Report - s.exe

Downloader PE File PE32
ScreenShot
Created 2024.04.12 15:06 Machine s1_win7_x6401
Filename s.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
9
Behavior Score
2.2
ZERO API file : clean
VT API (file) 62 detected (AIDetectMalware, Malicious, score, Rincux2, unsafe, Save, confidence, 100%, Farfli, high confidence, Artemis, cvwswi, CLASSIC, DownLoader30, moderate, Behav, Zegost, whxp, Detected, ai score=88, BlkIC, IMG@1qp8gx, Busky, Eldorado, Gencirc, GenAsa, eZKDk3+DpPk, Static AI, Malicious PE, susgen)
md5 2881b6c878569feb65190b203f22c7ed
sha256 6880592124f2c7857208159286944c9121648c03ec6bfff623e657b05fa35a01
ssdeep 1536:Vpny2CcY9pqEdh+L//0S0aAKayPaJwert2IS4xN9mr4:DDWpqE8X0UjPOwQZN9u4
imphash bcaf90e13bddfb8d6434b602a3a882cd
impfuzzy 6:dBJAEHGDzyRlbRmVOZ/EwyXyOZgQWvI/wvBQyu2b+ZSZo8tBB46PIIAbn1148UAc:VA/DzqYOZ9yXoQn/wZ9UZSXQIIIATbZc
  Network IP location

Signature (4cnts)

Level Description
danger File has been identified by 62 AntiVirus engines on VirusTotal as malicious
notice Foreign language identified in PE resource
notice The binary likely contains encrypted or compressed data indicative of a packer
info The executable contains unknown PE section names indicative of a packer (could be a false positive)

Rules (3cnts)

Level Name Description Collection
watch Network_Downloader File Downloader binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.DLL
 0x429a90 LoadLibraryA
 0x429a94 GetProcAddress
 0x429a98 VirtualProtect
 0x429a9c VirtualAlloc
 0x429aa0 VirtualFree
 0x429aa4 ExitProcess
ADVAPI32.dll
 0x429aac RegOpenKeyA
AVICAP32.dll
 0x429ab4 capGetDriverDescriptionA
GDI32.dll
 0x429abc BitBlt
MSVCRT.dll
 0x429ac4 _iob
MSVFW32.dll
 0x429acc ICOpen
NETAPI32.dll
 0x429ad4 NetUserAdd
SHELL32.dll
 0x429adc ShellExecuteA
urlmon.dll
 0x429ae4 URLDownloadToFileA
USER32.dll
 0x429aec SetRect
WININET.dll
 0x429af4 InternetOpenA
WINMM.dll
 0x429afc mciSendStringA
WS2_32.dll
 0x429b04 sendto
WTSAPI32.dll
 0x429b0c WTSFreeMemory

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure