLC 46.99.175.217 mailcious

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.dll
 0x100a5000 CreateFileA
 0x100a5004 LeaveCriticalSection
 0x100a5008 GetLastError
 0x100a500c WaitForMultipleObjects
 0x100a5010 EnterCriticalSection
 0x100a5014 InitializeCriticalSection
 0x100a5018 WaitForSingleObject
 0x100a501c WideCharToMultiByte
 0x100a5020 DeleteCriticalSection
 0x100a5024 GetCurrentThread

EAT(Export Address Table) Library

0x1006d0f0 TyreDokgW


Similarity measure (PE file only) - Checking for service failure