Report - TrialP.exe

MPRESS PE File PE32
ScreenShot
Created 2024.07.04 17:04 Machine s1_win7_x6401
Filename TrialP.exe
Type MS-DOS executable, MZ for MS-DOS
AI Score
11
Behavior Score
4.2
ZERO API file : malware
VT API (file) 57 detected (AIDetectMalware, malicious, high confidence, score, Swrort, GenPack, Marte, Unsafe, Save, Meterpreter, Rozena, GenericRXAA, SaFlFaaGJTU, COBEACON, SMJMAC, Real Protect, high, Detected, ai score=82, A@4jwdqr, ABTrojan, YCAX, R135701, ZexaF, cmuaai7pdzmi, BScope, Genetic, Metasploit, GenAsa, LSJ6dfgnrwY, Static AI, Malicious PE, susgen, confidence, 100%)
md5 1b56ac299e10b84c9d04416ed1b309a2
sha256 29c8a6f9f4ff78e6019fbf55c882966f7af611b7c470cebe763b0c356756f351
ssdeep 768:qaQGlqpqlh7yIJ1/c6tnI2Nc5xeABGCfUHVWBEM7bVDy+PUWe+ji7DeWq3:qa84h7Z06tnIy2GCIWBp7ZDy+PUOJWq3
imphash fc2ca0dd2bd0f0a143659652556a192d
impfuzzy 3:sUx2AEZsS9KTXzn/MomlWAJSUOQ/sv1+AE:nERGDioUOQ/st8
  Network IP location

Signature (6cnts)

Level Description
danger Connects to IP addresses that are no longer responding to requests (legitimate services will remain up-and-running usually)
danger File has been identified by 57 AntiVirus engines on VirusTotal as malicious
watch Communicates with host for which no DNS query was performed
notice Allocates read-write-execute memory (usually to unpack itself)
notice The binary likely contains encrypted or compressed data indicative of a packer
info The executable contains unknown PE section names indicative of a packer (could be a false positive)

Rules (3cnts)

Level Name Description Collection
watch MPRESS_Zero MPRESS packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (1cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
89.197.154.116 GB Virtual1 Limited 89.197.154.116 mailcious

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.DLL
 0x416078 GetModuleHandleA
 0x41607c GetProcAddress
MSVCRT.dll
 0x416084 _iob
ADVAPI32.dll
 0x41608c FreeSid
WSOCK32.dll
 0x416094 getsockopt
WS2_32.dll
 0x41609c WSARecv

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure