Report - amer.exe

EnigmaProtector UPX PE32 PE File
ScreenShot
Created 2024.01.17 15:16 Machine s1_win7_x6401
Filename amer.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
10
Behavior Score
2.4
ZERO API file : clean
VT API (file) 38 detected (AIDetectMalware, malicious, high confidence, score, GenericRXMR, unsafe, GenericKDZ, Attribute, HighConfidence, Enigma, PWSX, AGEN, Generic ML PUA, Detected, EnigmaProtector, Bladabindi, Eldorado, ZexaF, uH0@aCa9Bkji, Wacatac, Probably Heur, ExeHeaderL, Static AI, Malicious PE, susgen, confidence, 100%)
md5 b724b7b724854f8bcc44505303036f41
sha256 d7d7fe29c6c71216afceb7185e7dbf5349b8626fa5dccfcff0c553002a206b32
ssdeep 24576:LjV1Lcuz3wB/E3u1zYHoMw6fKD959IJoJNZJw8VWnhYUHLAy5Tyiz0:L/5e16U6A9593pDWOUrN5Tys0
imphash fc5d3d653af3c3decf6e755f0007c4f6
impfuzzy 6:nERGDvZ/OiBJAEcXQwDLzRgSdn8BbMqtYbd+B6n9fd:EcDvZGqA9AwDXRgKQc59F
  Network IP location

Signature (6cnts)

Level Description
danger File has been identified by 38 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice The binary likely contains encrypted or compressed data indicative of a packer
info Checks amount of memory in system
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)

Rules (4cnts)

Level Name Description Collection
warning EnigmaProtector_IN EnigmaProtector binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x710118 GetModuleHandleA
 0x71011c GetProcAddress
 0x710120 ExitProcess
 0x710124 LoadLibraryA
user32.dll
 0x71012c MessageBoxA
advapi32.dll
 0x710134 RegCloseKey
oleaut32.dll
 0x71013c SysFreeString
gdi32.dll
 0x710144 CreateFontA
shell32.dll
 0x71014c ShellExecuteA
version.dll
 0x710154 GetFileVersionInfoA
WININET.dll
 0x71015c HttpOpenRequestA
WS2_32.dll
 0x710164 closesocket

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure