Report - TrueCrypt_nKJqAu.exe

Generic Malware Malicious Library Malicious Packer UPX PE64 PE File OS Processor Check
ScreenShot
Created 2024.03.29 08:12 Machine s1_win7_x6401
Filename TrueCrypt_nKJqAu.exe
Type PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
AI Score
5
Behavior Score
1.8
ZERO API file : mailcious
VT API (file) 48 detected (AIDetectMalware, malicious, high confidence, score, TrojanPWS, Expiro, GenericKDZ, unsafe, Vftw, Attribute, HighConfidence, a variant of WinGo, FormBook, AGEN, SMOKELOADER, YXEC1Z, Detected, ai score=85, ZgRAT, Casdet, Antis, OLUV5G, Eldorado, Chgt, CLASSIC, confidence, 100%)
md5 0cb4cc8a9f145e69c6765bc81faacc7e
sha256 adad8b635d0e68f9bbef153e5abb427d85de2e3a4f786668912074b8419ee239
ssdeep 49152:fjIJ/Kg6NGN+V+efZCM8jr/dWQciyvFTaFAtfP322EcERaScBg:0FtKk3eSJ8T4cHgYw
imphash 5929190c8765f5bc37b052ab5c6c53e7
impfuzzy 48:qJrKxMCy9cmwKeFR+2u42xQ2HpdXiX1PJOmSnlTJGfYJ861k1vcqTjz:qJexMCyamCRHu42xQ2HPXiX1PgblTJGh
  Network IP location

Signature (4cnts)

Level Description
danger File has been identified by 48 AntiVirus engines on VirusTotal as malicious
danger File has been identified by 48 AntiVirus engines on VirusTotal as malicious
notice The binary likely contains encrypted or compressed data indicative of a packer
info One or more processes crashed

Rules (13cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch Malicious_Packer_Zero Malicious Packer binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE64 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)
info 1 dumpmem
info 1 memory
info 1 office
info 1 scripts
info 1 urls
info 94102 shellcode

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.dll
&emsp


Similarity measure (PE file only) - Checking for service failure