Report - 66ca11c91d783_vaelw.exe#space

Antivirus PE File .NET EXE PE32
ScreenShot
Created 2024.08.25 19:01 Machine s1_win7_x6401
Filename 66ca11c91d783_vaelw.exe#space
Type PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
AI Score
5
Behavior Score
2.8
ZERO API file : malware
VT API (file) 32 detected (AIDetectMalware, malicious, high confidence, Artemis, Unsafe, Kryptik, Vi9j, Attribute, HighConfidence, GenKryptik, HAXT, PWSX, MSIL@AI, MSIL2, Ea3nhGtjHIHjp+u1F7pCQQ, VIDAR, YXEHYZ, psrub, Sabsik, 5H4YRR, ABTrojan, RTSR, ApplicationInfo, ZemsilF, mm2@ayz7i0ii, RedLineStealer, Chgt, confidence, 100%)
md5 ad8a02a68b36bd0c78428d3552feacce
sha256 3891b4ca289d3c1ed1e73d2af779191c414552b79302a3546b45a43e2afe0423
ssdeep 3072:t7GCBMxBmNVP66jWNLndbhXj8nDdl8i2VfF0fBRb2PJu9fhxsPJt17So4kKYzEO:tyCBMxBmNVPdjAnqdln2VNJP0h+f8yEO
imphash f34d5f2d4577ed6d9ceec516c1f5a744
impfuzzy 3:rGsLdAIEK:tf
  Network IP location

Signature (8cnts)

Level Description
danger File has been identified by 32 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice The binary likely contains encrypted or compressed data indicative of a packer
info Checks amount of memory in system
info Checks if process is being debugged by a debugger
info Command line console output was observed
info Queries for the computername
info This executable has a PDB path

Rules (4cnts)

Level Name Description Collection
watch Antivirus Contains references to security software binaries (upload)
info Is_DotNET_EXE (no description) binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

mscoree.dll
 0x402000 _CorExeMain

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure