Report - Apex.exe

PE File PE32
ScreenShot
Created 2024.08.05 11:18 Machine s1_win7_x6403
Filename Apex.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
7
Behavior Score
3.4
ZERO API file : malware
VT API (file) 54 detected (AIDetectMalware, BlackMoon, malicious, high confidence, score, TeslaCrypt, Unsafe, Vb4g, Attribute, HighConfidence, A suspicious, Artemis, MalwareX, CLOUD, Redcap, iznxb, YXEHDZ, Real Protect, high, Detected, ai score=83, MUPX, Gen@24tbus, Upatre, Eldorado, Malpacked5, ZexaF, OqKfaWJfh9bb, BScope, DiskWriter, ChinAd, Vsmw, Static AI, Malicious PE, Dinwod, frindll, confidence)
md5 017933f498a5e5fec5429ac2a1dc3b4a
sha256 e9882e6012a21213aeb9f6f4ea8d5e23e52afae6b8993a352bfc582bcc42c3fe
ssdeep 12288:k06bh5/NxtL/fnCchqxdQ36oAT4fUrYhfRE8aK88dPVJm+CGXbu6731CJCoSe:kBbh5/Nxtrh4u36N4fUspWg3m/Glz1Cv
imphash b884193883789084b22da422ca7bc7ef
impfuzzy 6:omRgsfMVWZRXgBJAEoZ/OEGDzyRFg3E6+EduLbBnaMBxAdYgW46PWTXmJJcJQZQx:omRgWMIxgABZG/Dzyg3ETEduxJ45NIeR
  Network IP location

Signature (7cnts)

Level Description
danger File has been identified by 54 AntiVirus engines on VirusTotal as malicious
watch Communicates with host for which no DNS query was performed
notice Allocates read-write-execute memory (usually to unpack itself)
notice Foreign language identified in PE resource
notice The binary likely contains encrypted or compressed data indicative of a packer
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)

Rules (2cnts)

Level Name Description Collection
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (2cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://42.193.241.116:19920/1p172BRmPZK29yhc1OKl/?card=&mac=&soft=apex&Var=1 Unknown 42.193.241.116 clean
42.193.241.116 Unknown 42.193.241.116 malware

Suricata ids

PE API

IAT(Import Address Table) Library

ADVAPI32.dll
 0x599140 RegCloseKey
COMCTL32.dll
 0x599148 None
GDI32.dll
 0x599150 SaveDC
iphlpapi.dll
 0x599158 GetAdaptersInfo
KERNEL32.DLL
 0x599160 LoadLibraryA
 0x599164 ExitProcess
 0x599168 GetProcAddress
 0x59916c VirtualProtect
ole32.dll
 0x599174 OleRun
OLEAUT32.dll
 0x59917c VariantInit
oledlg.dll
 0x599184 None
RASAPI32.dll
 0x59918c RasHangUpA
SHELL32.dll
 0x599194 DragFinish
SHLWAPI.dll
 0x59919c PathFileExistsA
USER32.dll
 0x5991a4 GetDC
WININET.dll
 0x5991ac InternetOpenA
WINSPOOL.DRV
 0x5991b4 ClosePrinter
WSOCK32.dll
 0x5991bc send

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure