Report - old.exe

PE64 PE File
ScreenShot
Created 2023.08.11 08:54 Machine s1_win7_x6401
Filename old.exe
Type PE32+ executable (GUI) x86-64, for MS Windows
AI Score
8
Behavior Score
2.4
ZERO API file : malware
VT API (file)
md5 657dc4f38e42f897d0591605cb20ee3e
sha256 00a69f8222c10b96f1b5826bcc718ee6cda420bcca779670c2395084e042db1c
ssdeep 24:eFGStrJ9u0/6j/wdnZdkBQAVn1YjGKZqoeNDMSCvOXpmB:is00/wdkBQAqCKSD9C2kB
imphash b4c6fff030479aa3b12625be67bf4914
impfuzzy 3:siBJJ671MOB:tUZB
  Network IP location

Signature (4cnts)

Level Description
danger Connects to IP addresses that are no longer responding to requests (legitimate services will remain up-and-running usually)
watch Communicates with host for which no DNS query was performed
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)

Rules (2cnts)

Level Name Description Collection
info IsPE64 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (1cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
134.122.75.115 DE DIGITALOCEAN-ASN 134.122.75.115 clean

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.dll
 0x140003000 VirtualAlloc
 0x140003008 ExitProcess

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure