Report - QmapmAFtEUjYUodvdxV63DhsGuLq96iCMXuBvaGx2mhdpq

PE File PE64
ScreenShot
Created 2023.09.11 08:08 Machine s1_win7_x6401
Filename QmapmAFtEUjYUodvdxV63DhsGuLq96iCMXuBvaGx2mhdpq
Type PE32+ executable (GUI) x86-64, for MS Windows
AI Score Not founds Behavior Score
1.0
ZERO API file : malware
VT API (file)
md5 bca408ca8e4a4d10c877744bfb58b43f
sha256 fbb1f62b75df3af3305a3bca694e4050dbd86718390db2f737a5db2d8cca96ee
ssdeep 24576:i/U/qOJD8wC779sjdllpjLEtJgIf1E+UR9t1S+qWXqyS56Pta2RjMb3lUS/cr:i/pewwmsffXd+Unt1KWXsGJVMb3lbo
imphash 768cce1a3135ef56ac91aeb097edfe55
impfuzzy 6:o41wT3WTD1Fz8IK9Iay4PMtsUpBJAEoZ/OEGDzyRFfEfjwi/QKRn:o4MuD1FwOay4PKRABZG/DzQfE7wi9Rn
  Network IP location

Signature (3cnts)

Level Description
notice The binary likely contains encrypted or compressed data indicative of a packer
notice The executable is compressed using UPX
info One or more processes crashed

Rules (2cnts)

Level Name Description Collection
info IsPE64 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

ADVAPI32.dll
 0x140446884 EventWrite
api-ms-win-crt-heap-l1-1-0.dll
 0x140446894 free
api-ms-win-crt-locale-l1-1-0.dll
 0x1404468a4 _configthreadlocale
api-ms-win-crt-math-l1-1-0.dll
 0x1404468b4 pow
api-ms-win-crt-runtime-l1-1-0.dll
 0x1404468c4 exit
api-ms-win-crt-stdio-l1-1-0.dll
 0x1404468d4 _set_fmode
api-ms-win-crt-string-l1-1-0.dll
 0x1404468e4 strcmp
KERNEL32.DLL
 0x1404468f4 LoadLibraryA
 0x1404468fc ExitProcess
 0x140446904 GetProcAddress
 0x14044690c VirtualProtect
ncrypt.dll
 0x14044691c BCryptEncrypt
ole32.dll
 0x14044692c CoCreateGuid
USER32.dll
 0x14044693c LoadStringW

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure