Report - sqlite3.dll

UPX Malicious Library ASPack OS Processor Check DLL PE File PE32
ScreenShot
Created 2023.06.23 09:19 Machine s1_win7_x6403
Filename sqlite3.dll
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
AI Score
5
Behavior Score
2.0
ZERO API file : malware
VT API (file) 13 detected (AIDetectMalware, Save, malicious, confidence, Attribute, HighConfidence, high confidence, Casdet, Artemis, BScope, ZedlaF, dy4baWmvH4)
md5 e53d7ba028f3df8918c7447db0e05df8
sha256 1440bc84cd404b9a3712955f77ea0ae06ca2a07b7c441ef261bc4407dd4f8877
ssdeep 1536:lDm8aNg+j7Ahr26oXZzZZpAsWnBCcdGje5WcA:7aNHmq6oXZzZT+jGjeB
imphash 5a498eee87e4d89512a84502f500181f
impfuzzy 3:sU9KTXzhAXwSx2AEZsWBJA4:HGDmErBJA4
  Network IP location

Signature (6cnts)

Level Description
watch File has been identified by 13 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice The binary likely contains encrypted or compressed data indicative of a packer
info Checks if process is being debugged by a debugger
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The executable uses a known packer

Rules (7cnts)

Level Name Description Collection
watch ASPack_Zero ASPack packed file binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsDLL (no description) binaries (upload)
info IsPE32 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x10014fb8 GetProcAddress
 0x10014fbc GetModuleHandleA
 0x10014fc0 LoadLibraryA

EAT(Export Address Table) Library

0x10001000 sqlite3_backup_finish
0x10001000 sqlite3_backup_init
0x10001000 sqlite3_backup_step
0x10001000 sqlite3_close
0x10001000 sqlite3_column_text
0x10001000 sqlite3_errcode
0x10001000 sqlite3_exec
0x10001000 sqlite3_finalize
0x10001000 sqlite3_free
0x10001010 sqlite3_open
0x10001000 sqlite3_prepare_v2
0x10001000 sqlite3_step


Similarity measure (PE file only) - Checking for service failure