Report - file22.exe

PE File PE32
ScreenShot
Created 2021.06.08 10:49 Machine s1_win7_x6401
Filename file22.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
6
Behavior Score
1.4
ZERO API file : clean
VT API (file)
md5 4b7f05a9dc569f83f9a2aed17d165e29
sha256 67a3f3fde86611605ca136cb40e1ac6d2ac2459d8ba8d5452c0cf601adc86749
ssdeep 24576:0mmSOqlDkOkFWrvv4n2zjP/zRSp1jP6xl:0mmDQIVWLRP/zRSpm
imphash 0200a5dd8d1709f649a5a9e3e9bb07c0
impfuzzy 192:f30Nf1QEbuuArSUvK9RiooqE6pCPbOQ0O:f3Q1NAA9vkPbOQD
  Network IP location

Signature (5cnts)

Level Description
notice Foreign language identified in PE resource
notice The binary likely contains encrypted or compressed data indicative of a packer
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The executable uses a known packer
info The file contains an unknown PE resource name possibly indicative of a packer

Rules (2cnts)

Level Name Description Collection
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x466140 DeleteCriticalSection
 0x466144 LeaveCriticalSection
 0x466148 EnterCriticalSection
 0x46614c InitializeCriticalSection
 0x466150 VirtualFree
 0x466154 VirtualAlloc
 0x466158 LocalFree
 0x46615c LocalAlloc
 0x466160 GetVersion
 0x466164 GetCurrentThreadId
 0x466168 InterlockedDecrement
 0x46616c InterlockedIncrement
 0x466170 VirtualQuery
 0x466174 WideCharToMultiByte
 0x466178 MultiByteToWideChar
 0x46617c lstrlenA
 0x466180 lstrcpynA
 0x466184 LoadLibraryExA
 0x466188 GetThreadLocale
 0x46618c GetStartupInfoA
 0x466190 GetProcAddress
 0x466194 GetModuleHandleA
 0x466198 GetModuleFileNameA
 0x46619c GetLocaleInfoA
 0x4661a0 GetCommandLineA
 0x4661a4 FreeLibrary
 0x4661a8 FindFirstFileA
 0x4661ac FindClose
 0x4661b0 ExitProcess
 0x4661b4 WriteFile
 0x4661b8 UnhandledExceptionFilter
 0x4661bc RtlUnwind
 0x4661c0 RaiseException
 0x4661c4 GetStdHandle
user32.dll
 0x4661cc GetKeyboardType
 0x4661d0 LoadStringA
 0x4661d4 MessageBoxA
 0x4661d8 CharNextA
advapi32.dll
 0x4661e0 RegQueryValueExA
 0x4661e4 RegOpenKeyExA
 0x4661e8 RegCloseKey
oleaut32.dll
 0x4661f0 SysFreeString
 0x4661f4 SysReAllocStringLen
 0x4661f8 SysAllocStringLen
kernel32.dll
 0x466200 TlsSetValue
 0x466204 TlsGetValue
 0x466208 LocalAlloc
 0x46620c GetModuleHandleA
advapi32.dll
 0x466214 RegQueryValueExA
 0x466218 RegOpenKeyExA
 0x46621c RegCloseKey
kernel32.dll
 0x466224 lstrcpyA
 0x466228 WriteFile
 0x46622c WaitForSingleObject
 0x466230 VirtualQuery
 0x466234 VirtualAlloc
 0x466238 Sleep
 0x46623c SizeofResource
 0x466240 SetThreadLocale
 0x466244 SetFilePointer
 0x466248 SetEvent
 0x46624c SetErrorMode
 0x466250 SetEndOfFile
 0x466254 ResetEvent
 0x466258 ReadFile
 0x46625c MultiByteToWideChar
 0x466260 MulDiv
 0x466264 LockResource
 0x466268 LoadResource
 0x46626c LoadLibraryA
 0x466270 LeaveCriticalSection
 0x466274 InitializeCriticalSection
 0x466278 GlobalUnlock
 0x46627c GlobalReAlloc
 0x466280 GlobalHandle
 0x466284 GlobalLock
 0x466288 GlobalFree
 0x46628c GlobalFindAtomA
 0x466290 GlobalDeleteAtom
 0x466294 GlobalAlloc
 0x466298 GlobalAddAtomA
 0x46629c GetVersionExA
 0x4662a0 GetVersion
 0x4662a4 GetTickCount
 0x4662a8 GetThreadLocale
 0x4662ac GetSystemInfo
 0x4662b0 GetStringTypeExA
 0x4662b4 GetStdHandle
 0x4662b8 GetProcAddress
 0x4662bc GetModuleHandleA
 0x4662c0 GetModuleFileNameA
 0x4662c4 GetLocaleInfoA
 0x4662c8 GetLocalTime
 0x4662cc GetLastError
 0x4662d0 GetFullPathNameA
 0x4662d4 GetDiskFreeSpaceA
 0x4662d8 GetDateFormatA
 0x4662dc GetCurrentThreadId
 0x4662e0 GetCurrentProcessId
 0x4662e4 GetComputerNameA
 0x4662e8 GetCPInfo
 0x4662ec GetACP
 0x4662f0 FreeResource
 0x4662f4 InterlockedExchange
 0x4662f8 FreeLibrary
 0x4662fc FormatMessageA
 0x466300 FindResourceA
 0x466304 EnumCalendarInfoA
 0x466308 EnterCriticalSection
 0x46630c DeleteCriticalSection
 0x466310 CreateThread
 0x466314 CreateFileA
 0x466318 CreateEventA
 0x46631c CompareStringA
 0x466320 CloseHandle
version.dll
 0x466328 VerQueryValueA
 0x46632c GetFileVersionInfoSizeA
 0x466330 GetFileVersionInfoA
gdi32.dll
 0x466338 UnrealizeObject
 0x46633c StretchBlt
 0x466340 SetWindowOrgEx
 0x466344 SetViewportOrgEx
 0x466348 SetTextColor
 0x46634c SetStretchBltMode
 0x466350 SetROP2
 0x466354 SetPixel
 0x466358 SetDIBColorTable
 0x46635c SetBrushOrgEx
 0x466360 SetBkMode
 0x466364 SetBkColor
 0x466368 SelectPalette
 0x46636c SelectObject
 0x466370 SelectClipRgn
 0x466374 SaveDC
 0x466378 RestoreDC
 0x46637c Rectangle
 0x466380 RectVisible
 0x466384 RealizePalette
 0x466388 Polyline
 0x46638c PatBlt
 0x466390 MoveToEx
 0x466394 MaskBlt
 0x466398 LineTo
 0x46639c IntersectClipRect
 0x4663a0 GetWindowOrgEx
 0x4663a4 GetTextMetricsA
 0x4663a8 GetTextExtentPoint32A
 0x4663ac GetSystemPaletteEntries
 0x4663b0 GetStockObject
 0x4663b4 GetPixel
 0x4663b8 GetPaletteEntries
 0x4663bc GetObjectA
 0x4663c0 GetFontLanguageInfo
 0x4663c4 GetDeviceCaps
 0x4663c8 GetDIBits
 0x4663cc GetDIBColorTable
 0x4663d0 GetDCOrgEx
 0x4663d4 GetCurrentPositionEx
 0x4663d8 GetClipBox
 0x4663dc GetBrushOrgEx
 0x4663e0 GetBitmapBits
 0x4663e4 ExcludeClipRect
 0x4663e8 DeleteObject
 0x4663ec DeleteDC
 0x4663f0 CreateSolidBrush
 0x4663f4 CreatePenIndirect
 0x4663f8 CreatePalette
 0x4663fc CreateHalftonePalette
 0x466400 CreateFontIndirectA
 0x466404 CreateDIBitmap
 0x466408 CreateDIBSection
 0x46640c CreateCompatibleDC
 0x466410 CreateCompatibleBitmap
 0x466414 CreateBrushIndirect
 0x466418 CreateBitmap
 0x46641c BitBlt
user32.dll
 0x466424 CreateWindowExA
 0x466428 WindowFromPoint
 0x46642c WinHelpA
 0x466430 WaitMessage
 0x466434 UpdateWindow
 0x466438 UnregisterClassA
 0x46643c UnhookWindowsHookEx
 0x466440 TranslateMessage
 0x466444 TranslateMDISysAccel
 0x466448 TrackPopupMenu
 0x46644c SystemParametersInfoA
 0x466450 ShowWindow
 0x466454 ShowScrollBar
 0x466458 ShowOwnedPopups
 0x46645c ShowCursor
 0x466460 SetWindowsHookExA
 0x466464 SetWindowTextA
 0x466468 SetWindowPos
 0x46646c SetWindowPlacement
 0x466470 SetWindowLongA
 0x466474 SetTimer
 0x466478 SetScrollRange
 0x46647c SetScrollPos
 0x466480 SetScrollInfo
 0x466484 SetRect
 0x466488 SetPropA
 0x46648c SetParent
 0x466490 SetMenuItemInfoA
 0x466494 SetMenu
 0x466498 SetForegroundWindow
 0x46649c SetFocus
 0x4664a0 SetCursor
 0x4664a4 SetClassLongA
 0x4664a8 SetCapture
 0x4664ac SetActiveWindow
 0x4664b0 SendMessageA
 0x4664b4 ScrollWindow
 0x4664b8 ScreenToClient
 0x4664bc RemovePropA
 0x4664c0 RemoveMenu
 0x4664c4 ReleaseDC
 0x4664c8 ReleaseCapture
 0x4664cc RegisterWindowMessageA
 0x4664d0 RegisterClipboardFormatA
 0x4664d4 RegisterClassA
 0x4664d8 RedrawWindow
 0x4664dc PtInRect
 0x4664e0 PostQuitMessage
 0x4664e4 PostMessageA
 0x4664e8 PeekMessageA
 0x4664ec OffsetRect
 0x4664f0 OemToCharA
 0x4664f4 MessageBoxA
 0x4664f8 MapWindowPoints
 0x4664fc MapVirtualKeyA
 0x466500 LoadStringA
 0x466504 LoadKeyboardLayoutA
 0x466508 LoadIconA
 0x46650c LoadCursorFromFileW
 0x466510 LoadCursorFromFileA
 0x466514 LoadCursorA
 0x466518 LoadBitmapA
 0x46651c KillTimer
 0x466520 IsZoomed
 0x466524 IsWindowVisible
 0x466528 IsWindowEnabled
 0x46652c IsWindow
 0x466530 IsRectEmpty
 0x466534 IsIconic
 0x466538 IsDialogMessageA
 0x46653c IsChild
 0x466540 InvalidateRect
 0x466544 IntersectRect
 0x466548 InsertMenuItemA
 0x46654c InsertMenuA
 0x466550 InflateRect
 0x466554 GetWindowThreadProcessId
 0x466558 GetWindowTextA
 0x46655c GetWindowRect
 0x466560 GetWindowPlacement
 0x466564 GetWindowLongA
 0x466568 GetWindowDC
 0x46656c GetTopWindow
 0x466570 GetSystemMetrics
 0x466574 GetSystemMenu
 0x466578 GetSysColorBrush
 0x46657c GetSysColor
 0x466580 GetSubMenu
 0x466584 GetScrollRange
 0x466588 GetScrollPos
 0x46658c GetScrollInfo
 0x466590 GetPropA
 0x466594 GetParent
 0x466598 GetWindow
 0x46659c GetMenuStringA
 0x4665a0 GetMenuState
 0x4665a4 GetMenuItemInfoA
 0x4665a8 GetMenuItemID
 0x4665ac GetMenuItemCount
 0x4665b0 GetMenu
 0x4665b4 GetLastActivePopup
 0x4665b8 GetKeyboardState
 0x4665bc GetKeyboardLayoutList
 0x4665c0 GetKeyboardLayout
 0x4665c4 GetKeyState
 0x4665c8 GetKeyNameTextA
 0x4665cc GetIconInfo
 0x4665d0 GetForegroundWindow
 0x4665d4 GetFocus
 0x4665d8 GetDesktopWindow
 0x4665dc GetDCEx
 0x4665e0 GetDC
 0x4665e4 GetCursorPos
 0x4665e8 GetCursor
 0x4665ec GetClientRect
 0x4665f0 GetClassNameA
 0x4665f4 GetClassInfoA
 0x4665f8 GetCapture
 0x4665fc GetActiveWindow
 0x466600 FrameRect
 0x466604 FindWindowA
 0x466608 FillRect
 0x46660c EqualRect
 0x466610 EnumWindows
 0x466614 EnumThreadWindows
 0x466618 EndPaint
 0x46661c EnableWindow
 0x466620 EnableScrollBar
 0x466624 EnableMenuItem
 0x466628 DrawTextA
 0x46662c DrawMenuBar
 0x466630 DrawIconEx
 0x466634 DrawIcon
 0x466638 DrawFrameControl
 0x46663c DrawEdge
 0x466640 DispatchMessageA
 0x466644 DestroyWindow
 0x466648 DestroyMenu
 0x46664c DestroyIcon
 0x466650 DestroyCursor
 0x466654 DeleteMenu
 0x466658 DefWindowProcA
 0x46665c DefMDIChildProcA
 0x466660 DefFrameProcA
 0x466664 CreatePopupMenu
 0x466668 CreateMenu
 0x46666c CreateIcon
 0x466670 ClientToScreen
 0x466674 CheckMenuItem
 0x466678 CallWindowProcA
 0x46667c CallNextHookEx
 0x466680 BeginPaint
 0x466684 CharNextA
 0x466688 CharLowerA
 0x46668c CharUpperBuffA
 0x466690 CharToOemA
 0x466694 AdjustWindowRectEx
 0x466698 ActivateKeyboardLayout
kernel32.dll
 0x4666a0 Sleep
oleaut32.dll
 0x4666a8 SafeArrayPtrOfIndex
 0x4666ac SafeArrayPutElement
 0x4666b0 SafeArrayGetElement
 0x4666b4 SafeArrayUnaccessData
 0x4666b8 SafeArrayAccessData
 0x4666bc SafeArrayGetUBound
 0x4666c0 SafeArrayGetLBound
 0x4666c4 SafeArrayCreate
 0x4666c8 VariantChangeType
 0x4666cc VariantCopyInd
 0x4666d0 VariantCopy
 0x4666d4 VariantClear
 0x4666d8 VariantInit
ole32.dll
 0x4666e0 CoUninitialize
 0x4666e4 CoInitialize
oleaut32.dll
 0x4666ec GetErrorInfo
 0x4666f0 SysFreeString
comctl32.dll
 0x4666f8 ImageList_SetIconSize
 0x4666fc ImageList_GetIconSize
 0x466700 ImageList_Write
 0x466704 ImageList_Read
 0x466708 ImageList_GetDragImage
 0x46670c ImageList_DragShowNolock
 0x466710 ImageList_SetDragCursorImage
 0x466714 ImageList_DragMove
 0x466718 ImageList_DragLeave
 0x46671c ImageList_DragEnter
 0x466720 ImageList_EndDrag
 0x466724 ImageList_BeginDrag
 0x466728 ImageList_Remove
 0x46672c ImageList_DrawEx
 0x466730 ImageList_Draw
 0x466734 ImageList_GetBkColor
 0x466738 ImageList_SetBkColor
 0x46673c ImageList_ReplaceIcon
 0x466740 ImageList_Add
 0x466744 ImageList_GetImageCount
 0x466748 ImageList_Destroy
 0x46674c ImageList_Create

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure