ScreenShot
Created | 2023.11.07 07:42 | Machine | s1_win7_x6401 |
Filename | My2.exe | ||
Type | PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows | ||
AI Score |
|
Behavior Score |
|
ZERO API | file : malware | ||
VT API (file) | |||
md5 | 9873907d252dcecd6baea9a11ac4b0da | ||
sha256 | a5c68511132b9590f0d60bc6fa5f43999c25d636d0b29aae1ff3787688907fe7 | ||
ssdeep | 98304:jkIr0MF/LGIgU95JrA8MjLiwlqVwDfb1BrOuQ4:jkIr0MF/FV95BA8hwgCpO2 | ||
imphash | cfc2f6e0ad47e701959f21a8d2a686e9 | ||
impfuzzy | 12:YRJRJJoARZqRVPXJHqV0MHHGf5XGXKiEG6eGJwk6lm/GaJqfZJVZJn:8fjBcVK0MGf5XGf6Zykom/GCqxvZJn |
Network IP location
Signature (1cnts)
Level | Description |
---|---|
notice | The binary likely contains encrypted or compressed data indicative of a packer |
Rules (2cnts)
Level | Name | Description | Collection |
---|---|---|---|
info | IsPE64 | (no description) | binaries (upload) |
info | PE_Header_Zero | PE File Signature | binaries (upload) |
PE API
IAT(Import Address Table) Library
KERNEL32.dll
0x14053e1a8 DeleteCriticalSection
0x14053e1b0 EnterCriticalSection
0x14053e1b8 GetLastError
0x14053e1c0 InitializeCriticalSection
0x14053e1c8 LeaveCriticalSection
0x14053e1d0 SetUnhandledExceptionFilter
0x14053e1d8 Sleep
0x14053e1e0 TlsGetValue
0x14053e1e8 VirtualProtect
0x14053e1f0 VirtualQuery
msvcrt.dll
0x14053e200 __C_specific_handler
0x14053e208 __getmainargs
0x14053e210 __initenv
0x14053e218 __iob_func
0x14053e220 __set_app_type
0x14053e228 __setusermatherr
0x14053e230 _amsg_exit
0x14053e238 _cexit
0x14053e240 _commode
0x14053e248 _fmode
0x14053e250 _initterm
0x14053e258 _onexit
0x14053e260 abort
0x14053e268 calloc
0x14053e270 exit
0x14053e278 fprintf
0x14053e280 fputs
0x14053e288 free
0x14053e290 malloc
0x14053e298 memset
0x14053e2a0 signal
0x14053e2a8 strcat
0x14053e2b0 strlen
0x14053e2b8 strncmp
0x14053e2c0 strstr
0x14053e2c8 vfprintf
0x14053e2d0 wcscat
0x14053e2d8 wcscpy
0x14053e2e0 wcslen
0x14053e2e8 wcsncmp
0x14053e2f0 wcsstr
0x14053e2f8 _wcsnicmp
0x14053e300 _wcsicmp
EAT(Export Address Table) is none
KERNEL32.dll
0x14053e1a8 DeleteCriticalSection
0x14053e1b0 EnterCriticalSection
0x14053e1b8 GetLastError
0x14053e1c0 InitializeCriticalSection
0x14053e1c8 LeaveCriticalSection
0x14053e1d0 SetUnhandledExceptionFilter
0x14053e1d8 Sleep
0x14053e1e0 TlsGetValue
0x14053e1e8 VirtualProtect
0x14053e1f0 VirtualQuery
msvcrt.dll
0x14053e200 __C_specific_handler
0x14053e208 __getmainargs
0x14053e210 __initenv
0x14053e218 __iob_func
0x14053e220 __set_app_type
0x14053e228 __setusermatherr
0x14053e230 _amsg_exit
0x14053e238 _cexit
0x14053e240 _commode
0x14053e248 _fmode
0x14053e250 _initterm
0x14053e258 _onexit
0x14053e260 abort
0x14053e268 calloc
0x14053e270 exit
0x14053e278 fprintf
0x14053e280 fputs
0x14053e288 free
0x14053e290 malloc
0x14053e298 memset
0x14053e2a0 signal
0x14053e2a8 strcat
0x14053e2b0 strlen
0x14053e2b8 strncmp
0x14053e2c0 strstr
0x14053e2c8 vfprintf
0x14053e2d0 wcscat
0x14053e2d8 wcscpy
0x14053e2e0 wcslen
0x14053e2e8 wcsncmp
0x14053e2f0 wcsstr
0x14053e2f8 _wcsnicmp
0x14053e300 _wcsicmp
EAT(Export Address Table) is none