One or more potentially interesting buffers were extracted, these generally contain injected code, configuration data, etc.
Allocates read-write-execute memory (usually to unpack itself)
(2 个事件)
| Time & API |
Arguments |
Status |
Return |
Repeated |
1619719516.785374
NtProtectVirtualMemory
|
process_identifier:
2196
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
1
length:
40960
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
base_address:
0x0371f000
|
success
|
0 |
0
|
1619719516.832374
NtAllocateVirtualMemory
|
process_identifier:
2196
region_size:
40960
stack_dep_bypass:
0
stack_pivoted:
0
heap_dep_bypass:
0
protection:
64
(PAGE_EXECUTE_READWRITE)
process_handle:
0xffffffff
allocation_type:
4096
(MEM_COMMIT)
base_address:
0x00320000
|
success
|
0 |
0
|
Foreign language identified in PE resource
(13 个事件)
| name |
RT_ICON |
language |
LANG_GEORGIAN |
offset |
0x02f18868 |
filetype |
GLS_BINARY_LSB_FIRST |
sublanguage |
SUBLANG_DEFAULT |
size |
0x00000468 |
| name |
RT_ICON |
language |
LANG_GEORGIAN |
offset |
0x02f18868 |
filetype |
GLS_BINARY_LSB_FIRST |
sublanguage |
SUBLANG_DEFAULT |
size |
0x00000468 |
| name |
RT_ICON |
language |
LANG_GEORGIAN |
offset |
0x02f18868 |
filetype |
GLS_BINARY_LSB_FIRST |
sublanguage |
SUBLANG_DEFAULT |
size |
0x00000468 |
| name |
RT_ICON |
language |
LANG_GEORGIAN |
offset |
0x02f18868 |
filetype |
GLS_BINARY_LSB_FIRST |
sublanguage |
SUBLANG_DEFAULT |
size |
0x00000468 |
| name |
RT_ICON |
language |
LANG_GEORGIAN |
offset |
0x02f18868 |
filetype |
GLS_BINARY_LSB_FIRST |
sublanguage |
SUBLANG_DEFAULT |
size |
0x00000468 |
| name |
RT_ICON |
language |
LANG_GEORGIAN |
offset |
0x02f18868 |
filetype |
GLS_BINARY_LSB_FIRST |
sublanguage |
SUBLANG_DEFAULT |
size |
0x00000468 |
| name |
RT_ICON |
language |
LANG_GEORGIAN |
offset |
0x02f18868 |
filetype |
GLS_BINARY_LSB_FIRST |
sublanguage |
SUBLANG_DEFAULT |
size |
0x00000468 |
| name |
RT_ICON |
language |
LANG_GEORGIAN |
offset |
0x02f18868 |
filetype |
GLS_BINARY_LSB_FIRST |
sublanguage |
SUBLANG_DEFAULT |
size |
0x00000468 |
| name |
RT_ICON |
language |
LANG_GEORGIAN |
offset |
0x02f18868 |
filetype |
GLS_BINARY_LSB_FIRST |
sublanguage |
SUBLANG_DEFAULT |
size |
0x00000468 |
| name |
RT_ICON |
language |
LANG_GEORGIAN |
offset |
0x02f18868 |
filetype |
GLS_BINARY_LSB_FIRST |
sublanguage |
SUBLANG_DEFAULT |
size |
0x00000468 |
| name |
RT_ICON |
language |
LANG_GEORGIAN |
offset |
0x02f18868 |
filetype |
GLS_BINARY_LSB_FIRST |
sublanguage |
SUBLANG_DEFAULT |
size |
0x00000468 |
| name |
RT_GROUP_ICON |
language |
LANG_GEORGIAN |
offset |
0x02f18cd0 |
filetype |
data |
sublanguage |
SUBLANG_DEFAULT |
size |
0x0000003e |
| name |
RT_GROUP_ICON |
language |
LANG_GEORGIAN |
offset |
0x02f18cd0 |
filetype |
data |
sublanguage |
SUBLANG_DEFAULT |
size |
0x0000003e |
The binary likely contains encrypted or compressed data indicative of a packer
(2 个事件)
| entropy |
7.270449298386769 |
section |
{'size_of_data': '0x0001b800', 'virtual_address': '0x00001000', 'entropy': 7.270449298386769, 'name': '.text', 'virtual_size': '0x0001b70c'} |
description |
A section with a high entropy has been found |
| entropy |
0.6094182825484764 |
description |
Overall entropy of this PE file is high |