Report - code.exe

Formbook Generic Malware Malicious Library UPX PE File PE32 DLL
ScreenShot
Created 2025.02.07 14:23 Machine s1_win7_x6401
Filename code.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
8
Behavior Score
6.6
ZERO API file : malware
VT API (file) 53 detected (AIDetectMalware, Formbook, Malicious, score, sdum, VirRansom, Mikey, Unsafe, confidence, 100%, Attribute, HighConfidence, high confidence, TrojanX, CLASSIC, ZPACK, Possible, Real Protect, Static AI, Malicious PE, Detected, Eldorado, R647393, Artemis, BScope, Jtgl, susgen)
md5 88ba5ea93cd4d63db0c02028808483d5
sha256 27632516b503084b7a82223985ade9d419829b073a0da07411877f97e218e4a7
ssdeep 6144:adbUUC1t/5mHkcx+rN4m0X+zWjw3sSVZZJa4zxjcOcRyb1oY7mRXx:adfCL/5Brmm04SosmNa49ILRvXx
imphash
impfuzzy 3::
  Network IP location

Signature (13cnts)

Level Description
danger File has been identified by 53 AntiVirus engines on VirusTotal as malicious
watch Attempts to identify installed AV products by installation directory
watch Manipulates memory of a non-child process indicative of process injection
watch Used NtSetContextThread to modify a thread in a remote process indicative of process injection
notice A process attempted to delay the analysis task.
notice Allocates read-write-execute memory (usually to unpack itself)
notice Creates executable files on the filesystem
notice Drops an executable to the user AppData folder
notice One or more potentially interesting buffers were extracted
notice Performs some HTTP requests
notice Sends data using the HTTP POST Method
notice Steals private information from local Internet browsers
notice The binary likely contains encrypted or compressed data indicative of a packer

Rules (8cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (download)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (download)
info IsDLL (no description) binaries (download)
info IsPE32 (no description) binaries (download)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (download)
info PE_Header_Zero PE File Signature binaries (upload)

Network (43cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://www.laohuc58.net/q2xw/?Llh=86ngbchxwzH4i1X9t/6T/+Oi07pXbTio6Z6AqXex3cvjnWz71i6BmEbigKLnuir3o4hn/RqteaiiAlb4smyLAUyEx3YzLzbbvgN8NMjBPYT9mAET1dTBOG3s6KAnBEBCryIsKCY=&td=4M-32bF2uXv9 US CNSERVERS 23.225.159.42 clean
http://www.zltbd.top/1jgm/?Llh=eA6uj9mZZG+EKrxfswGApmXXI0p+YTaKp1gfdi5CfcM9nM+TLjgWcwBtgp/C7prMYA+QDtZzzV+0rSF+jYnqwmuWlATC+zwKaxmM0eLSIF6KRgpcsoHnjR3ICsIoHcDcBWoJljM=&td=4M-32bF2uXv9 US PEGTECHINC 198.2.236.221 43767 mailcious
http://www.lifesentials.life/ai0p/ US NAMECHEAP-NET 63.250.47.57 43769 mailcious
http://www.031234103.xyz/dcuq/?Llh=7EIrk2a44qM8+P4T8JDW5BXJ9n28PXV7+/6L2NN5PDXBTTL/JZ98MmX8dmN4cg/v65DfsXcqsYvOJsm24QtwtT24Ily7fae4aXU265y/XHAb6zWkMeauie4snRNRUk0nTZ2JMB0=&td=4M-32bF2uXv9 DE Hetzner Online GmbH 144.76.229.203 clean
http://www.dogebonus.xyz/0vny/ US AMAZON-02 13.248.169.48 clean
http://www.extremedoge.xyz/d8se/ US AMAZON-02 76.223.54.146 43765 mailcious
http://www.extremedoge.xyz/d8se/?Llh=/SD9pFSzQOAsk6zpabHlU9ZXbxrg7PaZHGb2u7tA7jL8hbNivAh91rSnEmMQYiYm2xILAWc0h2mK7v85Eb/bwmkVaqdX4hXL1d46fAKlPCExW94pmuU+QNfSRFIryEKBz6Xtm2w=&td=4M-32bF2uXv9 US AMAZON-02 76.223.54.146 43765 mailcious
http://www.dogebonus.xyz/0vny/?Llh=myEZ251pNFEUATDY+9yAk+s16G6gEHJ2TfH5Ex+eBmeHh8124vv24n+FuItehPX14VOi64VFrqeI2WDFhnLrQF1N78gHuIe9wI/OsVlX0IK+R23f3LJlJIi96OSfeEBtIW5OHg8=&td=4M-32bF2uXv9 US AMAZON-02 13.248.169.48 clean
http://www.sqlite.org/2018/sqlite-dll-win32-x86-3260000.zip US Linode, LLC 45.33.6.223 clean
http://www.lifesentials.life/ai0p/?Llh=rZDqlkYBI8Udwc1PV/KnJHNh6pEuqfnUU600R0dEHTi0g/oFcrH0VJPjKDcJsyDPkPK5dg/BoZxLcakNPxKVIp3FFoqOpAqATHzFTc0Kc7j4Hnf42/UwaR/YWWdcV10GGOZvjs0=&td=4M-32bF2uXv9 US NAMECHEAP-NET 63.250.47.57 43769 mailcious
http://www.67051.app/fm7p/?Llh=fBQGVIP7Njvsfk9lzF9d/sdBluYbkOx9Vaqk3JyU25ETPeViuHfhuXRn/X/4l2r/aQcZiXoH+567skXIk+or+vUABT2ejmBxdOFfcD/7nc+/oBxuIH8atQY3BV9A3FWHsGb3cNA=&td=4M-32bF2uXv9 HK 24.hk global BGP 103.215.78.119 43768 mailcious
http://www.meacci.xyz/y3n2/ US AMAZON-02 13.248.169.48 43766 mailcious
http://www.meacci.xyz/y3n2/?Llh=YYHifcw1ROMF/3Rui21dObVXjAOycMKtO4hXXvbRKVUVh0h/q4DM+aO7A1nlqnFctBzVAwzHmVAfM2sicI7T38fTXgwlOQpRgAWrULTRJOennTkobfA6A/gEUPp6kRoqEnphUcA=&td=4M-32bF2uXv9 US AMAZON-02 13.248.169.48 43766 mailcious
http://www.laohuc58.net/q2xw/ SG BGPNET Global ASN 27.124.4.246 clean
http://www.shibbets.xyz/c3po/?Llh=/Wnh70q18r/I0Nchd4hywIFo9BzviYpX0j5Xn0WCxuGW1YNIN7yCv1GXQYyzHI9oVtbk0Qn7crHFX7iLWoKgAm1hHHflXN/4uvMxriDJeHGGOSWZuqMgFDJgNgOgFdkkkLhhx7k=&td=4M-32bF2uXv9 US AMAZON-02 76.223.54.146 clean
http://www.031234103.xyz/dcuq/ DE Hetzner Online GmbH 144.76.229.203 clean
http://www.67051.app/fm7p/ HK 24.hk global BGP 103.215.78.119 43768 mailcious
http://www.shibbets.xyz/c3po/ US AMAZON-02 13.248.169.48 clean
http://www.zltbd.top/1jgm/ US PEGTECHINC 198.2.236.221 43767 mailcious
http://www.brothersharetender.xyz/zt2z/ US AMAZON-02 13.248.169.48 43764 mailcious
http://www.brothersharetender.xyz/zt2z/?Llh=xrZBxJYgw8cIQMiqB7MJTIt56Y5x1dzsCIunmK+cvRjjBmIrzA2dl/VKD+8Ko7RwD9ZNT3MsvQ9uHPPRt337yY3SQq9c32vIKb0ZpnkUqAHAqojpvsCz/3SLl1qRQBpJo+hmuPc=&td=4M-32bF2uXv9 US AMAZON-02 76.223.54.146 43764 mailcious
http://www.banjia0731.icu/7hg3/ US DXTL Tseung Kwan O Service 45.199.72.207 clean
http://www.banjia0731.icu/7hg3/?Llh=v5X+3+iEc/Uvt288LwqsYb5NJ0322hz3EXLj0Ccb66JVULuRjil5/VwtV230PPKy6CklN/m1lmp+ebN8FryGocLqxWElOtZH067PqeKPuYFK80ONFwqGcRNYKgFa/Hst8tVb9YA=&td=4M-32bF2uXv9 US DXTL Tseung Kwan O Service 45.199.72.207 clean
www.extremedoge.xyz US AMAZON-02 13.248.169.48 mailcious
www.dogebonus.xyz US AMAZON-02 76.223.54.146 clean
www.031234103.xyz DE Hetzner Online GmbH 144.76.229.203 clean
www.laohuc58.net SG BGPNET Global ASN 27.124.4.246 clean
www.banjia0731.icu US DXTL Tseung Kwan O Service 45.199.72.207 clean
www.meacci.xyz US AMAZON-02 76.223.54.146 mailcious
www.zltbd.top US PEGTECHINC 198.2.236.221 mailcious
www.lifesentials.life US NAMECHEAP-NET 63.250.47.57 mailcious
www.brothersharetender.xyz US AMAZON-02 13.248.169.48 mailcious
www.67051.app HK 24.hk global BGP 103.215.78.119 mailcious
www.shibbets.xyz US AMAZON-02 13.248.169.48 clean
76.223.54.146 US AMAZON-02 76.223.54.146 mailcious
144.76.229.203 DE Hetzner Online GmbH 144.76.229.203 clean
198.2.236.221 US PEGTECHINC 198.2.236.221 mailcious
45.199.72.207 US DXTL Tseung Kwan O Service 45.199.72.207 clean
27.124.4.246 SG BGPNET Global ASN 27.124.4.246 clean
13.248.169.48 US AMAZON-02 13.248.169.48 mailcious
45.33.6.223 US Linode, LLC 45.33.6.223 clean
63.250.47.57 US NAMECHEAP-NET 63.250.47.57 mailcious
103.215.78.119 HK 24.hk global BGP 103.215.78.119 mailcious

Suricata ids

PE API

IAT(Import Address Table) is none

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure