Report - winX32.exe

PE File .NET EXE PE32 Lnk Format GIF Format
ScreenShot
Created 2025.02.05 11:11 Machine s1_win7_x6403
Filename winX32.exe
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
AI Score
11
Behavior Score
6.4
ZERO API file : clean
VT API (file) 57 detected (AIDetectMalware, lWjm, GenericFC, S17873958, BackdoorNJRat, Bladabindi, Unsafe, malicious, confidence, 100%, BladabindiNET, Ratenjay, Windows, Njrat, KeyloggerX, Nanocore, AsyncRat, kvmqvs, CLASSIC, Gen7, BLADABI, Real Protect, moderate, score, Static AI, Malicious PE, Amonetize, ammc, Detected, atmn, Eldorado, R137413, Autorave, GdSda, QwHTj9qDKeg, NanoBot)
md5 eee37f6f66eafa13d9555dfc9ccb3805
sha256 ca569ad2e113c57c5ddeb1770ae4d63f579df3504306097ff8a16b1cb37dcaa9
ssdeep 384:fL1M2XwBNOaLNOFE/Av2yeCP1BBvMl7AQk93vmhm7UMKmIEecKdbXTzm9bVhcaM4:Te220M0Wl7A/vMHTi9bD
imphash f34d5f2d4577ed6d9ceec516c1f5a744
impfuzzy 3:rGsLdAIEK:tf
  Network IP location

Signature (15cnts)

Level Description
danger File has been identified by 57 AntiVirus engines on VirusTotal as malicious
watch Installs itself for autorun at Windows startup
notice A process attempted to delay the analysis task.
notice Allocates read-write-execute memory (usually to unpack itself)
notice Checks for the Locally Unique Identifier on the system for a suspicious privilege
notice Checks whether any human activity is being performed by constantly checking whether the foreground window changed
notice Connects to a Dynamic DNS Domain
notice Creates a shortcut to an executable file
notice Creates executable files on the filesystem
notice Drops a binary and executes it
notice Drops an executable to the user AppData folder
notice Uses Windows utilities for basic Windows functionality
info Checks if process is being debugged by a debugger
info One or more processes crashed
info Queries for the computername

Rules (8cnts)

Level Name Description Collection
info Is_DotNET_EXE (no description) binaries (download)
info Is_DotNET_EXE (no description) binaries (upload)
info IsPE32 (no description) binaries (download)
info IsPE32 (no description) binaries (upload)
info lnk_file_format Microsoft Windows Shortcut File Format binaries (download)
info Lnk_Format_Zero LNK Format binaries (download)
info PE_Header_Zero PE File Signature binaries (download)
info PE_Header_Zero PE File Signature binaries (upload)

Network (2cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
sosomyhestor.ddns.net SA Bayanat Al-Oula For Network Services Limited Co. 46.153.112.54 clean
46.153.112.54 SA Bayanat Al-Oula For Network Services Limited Co. 46.153.112.54 clean

Suricata ids

PE API

IAT(Import Address Table) Library

mscoree.dll
 0x402000 _CorExeMain

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure