Report - t.msi

Gen2 Malicious Library ASPack UPX OS Processor Check CAB MSOffice File DLL PE32 PE File
ScreenShot
Created 2023.03.27 10:57 Machine s1_win7_x6401
Filename t.msi
Type Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code pa
AI Score Not founds Behavior Score
6.2
ZERO API file : clean
VT API (file) 7 detected (NetFilter, A potentially unsafe, ZJJwIJgT9j, Artemis, Teramind, Malware@#2v55sd6wgpsq7)
md5 a62037c1812df2774da6257f465d5b78
sha256 dc97da11663e5a9041962e5457291bb888c974bc13c89af37403c32973814e8c
ssdeep 786432:syLPvc48WEw3PYHrqavl0ztWtjZanLHmUhg24yVs3:BLP048dwfYHhq2YnLFi2j
imphash
impfuzzy
  Network IP location

Signature (13cnts)

Level Description
danger Connects to IP addresses that are no longer responding to requests (legitimate services will remain up-and-running usually)
watch Communicates with host for which no DNS query was performed
watch One or more of the buffers contains an embedded PE file
notice Allocates read-write-execute memory (usually to unpack itself)
notice Checks for the Locally Unique Identifier on the system for a suspicious privilege
notice Drops an executable to the user AppData folder
notice File has been identified by 7 AntiVirus engines on VirusTotal as malicious
notice One or more potentially interesting buffers were extracted
notice Performs some HTTP requests
notice Queries the disk size which could be used to detect virtual machine with small fixed size or dynamic allocation
info Checks amount of memory in system
info Checks if process is being debugged by a debugger
info Queries for the computername

Rules (12cnts)

Level Name Description Collection
watch ASPack_Zero ASPack packed file binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (download)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (download)
info CAB_file_format CAB archive file binaries (upload)
info IsDLL (no description) binaries (download)
info IsPE32 (no description) binaries (download)
info Microsoft_Office_File_Zero Microsoft Office File binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (download)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (download)
info Win32_Trojan_Gen_2_0904B0_Zero Win32 Trojan Gen binaries (upload)

Network (12cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEAP7r%2BFw4Evn1FZeRLt68uo%3D US EDGECAST 152.195.38.76 clean
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAewQY2lHhSMMxu83rcTgyM%3D US EDGECAST 152.195.38.76 clean
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDZGCsCkDHH%2BXwJVKt4ohdOTWBUQQUy1yTroib%2FkNvVlBSAm14%2FKzhsVoCEA1e%2BQMDwigDd9%2FgTXTiCGE%3D US EDGECAST 152.195.38.76 clean
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAPxtOFfOoLxFJZ4s9fYR1w%3D US EDGECAST 152.195.38.76 clean
ocsp.digicert.com US EDGECAST 152.195.38.76 clean
rt.teramind.co Unknown 132.226.193.252 clean
www.teramind.co US CLOUDFLARENET 104.22.19.138 clean
172.67.26.154 US CLOUDFLARENET 172.67.26.154 clean
152.195.38.76 US EDGECAST 152.195.38.76 clean
104.22.18.138 US CLOUDFLARENET 104.22.18.138 clean
141.144.250.131 GB NETDYNAMICS 141.144.250.131 clean
132.226.193.252 Unknown 132.226.193.252 clean

Suricata ids



Similarity measure (PE file only) - Checking for service failure