Report - netTime.exe

Malicious Packer Anti_VM PE File PE64
ScreenShot
Created 2023.09.18 16:44 Machine s1_win7_x6403
Filename netTime.exe
Type PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
AI Score
5
Behavior Score
3.0
ZERO API file : mailcious
VT API (file) 30 detected (AIDetectMalware, malicious, high confidence, YakbeexMSIL, Artemis, Vwha, DotNetGuard, confidence, 100%, Attribute, HighConfidence, A suspicious, CoinminerX, Mjgl, PackedNET, Miner, Vigorf, score, unsafe, Outbreak, PossibleThreat)
md5 c2f0ab10869de4c6b8b79556643249ff
sha256 16ff5dfd8729c37d99a097778c7aa85651179f9985878863babef59a5b0fde5d
ssdeep 49152:jowrxbfpsgAy5dxxCuWtMpE4yOeccKjLwrOwdDNRlKaBD4SAHHedm9iRsgUi29Uk:K+aeKvg/BNZDK1JA1xv
imphash
impfuzzy 3::
  Network IP location

Signature (8cnts)

Level Description
danger File has been identified by 30 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Checks for the Locally Unique Identifier on the system for a suspicious privilege
notice Creates executable files on the filesystem
info Checks amount of memory in system
info Checks if process is being debugged by a debugger
info One or more processes crashed
info The file contains an unknown PE resource name possibly indicative of a packer

Rules (8cnts)

Level Name Description Collection
watch Malicious_Packer_Zero Malicious Packer binaries (download)
watch Malicious_Packer_Zero Malicious Packer binaries (upload)
notice anti_vm_detect Possibly employs anti-virtualization techniques binaries (download)
notice anti_vm_detect Possibly employs anti-virtualization techniques binaries (upload)
info IsPE64 (no description) binaries (download)
info IsPE64 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (download)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) is none

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure