Report - client32.exe

UPX PE File PE32
ScreenShot
Created 2024.07.17 09:07 Machine s1_win7_x6401
Filename client32.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
3
Behavior Score
0.4
ZERO API file : clean
VT API (file) 6 detected (RemoteAdmin, NetSupportManager, AB potentially unsafe, Detected, Tool, BZJE, NetSupport)
md5 9497aece91e1ccc495ca26ae284600b9
sha256 1b63f83f06dbd9125a6983a36e0dbd64026bb4f535e97c5df67c1563d91eff89
ssdeep 1536:HtvrImfzoXK6DDvvvDvpvZMt+pan/opgRl2:lImfzoXK9/o66
imphash 78ed70ebeb178ed1bae5921d2ed514bc
impfuzzy 3:rfeZpPwSd1EL/KfOAXLs1MO/OywSx2AEZsSW+RAKD:rIrOLEOAQZ/O4E3yE
  Network IP location

Signature (1cnts)

Level Description
notice File has been identified by 6 AntiVirus engines on VirusTotal as malicious

Rules (3cnts)

Level Name Description Collection
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

PCICL32.dll
 0x40306c _NSMClient32@8
KERNEL32.dll
 0x403058 GetCommandLineA
 0x40305c ExitProcess
 0x403060 GetModuleHandleA
 0x403064 GetStartupInfoA

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure