ScreenShot
Created | 2023.10.10 10:18 | Machine | s1_win7_x6401 |
Filename | bQ1X.exe | ||
Type | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed | ||
AI Score |
|
Behavior Score |
|
ZERO API | file : clean | ||
VT API (file) | 61 detected (AIDetectMalware, Remcos, Dacic, Artemis, Rescoms, Save, malicious, confidence, 100%, Kryptik, Genus, Eldorado, moderate confidence, score, kakzkh, RATX, Gencirc, DownLoader46, YXDJIZ, high, Emogen, Outbreak, Detected, ZexaF, omGfaCWC6Qfi, ai score=80, unsafe, FKuWrtG2iWT, yzloPsMaQAE, Static AI, Malicious PE, susgen) | ||
md5 | e230cdc004aa4fa4b61f66fbfd701ee5 | ||
sha256 | 431f53278c89aa423d08ddc7ea4ddaa23e1c40cf7910b764201efd6890af7afe | ||
ssdeep | 3072:2OSI2I7txG68nYrugMZJMfsciIpuKNtrUQlAK3qSjYPS+IAXb3Ixi5eFrgurIlN1:zvG68YrvM80ypnjAedo3qiGUY2ChzIT | ||
imphash | bc4f8e98d1041d53dd63bfb91ed10d0a | ||
impfuzzy | 6:omRgCHWvC365rBJAEoZ/OEGDzyRZr4/b4RUptIKVSZozAhQcY460qtZGvR:omRgYh+ABZG/Dzgr4kYSIAx72ZGJ |
Network IP location
Signature (7cnts)
Level | Description |
---|---|
danger | File has been identified by 61 AntiVirus engines on VirusTotal as malicious |
danger | Connects to an IP address that is no longer responding to requests (legitimate services will remain up-and-running usually) |
watch | Creates a windows hook that monitors keyboard input (keylogger) |
notice | A process attempted to delay the analysis task. |
notice | Connects to a Dynamic DNS Domain |
notice | The binary likely contains encrypted or compressed data indicative of a packer |
notice | The executable is compressed using UPX |
Rules (4cnts)
Level | Name | Description | Collection |
---|---|---|---|
watch | Malicious_Packer_Zero | Malicious Packer | binaries (upload) |
watch | Network_Downloader | File Downloader | binaries (upload) |
info | IsPE32 | (no description) | binaries (upload) |
info | PE_Header_Zero | PE File Signature | binaries (upload) |
PE API
IAT(Import Address Table) Library
ADVAPI32.dll
0x489724 RegCloseKey
GDI32.dll
0x48972c BitBlt
gdiplus.dll
0x489734 GdipFree
KERNEL32.DLL
0x48973c LoadLibraryA
0x489740 ExitProcess
0x489744 GetProcAddress
0x489748 VirtualProtect
ole32.dll
0x489750 CoGetObject
SHELL32.dll
0x489758 ExtractIconA
SHLWAPI.dll
0x489760 StrToIntA
urlmon.dll
0x489768 URLDownloadToFileW
USER32.dll
0x489770 DrawIcon
WININET.dll
0x489778 InternetOpenW
WINMM.dll
0x489780 waveInOpen
WS2_32.dll
0x489788 socket
EAT(Export Address Table) is none
ADVAPI32.dll
0x489724 RegCloseKey
GDI32.dll
0x48972c BitBlt
gdiplus.dll
0x489734 GdipFree
KERNEL32.DLL
0x48973c LoadLibraryA
0x489740 ExitProcess
0x489744 GetProcAddress
0x489748 VirtualProtect
ole32.dll
0x489750 CoGetObject
SHELL32.dll
0x489758 ExtractIconA
SHLWAPI.dll
0x489760 StrToIntA
urlmon.dll
0x489768 URLDownloadToFileW
USER32.dll
0x489770 DrawIcon
WININET.dll
0x489778 InternetOpenW
WINMM.dll
0x489780 waveInOpen
WS2_32.dll
0x489788 socket
EAT(Export Address Table) is none