Report - George.exe

UPX PE File PE32
ScreenShot
Created 2024.06.24 11:36 Machine s1_win7_x6403
Filename George.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
5
Behavior Score
2.4
ZERO API file : malware
VT API (file) 25 detected (AIDetectMalware, LummaStealer, malicious, high confidence, Unsafe, Vn5p, Attribute, HighConfidence, Artemis, hItpm0rPheO, YXEFWZ, high, score, CCIH, Static AI, Malicious PE, MxResIcn, confidence)
md5 5bb3677a298d7977d73c2d47b805b9c3
sha256 85eb3f6ba52fe0fd232f8c3371d87f7d363f821953c344936ab87728ba6a627f
ssdeep 98304:/U1ygjPf+YEwNhQ9li49Zv85P95RPwAaj249R5EkDAUR:M0iPG4hQzi49ZgP/Rmj2gwkDA
imphash 1a02d69b15f5b6a928d42e49d3ab56e5
impfuzzy 6:oZ/KiwNbsKn6QgymvOYpjtlJoZ/O4ErBJAEHGDW:oZCiwxrnfgfTOZGJjA/DW
  Network IP location

Signature (6cnts)

Level Description
warning File has been identified by 25 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice The binary likely contains encrypted or compressed data indicative of a packer
notice The executable is likely packed with VMProtect
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The file contains an unknown PE resource name possibly indicative of a packer

Rules (3cnts)

Level Name Description Collection
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.dll
 0x6e2000 ExitProcess
ole32.dll
 0x6e2008 CoCreateInstance
OLEAUT32.dll
 0x6e2010 SysAllocString
USER32.dll
 0x6e2018 CloseClipboard
GDI32.dll
 0x6e2020 BitBlt
KERNEL32.dll
 0x6e2028 GetSystemTimeAsFileTime
KERNEL32.dll
 0x6e2030 HeapAlloc
 0x6e2034 HeapFree
 0x6e2038 ExitProcess
 0x6e203c GetModuleHandleA
 0x6e2040 LoadLibraryA
 0x6e2044 GetProcAddress

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure