ScreenShot
Created | 2021.03.10 15:43 | Machine | s1_win7_x6401 |
Filename | ElsI5ohZ.exe | ||
Type | PE32 executable (DLL) (GUI) Intel 80386, for MS Windows | ||
AI Score |
|
Behavior Score |
|
ZERO API | file : clean | ||
VT API (file) | |||
md5 | eb9efca301b5883879d394fcd2da35f1 | ||
sha256 | b6cc1bb47a47eab1e79f578b187723021faff14cccde6a2eb319bddd4779ee09 | ||
ssdeep | 3072:3Tcr3VWYFcXTNZEjmL18zM7cXzAMsT7bXsObx7UpYN4IO6KMZJpSx:3TMFWYYTNKjmLyg7ozALzXsONUhIl/Zy | ||
imphash | 554e238e1840919675ea2a74968f15ab | ||
impfuzzy | 6:XAu6FIvX6lFBJAMWBJAEnEo1zhgXKUHXQTw2qn:G+vXyNApAJo1z+XtA0Nn |
Network IP location
Signature (3cnts)
Level | Description |
---|---|
notice | The binary likely contains encrypted or compressed data indicative of a packer |
info | The executable contains unknown PE section names indicative of a packer (could be a false positive) |
info | The executable uses a known packer |
Rules (8cnts)
Level | Name | Description | Collection |
---|---|---|---|
info | IsDLL | (no description) | binaries (upload) |
info | IsPE32 | (no description) | binaries (upload) |
info | PE_Header_Zero | PE File Signature Zero | binaries (upload) |
info | HasDebugData | DebugData Check | binaries (upload) |
info | HasModified_DOS_Message | DOS Message Check | binaries (upload) |
info | HasRichSignature | Rich Signature Check | binaries (upload) |
info | IsPacked | Entropy Check | binaries (upload) |
info | IsWindowsGUI | (no description) | binaries (upload) |
Network (0cnts) ?
Request | CC | ASN Co | IP4 | Rule ? | ZERO ? |
---|
Suricata ids
PE API
IAT(Import Address Table) Library
KERNEL32.dll
0x406008 CloseHandle
0x40600c IsBadStringPtrW
0x406010 OutputDebugStringA
0x406014 LoadLibraryExA
0x406018 LoadLibraryA
0x40601c GetModuleHandleA
0x406020 GenerateConsoleCtrlEvent
ADVAPI32.dll
0x406000 RegLoadAppKeyW
USER32.dll
0x406028 TranslateMessage
0x40602c RegisterDeviceNotificationA
EAT(Export Address Table) is none
KERNEL32.dll
0x406008 CloseHandle
0x40600c IsBadStringPtrW
0x406010 OutputDebugStringA
0x406014 LoadLibraryExA
0x406018 LoadLibraryA
0x40601c GetModuleHandleA
0x406020 GenerateConsoleCtrlEvent
ADVAPI32.dll
0x406000 RegLoadAppKeyW
USER32.dll
0x406028 TranslateMessage
0x40602c RegisterDeviceNotificationA
EAT(Export Address Table) is none