Report - alg.exe

Browser Login Data Stealer Generic Malware Anti_VM PE64 PE File ZIP Format
ScreenShot
Created 2023.07.20 13:31 Machine s1_win7_x6402
Filename alg.exe
Type PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
AI Score
4
Behavior Score
4.6
ZERO API
VT API (file) 28 detected (GenericKD, unsafe, Vimn, Malicious, score, PWSX, Artemis, xgsya, ai score=82, Wacapew, Chgt, susgen, Behavior, confidence)
md5 150e53a8c852ac5f23f47aceef452542
sha256 012063e0b7b4f7f3ce50574797112f95492772a9b75fc3d0934a91cc60faa240
ssdeep 384:Kz+m1kuPZXHcaYbT1AnoKRiwWy8PG8Xj6r:KzrOeZXHYbxcPRixy8e8XjS
imphash
impfuzzy 3::
  Network IP location

Signature (12cnts)

Level Description
warning File has been identified by 28 AntiVirus engines on VirusTotal as malicious
watch Attempts to detect Cuckoo Sandbox through the presence of a file
watch Harvests credentials from local email clients
notice Allocates read-write-execute memory (usually to unpack itself)
notice Creates a shortcut to an executable file
notice Queries the disk size which could be used to detect virtual machine with small fixed size or dynamic allocation
notice Steals private information from local Internet browsers
info Checks amount of memory in system
info Checks if process is being debugged by a debugger
info Collects information to fingerprint the system (MachineGuid
info This executable has a PDB path
info Tries to locate where the browsers are installed

Rules (6cnts)

Level Name Description Collection
danger infoStealer_browser_b_Zero browser info stealer binaries (download)
warning Generic_Malware_Zero Generic Malware binaries (upload)
notice anti_vm_detect Possibly employs anti-virtualization techniques binaries (download)
info IsPE64 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)
info zip_file_format ZIP file format binaries (download)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) is none

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure