ScreenShot
Created 2022.10.10 15:06 Machine s1_win7_x6401
Filename ea47d.exe
Type PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
AI Score Not founds Behavior Score
0.0
ZERO API file : malware
VT API (file) 52 detected (Trojan.GenericKD.62083950, Trojan.Win64.S.InfoStealer.5344256, Win64.Trojan-QQPass.QQRob.Wmhl, Trojan.Obfuscated.Win32.113100, Win32.Troj.Generic_a.a.(kcloud), Unsafe, Malicious, BehavesLike.Win64.Trickbot.tc, malicious.95df19, Detected, Trojan.Win64.Packed.Vphy, Packed:Application/Obfuscated.ac1ca2fd, Artemis!96C4414583E7, HEUR/AGEN.1216915, Win64:Malware-gen, Ransom.Win64.Sabsik.ns, Trojan ( 0058e3dd1 ), Trojan.Malware.300983.susgen, ApplicUnwnt@#3gbcci43nz07u, W64/ABRisk.IHHN-5411, HEUR:Trojan-PSW.Win64.BroPass.pef, PUA.Obfuscated, Malware.Generic!8.BA4C (CLOUD), malicious (moderate confidence), Trojan.Multi, Adware/Backdoor_Win64_SILVER, Trojan.MalPack.GO, Trojan.Multi.Generic.4!c, Trj/Chgt.AD, a variant of WinGo/Packed.Obfuscated.A suspicious, Malicious (score: 100), Trojan.Siggen18.47425, Backdoor.Win64.SILVER.YXCIOZ, Trojan:Win32/Tiggre!rfn, Trojan.GenericKD.62083950 (B), suspicious.low.ml.score, Mal/Generic-S, generic.ml, Trojan.Win64.Genus.BJF, Trojan/Generic.ASMalwIH.31, malware (ai score=86), Trojan.Generic.D3B3536E, Trojan.Gen.MBT)
md5 96c4414583e7e3579777a353b83d28ec
sha256 1bc603353458914437c6691837f2fa04ce0eed5b1ab302da73bdf0cc7be470ee
ssdeep 98304:+y8fD+M1bSJYW+dTwjLIo8UKiO3Rkb/Fb5Ks5XXPaDdZdOOgKuDcEwB4WkjD8P:6fZOeW+RoRKimR2bIsJXis5nDcU5n
imphash 9aebf3da4677af9275c461261e5abde3
impfuzzy 3:swBJAEPw1MO/OywS9KTXzhAXwEQaxRGUq:dBJAEoZ/OEGDzyRs
  Network IP location

Signature (0cnts)

Level Description

Rules (0cnts)

Level Name Description Collection

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.DLL
 0x16c903c LoadLibraryA
 0x16c9044 ExitProcess
 0x16c904c GetProcAddress
 0x16c9054 VirtualProtect
msvcrt.dll
 0x16c9064 exit

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure