Report - atualiza_tec.exe

ScreenShot
Created 2021.04.16 09:58 Machine s1_win7_x6402
Filename atualiza_tec.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
7
Behavior Score
4.0
ZERO API file : clean
VT API (file) 10 detected (AIDetectVM, malware2, Malicious, Artemis, TScope, Delf, Unsafe, Score, ZelphiF, HGW@a4ODLjoG, GdSda)
md5 a6ac13ea37c979e7623b73b8ac8670eb
sha256 c41e59e5e3c85ccf7f88f316b7ed81659be1864e2c9c87da5c881cb23d291cfc
ssdeep 12288:tusISQoVSFM0oTHCbi+dY/n4VDY1SSjxnsnd+:MLcEFzeIxcn4m1S2snd
imphash b0ccbf4d143e5aa9ee3a7c2cc747a74e
impfuzzy 192:f3yNG1a4/1buuAxSUvK9/qooqEXo72POQRk:f3Z1lAq9JUPOQO
  Network IP location

Signature (10cnts)

Level Description
warning Generates some ICMP traffic
watch Communicates with host for which no DNS query was performed
watch File has been identified by 10 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Foreign language identified in PE resource
notice Performs some HTTP requests
info Checks amount of memory in system
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The executable uses a known packer

Rules (14cnts)

Level Name Description Collection
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature Zero binaries (upload)
info borland_delphi Borland Delphi 2.0 - 7.0 / 2005 - 2007 binaries (upload)
info IsWindowsGUI (no description) binaries (upload)
info keylogger Run a keylogger binaries (upload)
info network_dns Communications use DNS binaries (upload)
info network_ssl Communications over SSL binaries (upload)
info network_tcp_listen Listen for incoming communication binaries (upload)
info network_tcp_socket Communications over RAW socket binaries (upload)
info network_udp_sock Communications over UDP network binaries (upload)
info screenshot Take screenshot binaries (upload)
info Str_Win32_Winsock2_Library Match Winsock 2 API library declaration binaries (upload)
info win_files_operation Affect private profile binaries (upload)
info win_registry Affect system registries binaries (upload)

Network (3cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://www.technoinfo.com.br/softwares/tcommerce_atual/Tcommerce.exe BR CI CENTRO DE INFORMACOES LTDA 177.47.177.54 clean
www.technoinfo.com.br BR CI CENTRO DE INFORMACOES LTDA 177.47.177.54 clean
177.47.177.54 BR CI CENTRO DE INFORMACOES LTDA 177.47.177.54 clean

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x473118 DeleteCriticalSection
 0x47311c LeaveCriticalSection
 0x473120 EnterCriticalSection
 0x473124 InitializeCriticalSection
 0x473128 VirtualFree
 0x47312c VirtualAlloc
 0x473130 LocalFree
 0x473134 LocalAlloc
 0x473138 GetVersion
 0x47313c GetCurrentThreadId
 0x473140 InterlockedDecrement
 0x473144 InterlockedIncrement
 0x473148 VirtualQuery
 0x47314c WideCharToMultiByte
 0x473150 MultiByteToWideChar
 0x473154 lstrlenA
 0x473158 lstrcpynA
 0x47315c LoadLibraryExA
 0x473160 GetThreadLocale
 0x473164 GetStartupInfoA
 0x473168 GetProcAddress
 0x47316c GetModuleHandleA
 0x473170 GetModuleFileNameA
 0x473174 GetLocaleInfoA
 0x473178 GetCommandLineA
 0x47317c FreeLibrary
 0x473180 FindFirstFileA
 0x473184 FindClose
 0x473188 ExitProcess
 0x47318c ExitThread
 0x473190 CreateThread
 0x473194 WriteFile
 0x473198 UnhandledExceptionFilter
 0x47319c RtlUnwind
 0x4731a0 RaiseException
 0x4731a4 GetStdHandle
user32.dll
 0x4731ac GetKeyboardType
 0x4731b0 LoadStringA
 0x4731b4 MessageBoxA
 0x4731b8 CharNextA
advapi32.dll
 0x4731c0 RegQueryValueExA
 0x4731c4 RegOpenKeyExA
 0x4731c8 RegCloseKey
oleaut32.dll
 0x4731d0 SysFreeString
 0x4731d4 SysReAllocStringLen
 0x4731d8 SysAllocStringLen
kernel32.dll
 0x4731e0 TlsSetValue
 0x4731e4 TlsGetValue
 0x4731e8 LocalAlloc
 0x4731ec GetModuleHandleA
advapi32.dll
 0x4731f4 RegQueryValueExA
 0x4731f8 RegOpenKeyExA
 0x4731fc RegCloseKey
kernel32.dll
 0x473204 lstrcpyA
 0x473208 WriteFile
 0x47320c WaitForSingleObject
 0x473210 VirtualQuery
 0x473214 VirtualAlloc
 0x473218 TerminateProcess
 0x47321c Sleep
 0x473220 SizeofResource
 0x473224 SetThreadLocale
 0x473228 SetFilePointer
 0x47322c SetEvent
 0x473230 SetErrorMode
 0x473234 SetEndOfFile
 0x473238 ResumeThread
 0x47323c ResetEvent
 0x473240 ReadFile
 0x473244 OpenProcess
 0x473248 MulDiv
 0x47324c MoveFileA
 0x473250 LockResource
 0x473254 LoadResource
 0x473258 LoadLibraryA
 0x47325c LeaveCriticalSection
 0x473260 InitializeCriticalSection
 0x473264 GlobalUnlock
 0x473268 GlobalReAlloc
 0x47326c GlobalHandle
 0x473270 GlobalLock
 0x473274 GlobalFree
 0x473278 GlobalFindAtomA
 0x47327c GlobalDeleteAtom
 0x473280 GlobalAlloc
 0x473284 GlobalAddAtomA
 0x473288 GetVersionExA
 0x47328c GetVersion
 0x473290 GetTimeZoneInformation
 0x473294 GetTickCount
 0x473298 GetThreadLocale
 0x47329c GetTempPathA
 0x4732a0 GetSystemInfo
 0x4732a4 GetStringTypeExA
 0x4732a8 GetStdHandle
 0x4732ac GetProcAddress
 0x4732b0 GetModuleHandleA
 0x4732b4 GetModuleFileNameA
 0x4732b8 GetLocaleInfoA
 0x4732bc GetLocalTime
 0x4732c0 GetLastError
 0x4732c4 GetFullPathNameA
 0x4732c8 GetFileSize
 0x4732cc GetExitCodeThread
 0x4732d0 GetDiskFreeSpaceA
 0x4732d4 GetDateFormatA
 0x4732d8 GetCurrentThreadId
 0x4732dc GetCurrentProcessId
 0x4732e0 GetCPInfo
 0x4732e4 GetACP
 0x4732e8 FreeResource
 0x4732ec InterlockedIncrement
 0x4732f0 InterlockedExchange
 0x4732f4 InterlockedDecrement
 0x4732f8 FreeLibrary
 0x4732fc FormatMessageA
 0x473300 FindResourceA
 0x473304 FindFirstFileA
 0x473308 FindClose
 0x47330c FileTimeToLocalFileTime
 0x473310 FileTimeToDosDateTime
 0x473314 EnumCalendarInfoA
 0x473318 EnterCriticalSection
 0x47331c DeleteCriticalSection
 0x473320 CreateThread
 0x473324 CreateFileA
 0x473328 CreateEventA
 0x47332c CompareStringA
 0x473330 CloseHandle
version.dll
 0x473338 VerQueryValueA
 0x47333c GetFileVersionInfoSizeA
 0x473340 GetFileVersionInfoA
gdi32.dll
 0x473348 UnrealizeObject
 0x47334c StretchBlt
 0x473350 SetWindowOrgEx
 0x473354 SetWinMetaFileBits
 0x473358 SetViewportOrgEx
 0x47335c SetTextColor
 0x473360 SetStretchBltMode
 0x473364 SetROP2
 0x473368 SetPixel
 0x47336c SetEnhMetaFileBits
 0x473370 SetDIBColorTable
 0x473374 SetBrushOrgEx
 0x473378 SetBkMode
 0x47337c SetBkColor
 0x473380 SelectPalette
 0x473384 SelectObject
 0x473388 SaveDC
 0x47338c RoundRect
 0x473390 RestoreDC
 0x473394 Rectangle
 0x473398 RectVisible
 0x47339c RealizePalette
 0x4733a0 PlayEnhMetaFile
 0x4733a4 PatBlt
 0x4733a8 MoveToEx
 0x4733ac MaskBlt
 0x4733b0 LineTo
 0x4733b4 IntersectClipRect
 0x4733b8 GetWindowOrgEx
 0x4733bc GetWinMetaFileBits
 0x4733c0 GetTextMetricsA
 0x4733c4 GetTextExtentPointA
 0x4733c8 GetTextExtentPoint32A
 0x4733cc GetSystemPaletteEntries
 0x4733d0 GetStockObject
 0x4733d4 GetPixel
 0x4733d8 GetPaletteEntries
 0x4733dc GetObjectA
 0x4733e0 GetEnhMetaFilePaletteEntries
 0x4733e4 GetEnhMetaFileHeader
 0x4733e8 GetEnhMetaFileBits
 0x4733ec GetDeviceCaps
 0x4733f0 GetDIBits
 0x4733f4 GetDIBColorTable
 0x4733f8 GetDCOrgEx
 0x4733fc GetCurrentPositionEx
 0x473400 GetClipBox
 0x473404 GetBrushOrgEx
 0x473408 GetBitmapBits
 0x47340c ExcludeClipRect
 0x473410 Ellipse
 0x473414 DeleteObject
 0x473418 DeleteEnhMetaFile
 0x47341c DeleteDC
 0x473420 CreateSolidBrush
 0x473424 CreatePenIndirect
 0x473428 CreatePalette
 0x47342c CreateHalftonePalette
 0x473430 CreateFontIndirectA
 0x473434 CreateDIBitmap
 0x473438 CreateDIBSection
 0x47343c CreateCompatibleDC
 0x473440 CreateCompatibleBitmap
 0x473444 CreateBrushIndirect
 0x473448 CreateBitmap
 0x47344c CopyEnhMetaFileA
 0x473450 BitBlt
user32.dll
 0x473458 CreateWindowExA
 0x47345c WindowFromPoint
 0x473460 WinHelpA
 0x473464 WaitMessage
 0x473468 UpdateWindow
 0x47346c UnregisterClassA
 0x473470 UnhookWindowsHookEx
 0x473474 TranslateMessage
 0x473478 TranslateMDISysAccel
 0x47347c TrackPopupMenu
 0x473480 SystemParametersInfoA
 0x473484 ShowWindow
 0x473488 ShowScrollBar
 0x47348c ShowOwnedPopups
 0x473490 ShowCursor
 0x473494 SetWindowsHookExA
 0x473498 SetWindowTextA
 0x47349c SetWindowPos
 0x4734a0 SetWindowPlacement
 0x4734a4 SetWindowLongA
 0x4734a8 SetTimer
 0x4734ac SetScrollRange
 0x4734b0 SetScrollPos
 0x4734b4 SetScrollInfo
 0x4734b8 SetRect
 0x4734bc SetPropA
 0x4734c0 SetParent
 0x4734c4 SetMenuItemInfoA
 0x4734c8 SetMenu
 0x4734cc SetForegroundWindow
 0x4734d0 SetFocus
 0x4734d4 SetCursor
 0x4734d8 SetClipboardData
 0x4734dc SetClassLongA
 0x4734e0 SetCapture
 0x4734e4 SetActiveWindow
 0x4734e8 SendMessageA
 0x4734ec ScrollWindow
 0x4734f0 ScreenToClient
 0x4734f4 RemovePropA
 0x4734f8 RemoveMenu
 0x4734fc ReleaseDC
 0x473500 ReleaseCapture
 0x473504 RegisterWindowMessageA
 0x473508 RegisterClipboardFormatA
 0x47350c RegisterClassA
 0x473510 RedrawWindow
 0x473514 PtInRect
 0x473518 PostQuitMessage
 0x47351c PostMessageA
 0x473520 PeekMessageA
 0x473524 OpenClipboard
 0x473528 OffsetRect
 0x47352c OemToCharA
 0x473530 MsgWaitForMultipleObjects
 0x473534 MessageBoxA
 0x473538 MessageBeep
 0x47353c MapWindowPoints
 0x473540 MapVirtualKeyA
 0x473544 LoadStringA
 0x473548 LoadKeyboardLayoutA
 0x47354c LoadIconA
 0x473550 LoadCursorA
 0x473554 LoadBitmapA
 0x473558 KillTimer
 0x47355c IsZoomed
 0x473560 IsWindowVisible
 0x473564 IsWindowEnabled
 0x473568 IsWindow
 0x47356c IsRectEmpty
 0x473570 IsIconic
 0x473574 IsDialogMessageA
 0x473578 IsChild
 0x47357c InvalidateRect
 0x473580 IntersectRect
 0x473584 InsertMenuItemA
 0x473588 InsertMenuA
 0x47358c InflateRect
 0x473590 GetWindowThreadProcessId
 0x473594 GetWindowTextA
 0x473598 GetWindowRect
 0x47359c GetWindowPlacement
 0x4735a0 GetWindowLongA
 0x4735a4 GetWindowDC
 0x4735a8 GetTopWindow
 0x4735ac GetSystemMetrics
 0x4735b0 GetSystemMenu
 0x4735b4 GetSysColorBrush
 0x4735b8 GetSysColor
 0x4735bc GetSubMenu
 0x4735c0 GetScrollRange
 0x4735c4 GetScrollPos
 0x4735c8 GetScrollInfo
 0x4735cc GetPropA
 0x4735d0 GetParent
 0x4735d4 GetWindow
 0x4735d8 GetMenuStringA
 0x4735dc GetMenuState
 0x4735e0 GetMenuItemInfoA
 0x4735e4 GetMenuItemID
 0x4735e8 GetMenuItemCount
 0x4735ec GetMenu
 0x4735f0 GetLastActivePopup
 0x4735f4 GetKeyboardState
 0x4735f8 GetKeyboardLayoutList
 0x4735fc GetKeyboardLayout
 0x473600 GetKeyState
 0x473604 GetKeyNameTextA
 0x473608 GetIconInfo
 0x47360c GetForegroundWindow
 0x473610 GetFocus
 0x473614 GetDesktopWindow
 0x473618 GetDCEx
 0x47361c GetDC
 0x473620 GetCursorPos
 0x473624 GetCursor
 0x473628 GetClipboardData
 0x47362c GetClientRect
 0x473630 GetClassNameA
 0x473634 GetClassInfoA
 0x473638 GetCapture
 0x47363c GetActiveWindow
 0x473640 FrameRect
 0x473644 FindWindowA
 0x473648 FillRect
 0x47364c EqualRect
 0x473650 EnumWindows
 0x473654 EnumThreadWindows
 0x473658 EndPaint
 0x47365c EnableWindow
 0x473660 EnableScrollBar
 0x473664 EnableMenuItem
 0x473668 EmptyClipboard
 0x47366c DrawTextA
 0x473670 DrawMenuBar
 0x473674 DrawIconEx
 0x473678 DrawIcon
 0x47367c DrawFrameControl
 0x473680 DrawEdge
 0x473684 DispatchMessageA
 0x473688 DestroyWindow
 0x47368c DestroyMenu
 0x473690 DestroyIcon
 0x473694 DestroyCursor
 0x473698 DeleteMenu
 0x47369c DefWindowProcA
 0x4736a0 DefMDIChildProcA
 0x4736a4 DefFrameProcA
 0x4736a8 CreatePopupMenu
 0x4736ac CreateMenu
 0x4736b0 CreateIcon
 0x4736b4 CloseClipboard
 0x4736b8 ClientToScreen
 0x4736bc CheckMenuItem
 0x4736c0 CallWindowProcA
 0x4736c4 CallNextHookEx
 0x4736c8 BeginPaint
 0x4736cc CharNextA
 0x4736d0 CharLowerBuffA
 0x4736d4 CharLowerA
 0x4736d8 CharUpperBuffA
 0x4736dc CharToOemA
 0x4736e0 AdjustWindowRectEx
 0x4736e4 ActivateKeyboardLayout
kernel32.dll
 0x4736ec Sleep
oleaut32.dll
 0x4736f4 SafeArrayPtrOfIndex
 0x4736f8 SafeArrayGetUBound
 0x4736fc SafeArrayGetLBound
 0x473700 SafeArrayCreate
 0x473704 VariantChangeType
 0x473708 VariantCopy
 0x47370c VariantClear
 0x473710 VariantInit
comctl32.dll
 0x473718 ImageList_SetIconSize
 0x47371c ImageList_GetIconSize
 0x473720 ImageList_Write
 0x473724 ImageList_Read
 0x473728 ImageList_GetDragImage
 0x47372c ImageList_DragShowNolock
 0x473730 ImageList_SetDragCursorImage
 0x473734 ImageList_DragMove
 0x473738 ImageList_DragLeave
 0x47373c ImageList_DragEnter
 0x473740 ImageList_EndDrag
 0x473744 ImageList_BeginDrag
 0x473748 ImageList_Remove
 0x47374c ImageList_DrawEx
 0x473750 ImageList_Draw
 0x473754 ImageList_GetBkColor
 0x473758 ImageList_SetBkColor
 0x47375c ImageList_ReplaceIcon
 0x473760 ImageList_Add
 0x473764 ImageList_GetImageCount
 0x473768 ImageList_Destroy
 0x47376c ImageList_Create
 0x473770 InitCommonControls

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure