Report - clip.exe

Themida Packer Generic Malware Malicious Library PE File PE64
ScreenShot
Created 2023.10.31 17:49 Machine s1_win7_x6403
Filename clip.exe
Type PE32+ executable (GUI) x86-64, for MS Windows
AI Score
1
Behavior Score
2.6
ZERO API file : malware
VT API (file) 28 detected (Drixed, Artemis, unsafe, Vkwm, GenericKD, malicious, confidence, Attribute, HighConfidence, high confidence, Themida, L suspicious, score, Injuke, itwb, CLOUD, high, Sabsik, Chgt, Rqil, Static AI, Suspicious PE, RATX)
md5 b19c968d8ef12e145edacf8578f3440b
sha256 79c621ca4b6e73deefbd9e2c8dd69b762db796e75809cbd3ce23bce22074ad88
ssdeep 98304:Zht/xglJbdi6vLPnGlGXUn1k42L4NodEiAG7gbR7XMqcqYhWxtGj:ZhtxglJbgAPGlGkiVcS/+d7XrIMxo
imphash 8d2803775af2b344d65712330e01834f
impfuzzy 6:nE7zRhXYCSuVXIuJ7D/QKRa2YItHGXrmIOsU7g9IayMt8umxxWTD1FF:EHRy1aXIut9RqBbmIc77anyPuD1FF
  Network IP location

Signature (6cnts)

Level Description
warning File has been identified by 28 AntiVirus engines on VirusTotal as malicious
watch Tries to unhook Windows functions monitored by Cuckoo
notice Allocates read-write-execute memory (usually to unpack itself)
notice The binary likely contains encrypted or compressed data indicative of a packer
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)

Rules (5cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (upload)
warning themida_packer themida packer binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
info IsPE64 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x14022c2b8 GetModuleHandleA
ADVAPI32.dll
 0x14022c2c8 RegCreateKeyExW
crypt.dll
 0x14022c2d8 BCryptCloseAlgorithmProvider
ole32.dll
 0x14022c2e8 CoTaskMemFree
USER32.dll
 0x14022c2f8 LoadStringW
api-ms-win-crt-heap-l1-1-0.dll
 0x14022c308 malloc
api-ms-win-crt-math-l1-1-0.dll
 0x14022c318 __setusermatherr
api-ms-win-crt-string-l1-1-0.dll
 0x14022c328 _stricmp
api-ms-win-crt-runtime-l1-1-0.dll
 0x14022c338 _initterm_e
api-ms-win-crt-stdio-l1-1-0.dll
 0x14022c348 __stdio_common_vsprintf_s
api-ms-win-crt-locale-l1-1-0.dll
 0x14022c358 _configthreadlocale

EAT(Export Address Table) Library

0x1402005c0 DotNetRuntimeDebugHeader


Similarity measure (PE file only) - Checking for service failure