Report - richedit.exe

PE File PE32
ScreenShot
Created 2021.05.26 09:02 Machine s1_win7_x6401
Filename richedit.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
4
Behavior Score
2.2
ZERO API file : malware
VT API (file) 31 detected (DownLoad4, Generic PWS, Unsafe, malicious, QQMusic, dgryww, Pgwl, susgen, ai score=99, ASMalwS, Occamy, Bitrep, CLOUD, Cp0N0fXtH4o)
md5 b89786dcab1dc0b2c71d410c73a9bf8d
sha256 c41cfbf30ba7bcc2e7d12562b82ab474911f73f12944df0e3c6865f5ae3e2a0f
ssdeep 6144:U68VxO9tfae9o0fzdzXPUbzyEIrqKJWOwp51ayTGu2fUcIlCpoiNr0ezlG:UdVxO9wey2dbUvuJwccGuSUY6mRBG
imphash f87f547edd1664aa82f0b758045a2f45
impfuzzy 192:4gXebuBF1QoGBbuuX4SUvK9YkQoqyUOiD:4gXeb+1SX99kb
  Network IP location

Signature (5cnts)

Level Description
danger File has been identified by 31 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Foreign language identified in PE resource
info Checks amount of memory in system
info The executable contains unknown PE section names indicative of a packer (could be a false positive)

Rules (2cnts)

Level Name Description Collection
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x45712c GetCurrentThreadId
 0x457130 DeleteCriticalSection
 0x457134 LeaveCriticalSection
 0x457138 EnterCriticalSection
 0x45713c InitializeCriticalSection
 0x457140 VirtualFree
 0x457144 VirtualAlloc
 0x457148 LocalFree
 0x45714c LocalAlloc
 0x457150 InterlockedDecrement
 0x457154 InterlockedIncrement
 0x457158 VirtualQuery
 0x45715c WideCharToMultiByte
 0x457160 MultiByteToWideChar
 0x457164 lstrlenA
 0x457168 lstrcpyA
 0x45716c LoadLibraryExA
 0x457170 GetThreadLocale
 0x457174 GetStartupInfoA
 0x457178 GetModuleFileNameA
 0x45717c GetLocaleInfoA
 0x457180 GetLastError
 0x457184 GetCommandLineA
 0x457188 FreeLibrary
 0x45718c ExitProcess
 0x457190 WriteFile
 0x457194 SetFilePointer
 0x457198 SetEndOfFile
 0x45719c RtlUnwind
 0x4571a0 ReadFile
 0x4571a4 RaiseException
 0x4571a8 GetStdHandle
 0x4571ac GetFileSize
 0x4571b0 GetFileType
 0x4571b4 CreateFileA
 0x4571b8 CloseHandle
user32.dll
 0x4571c0 GetKeyboardType
 0x4571c4 LoadStringA
 0x4571c8 MessageBoxA
advapi32.dll
 0x4571d0 RegQueryValueExA
 0x4571d4 RegOpenKeyExA
 0x4571d8 RegCloseKey
oleaut32.dll
 0x4571e0 VariantChangeTypeEx
 0x4571e4 VariantCopyInd
 0x4571e8 VariantClear
 0x4571ec SysStringLen
 0x4571f0 SysFreeString
 0x4571f4 SysReAllocStringLen
 0x4571f8 SysAllocStringLen
kernel32.dll
 0x457200 TlsSetValue
 0x457204 TlsGetValue
 0x457208 LocalAlloc
 0x45720c GetModuleHandleA
 0x457210 GetModuleFileNameA
advapi32.dll
 0x457218 RegQueryValueExA
 0x45721c RegOpenKeyExA
 0x457220 RegCloseKey
kernel32.dll
 0x457228 lstrcpyA
 0x45722c WriteFile
 0x457230 WaitForSingleObject
 0x457234 VirtualQuery
 0x457238 VirtualAlloc
 0x45723c Sleep
 0x457240 SizeofResource
 0x457244 SetThreadLocale
 0x457248 SetFilePointer
 0x45724c SetEvent
 0x457250 SetErrorMode
 0x457254 SetEndOfFile
 0x457258 ReadFile
 0x45725c MulDiv
 0x457260 LockResource
 0x457264 LoadResource
 0x457268 LoadLibraryA
 0x45726c LeaveCriticalSection
 0x457270 InitializeCriticalSection
 0x457274 GlobalUnlock
 0x457278 GlobalReAlloc
 0x45727c GlobalHandle
 0x457280 GlobalLock
 0x457284 GlobalFree
 0x457288 GlobalDeleteAtom
 0x45728c GlobalAlloc
 0x457290 GlobalAddAtomA
 0x457294 GetVersionExA
 0x457298 GetVersion
 0x45729c GetTickCount
 0x4572a0 GetThreadLocale
 0x4572a4 GetSystemInfo
 0x4572a8 GetProcAddress
 0x4572ac GetModuleHandleA
 0x4572b0 GetModuleFileNameA
 0x4572b4 GetLocaleInfoA
 0x4572b8 GetLastError
 0x4572bc GetDiskFreeSpaceA
 0x4572c0 GetCurrentThreadId
 0x4572c4 GetCurrentProcessId
 0x4572c8 GetCPInfo
 0x4572cc FreeResource
 0x4572d0 FreeLibrary
 0x4572d4 FormatMessageA
 0x4572d8 FindResourceA
 0x4572dc EnumCalendarInfoA
 0x4572e0 EnterCriticalSection
 0x4572e4 DeleteCriticalSection
 0x4572e8 CreateThread
 0x4572ec CreateFileA
 0x4572f0 CreateEventA
 0x4572f4 CompareStringA
 0x4572f8 CloseHandle
version.dll
 0x457300 VerQueryValueA
 0x457304 GetFileVersionInfoSizeA
 0x457308 GetFileVersionInfoA
gdi32.dll
 0x457310 UnrealizeObject
 0x457314 StretchBlt
 0x457318 SetWindowOrgEx
 0x45731c SetWinMetaFileBits
 0x457320 SetViewportOrgEx
 0x457324 SetTextColor
 0x457328 SetStretchBltMode
 0x45732c SetROP2
 0x457330 SetPixel
 0x457334 SetEnhMetaFileBits
 0x457338 SetDIBColorTable
 0x45733c SetBrushOrgEx
 0x457340 SetBkMode
 0x457344 SetBkColor
 0x457348 SelectPalette
 0x45734c SelectObject
 0x457350 SaveDC
 0x457354 RestoreDC
 0x457358 Rectangle
 0x45735c RectVisible
 0x457360 RealizePalette
 0x457364 Polyline
 0x457368 PlayEnhMetaFile
 0x45736c PatBlt
 0x457370 MoveToEx
 0x457374 MaskBlt
 0x457378 LineTo
 0x45737c IntersectClipRect
 0x457380 GetWindowOrgEx
 0x457384 GetWinMetaFileBits
 0x457388 GetTextMetricsA
 0x45738c GetTextExtentPointA
 0x457390 GetTextExtentPoint32A
 0x457394 GetSystemPaletteEntries
 0x457398 GetStockObject
 0x45739c GetRgnBox
 0x4573a0 GetPixel
 0x4573a4 GetPaletteEntries
 0x4573a8 GetObjectA
 0x4573ac GetEnhMetaFilePaletteEntries
 0x4573b0 GetEnhMetaFileHeader
 0x4573b4 GetEnhMetaFileBits
 0x4573b8 GetDeviceCaps
 0x4573bc GetDIBits
 0x4573c0 GetDIBColorTable
 0x4573c4 GetDCOrgEx
 0x4573c8 GetCurrentPositionEx
 0x4573cc GetClipBox
 0x4573d0 GetBrushOrgEx
 0x4573d4 GetBitmapBits
 0x4573d8 ExcludeClipRect
 0x4573dc EnumFontsA
 0x4573e0 EnumFontFamiliesExA
 0x4573e4 DeleteObject
 0x4573e8 DeleteEnhMetaFile
 0x4573ec DeleteDC
 0x4573f0 CreateSolidBrush
 0x4573f4 CreateRectRgn
 0x4573f8 CreatePenIndirect
 0x4573fc CreatePalette
 0x457400 CreateHalftonePalette
 0x457404 CreateFontIndirectA
 0x457408 CreateDIBitmap
 0x45740c CreateDIBSection
 0x457410 CreateCompatibleDC
 0x457414 CreateCompatibleBitmap
 0x457418 CreateBrushIndirect
 0x45741c CreateBitmap
 0x457420 CopyEnhMetaFileA
 0x457424 CombineRgn
 0x457428 BitBlt
user32.dll
 0x457430 WindowFromPoint
 0x457434 WinHelpA
 0x457438 WaitMessage
 0x45743c UpdateWindow
 0x457440 UnregisterClassA
 0x457444 UnhookWindowsHookEx
 0x457448 TranslateMessage
 0x45744c TranslateMDISysAccel
 0x457450 TrackPopupMenu
 0x457454 SystemParametersInfoA
 0x457458 ShowWindow
 0x45745c ShowScrollBar
 0x457460 ShowOwnedPopups
 0x457464 ShowCursor
 0x457468 SetWindowRgn
 0x45746c SetWindowsHookExA
 0x457470 SetWindowTextA
 0x457474 SetWindowPos
 0x457478 SetWindowPlacement
 0x45747c SetWindowLongA
 0x457480 SetTimer
 0x457484 SetScrollRange
 0x457488 SetScrollPos
 0x45748c SetScrollInfo
 0x457490 SetRect
 0x457494 SetPropA
 0x457498 SetMenuItemInfoA
 0x45749c SetMenu
 0x4574a0 SetForegroundWindow
 0x4574a4 SetFocus
 0x4574a8 SetCursor
 0x4574ac SetCapture
 0x4574b0 SetActiveWindow
 0x4574b4 SendMessageA
 0x4574b8 ScrollWindow
 0x4574bc ScreenToClient
 0x4574c0 RemovePropA
 0x4574c4 RemoveMenu
 0x4574c8 ReleaseDC
 0x4574cc ReleaseCapture
 0x4574d0 RegisterWindowMessageA
 0x4574d4 RegisterClipboardFormatA
 0x4574d8 RegisterClassA
 0x4574dc RedrawWindow
 0x4574e0 PtInRect
 0x4574e4 PostQuitMessage
 0x4574e8 PostMessageA
 0x4574ec PeekMessageA
 0x4574f0 OffsetRect
 0x4574f4 OemToCharA
 0x4574f8 MessageBoxA
 0x4574fc MessageBeep
 0x457500 MapWindowPoints
 0x457504 MapVirtualKeyA
 0x457508 LoadStringA
 0x45750c LoadIconA
 0x457510 LoadCursorA
 0x457514 LoadBitmapA
 0x457518 KillTimer
 0x45751c IsZoomed
 0x457520 IsWindowVisible
 0x457524 IsWindowEnabled
 0x457528 IsWindow
 0x45752c IsIconic
 0x457530 IsDialogMessageA
 0x457534 IsChild
 0x457538 InvalidateRect
 0x45753c IntersectRect
 0x457540 InsertMenuItemA
 0x457544 InsertMenuA
 0x457548 InflateRect
 0x45754c GetWindowThreadProcessId
 0x457550 GetWindowTextA
 0x457554 GetWindowRgn
 0x457558 GetWindowRect
 0x45755c GetWindowPlacement
 0x457560 GetWindowLongA
 0x457564 GetWindowDC
 0x457568 GetTopWindow
 0x45756c GetSystemMetrics
 0x457570 GetSystemMenu
 0x457574 GetSysColor
 0x457578 GetSubMenu
 0x45757c GetScrollRange
 0x457580 GetScrollPos
 0x457584 GetScrollInfo
 0x457588 GetPropA
 0x45758c GetParent
 0x457590 GetWindow
 0x457594 GetMenuStringA
 0x457598 GetMenuState
 0x45759c GetMenuItemInfoA
 0x4575a0 GetMenuItemID
 0x4575a4 GetMenuItemCount
 0x4575a8 GetMenu
 0x4575ac GetLastActivePopup
 0x4575b0 GetKeyboardState
 0x4575b4 GetKeyboardLayoutList
 0x4575b8 GetKeyboardLayout
 0x4575bc GetKeyState
 0x4575c0 GetKeyNameTextA
 0x4575c4 GetIconInfo
 0x4575c8 GetForegroundWindow
 0x4575cc GetFocus
 0x4575d0 GetDlgItem
 0x4575d4 GetDesktopWindow
 0x4575d8 GetDCEx
 0x4575dc GetDC
 0x4575e0 GetCursorPos
 0x4575e4 GetCursor
 0x4575e8 GetClipboardData
 0x4575ec GetClientRect
 0x4575f0 GetClassInfoA
 0x4575f4 GetCapture
 0x4575f8 GetActiveWindow
 0x4575fc FrameRect
 0x457600 FindWindowA
 0x457604 FillRect
 0x457608 EqualRect
 0x45760c EnumWindows
 0x457610 EnumThreadWindows
 0x457614 EndPaint
 0x457618 EnableWindow
 0x45761c EnableScrollBar
 0x457620 EnableMenuItem
 0x457624 DrawTextA
 0x457628 DrawMenuBar
 0x45762c DrawIcon
 0x457630 DrawFrameControl
 0x457634 DrawFocusRect
 0x457638 DrawEdge
 0x45763c DispatchMessageA
 0x457640 DestroyWindow
 0x457644 DestroyMenu
 0x457648 DestroyIcon
 0x45764c DestroyCursor
 0x457650 DeleteMenu
 0x457654 DefWindowProcA
 0x457658 DefMDIChildProcA
 0x45765c DefFrameProcA
 0x457660 CreateWindowExA
 0x457664 CreatePopupMenu
 0x457668 CreateMenu
 0x45766c CreateIcon
 0x457670 ClientToScreen
 0x457674 CheckMenuItem
 0x457678 CallWindowProcA
 0x45767c CallNextHookEx
 0x457680 BeginPaint
 0x457684 CharLowerBuffA
 0x457688 CharLowerA
 0x45768c AdjustWindowRectEx
 0x457690 ActivateKeyboardLayout
ole32.dll
 0x457698 IsEqualGUID
comctl32.dll
 0x4576a0 ImageList_GetImageInfo
 0x4576a4 ImageList_SetIconSize
 0x4576a8 ImageList_GetIconSize
 0x4576ac ImageList_Read
 0x4576b0 ImageList_GetDragImage
 0x4576b4 ImageList_DragShowNolock
 0x4576b8 ImageList_SetDragCursorImage
 0x4576bc ImageList_DragMove
 0x4576c0 ImageList_DragLeave
 0x4576c4 ImageList_DragEnter
 0x4576c8 ImageList_EndDrag
 0x4576cc ImageList_BeginDrag
 0x4576d0 ImageList_Remove
 0x4576d4 ImageList_DrawEx
 0x4576d8 ImageList_Replace
 0x4576dc ImageList_Draw
 0x4576e0 ImageList_GetBkColor
 0x4576e4 ImageList_SetBkColor
 0x4576e8 ImageList_ReplaceIcon
 0x4576ec ImageList_Add
 0x4576f0 ImageList_GetImageCount
 0x4576f4 ImageList_Destroy
 0x4576f8 ImageList_Create
 0x4576fc InitCommonControls
comdlg32.dll
 0x457704 GetOpenFileNameA
shell32.dll
 0x45770c ShellExecuteA

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure