ScreenShot
Created | 2023.08.08 18:54 | Machine | s1_win7_x6403 |
Filename | Setup.exe | ||
Type | PE32+ executable (GUI) x86-64, for MS Windows | ||
AI Score |
|
Behavior Score |
|
ZERO API | file : malware | ||
VT API (file) | 11 detected (Vuhj, malicious, Attribute, HighConfidence, score, PWSZbot, Artemis, Static AI, Suspicious PE, susgen, confidence) | ||
md5 | 60c09568374a7cc6fde4472e2f381d25 | ||
sha256 | c0f4ea0ef091c50c5e7219dc0944e0f01700dd23d0a37c956269ceb044e47264 | ||
ssdeep | 6144:6JOV4xvpsoZcMetN3wUpvwVP570Kk6NON77tcJN0LQKmfF5Ibxm:B2NqkWN3whVPjk6S7tcJNF3 | ||
imphash | 4329317f7ab113ac74b684563abcf41d | ||
impfuzzy | 6:omRgAuZulFBJAEoZ/OEGDzyRXcP6WNLbV46d:omRgAuZ+NABZG/DzjzKC |
Network IP location
Signature (4cnts)
Level | Description |
---|---|
watch | File has been identified by 11 AntiVirus engines on VirusTotal as malicious |
notice | The binary likely contains encrypted or compressed data indicative of a packer |
notice | The executable is compressed using UPX |
info | One or more processes crashed |
Rules (3cnts)
Level | Name | Description | Collection |
---|---|---|---|
watch | UPX_Zero | UPX packed file | binaries (upload) |
info | IsPE64 | (no description) | binaries (upload) |
info | PE_Header_Zero | PE File Signature | binaries (upload) |
Network (0cnts) ?
Request | CC | ASN Co | IP4 | Rule ? | ZERO ? |
---|
Suricata ids
PE API
IAT(Import Address Table) Library
ADVAPI32.dll
0x1400e85e4 RegCloseKey
CRYPT32.dll
0x1400e85f4 CryptBinaryToStringA
KERNEL32.DLL
0x1400e8604 LoadLibraryA
0x1400e860c ExitProcess
0x1400e8614 GetProcAddress
0x1400e861c VirtualProtect
ole32.dll
0x1400e862c CoInitializeEx
OLEAUT32.dll
0x1400e863c SysAllocString
SHELL32.dll
0x1400e864c ShellExecuteA
WININET.dll
0x1400e865c InternetOpenA
EAT(Export Address Table) is none
ADVAPI32.dll
0x1400e85e4 RegCloseKey
CRYPT32.dll
0x1400e85f4 CryptBinaryToStringA
KERNEL32.DLL
0x1400e8604 LoadLibraryA
0x1400e860c ExitProcess
0x1400e8614 GetProcAddress
0x1400e861c VirtualProtect
ole32.dll
0x1400e862c CoInitializeEx
OLEAUT32.dll
0x1400e863c SysAllocString
SHELL32.dll
0x1400e864c ShellExecuteA
WININET.dll
0x1400e865c InternetOpenA
EAT(Export Address Table) is none