Report - bsso_launcher_v1.exe

Malicious Library UPX PE File PE64 ftp OS Processor Check
ScreenShot
Created 2024.08.09 07:56 Machine s1_win7_x6401
Filename bsso_launcher_v1.exe
Type PE32+ executable (GUI) x86-64, for MS Windows
AI Score
5
Behavior Score
5.2
ZERO API file : malware
VT API (file)
md5 6a60f6fbd451bfb11d0c943706ceda0a
sha256 82c2f0af2f595ff2656f3c418246ffd7f8daa22d0cc38605977def4e42fd32bd
ssdeep 49152:BYdvcy8kcu0RxBU+89fH341MhWCDlRA6BXuhb4cFxcuUo:BYdcl/3RxeH3dhV4LhUcFxcuUo
imphash
impfuzzy 3::
  Network IP location

Signature (13cnts)

Level Description
watch Communicates with host for which no DNS query was performed
watch Drops a binary and executes it
watch Installs Tor on the machine
notice Allocates read-write-execute memory (usually to unpack itself)
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
notice Checks adapter addresses which can be used to detect virtual network interfaces
notice Communication to multiple IPs on high port numbers possibly indicative of a peer-to-peer (P2P) or non-standard command and control protocol
notice Creates executable files on the filesystem
notice Starts servers listening
notice The binary likely contains encrypted or compressed data indicative of a packer
info Checks amount of memory in system
info Checks if process is being debugged by a debugger
info One or more processes crashed

Rules (8cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (download)
watch UPX_Zero UPX packed file binaries (download)
info ftp_command ftp command binaries (download)
info IsPE64 (no description) binaries (download)
info IsPE64 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (download)
info PE_Header_Zero PE File Signature binaries (download)
info PE_Header_Zero PE File Signature binaries (upload)

Network (5cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
84.240.60.234 LT Penkiu kontinentu komunikaciju centras, Ltd. 84.240.60.234 clean
199.195.253.180 US PONYNET 199.195.253.180 clean
178.33.36.64 FR OVH SAS 178.33.36.64 clean
137.226.34.45 DE RWTH Aachen University 137.226.34.45 clean
145.239.136.129 FR OVH SAS 145.239.136.129 clean

Suricata ids

PE API

IAT(Import Address Table) is none

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure