Report - kg.exe

PE File PE32 MZP Format
ScreenShot
Created 2024.10.21 13:49 Machine s1_win7_x6401
Filename kg.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
9
Behavior Score
3.2
ZERO API file : malware
VT API (file) 45 detected (AIDetectMalware, Viking, lz9q, malicious, high confidence, score, Hacktool, AdwareClickSpring, Misc, Unsafe, Skeeyah, Vn22, Mosuck, AO potentially unsafe, Crack, Adobesuite, Tool, CLOUD, CRCK, ADOBECS, high, Static AI, Suspicious PE, Detected, ai score=99, se62747, Keygen@133zf, HTON, R4441, ZelphiF, dmGfaWC33Pic, MoSucker, Wacatac, CrackTool, GenAsa, sfYSO2vrum0, susgen, Crackin, grayware, confidence)
md5 ed8c78a13d8e1f2fa403ed013f9bdeca
sha256 7b2caa5017640cc39e49b35cf91bf4d2c1d94ec168603e26c1d60e7649ec559f
ssdeep 1536:X8GYgpVXkc3/RQJpxWOfOMDv2mmT1jMeDT:XvX7WJpxWOfOMD+3iev
imphash 042f854aa40eb5213ffd940a2e18951a
impfuzzy 3:swBJAEPwS9KTXzhAXw1MO/EX9CROXCHL02/cWwzmnQLgGn:dBJAEHGDvZ/EwRgCHDPfnugG
  Network IP location

Signature (8cnts)

Level Description
danger File has been identified by 45 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Foreign language identified in PE resource
notice The binary likely contains encrypted or compressed data indicative of a packer
info Checks amount of memory in system
info Checks if process is being debugged by a debugger
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The executable uses a known packer

Rules (3cnts)

Level Name Description Collection
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.DLL
 0x42566c LoadLibraryA
 0x425670 GetProcAddress
 0x425674 ExitProcess
advapi32.dll
 0x42567c RegCloseKey
gdi32.dll
 0x425684 SetROP2
msvcrt.dll
 0x42568c memset
oleaut32.dll
 0x425694 SysFreeString
user32.dll
 0x42569c GetDC

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure