Report - install.msi

Generic Malware Malicious Library MSOffice File CAB OS Processor Check
ScreenShot
Created 2025.01.10 12:58 Machine s1_win7_x6403
Filename install.msi
Type Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Microsoft Edge 131.0.2903.112, Subject: Microsoft Edge, Author: Microsoft Corporation, Keywords: Installer, Template: Intel;1033, Revision
AI Score Not founds Behavior Score
2.4
ZERO API file : mailcious
VT API (file) 13 detected (Lazy, Heavy, GenInflated)
md5 872cb99a4886350aa57b1c40bba29b1c
sha256 e16baa228ab77485f38b335510270943ab54df755bf72987ac229d819bb85401
ssdeep 24576:Wt9cpVDhf6x7VZTi1RldQkwadtGaxft3UbV7mqppdq:ZpRhSxHTi1zmkltRt3UB7me
imphash
impfuzzy
  Network IP location

Signature (7cnts)

Level Description
watch File has been identified by 13 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Checks for the Locally Unique Identifier on the system for a suspicious privilege
notice Queries the disk size which could be used to detect virtual machine with small fixed size or dynamic allocation
info Checks amount of memory in system
info Checks if process is being debugged by a debugger
info Queries for the computername

Rules (5cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
info CAB_file_format CAB archive file binaries (upload)
info Microsoft_Office_File_Zero Microsoft Office File binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)

Network (99cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://qcoysaaooaiccqyu.xyz:443/api/client_hello RU FOP Samosenok Alexandr Sergeevich 193.32.177.34 clean
gwyooeiscmwguqms.xyz Unknown clean
oqyaoykomyoygics.xyz Unknown
oyewqwkusieeoqey.xyz Unknown clean
ggicikyqcaiyguee.xyz Unknown clean
ommwaqgaemsmcqwc.xyz Unknown clean
suwkomiqcykeyako.xyz Unknown clean
cauewwukyywyqiei.xyz Unknown clean
wuuiumemmigyyauq.xyz Unknown
kwuuwgemogmuomwq.xyz Unknown
ymseciekayuweoww.xyz Unknown
uiggameqqycugsqw.xyz Unknown clean
yyimcoiwgckeakcm.xyz Unknown clean
ukyokaigmmkumgoa.xyz Unknown
uecouukwkuceyuwg.xyz Unknown clean
maoeeogmuauywsyu.xyz Unknown clean
keosqeosukqcooco.xyz Unknown clean
awyomscgweuqmgaw.xyz Unknown clean
awwomgcseeqwkkom.xyz Unknown clean
oyocwswugeiqqyoo.xyz Unknown clean
akueuaicusaoieiy.xyz Unknown clean
qwywqgsmgaoiwsga.xyz Unknown clean
ewacuagosgqmuocm.xyz Unknown clean
eyoyssauceguqwmk.xyz Unknown clean
acwomuuukiomgqkm.xyz Unknown clean
keykoekseemyiewq.xyz Unknown clean
eyoaceoookqskqmy.xyz Unknown clean
ismqaewykmoiguki.xyz Unknown clean
eyiyueewuaqmmwcm.xyz Unknown clean
osmoygyawqmmimkq.xyz Unknown clean
qcoysaaooaiccqyu.xyz RU FOP Samosenok Alexandr Sergeevich 193.32.177.34 clean
ekcwemuekgqsimae.xyz Unknown clean
qiswokuokugiooky.xyz Unknown clean
immyecuqwkiyscys.xyz Unknown clean
sauygqecsusickcu.xyz Unknown clean
saumycuogqsqykes.xyz Unknown clean
oekcyqqggaegsesm.xyz Unknown clean
goeykqccmemkswom.xyz Unknown clean
keguuyioweymiaws.xyz Unknown clean
osaymwoggqqycmse.xyz Unknown clean
isaeicumkcuwqmqq.xyz Unknown clean
smaaowemwiwggocu.xyz Unknown clean
eqakguiwiqacqiwg.xyz Unknown clean
ososwckwcqmmwqcy.xyz Unknown clean
qwqsoyoqkymakowm.xyz Unknown clean
kkcqgowgkcoyokcu.xyz Unknown clean
ymqaaskiwomkucuy.xyz Unknown clean
wuokiysmiucoucak.xyz Unknown clean
smoswyoekkccyuga.xyz Unknown clean
gwwcqeykmseicgaw.xyz Unknown clean
wgcaouuqqqwucogy.xyz Unknown clean
ymmcwogyimsuqmcc.xyz Unknown clean
qqqmeagkkosgcayo.xyz Unknown clean
ukicsmiwggcwksam.xyz Unknown clean
gwamoggwyegsseao.xyz Unknown clean
ymuiggyusggsymoi.xyz Unknown clean
ymysimqoykwqeqiq.xyz Unknown clean
qcyksokwumicscaa.xyz Unknown clean
kkwkgmcoawgaoiwg.xyz Unknown clean
immcqsiceooqyaay.xyz Unknown clean
iyaikmkkowcqemsi.xyz Unknown clean
qigcqiaomwieqwka.xyz Unknown clean
smckcsaioceiyasu.xyz Unknown clean
eswweuycwwiiykwo.xyz Unknown clean
owaaygsacguucaye.xyz Unknown clean
iagisciiyoemgwaa.xyz Unknown clean
kwmcuwccqmuecgea.xyz Unknown clean
isemauqkwwiumyky.xyz Unknown clean
ukaiiiyqoooycyqm.xyz Unknown clean
omgooecquoweeomo.xyz Unknown clean
wucwykasawokemaw.xyz Unknown clean
smwsugycuuckemue.xyz Unknown
esiaisyasoaoqwki.xyz Unknown
uwgicagyykoommga.xyz Unknown
aksuakswwkiimamq.xyz Unknown
omsqkuiwcwoegooq.xyz Unknown
maiyuocqqiqiiskw.xyz Unknown
omgcoecwsqiuqyug.xyz Unknown
gwoyamckoqoaauoq.xyz Unknown
ysiwwoeeaaskykaw.xyz Unknown
qiswcssocuqsaqkq.xyz Unknown
osaeyoiqoqawauga.xyz Unknown
wgqyouayikuyuqmk.xyz Unknown
kecgikusmakuksma.xyz Unknown
omasqkwqyskcagwi.xyz Unknown
auayomwkewcomwas.xyz Unknown
goguooqkgysueime.xyz Unknown
muwqwgaaymomgwmi.xyz Unknown
uksgyqiqaaiaiesi.xyz Unknown
gcmiymmqgwuquokm.xyz Unknown
giqukkwwcwgqcisg.xyz Unknown
kwaywmaequkqccai.xyz Unknown
esimsqgcwwwmyoqc.xyz Unknown
imigkomgmqgmakqk.xyz Unknown
ukmcqucewskcqygg.xyz Unknown
ysawassgkwqygmmq.xyz Unknown
kqmsgskwgemyueya.xyz Unknown
imgeoyougkmmeuec.xyz Unknown
193.32.177.34 RU FOP Samosenok Alexandr Sergeevich 193.32.177.34 clean

Suricata ids



Similarity measure (PE file only) - Checking for service failure