Report - client32.exe

UPX PE File PE32
ScreenShot
Created 2023.08.16 07:42 Machine s1_win7_x6401
Filename client32.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
6
Behavior Score
0.6
ZERO API file : clean
VT API (file) 5 detected (Tool, NetSup, RemoteAdmin, BScope, NetSupport, Hacktool, CLOUD)
md5 a2b46c59f6e7e395d479b09464ecdba0
sha256 89f0c8f170fe9ea28b1056517160e92e2d7d4e8aa81f4ed696932230413a6ce1
ssdeep 768:rNd8VZl6FhWr80/aVr2pe/1G42KFKcMkjWBr2pe/zcKFKcMkA:rfO0hGSBee/1GVIrveee/IIrU
imphash a9d50692e95b79723f3e76fcf70d023e
impfuzzy 3:rfeZpPwSd1EL/K5sJ1MO/OywSx2ASAy0JSW+RAKV:rIrOLGoZ/O4S3yS
  Network IP location

Signature (2cnts)

Level Description
notice File has been identified by 5 AntiVirus engines on VirusTotal as malicious
info This executable has a PDB path

Rules (3cnts)

Level Name Description Collection
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

PCICL32.dll
 0x402014 _NSMClient32@8
KERNEL32.dll
 0x402000 GetCommandLineW
 0x402004 ExitProcess
 0x402008 GetModuleHandleW
 0x40200c GetStartupInfoW

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure