ScreenShot
Created | 2024.10.15 14:24 | Machine | s1_win7_x6403 |
Filename | swf.exe | ||
Type | PE32 executable (GUI) Intel 80386, for MS Windows | ||
AI Score |
|
Behavior Score |
|
ZERO API | file : malware | ||
VT API (file) | 18 detected (AIDetectMalware, Malicious, score, Munp, high confidence, multiple detections, Ekstak, aytqu, AGEN) | ||
md5 | c02569d1105aa9135737cf3c1052e9dc | ||
sha256 | 5dfba42ad0a0f331b9e08013ba5815a527f8dd01e0703a75a6a77028ede45756 | ||
ssdeep | 98304:uayhREQVam9d4DgkTz6ALYvqGUaOnA1u6DfBYi3U7RI6da0K9amv+Bj:YnBV3fOngzb28xklj | ||
imphash | 884310b1928934402ea6fec1dbd3cf5e | ||
impfuzzy | 48:8cfp1rcQX0gebPCDr+ZbldH9AOZGwt+Eu55T/lGB:8cfpdcqNebqDrmrHW2 |
Network IP location
Signature (10cnts)
Level | Description |
---|---|
watch | Deletes executed files from disk |
watch | File has been identified by 18 AntiVirus engines on VirusTotal as malicious |
notice | Allocates read-write-execute memory (usually to unpack itself) |
notice | Creates executable files on the filesystem |
notice | Drops an executable to the user AppData folder |
notice | Queries for potentially installed applications |
info | Checks if process is being debugged by a debugger |
info | One or more processes crashed |
info | Queries for the computername |
info | The executable contains unknown PE section names indicative of a packer (could be a false positive) |
Rules (21cnts)
Level | Name | Description | Collection |
---|---|---|---|
danger | Win32_Trojan_Emotet_2_Zero | Win32 Trojan Emotet | binaries (download) |
danger | Win32_Trojan_Emotet_2_Zero | Win32 Trojan Emotet | binaries (upload) |
danger | Win32_Trojan_Gen_1_0904B0_Zero | Win32 Trojan Emotet | binaries (download) |
warning | Generic_Malware_Zero | Generic Malware | binaries (download) |
watch | Admin_Tool_IN_Zero | Admin Tool Sysinternals | binaries (download) |
watch | ConfuserEx_Zero | Confuser .NET | binaries (download) |
watch | ConfuserEx_Zero | Confuser .NET | binaries (upload) |
watch | Malicious_Library_Zero | Malicious_Library | binaries (download) |
watch | Malicious_Library_Zero | Malicious_Library | binaries (upload) |
watch | UPX_Zero | UPX packed file | binaries (download) |
watch | UPX_Zero | UPX packed file | binaries (upload) |
info | DllRegisterServer_Zero | execute regsvr32.exe | binaries (download) |
info | IsDLL | (no description) | binaries (download) |
info | IsPE32 | (no description) | binaries (download) |
info | IsPE32 | (no description) | binaries (upload) |
info | IsPE64 | (no description) | binaries (download) |
info | mzp_file_format | MZP(Delphi) file format | binaries (download) |
info | mzp_file_format | MZP(Delphi) file format | binaries (upload) |
info | OS_Processor_Check_Zero | OS Processor Check | binaries (download) |
info | PE_Header_Zero | PE File Signature | binaries (download) |
info | PE_Header_Zero | PE File Signature | binaries (upload) |
Network (0cnts) ?
Request | CC | ASN Co | IP4 | Rule ? | ZERO ? |
---|
Suricata ids
PE API
IAT(Import Address Table) Library
kernel32.dll
0x40c0b4 DeleteCriticalSection
0x40c0b8 LeaveCriticalSection
0x40c0bc EnterCriticalSection
0x40c0c0 InitializeCriticalSection
0x40c0c4 VirtualFree
0x40c0c8 VirtualAlloc
0x40c0cc LocalFree
0x40c0d0 LocalAlloc
0x40c0d4 WideCharToMultiByte
0x40c0d8 TlsSetValue
0x40c0dc TlsGetValue
0x40c0e0 MultiByteToWideChar
0x40c0e4 GetModuleHandleA
0x40c0e8 GetLastError
0x40c0ec GetCommandLineA
0x40c0f0 WriteFile
0x40c0f4 SetFilePointer
0x40c0f8 SetEndOfFile
0x40c0fc RtlUnwind
0x40c100 ReadFile
0x40c104 RaiseException
0x40c108 GetStdHandle
0x40c10c GetFileSize
0x40c110 GetSystemTime
0x40c114 GetFileType
0x40c118 ExitProcess
0x40c11c CreateFileA
0x40c120 CloseHandle
user32.dll
0x40c128 MessageBoxA
oleaut32.dll
0x40c130 VariantChangeTypeEx
0x40c134 VariantCopyInd
0x40c138 VariantClear
0x40c13c SysStringLen
0x40c140 SysAllocStringLen
advapi32.dll
0x40c148 RegQueryValueExA
0x40c14c RegOpenKeyExA
0x40c150 RegCloseKey
0x40c154 OpenProcessToken
0x40c158 LookupPrivilegeValueA
kernel32.dll
0x40c160 WriteFile
0x40c164 VirtualQuery
0x40c168 VirtualProtect
0x40c16c VirtualFree
0x40c170 VirtualAlloc
0x40c174 Sleep
0x40c178 SizeofResource
0x40c17c SetLastError
0x40c180 SetFilePointer
0x40c184 SetErrorMode
0x40c188 SetEndOfFile
0x40c18c RemoveDirectoryA
0x40c190 ReadFile
0x40c194 LockResource
0x40c198 LoadResource
0x40c19c LoadLibraryA
0x40c1a0 IsDBCSLeadByte
0x40c1a4 GetWindowsDirectoryA
0x40c1a8 GetVersionExA
0x40c1ac GetUserDefaultLangID
0x40c1b0 GetSystemInfo
0x40c1b4 GetSystemDefaultLCID
0x40c1b8 GetProcAddress
0x40c1bc GetModuleHandleA
0x40c1c0 GetModuleFileNameA
0x40c1c4 GetLocaleInfoA
0x40c1c8 GetLastError
0x40c1cc GetFullPathNameA
0x40c1d0 GetFileSize
0x40c1d4 GetFileAttributesA
0x40c1d8 GetExitCodeProcess
0x40c1dc GetEnvironmentVariableA
0x40c1e0 GetCurrentProcess
0x40c1e4 GetCommandLineA
0x40c1e8 GetACP
0x40c1ec InterlockedExchange
0x40c1f0 FormatMessageA
0x40c1f4 FindResourceA
0x40c1f8 DeleteFileA
0x40c1fc CreateProcessA
0x40c200 CreateFileA
0x40c204 CreateDirectoryA
0x40c208 CloseHandle
user32.dll
0x40c210 TranslateMessage
0x40c214 SetWindowLongA
0x40c218 PeekMessageA
0x40c21c MsgWaitForMultipleObjects
0x40c220 MessageBoxA
0x40c224 LoadStringA
0x40c228 ExitWindowsEx
0x40c22c DispatchMessageA
0x40c230 DestroyWindow
0x40c234 CreateWindowExA
0x40c238 CallWindowProcA
0x40c23c CharPrevA
comctl32.dll
0x40c244 InitCommonControls
advapi32.dll
0x40c24c AdjustTokenPrivileges
EAT(Export Address Table) is none
kernel32.dll
0x40c0b4 DeleteCriticalSection
0x40c0b8 LeaveCriticalSection
0x40c0bc EnterCriticalSection
0x40c0c0 InitializeCriticalSection
0x40c0c4 VirtualFree
0x40c0c8 VirtualAlloc
0x40c0cc LocalFree
0x40c0d0 LocalAlloc
0x40c0d4 WideCharToMultiByte
0x40c0d8 TlsSetValue
0x40c0dc TlsGetValue
0x40c0e0 MultiByteToWideChar
0x40c0e4 GetModuleHandleA
0x40c0e8 GetLastError
0x40c0ec GetCommandLineA
0x40c0f0 WriteFile
0x40c0f4 SetFilePointer
0x40c0f8 SetEndOfFile
0x40c0fc RtlUnwind
0x40c100 ReadFile
0x40c104 RaiseException
0x40c108 GetStdHandle
0x40c10c GetFileSize
0x40c110 GetSystemTime
0x40c114 GetFileType
0x40c118 ExitProcess
0x40c11c CreateFileA
0x40c120 CloseHandle
user32.dll
0x40c128 MessageBoxA
oleaut32.dll
0x40c130 VariantChangeTypeEx
0x40c134 VariantCopyInd
0x40c138 VariantClear
0x40c13c SysStringLen
0x40c140 SysAllocStringLen
advapi32.dll
0x40c148 RegQueryValueExA
0x40c14c RegOpenKeyExA
0x40c150 RegCloseKey
0x40c154 OpenProcessToken
0x40c158 LookupPrivilegeValueA
kernel32.dll
0x40c160 WriteFile
0x40c164 VirtualQuery
0x40c168 VirtualProtect
0x40c16c VirtualFree
0x40c170 VirtualAlloc
0x40c174 Sleep
0x40c178 SizeofResource
0x40c17c SetLastError
0x40c180 SetFilePointer
0x40c184 SetErrorMode
0x40c188 SetEndOfFile
0x40c18c RemoveDirectoryA
0x40c190 ReadFile
0x40c194 LockResource
0x40c198 LoadResource
0x40c19c LoadLibraryA
0x40c1a0 IsDBCSLeadByte
0x40c1a4 GetWindowsDirectoryA
0x40c1a8 GetVersionExA
0x40c1ac GetUserDefaultLangID
0x40c1b0 GetSystemInfo
0x40c1b4 GetSystemDefaultLCID
0x40c1b8 GetProcAddress
0x40c1bc GetModuleHandleA
0x40c1c0 GetModuleFileNameA
0x40c1c4 GetLocaleInfoA
0x40c1c8 GetLastError
0x40c1cc GetFullPathNameA
0x40c1d0 GetFileSize
0x40c1d4 GetFileAttributesA
0x40c1d8 GetExitCodeProcess
0x40c1dc GetEnvironmentVariableA
0x40c1e0 GetCurrentProcess
0x40c1e4 GetCommandLineA
0x40c1e8 GetACP
0x40c1ec InterlockedExchange
0x40c1f0 FormatMessageA
0x40c1f4 FindResourceA
0x40c1f8 DeleteFileA
0x40c1fc CreateProcessA
0x40c200 CreateFileA
0x40c204 CreateDirectoryA
0x40c208 CloseHandle
user32.dll
0x40c210 TranslateMessage
0x40c214 SetWindowLongA
0x40c218 PeekMessageA
0x40c21c MsgWaitForMultipleObjects
0x40c220 MessageBoxA
0x40c224 LoadStringA
0x40c228 ExitWindowsEx
0x40c22c DispatchMessageA
0x40c230 DestroyWindow
0x40c234 CreateWindowExA
0x40c238 CallWindowProcA
0x40c23c CharPrevA
comctl32.dll
0x40c244 InitCommonControls
advapi32.dll
0x40c24c AdjustTokenPrivileges
EAT(Export Address Table) is none