Report - offic%E8%A1%A8%E6%A0%BCluck.exe

UPX PE File PE64
ScreenShot
Created 2024.07.07 18:50 Machine s1_win7_x6403
Filename offic%E8%A1%A8%E6%A0%BCluck.exe
Type PE32+ executable (GUI) x86-64, for MS Windows
AI Score Not founds Behavior Score
2.6
ZERO API file : malware
VT API (file) 49 detected (AIDetectMalware, Malicious, score, GenericKD, Unsafe, Kryptik, V4p7, Attribute, HighConfidence, Artemis, CrypterX, LF6lrnsStYC, aygdi, R023C0XG224, GenKD, Detected, Malware@#1kjjsv0kxllxl, Casdet, ABTrojan, MYMG, Chgt, Gencirc, ai score=80, susgen, confidence)
md5 06592a8ca068935d98a5ada152e3393d
sha256 acce6a3f4a8de7b556e74279744466adf4ec318a9fc03c639cdbc7f47c60da0d
ssdeep 196608:nQvu0707Woow7L3XW0GDB8Zm6Y5Ao6YrRR7EDzrFa8vXGb1HOZp/tWIIe/kUCzUb:nN0707b4B2m6Y5Ao6GR7+hZ2b1HkmKbz
imphash 53880e0e758436150751a6d80bd6a537
impfuzzy 12:8MyyuD1FwBbmIYayjABZG/DzOSGj2n2Qc6U:8Myyu5FwBbAbjC+DiRjUo
  Network IP location

Signature (5cnts)

Level Description
danger File has been identified by 49 AntiVirus engines on VirusTotal as malicious
notice Foreign language identified in PE resource
notice The binary likely contains encrypted or compressed data indicative of a packer
notice The executable is compressed using UPX
info The file contains an unknown PE resource name possibly indicative of a packer

Rules (3cnts)

Level Name Description Collection
watch UPX_Zero UPX packed file binaries (upload)
info IsPE64 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

api-ms-win-crt-filesystem-l1-1-0.dll
 0x141be9fec _lock_file
api-ms-win-crt-heap-l1-1-0.dll
 0x141be9ffc free
api-ms-win-crt-locale-l1-1-0.dll
 0x141bea00c _configthreadlocale
api-ms-win-crt-math-l1-1-0.dll
 0x141bea01c __setusermatherr
api-ms-win-crt-runtime-l1-1-0.dll
 0x141bea02c exit
api-ms-win-crt-stdio-l1-1-0.dll
 0x141bea03c fgetc
KERNEL32.DLL
 0x141bea04c LoadLibraryA
 0x141bea054 ExitProcess
 0x141bea05c GetProcAddress
 0x141bea064 VirtualProtect
MSVCP140.dll
 0x141bea074 ??1_Lockit@std@@QEAA@XZ
VCRUNTIME140.dll
 0x141bea084 memset
VCRUNTIME140_1.dll
 0x141bea094 __CxxFrameHandler4
WININET.dll
 0x141bea0a4 InternetOpenW

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure