Windows
Analysis Report
VirusSick.exe
Overview
General Information
Detection
Score: | 56 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a debugger is running (OutputDebugString,GetLastError)
Contains functionality to dynamically determine API calls
Contains functionality to query CPU information (cpuid)
Contains functionality to record screenshots
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Deletes files inside the Windows folder
Detected potential crypto function
Found inlined nop instructions (likely shell or obfuscated code)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
IP address seen in connection with other malware
PE file contains more sections than normal
PE file contains sections with non-standard names
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses Microsoft's Enhanced Cryptographic Provider
Uses code obfuscation techniques (call, push, ret)
Classification
- System is w10x64
VirusSick.exe (PID: 6836 cmdline:
"C:\Users\ user\Deskt op\VirusSi ck.exe" MD5: 9144CF49BEE346952AB9F46B20240D08) cmd.exe (PID: 760 cmdline:
C:\Windows \system32\ cmd.exe /c start "" "http://ww w.drinkify .org" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) conhost.exe (PID: 5660 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) chrome.exe (PID: 5728 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --s tart-maxim ized --sin gle-argume nt http:// www.drinki fy.org/ MD5: E81F54E6C1129887AEA47E7D092680BF) chrome.exe (PID: 6484 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --no-pre-r ead-main-d ll --field -trial-han dle=1880,i ,826262387 0461844564 ,809522073 933189353, 262144 --d isable-fea tures=Opti mizationGu ideModelDo wnloading, Optimizati onHints,Op timization HintsFetch ing,Optimi zationTarg etPredicti on --varia tions-seed -version=2 0250306-18 3004.42900 0 --mojo-p latform-ch annel-hand le=2020 /p refetch:3 MD5: E81F54E6C1129887AEA47E7D092680BF)
- cleanup
⊘No configs have been found
⊘No yara matches
⊘No Sigma rule has matched
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-03-12T00:50:06.209798+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49682 | 172.67.74.152 | 443 | TCP |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | Code function: | 0_2_004C1520 |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Code function: | 0_2_004F0150 | |
Source: | Code function: | 0_2_00548160 | |
Source: | Code function: | 0_2_00544314 | |
Source: | Code function: | 0_2_005363E4 | |
Source: | Code function: | 0_2_0053C3A0 | |
Source: | Code function: | 0_2_0054E4B0 | |
Source: | Code function: | 0_2_0054E4B0 | |
Source: | Code function: | 0_2_0053C5B0 | |
Source: | Code function: | 0_2_004F0600 | |
Source: | Code function: | 0_2_004F0720 | |
Source: | Code function: | 0_2_00546A80 | |
Source: | Code function: | 0_2_00548B50 | |
Source: | Code function: | 0_2_00548B50 | |
Source: | Code function: | 0_2_00548B50 | |
Source: | Code function: | 0_2_00546CB0 | |
Source: | Code function: | 0_2_004FB140 | |
Source: | Code function: | 0_2_004F9120 | |
Source: | Code function: | 0_2_004F91BC | |
Source: | Code function: | 0_2_004EB270 | |
Source: | Code function: | 0_2_00549210 | |
Source: | Code function: | 0_2_00549210 | |
Source: | Code function: | 0_2_00549210 | |
Source: | Code function: | 0_2_005432D2 | |
Source: | Code function: | 0_2_004EB2E2 | |
Source: | Code function: | 0_2_004F9350 | |
Source: | Code function: | 0_2_004F93EC | |
Source: | Code function: | 0_2_0057F380 | |
Source: | Code function: | 0_2_004F9420 | |
Source: | Code function: | 0_2_004F9420 | |
Source: | Code function: | 0_2_004F94BC | |
Source: | Code function: | 0_2_004F956C | |
Source: | Code function: | 0_2_005415C4 | |
Source: | Code function: | 0_2_004F96D0 | |
Source: | Code function: | 0_2_004F976C | |
Source: | Code function: | 0_2_004EF770 | |
Source: | Code function: | 0_2_0057B7F0 | |
Source: | Code function: | 0_2_0052B960 | |
Source: | Code function: | 0_2_004F9900 | |
Source: | Code function: | 0_2_004F99D0 | |
Source: | Code function: | 0_2_004F99D0 | |
Source: | Code function: | 0_2_004F999C | |
Source: | Code function: | 0_2_004F9A6C | |
Source: | Code function: | 0_2_004F9B1C | |
Source: | Code function: | 0_2_004FDC61 | |
Source: | Code function: | 0_2_004FDC61 | |
Source: | Code function: | 0_2_004FDC61 | |
Source: | Code function: | 0_2_004FDD0C | |
Source: | Code function: | 0_2_004FDDBC | |
Source: | Code function: | 0_2_004FDE6C | |
Source: | Code function: | 0_2_004FBE30 | |
Source: | Code function: | 0_2_00543FC4 |
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: |
Source: | Suricata IDS: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: |