ScreenShot
Created | 2023.09.11 08:08 | Machine | s1_win7_x6401 |
Filename | QmapmAFtEUjYUodvdxV63DhsGuLq96iCMXuBvaGx2mhdpq | ||
Type | PE32+ executable (GUI) x86-64, for MS Windows | ||
AI Score | Not founds | Behavior Score |
|
ZERO API | file : malware | ||
VT API (file) | |||
md5 | bca408ca8e4a4d10c877744bfb58b43f | ||
sha256 | fbb1f62b75df3af3305a3bca694e4050dbd86718390db2f737a5db2d8cca96ee | ||
ssdeep | 24576:i/U/qOJD8wC779sjdllpjLEtJgIf1E+UR9t1S+qWXqyS56Pta2RjMb3lUS/cr:i/pewwmsffXd+Unt1KWXsGJVMb3lbo | ||
imphash | 768cce1a3135ef56ac91aeb097edfe55 | ||
impfuzzy | 6:o41wT3WTD1Fz8IK9Iay4PMtsUpBJAEoZ/OEGDzyRFfEfjwi/QKRn:o4MuD1FwOay4PKRABZG/DzQfE7wi9Rn |
Network IP location
Signature (3cnts)
Level | Description |
---|---|
notice | The binary likely contains encrypted or compressed data indicative of a packer |
notice | The executable is compressed using UPX |
info | One or more processes crashed |
Rules (2cnts)
Level | Name | Description | Collection |
---|---|---|---|
info | IsPE64 | (no description) | binaries (upload) |
info | PE_Header_Zero | PE File Signature | binaries (upload) |
Network (0cnts) ?
Request | CC | ASN Co | IP4 | Rule ? | ZERO ? |
---|
Suricata ids
PE API
IAT(Import Address Table) Library
ADVAPI32.dll
0x140446884 EventWrite
api-ms-win-crt-heap-l1-1-0.dll
0x140446894 free
api-ms-win-crt-locale-l1-1-0.dll
0x1404468a4 _configthreadlocale
api-ms-win-crt-math-l1-1-0.dll
0x1404468b4 pow
api-ms-win-crt-runtime-l1-1-0.dll
0x1404468c4 exit
api-ms-win-crt-stdio-l1-1-0.dll
0x1404468d4 _set_fmode
api-ms-win-crt-string-l1-1-0.dll
0x1404468e4 strcmp
KERNEL32.DLL
0x1404468f4 LoadLibraryA
0x1404468fc ExitProcess
0x140446904 GetProcAddress
0x14044690c VirtualProtect
ncrypt.dll
0x14044691c BCryptEncrypt
ole32.dll
0x14044692c CoCreateGuid
USER32.dll
0x14044693c LoadStringW
EAT(Export Address Table) is none
ADVAPI32.dll
0x140446884 EventWrite
api-ms-win-crt-heap-l1-1-0.dll
0x140446894 free
api-ms-win-crt-locale-l1-1-0.dll
0x1404468a4 _configthreadlocale
api-ms-win-crt-math-l1-1-0.dll
0x1404468b4 pow
api-ms-win-crt-runtime-l1-1-0.dll
0x1404468c4 exit
api-ms-win-crt-stdio-l1-1-0.dll
0x1404468d4 _set_fmode
api-ms-win-crt-string-l1-1-0.dll
0x1404468e4 strcmp
KERNEL32.DLL
0x1404468f4 LoadLibraryA
0x1404468fc ExitProcess
0x140446904 GetProcAddress
0x14044690c VirtualProtect
ncrypt.dll
0x14044691c BCryptEncrypt
ole32.dll
0x14044692c CoCreateGuid
USER32.dll
0x14044693c LoadStringW
EAT(Export Address Table) is none