Report - cutscroll.png

tor Gen1 Emotet PE File PE32
ScreenShot
Created 2021.05.07 11:34 Machine s1_win7_x6401
Filename cutscroll.png
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
9
Behavior Score
6.4
ZERO API file : clean
VT API (file)
md5 5ceaa6deb3ee0395632e64da64077689
sha256 fc8d296183d79ceda7099a5c1e473ef97ce7c43fe1a1d09b7144c51c0cd4a0be
ssdeep 12288:xP21tyvE++Tpiteq5bx/5LfBuXqL+cdTl+Cow:xgtyM++TpSR7KXkf0w
imphash 45ac993c4456effdce556743d114901e
impfuzzy 192:y7pNaWJgvrF9hM68kZggOWQV16i9FecFcHc7ZD:aMRvh9hUkEB9YYwM
  Network IP location

Signature (14cnts)

Level Description
danger Connects to IP addresses that are no longer responding to requests (legitimate services will remain up-and-running usually)
watch Communicates with host for which no DNS query was performed
notice Allocates read-write-execute memory (usually to unpack itself)
notice Checks adapter addresses which can be used to detect virtual network interfaces
notice Checks for the Locally Unique Identifier on the system for a suspicious privilege
notice Creates a suspicious process
notice HTTP traffic contains suspicious features which may be indicative of malware related traffic
notice One or more potentially interesting buffers were extracted
notice Performs some HTTP requests
notice Terminates another process
notice The binary likely contains encrypted or compressed data indicative of a packer
info One or more processes crashed
info Queries for the computername
info The executable uses a known packer

Rules (5cnts)

Level Name Description Collection
danger Win32_Trojan_Emotet_1_Zero Win32 Trojan Emotet binaries (upload)
danger Win32_Trojan_Emotet_2_Zero Win32 Trojan Emotet binaries (upload)
danger Win32_Trojan_Gen_1_0904B0_Zero Win32 Trojan Emotet binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (5cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
https://117.54.250.246/lib95/TEST22-PC_W617601.17CBB1F79387D3BF80BB1A2B3BA9BB75/5/kps/ ID INDO Internet, PT 117.54.250.246 1304 mailcious
103.66.72.217 IN RailTel Corporation of India Ltd., Internet Service Provider, New Delhi 103.66.72.217 mailcious
115.73.211.230 VN Viettel Group 115.73.211.230 mailcious
181.176.161.143 PE VIETTEL PERU S.A.C. 181.176.161.143 mailcious
117.54.250.246 ID INDO Internet, PT 117.54.250.246 mailcious

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.dll
 0x457ca8 HeapReAlloc
 0x457cac HeapSize
 0x457cb0 GetACP
 0x457cb4 GetTimeZoneInformation
 0x457cb8 GetSystemTime
 0x457cbc GetLocalTime
 0x457cc0 FatalAppExitA
 0x457cc4 UnhandledExceptionFilter
 0x457cc8 HeapDestroy
 0x457ccc HeapCreate
 0x457cd0 VirtualFree
 0x457cd4 VirtualAlloc
 0x457cd8 IsBadWritePtr
 0x457cdc FreeEnvironmentStringsA
 0x457ce0 FreeEnvironmentStringsW
 0x457ce4 GetEnvironmentStrings
 0x457ce8 GetEnvironmentStringsW
 0x457cec SetHandleCount
 0x457cf0 GetStdHandle
 0x457cf4 LCMapStringA
 0x457cf8 LCMapStringW
 0x457cfc RaiseException
 0x457d00 GetStringTypeW
 0x457d04 SetUnhandledExceptionFilter
 0x457d08 Sleep
 0x457d0c IsBadReadPtr
 0x457d10 IsBadCodePtr
 0x457d14 IsValidLocale
 0x457d18 IsValidCodePage
 0x457d1c GetLocaleInfoA
 0x457d20 EnumSystemLocalesA
 0x457d24 GetUserDefaultLCID
 0x457d28 GetVersionExA
 0x457d2c SetConsoleCtrlHandler
 0x457d30 CompareStringA
 0x457d34 CompareStringW
 0x457d38 SetEnvironmentVariableA
 0x457d3c GetLocaleInfoW
 0x457d40 TerminateProcess
 0x457d44 GetFileType
 0x457d48 SetStdHandle
 0x457d4c SetCurrentDirectoryA
 0x457d50 GetDriveTypeA
 0x457d54 GetProfileStringA
 0x457d58 HeapFree
 0x457d5c ExitProcess
 0x457d60 GetCommandLineA
 0x457d64 GetStartupInfoA
 0x457d68 HeapAlloc
 0x457d6c ExitThread
 0x457d70 CreateThread
 0x457d74 RtlUnwind
 0x457d78 FileTimeToLocalFileTime
 0x457d7c FileTimeToSystemTime
 0x457d80 SetErrorMode
 0x457d84 GetOEMCP
 0x457d88 GetCPInfo
 0x457d8c SizeofResource
 0x457d90 GetProcessVersion
 0x457d94 GetCurrentDirectoryA
 0x457d98 WritePrivateProfileStringA
 0x457d9c GetPrivateProfileStringA
 0x457da0 GetPrivateProfileIntA
 0x457da4 GlobalFlags
 0x457da8 TlsGetValue
 0x457dac LocalReAlloc
 0x457db0 TlsSetValue
 0x457db4 GlobalReAlloc
 0x457db8 TlsFree
 0x457dbc GlobalHandle
 0x457dc0 TlsAlloc
 0x457dc4 LocalAlloc
 0x457dc8 SetFileAttributesA
 0x457dcc SetFileTime
 0x457dd0 SystemTimeToFileTime
 0x457dd4 LocalFileTimeToFileTime
 0x457dd8 GetFileTime
 0x457ddc GetFileSize
 0x457de0 GetFileAttributesA
 0x457de4 GetShortPathNameA
 0x457de8 GetThreadLocale
 0x457dec GetStringTypeExA
 0x457df0 GetFullPathNameA
 0x457df4 GetVolumeInformationA
 0x457df8 FindFirstFileA
 0x457dfc FindClose
 0x457e00 DeleteFileA
 0x457e04 MoveFileA
 0x457e08 SetEndOfFile
 0x457e0c UnlockFile
 0x457e10 LockFile
 0x457e14 FlushFileBuffers
 0x457e18 SetFilePointer
 0x457e1c WriteFile
 0x457e20 ReadFile
 0x457e24 CreateFileA
 0x457e28 GetCurrentProcess
 0x457e2c DuplicateHandle
 0x457e30 GetLastError
 0x457e34 EnterCriticalSection
 0x457e38 LeaveCriticalSection
 0x457e3c DeleteCriticalSection
 0x457e40 InitializeCriticalSection
 0x457e44 lstrcpynA
 0x457e48 MulDiv
 0x457e4c SetLastError
 0x457e50 LoadLibraryA
 0x457e54 FreeLibrary
 0x457e58 GetVersion
 0x457e5c GetModuleFileNameA
 0x457e60 lstrcatA
 0x457e64 GlobalGetAtomNameA
 0x457e68 GlobalAddAtomA
 0x457e6c GlobalFindAtomA
 0x457e70 lstrcpyA
 0x457e74 GlobalUnlock
 0x457e78 GlobalFree
 0x457e7c LockResource
 0x457e80 FindResourceA
 0x457e84 LoadResource
 0x457e88 CreateEventA
 0x457e8c SuspendThread
 0x457e90 SetThreadPriority
 0x457e94 ResumeThread
 0x457e98 SetEvent
 0x457e9c CloseHandle
 0x457ea0 GlobalLock
 0x457ea4 GlobalAlloc
 0x457ea8 GlobalDeleteAtom
 0x457eac lstrcmpA
 0x457eb0 lstrcmpiA
 0x457eb4 GetCurrentThread
 0x457eb8 GetCurrentThreadId
 0x457ebc FormatMessageA
 0x457ec0 LocalFree
 0x457ec4 WideCharToMultiByte
 0x457ec8 InterlockedDecrement
 0x457ecc InterlockedIncrement
 0x457ed0 GetModuleHandleA
 0x457ed4 GetProcAddress
 0x457ed8 lstrlenA
 0x457edc MultiByteToWideChar
 0x457ee0 WaitForSingleObject
 0x457ee4 GetStringTypeA
USER32.dll
 0x457ff0 GetDlgItemInt
 0x457ff4 GetDlgItemTextA
 0x457ff8 SetDlgItemInt
 0x457ffc SetDlgItemTextA
 0x458000 IsDlgButtonChecked
 0x458004 ScrollWindowEx
 0x458008 IsDialogMessageA
 0x45800c SetWindowTextA
 0x458010 MoveWindow
 0x458014 wvsprintfA
 0x458018 ClientToScreen
 0x45801c GetWindowDC
 0x458020 BeginPaint
 0x458024 EndPaint
 0x458028 TabbedTextOutA
 0x45802c DrawTextA
 0x458030 GrayStringA
 0x458034 InflateRect
 0x458038 CharUpperA
 0x45803c LoadCursorA
 0x458040 SetCapture
 0x458044 ReleaseCapture
 0x458048 WaitMessage
 0x45804c GetDesktopWindow
 0x458050 GetWindowThreadProcessId
 0x458054 WindowFromPoint
 0x458058 GetClassNameA
 0x45805c PtInRect
 0x458060 InsertMenuA
 0x458064 DeleteMenu
 0x458068 GetMenuStringA
 0x45806c GetSysColorBrush
 0x458070 GetDialogBaseUnits
 0x458074 DestroyMenu
 0x458078 SetRectEmpty
 0x45807c LoadAcceleratorsA
 0x458080 TranslateAcceleratorA
 0x458084 LoadMenuA
 0x458088 SetMenu
 0x45808c ReuseDDElParam
 0x458090 UnpackDDElParam
 0x458094 BringWindowToTop
 0x458098 EqualRect
 0x45809c DeferWindowPos
 0x4580a0 BeginDeferWindowPos
 0x4580a4 EndDeferWindowPos
 0x4580a8 ScrollWindow
 0x4580ac GetScrollInfo
 0x4580b0 SetScrollInfo
 0x4580b4 ShowScrollBar
 0x4580b8 GetScrollRange
 0x4580bc SetScrollRange
 0x4580c0 GetScrollPos
 0x4580c4 SetScrollPos
 0x4580c8 GetTopWindow
 0x4580cc IsChild
 0x4580d0 GetCapture
 0x4580d4 WinHelpA
 0x4580d8 wsprintfA
 0x4580dc GetClassInfoA
 0x4580e0 RegisterClassA
 0x4580e4 GetMenu
 0x4580e8 GetMenuItemCount
 0x4580ec GetSubMenu
 0x4580f0 GetMenuItemID
 0x4580f4 CheckRadioButton
 0x4580f8 SetWindowPlacement
 0x4580fc GetWindowTextLengthA
 0x458100 GetWindowTextA
 0x458104 GetDlgCtrlID
 0x458108 DefWindowProcA
 0x45810c CreateWindowExA
 0x458110 SetFocus
 0x458114 SetPropA
 0x458118 UnhookWindowsHookEx
 0x45811c GetPropA
 0x458120 RemovePropA
 0x458124 GetMessageTime
 0x458128 GetForegroundWindow
 0x45812c SetForegroundWindow
 0x458130 GetWindow
 0x458134 SetWindowLongA
 0x458138 SetWindowPos
 0x45813c RegisterWindowMessageA
 0x458140 IntersectRect
 0x458144 SystemParametersInfoA
 0x458148 GetWindowPlacement
 0x45814c GetWindowRect
 0x458150 ReleaseDC
 0x458154 EndDialog
 0x458158 SetActiveWindow
 0x45815c IsWindow
 0x458160 CreateDialogIndirectParamA
 0x458164 DestroyWindow
 0x458168 GetDlgItem
 0x45816c GetMenuCheckMarkDimensions
 0x458170 LoadBitmapA
 0x458174 GetMenuState
 0x458178 ModifyMenuA
 0x45817c SetMenuItemBitmaps
 0x458180 CheckMenuItem
 0x458184 EnableMenuItem
 0x458188 GetFocus
 0x45818c GetNextDlgTabItem
 0x458190 GetMessageA
 0x458194 GetActiveWindow
 0x458198 GetKeyState
 0x45819c CallNextHookEx
 0x4581a0 ValidateRect
 0x4581a4 IsWindowVisible
 0x4581a8 GetCursorPos
 0x4581ac SetWindowsHookExA
 0x4581b0 GetParent
 0x4581b4 GetLastActivePopup
 0x4581b8 IsWindowEnabled
 0x4581bc GetWindowLongA
 0x4581c0 MessageBoxA
 0x4581c4 SetCursor
 0x4581c8 DispatchMessageA
 0x4581cc TranslateMessage
 0x4581d0 MsgWaitForMultipleObjects
 0x4581d4 UnregisterClassA
 0x4581d8 HideCaret
 0x4581dc ShowCaret
 0x4581e0 ShowOwnedPopups
 0x4581e4 PostQuitMessage
 0x4581e8 PostMessageA
 0x4581ec LoadStringA
 0x4581f0 OemToCharA
 0x4581f4 CharToOemA
 0x4581f8 InvalidateRect
 0x4581fc GetMessagePos
 0x458200 ScreenToClient
 0x458204 CheckDlgButton
 0x458208 UpdateWindow
 0x45820c SendDlgItemMessageA
 0x458210 TrackPopupMenu
 0x458214 MapWindowPoints
 0x458218 DrawStateA
 0x45821c DestroyIcon
 0x458220 GetSysColor
 0x458224 CopyRect
 0x458228 SetRect
 0x45822c OffsetRect
 0x458230 DrawFocusRect
 0x458234 GetDC
 0x458238 EnableWindow
 0x45823c IsIconic
 0x458240 GetSystemMetrics
 0x458244 GetClientRect
 0x458248 DrawIcon
 0x45824c SendMessageA
 0x458250 GetClassLongA
 0x458254 AdjustWindowRectEx
 0x458258 ExcludeUpdateRgn
 0x45825c DefDlgProcA
 0x458260 ShowWindow
 0x458264 LoadIconA
 0x458268 PeekMessageA
 0x45826c IsWindowUnicode
 0x458270 CharNextA
 0x458274 CallWindowProcA
GDI32.dll
 0x457b04 ScaleViewportExtEx
 0x457b08 SetWindowOrgEx
 0x457b0c OffsetWindowOrgEx
 0x457b10 SetWindowExtEx
 0x457b14 ScaleWindowExtEx
 0x457b18 SelectClipRgn
 0x457b1c ExcludeClipRect
 0x457b20 IntersectClipRect
 0x457b24 OffsetClipRgn
 0x457b28 MoveToEx
 0x457b2c LineTo
 0x457b30 SetTextAlign
 0x457b34 SetTextJustification
 0x457b38 SetTextCharacterExtra
 0x457b3c SetMapperFlags
 0x457b40 GetCurrentPositionEx
 0x457b44 ArcTo
 0x457b48 SetArcDirection
 0x457b4c PolyDraw
 0x457b50 PolylineTo
 0x457b54 SetColorAdjustment
 0x457b58 PolyBezierTo
 0x457b5c DeleteObject
 0x457b60 GetClipRgn
 0x457b64 CreateRectRgn
 0x457b68 SelectClipPath
 0x457b6c SetViewportExtEx
 0x457b70 PlayMetaFileRecord
 0x457b74 GetObjectType
 0x457b78 EnumMetaFile
 0x457b7c PlayMetaFile
 0x457b80 GetDeviceCaps
 0x457b84 GetViewportExtEx
 0x457b88 GetWindowExtEx
 0x457b8c CreatePen
 0x457b90 ExtCreatePen
 0x457b94 CreateSolidBrush
 0x457b98 CreateHatchBrush
 0x457b9c CreatePatternBrush
 0x457ba0 CreateDIBPatternBrushPt
 0x457ba4 PtVisible
 0x457ba8 RectVisible
 0x457bac TextOutA
 0x457bb0 ExtTextOutA
 0x457bb4 Escape
 0x457bb8 GetMapMode
 0x457bbc SetRectRgn
 0x457bc0 CombineRgn
 0x457bc4 CreateFontIndirectA
 0x457bc8 DPtoLP
 0x457bcc GetTextExtentPoint32A
 0x457bd0 GetTextMetricsA
 0x457bd4 OffsetViewportOrgEx
 0x457bd8 SetViewportOrgEx
 0x457bdc SetMapMode
 0x457be0 SetStretchBltMode
 0x457be4 SetROP2
 0x457be8 SetPolyFillMode
 0x457bec SetBkMode
 0x457bf0 SelectPalette
 0x457bf4 GetStockObject
 0x457bf8 SelectObject
 0x457bfc RestoreDC
 0x457c00 SaveDC
 0x457c04 StartDocA
 0x457c08 DeleteDC
 0x457c0c GetObjectA
 0x457c10 SetBkColor
 0x457c14 SetTextColor
 0x457c18 GetClipBox
 0x457c1c GetDCOrgEx
 0x457c20 CreateRectRgnIndirect
 0x457c24 PatBlt
 0x457c28 ExtSelectClipRgn
 0x457c2c CreateDIBitmap
 0x457c30 GetTextExtentPointA
 0x457c34 BitBlt
 0x457c38 CreateCompatibleDC
 0x457c3c CreateBitmap
comdlg32.dll
 0x45835c GetFileTitleA
WINSPOOL.DRV
 0x458324 ClosePrinter
 0x458328 OpenPrinterA
 0x45832c DocumentPropertiesA
ADVAPI32.dll
 0x457a4c RegQueryValueExA
 0x457a50 RegOpenKeyA
 0x457a54 RegCreateKeyExA
 0x457a58 RegOpenKeyExA
 0x457a5c RegSetValueExA
 0x457a60 RegDeleteValueA
 0x457a64 RegDeleteKeyA
 0x457a68 RegCloseKey
SHELL32.dll
 0x457fb4 DragFinish
 0x457fb8 SHGetFileInfoA
 0x457fbc DragAcceptFiles
 0x457fc0 DragQueryFileA
COMCTL32.dll
 0x457a9c ImageList_GetIconSize
 0x457aa0 None
 0x457aa4 ImageList_SetBkColor
 0x457aa8 ImageList_ReplaceIcon
 0x457aac None
 0x457ab0 ImageList_Destroy
 0x457ab4 ImageList_Create
 0x457ab8 ImageList_LoadImageA
 0x457abc ImageList_Merge
 0x457ac0 ImageList_Read
 0x457ac4 ImageList_Write
 0x457ac8 ImageList_GetIcon
 0x457acc None
OLEAUT32.dll
 0x457f84 SysAllocStringLen
urlmon.dll
 0x45838c URLDownloadToFileA

EAT(Export Address Table) Library

0x40111d dfcvdsfejderdgdcadsh


Similarity measure (PE file only) - Checking for service failure