ScreenShot
Created | 2023.06.23 09:19 | Machine | s1_win7_x6403 |
Filename | sqlite3.dll | ||
Type | PE32 executable (DLL) (GUI) Intel 80386, for MS Windows | ||
AI Score |
|
Behavior Score |
|
ZERO API | file : malware | ||
VT API (file) | 13 detected (AIDetectMalware, Save, malicious, confidence, Attribute, HighConfidence, high confidence, Casdet, Artemis, BScope, ZedlaF, dy4baWmvH4) | ||
md5 | e53d7ba028f3df8918c7447db0e05df8 | ||
sha256 | 1440bc84cd404b9a3712955f77ea0ae06ca2a07b7c441ef261bc4407dd4f8877 | ||
ssdeep | 1536:lDm8aNg+j7Ahr26oXZzZZpAsWnBCcdGje5WcA:7aNHmq6oXZzZT+jGjeB | ||
imphash | 5a498eee87e4d89512a84502f500181f | ||
impfuzzy | 3:sU9KTXzhAXwSx2AEZsWBJA4:HGDmErBJA4 |
Network IP location
Signature (6cnts)
Level | Description |
---|---|
watch | File has been identified by 13 AntiVirus engines on VirusTotal as malicious |
notice | Allocates read-write-execute memory (usually to unpack itself) |
notice | The binary likely contains encrypted or compressed data indicative of a packer |
info | Checks if process is being debugged by a debugger |
info | The executable contains unknown PE section names indicative of a packer (could be a false positive) |
info | The executable uses a known packer |
Rules (7cnts)
Level | Name | Description | Collection |
---|---|---|---|
watch | ASPack_Zero | ASPack packed file | binaries (upload) |
watch | Malicious_Library_Zero | Malicious_Library | binaries (upload) |
watch | UPX_Zero | UPX packed file | binaries (upload) |
info | IsDLL | (no description) | binaries (upload) |
info | IsPE32 | (no description) | binaries (upload) |
info | OS_Processor_Check_Zero | OS Processor Check | binaries (upload) |
info | PE_Header_Zero | PE File Signature | binaries (upload) |
Network (0cnts) ?
Request | CC | ASN Co | IP4 | Rule ? | ZERO ? |
---|
Suricata ids
PE API
IAT(Import Address Table) Library
kernel32.dll
0x10014fb8 GetProcAddress
0x10014fbc GetModuleHandleA
0x10014fc0 LoadLibraryA
EAT(Export Address Table) Library
0x10001000 sqlite3_backup_finish
0x10001000 sqlite3_backup_init
0x10001000 sqlite3_backup_step
0x10001000 sqlite3_close
0x10001000 sqlite3_column_text
0x10001000 sqlite3_errcode
0x10001000 sqlite3_exec
0x10001000 sqlite3_finalize
0x10001000 sqlite3_free
0x10001010 sqlite3_open
0x10001000 sqlite3_prepare_v2
0x10001000 sqlite3_step
kernel32.dll
0x10014fb8 GetProcAddress
0x10014fbc GetModuleHandleA
0x10014fc0 LoadLibraryA
EAT(Export Address Table) Library
0x10001000 sqlite3_backup_finish
0x10001000 sqlite3_backup_init
0x10001000 sqlite3_backup_step
0x10001000 sqlite3_close
0x10001000 sqlite3_column_text
0x10001000 sqlite3_errcode
0x10001000 sqlite3_exec
0x10001000 sqlite3_finalize
0x10001000 sqlite3_free
0x10001010 sqlite3_open
0x10001000 sqlite3_prepare_v2
0x10001000 sqlite3_step