Report - TrialR.exe

MPRESS PE File PE32
ScreenShot
Created 2024.07.04 16:59 Machine s1_win7_x6403
Filename TrialR.exe
Type MS-DOS executable, MZ for MS-DOS
AI Score
11
Behavior Score
4.2
ZERO API file : malware
VT API (file) 55 detected (AIDetectMalware, malicious, high confidence, score, Swrort, GenericRXAA, Unsafe, GenPack, Marte, Save, Meterpreter, Rozena, SaFlFaaGJTU, COBEACON, SMJMAC, Real Protect, moderate, Detected, HeurC, KVMH008, A@4jwdqr, R135701, ZexaF, cmuaaemocxei, BScope, Genetic, Metasploit, GenAsa, LSJ6dfgnrwY, ai score=80, susgen, confidence, 100%)
md5 e18a6528feb2a80af9a1cc435ed30bed
sha256 78f40dbc06bf9e63d2322bad4b70fefb29d6060292f91c12d82cbae449ed4d77
ssdeep 768:ZteOuhluA69L7MtikTzxJ1shFrccuHL6i7WzehAL7BfknCVN7DeWq3:Su7MZbOIHumhALZknCVYWq3
imphash fc2ca0dd2bd0f0a143659652556a192d
impfuzzy 3:sUx2AEZsS9KTXzn/MomlWAJSUOQ/sv1+AE:nERGDioUOQ/st8
  Network IP location

Signature (6cnts)

Level Description
danger Connects to IP addresses that are no longer responding to requests (legitimate services will remain up-and-running usually)
danger File has been identified by 55 AntiVirus engines on VirusTotal as malicious
watch Communicates with host for which no DNS query was performed
notice Allocates read-write-execute memory (usually to unpack itself)
notice The binary likely contains encrypted or compressed data indicative of a packer
info The executable contains unknown PE section names indicative of a packer (could be a false positive)

Rules (3cnts)

Level Name Description Collection
watch MPRESS_Zero MPRESS packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (1cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
89.197.154.116 GB Virtual1 Limited 89.197.154.116 mailcious

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.DLL
 0x416078 GetModuleHandleA
 0x41607c GetProcAddress
MSVCRT.dll
 0x416084 _iob
ADVAPI32.dll
 0x41608c FreeSid
WSOCK32.dll
 0x416094 getsockopt
WS2_32.dll
 0x41609c WSARecv

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure