ScreenShot
Created | 2023.05.29 13:29 | Machine | s1_win7_x6401 |
Filename | a02.exe | ||
Type | PE32 executable (GUI) Intel 80386, for MS Windows | ||
AI Score |
|
Behavior Score |
|
ZERO API | file : malware | ||
VT API (file) | 52 detected (AIDetectMalware, DownLoader45, GenericKD, Artemis, Raccoon, V2hh, TrojanPSW, malicious, ZexaF, @tW@aaOmYHli, Genus, ABRisk, ZFDM, Attribute, HighConfidence, multiple detections, score, N6dZUwGRupJ, Nekark, lfcoo, R014C0DER23, Static AI, Malicious PE, ai score=82, CREC, Detected, BScope, unsafe, GdSda, Gencirc, VMProtect, NDAoF, confidence, 100%) | ||
md5 | 820241820224a5c7eed0ca74b7420361 | ||
sha256 | 7740df954417683f1614403a7fa6607e7b9002ae045e25a07c8fd4e67f0b3c3f | ||
ssdeep | 98304:x4S0clXTS9EIv1281Ey0l6iEz0JzA3+rBAlrHC3dNtCLChB:v/lX3I9R1EFlnxJzVA1ALI+hB | ||
imphash | 9f8af27f520ea359d999bd8cba16dec6 | ||
impfuzzy | 24:HDogrlY3Um8dkt/Oov/Gy2cfh/J3I+FQHRyv0T4cjMDM21jYTmqyyjmNzbR1FhyX:cUpGt2MGDcfjb0ctqmPoehNz5n8 |
Network IP location
Signature (24cnts)
Level | Description |
---|---|
danger | File has been identified by 52 AntiVirus engines on VirusTotal as malicious |
danger | Connects to an IP address that is no longer responding to requests (legitimate services will remain up-and-running usually) |
danger | Executed a process and injected code into it |
watch | Allocates execute permission to another process indicative of possible code injection |
watch | Checks for the presence of known windows from debuggers and forensic tools |
watch | Communicates with host for which no DNS query was performed |
watch | Installs itself for autorun at Windows startup |
watch | One or more of the buffers contains an embedded PE file |
watch | Resumed a suspended thread in a remote process potentially indicative of process injection |
watch | Used NtSetContextThread to modify a thread in a remote process indicative of process injection |
notice | A process created a hidden window |
notice | Allocates read-write-execute memory (usually to unpack itself) |
notice | Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time) |
notice | Creates executable files on the filesystem |
notice | Creates hidden or system file |
notice | Drops an executable to the user AppData folder |
notice | One or more potentially interesting buffers were extracted |
notice | Performs some HTTP requests |
notice | The binary likely contains encrypted or compressed data indicative of a packer |
notice | Uses Windows utilities for basic Windows functionality |
notice | Yara rule detected in process memory |
info | Checks amount of memory in system |
info | Collects information to fingerprint the system (MachineGuid |
info | Command line console output was observed |
Rules (22cnts)
Level | Name | Description | Collection |
---|---|---|---|
danger | Raccoon_Stealer_1_Zero | Raccoon Stealer | binaries (download) |
danger | Raccoon_Stealer_1_Zero | Raccoon Stealer | binaries (upload) |
watch | Malicious_Library_Zero | Malicious_Library | binaries (download) |
watch | Malicious_Library_Zero | Malicious_Library | binaries (upload) |
watch | Malicious_Packer_Zero | Malicious Packer | binaries (download) |
watch | Malicious_Packer_Zero | Malicious Packer | binaries (upload) |
watch | VMProtect_Zero | VMProtect packed file | binaries (download) |
watch | VMProtect_Zero | VMProtect packed file | binaries (upload) |
info | anti_dbg | Checks if being debugged | memory |
info | DebuggerCheck__GlobalFlags | (no description) | memory |
info | DebuggerCheck__QueryInfo | (no description) | memory |
info | DebuggerHiding__Active | (no description) | memory |
info | DebuggerHiding__Thread | (no description) | memory |
info | disable_dep | Bypass DEP | memory |
info | IsPE32 | (no description) | binaries (download) |
info | IsPE32 | (no description) | binaries (upload) |
info | PE_Header_Zero | PE File Signature | binaries (download) |
info | PE_Header_Zero | PE File Signature | binaries (upload) |
info | PNG_Format_Zero | PNG Format | binaries (download) |
info | SEH__vba | (no description) | memory |
info | SEH__vectored | (no description) | memory |
info | ThreadControl__Context | (no description) | memory |
Network (6cnts) ?
Suricata ids
SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee)
ET INFO TLS Handshake Failure
ET INFO TLS Handshake Failure
PE API
IAT(Import Address Table) Library
KERNEL32.dll
0x40f03c CreateProcessA
0x40f040 MultiByteToWideChar
0x40f044 GetProcAddress
0x40f048 LoadLibraryA
0x40f04c GetModuleFileNameA
0x40f050 WinExec
0x40f054 CloseHandle
0x40f058 WideCharToMultiByte
0x40f05c WriteFile
0x40f060 GetSystemTime
0x40f064 ReadFile
0x40f068 FlushFileBuffers
0x40f06c GetFileTime
0x40f070 GetLastError
0x40f074 SystemTimeToFileTime
0x40f078 CreateFileA
0x40f07c GetTempPathA
0x40f080 Sleep
0x40f084 CreateMutexA
0x40f088 ExitProcess
0x40f08c GetLocaleInfoA
0x40f090 GetStringTypeW
0x40f094 GetStringTypeA
0x40f098 LCMapStringW
0x40f09c LCMapStringA
0x40f0a0 WriteConsoleW
0x40f0a4 GetConsoleOutputCP
0x40f0a8 WriteConsoleA
0x40f0ac SetStdHandle
0x40f0b0 InitializeCriticalSection
0x40f0b4 HeapFree
0x40f0b8 HeapAlloc
0x40f0bc TerminateProcess
0x40f0c0 GetCurrentProcess
0x40f0c4 UnhandledExceptionFilter
0x40f0c8 SetUnhandledExceptionFilter
0x40f0cc IsDebuggerPresent
0x40f0d0 GetCommandLineA
0x40f0d4 GetVersionExA
0x40f0d8 GetProcessHeap
0x40f0dc GetStartupInfoA
0x40f0e0 RaiseException
0x40f0e4 RtlUnwind
0x40f0e8 HeapDestroy
0x40f0ec HeapCreate
0x40f0f0 VirtualFree
0x40f0f4 DeleteCriticalSection
0x40f0f8 LeaveCriticalSection
0x40f0fc EnterCriticalSection
0x40f100 VirtualAlloc
0x40f104 HeapReAlloc
0x40f108 GetModuleHandleA
0x40f10c GetStdHandle
0x40f110 TlsGetValue
0x40f114 TlsAlloc
0x40f118 TlsSetValue
0x40f11c TlsFree
0x40f120 InterlockedIncrement
0x40f124 SetLastError
0x40f128 GetCurrentThreadId
0x40f12c InterlockedDecrement
0x40f130 FreeEnvironmentStringsA
0x40f134 GetEnvironmentStrings
0x40f138 FreeEnvironmentStringsW
0x40f13c GetEnvironmentStringsW
0x40f140 SetHandleCount
0x40f144 GetFileType
0x40f148 QueryPerformanceCounter
0x40f14c GetTickCount
0x40f150 GetCurrentProcessId
0x40f154 GetSystemTimeAsFileTime
0x40f158 HeapSize
0x40f15c SetFilePointer
0x40f160 GetConsoleCP
0x40f164 GetConsoleMode
0x40f168 GetCPInfo
0x40f16c GetACP
0x40f170 GetOEMCP
ADVAPI32.dll
0x40f000 RegCloseKey
0x40f004 RegOpenKeyExA
0x40f008 RegQueryValueExA
0x40f00c InitializeSecurityDescriptor
0x40f010 SetSecurityDescriptorDacl
0x40f014 RegCreateKeyExA
SHELL32.dll
0x40f178 SHGetSpecialFolderPathA
SHLWAPI.dll
0x40f180 PathFileExistsA
CRYPT32.dll
0x40f01c CryptStringToBinaryA
0x40f020 CertOpenStore
0x40f024 CertFreeCertificateContext
0x40f028 CertAddCertificateContextToStore
0x40f02c CertCloseStore
0x40f030 CertCreateCertificateContext
0x40f034 CertGetCertificateContextProperty
WINHTTP.dll
0x40f188 WinHttpQueryHeaders
0x40f18c WinHttpCloseHandle
0x40f190 WinHttpConnect
0x40f194 WinHttpQueryDataAvailable
0x40f198 WinHttpOpenRequest
0x40f19c WinHttpSetTimeouts
0x40f1a0 WinHttpReceiveResponse
0x40f1a4 WinHttpQueryOption
0x40f1a8 WinHttpOpen
0x40f1ac WinHttpAddRequestHeaders
0x40f1b0 WinHttpSetOption
0x40f1b4 WinHttpReadData
0x40f1b8 WinHttpSendRequest
EAT(Export Address Table) is none
KERNEL32.dll
0x40f03c CreateProcessA
0x40f040 MultiByteToWideChar
0x40f044 GetProcAddress
0x40f048 LoadLibraryA
0x40f04c GetModuleFileNameA
0x40f050 WinExec
0x40f054 CloseHandle
0x40f058 WideCharToMultiByte
0x40f05c WriteFile
0x40f060 GetSystemTime
0x40f064 ReadFile
0x40f068 FlushFileBuffers
0x40f06c GetFileTime
0x40f070 GetLastError
0x40f074 SystemTimeToFileTime
0x40f078 CreateFileA
0x40f07c GetTempPathA
0x40f080 Sleep
0x40f084 CreateMutexA
0x40f088 ExitProcess
0x40f08c GetLocaleInfoA
0x40f090 GetStringTypeW
0x40f094 GetStringTypeA
0x40f098 LCMapStringW
0x40f09c LCMapStringA
0x40f0a0 WriteConsoleW
0x40f0a4 GetConsoleOutputCP
0x40f0a8 WriteConsoleA
0x40f0ac SetStdHandle
0x40f0b0 InitializeCriticalSection
0x40f0b4 HeapFree
0x40f0b8 HeapAlloc
0x40f0bc TerminateProcess
0x40f0c0 GetCurrentProcess
0x40f0c4 UnhandledExceptionFilter
0x40f0c8 SetUnhandledExceptionFilter
0x40f0cc IsDebuggerPresent
0x40f0d0 GetCommandLineA
0x40f0d4 GetVersionExA
0x40f0d8 GetProcessHeap
0x40f0dc GetStartupInfoA
0x40f0e0 RaiseException
0x40f0e4 RtlUnwind
0x40f0e8 HeapDestroy
0x40f0ec HeapCreate
0x40f0f0 VirtualFree
0x40f0f4 DeleteCriticalSection
0x40f0f8 LeaveCriticalSection
0x40f0fc EnterCriticalSection
0x40f100 VirtualAlloc
0x40f104 HeapReAlloc
0x40f108 GetModuleHandleA
0x40f10c GetStdHandle
0x40f110 TlsGetValue
0x40f114 TlsAlloc
0x40f118 TlsSetValue
0x40f11c TlsFree
0x40f120 InterlockedIncrement
0x40f124 SetLastError
0x40f128 GetCurrentThreadId
0x40f12c InterlockedDecrement
0x40f130 FreeEnvironmentStringsA
0x40f134 GetEnvironmentStrings
0x40f138 FreeEnvironmentStringsW
0x40f13c GetEnvironmentStringsW
0x40f140 SetHandleCount
0x40f144 GetFileType
0x40f148 QueryPerformanceCounter
0x40f14c GetTickCount
0x40f150 GetCurrentProcessId
0x40f154 GetSystemTimeAsFileTime
0x40f158 HeapSize
0x40f15c SetFilePointer
0x40f160 GetConsoleCP
0x40f164 GetConsoleMode
0x40f168 GetCPInfo
0x40f16c GetACP
0x40f170 GetOEMCP
ADVAPI32.dll
0x40f000 RegCloseKey
0x40f004 RegOpenKeyExA
0x40f008 RegQueryValueExA
0x40f00c InitializeSecurityDescriptor
0x40f010 SetSecurityDescriptorDacl
0x40f014 RegCreateKeyExA
SHELL32.dll
0x40f178 SHGetSpecialFolderPathA
SHLWAPI.dll
0x40f180 PathFileExistsA
CRYPT32.dll
0x40f01c CryptStringToBinaryA
0x40f020 CertOpenStore
0x40f024 CertFreeCertificateContext
0x40f028 CertAddCertificateContextToStore
0x40f02c CertCloseStore
0x40f030 CertCreateCertificateContext
0x40f034 CertGetCertificateContextProperty
WINHTTP.dll
0x40f188 WinHttpQueryHeaders
0x40f18c WinHttpCloseHandle
0x40f190 WinHttpConnect
0x40f194 WinHttpQueryDataAvailable
0x40f198 WinHttpOpenRequest
0x40f19c WinHttpSetTimeouts
0x40f1a0 WinHttpReceiveResponse
0x40f1a4 WinHttpQueryOption
0x40f1a8 WinHttpOpen
0x40f1ac WinHttpAddRequestHeaders
0x40f1b0 WinHttpSetOption
0x40f1b4 WinHttpReadData
0x40f1b8 WinHttpSendRequest
EAT(Export Address Table) is none