ScreenShot
Created | 2023.03.08 11:18 | Machine | s1_win7_x6401 |
Filename | nigga.exe | ||
Type | PE32 executable (GUI) Intel 80386, for MS Windows | ||
AI Score |
|
Behavior Score |
|
ZERO API | file : malware | ||
VT API (file) | 37 detected (Jaik, GenKryptik, malicious, confidence, 100%, Attribute, HighConfidence, high confidence, GGOH, score, FileRepMalware, Misc, Iqil, Artemis, XPACK, Casdet, Detected, ai score=86, BScope, Zbot, unsafe, Undefined, cXDm1r1m2sI, GenAsa, SyceT1P2laA, Static AI, Suspicious PE, ZexaF, Rq0@aWsJZ9pi) | ||
md5 | 01d648ecf27b3e9a6415af8fab167ac9 | ||
sha256 | 70ebead6ea8cac65cb1fccb593f7751c6f9ca56333a828d7ce1f9b5c4e23f47a | ||
ssdeep | 12288:19HFJI/fb/r6WEc0YqxK72b3VrX05jtPXqRTLn57I:19H/I/fbuWEc0VxKSb9XMtqNLn5 | ||
imphash | 039032eedb13fb00811bf4343043c31c | ||
impfuzzy | 3:sUx2AEZsU:nE7 |
Network IP location
Signature (3cnts)
Level | Description |
---|---|
danger | File has been identified by 37 AntiVirus engines on VirusTotal as malicious |
notice | Allocates read-write-execute memory (usually to unpack itself) |
info | One or more processes crashed |
Rules (2cnts)
Level | Name | Description | Collection |
---|---|---|---|
info | IsPE32 | (no description) | binaries (upload) |
info | PE_Header_Zero | PE File Signature | binaries (upload) |
Network (0cnts) ?
Request | CC | ASN Co | IP4 | Rule ? | ZERO ? |
---|
Suricata ids
PE API
IAT(Import Address Table) Library
KERNEL32.dll
0x47e000 GetModuleHandleA
0x47e004 HeapCreate
EAT(Export Address Table) is none
KERNEL32.dll
0x47e000 GetModuleHandleA
0x47e004 HeapCreate
EAT(Export Address Table) is none