Edit tour
Windows
Analysis Report
Installer_QElectroTech-0.90_x86_64-win64+git7758-1.exe
Overview
General Information
Detection
Score: | 2 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 40% |
Signatures
Contains functionality for read data from the clipboard
Contains functionality to dynamically determine API calls
Contains functionality to shutdown / reboot the system
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Detected potential crypto function
Drops PE files
Found dropped PE file which has not been started or loaded
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Classification
- System is w10x64
- Installer_QElectroTech-0.90_x86_64-win64+git7758-1.exe (PID: 4832 cmdline:
"C:\Users\ user\Deskt op\Install er_QElectr oTech-0.90 _x86_64-wi n64+git775 8-1.exe" MD5: E5AD3C489DF53F87044FA7C6B3CD54FD)
- cleanup
⊘No configs have been found
⊘No yara matches
⊘No Sigma rule has matched
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-31T14:51:35.463305+0100 | 2022930 | 1 | A Network Trojan was detected | 172.202.163.200 | 443 | 192.168.2.5 | 49704 | TCP |
2024-10-31T14:52:15.310290+0100 | 2022930 | 1 | A Network Trojan was detected | 172.202.163.200 | 443 | 192.168.2.5 | 49896 | TCP |
Click to jump to signature section
Show All Signature Results
There are no malicious signatures, click here to show all signatures.
Source: | Static PE information: |
Source: | Window detected: |