Report - srg64.dll

Malicious Library VMProtect DLL PE64 PE File
ScreenShot
Created 2023.08.04 10:23 Machine s1_win7_x6401
Filename srg64.dll
Type PE32+ executable (DLL) (GUI) x86-64, for MS Windows
AI Score
5
Behavior Score
3.8
ZERO API file : clean
VT API (file) 14 detected (malicious, high confidence, confidence, Attribute, HighConfidence, VMProtect, L suspicious, score, VMProtBad, Wacatac, Detected, unsafe)
md5 85f8ed9c9f364b28d64e94075896df07
sha256 3c259a269cfbb752ca15046aca1bea4a31390e4674de632c5c9428e95b41db1d
ssdeep 98304:zikl1o/34cA08Fu4fZBgNL7bQMla48Llu8EAANISPatiDySc3L4uQbR:DFbRm/QMcu8qn4r5K
imphash 531372f8fed94a7a0e3b8ef647c7fcb7
impfuzzy 12:sQUlKjtajl3wfP9qZGoQtXJxZGb9AJcDfA5kLfP9m:UlKpnaQtXJHc9NDI5Q8
  Network IP location

Signature (8cnts)

Level Description
danger Connects to an IP address that is no longer responding to requests (legitimate services will remain up-and-running usually)
watch Communicates with host for which no DNS query was performed
watch File has been identified by 14 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice The binary likely contains encrypted or compressed data indicative of a packer
notice The executable is likely packed with VMProtect
info Checks if process is being debugged by a debugger
info The executable contains unknown PE section names indicative of a packer (could be a false positive)

Rules (5cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch VMProtect_Zero VMProtect packed file binaries (upload)
info IsDLL (no description) binaries (upload)
info IsPE64 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (1cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
5.42.65.67 RU CJSC Kolomna-Sviaz TV 5.42.65.67 mailcious

Suricata ids

PE API

IAT(Import Address Table) Library

user32.dll
 0x180425000 wsprintfA
ws2_32.dll
 0x180425010 getaddrinfo
advapi32.dll
 0x180425020 GetTokenInformation
kernel32.dll
 0x180425030 WriteFile
secur32.dll
 0x180425040 GetUserNameExA
ole32.dll
 0x180425050 CoUninitialize
WTSAPI32.dll
 0x180425060 WTSSendMessageW
kernel32.dll
 0x180425070 GetSystemTimeAsFileTime
user32.dll
 0x180425080 GetUserObjectInformationW
kernel32.dll
 0x180425090 LocalAlloc
 0x180425098 LocalFree
 0x1804250a0 GetModuleFileNameW
 0x1804250a8 GetProcessAffinityMask
 0x1804250b0 SetProcessAffinityMask
 0x1804250b8 SetThreadAffinityMask
 0x1804250c0 Sleep
 0x1804250c8 ExitProcess
 0x1804250d0 FreeLibrary
 0x1804250d8 LoadLibraryA
 0x1804250e0 GetModuleHandleA
 0x1804250e8 GetProcAddress
user32.dll
 0x1804250f8 GetProcessWindowStation
 0x180425100 GetUserObjectInformationW

EAT(Export Address Table) Library

0x180001020 rundll


Similarity measure (PE file only) - Checking for service failure