Report - ne983n8sn3lks3.exe

BlackMatter Ransomware PE File PE32
ScreenShot
Created 2023.05.22 08:59 Machine s1_win7_x6401
Filename ne983n8sn3lks3.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
11
Behavior Score
2.2
ZERO API file : malware
VT API (file) 57 detected (AIDetectMalware, Mint, Zard, Lockbit, S28885638, Qadars, Banking, Filecoder, Save, LockBit30, malicious, Eldorado, Windows, Ransomware, BlackMatter, score, ccmw, ZeroAccess, Gen7, SMYXCJN, high, Static AI, Suspicious PE, Crypmodng, Detected, R521581, ai score=82, unsafe, Genetic, CLASSIC, Rr0XixrjzqM, Outbreak, susgen, confidence, 100%)
md5 a96ac42f9ccc7d11663f2741d5dfe930
sha256 b923f1d2ece074dabe58bb6a603ed5d49e8d62044a1293a37e8afbcac029dded
ssdeep 3072:q6glyuxE4GsUPnliByocWepqzYq7G9HkRgeXCDy8MD5:q6gDBGpvEByocWe4Y7pkRgeS28MD5
imphash 41fb8cb2943df6de998b35a9d28668e8
impfuzzy 12:J9WMjUYA/mlAaByBaWtJT14yFE6BJNCQ6UaJjAGtbJpOGOovC:JpAYA/KAaBSvR14yFEkJNCQ6UaJjtFpE
  Network IP location

Signature (4cnts)

Level Description
danger File has been identified by 57 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice The binary likely contains encrypted or compressed data indicative of a packer
info The executable contains unknown PE section names indicative of a packer (could be a false positive)

Rules (3cnts)

Level Name Description Collection
danger BlackMatter_Ransomware_IN BlackMatter Ransomware binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

gdi32.dll
 0x41a050 SetPixel
 0x41a054 SetDCBrushColor
 0x41a058 SelectPalette
 0x41a05c GetTextColor
 0x41a060 GetDeviceCaps
 0x41a064 CreateSolidBrush
USER32.dll
 0x41a020 DefWindowProcW
 0x41a024 CreateMenu
 0x41a028 EndDialog
 0x41a02c GetDlgItem
 0x41a030 GetKeyNameTextW
 0x41a034 GetMessageW
 0x41a038 GetWindowTextW
 0x41a03c IsDlgButtonChecked
 0x41a040 LoadImageW
 0x41a044 LoadMenuW
 0x41a048 DialogBoxParamW
KERNEL32.dll
 0x41a000 SetLastError
 0x41a004 LoadLibraryW
 0x41a008 GetTickCount
 0x41a00c GetLastError
 0x41a010 GetCommandLineW
 0x41a014 GetCommandLineA
 0x41a018 FreeLibrary

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure