Report - iTV.exe

PE File OS Processor Check PE32
ScreenShot
Created 2021.06.24 19:29 Machine s1_win7_x6401
Filename iTV.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
4
Behavior Score
1.2
ZERO API file : clean
VT API (file) 13 detected (AIDetect, malware2, Unsafe, Malicious, GenericRXIL, MachineLearning, Anomalous, R002H06FF21, ET#96%, RDMK, cmRtazqxU2Ld1v7FkGy8KfzSmmn0, PossibleThreat)
md5 2a270d6a0d77fd1e12f813c8f8661e86
sha256 df756941e80feb206d83104d332b3546982a2c49a5dd9de78b960368a14be573
ssdeep 12288:ojABXv+PHDjGgbDvvLcK1RZBoQ/30m7arxcK:osh+PegbD3PRLB/0xcK
imphash 761791ada53212fb7aeb4619600bade1
impfuzzy 96:uQpOlV97xL43r561pcfmtvvB2DA4PsTYMYBGZeTEf/FovG:1ps7GwvvB2DA4kTz63EHFiG
  Network IP location

Signature (3cnts)

Level Description
watch File has been identified by 13 AntiVirus engines on VirusTotal as malicious
notice The binary likely contains encrypted or compressed data indicative of a packer
info The file contains an unknown PE resource name possibly indicative of a packer

Rules (3cnts)

Level Name Description Collection
info IsPE32 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.dll
 0x43d0bc MulDiv
 0x43d0c0 GetCurrentThreadId
 0x43d0c4 SetLastError
 0x43d0c8 FreeLibrary
 0x43d0cc LoadLibraryExA
 0x43d0d0 GetModuleHandleA
 0x43d0d4 SetEnvironmentVariableA
 0x43d0d8 CompareStringW
 0x43d0dc CompareStringA
 0x43d0e0 GetLocaleInfoW
 0x43d0e4 SetStdHandle
 0x43d0e8 SetFilePointer
 0x43d0ec WriteConsoleW
 0x43d0f0 GetConsoleOutputCP
 0x43d0f4 WriteConsoleA
 0x43d0f8 GetCurrentProcessId
 0x43d0fc GetTickCount
 0x43d100 QueryPerformanceCounter
 0x43d104 GetEnvironmentStringsW
 0x43d108 FreeEnvironmentStringsW
 0x43d10c GetEnvironmentStrings
 0x43d110 FreeEnvironmentStringsA
 0x43d114 HeapSize
 0x43d118 GetStringTypeW
 0x43d11c GetStringTypeA
 0x43d120 IsValidCodePage
 0x43d124 IsValidLocale
 0x43d128 EnumSystemLocalesA
 0x43d12c GetUserDefaultLCID
 0x43d130 LCMapStringW
 0x43d134 LCMapStringA
 0x43d138 GetOEMCP
 0x43d13c GetCPInfo
 0x43d140 TlsFree
 0x43d144 TlsSetValue
 0x43d148 lstrcmpA
 0x43d14c TlsGetValue
 0x43d150 GetFileType
 0x43d154 SetHandleCount
 0x43d158 FlushFileBuffers
 0x43d15c GetConsoleMode
 0x43d160 GetConsoleCP
 0x43d164 GetStdHandle
 0x43d168 ExitProcess
 0x43d16c IsDebuggerPresent
 0x43d170 SetUnhandledExceptionFilter
 0x43d174 UnhandledExceptionFilter
 0x43d178 TerminateProcess
 0x43d17c HeapCreate
 0x43d180 HeapDestroy
 0x43d184 GetStartupInfoA
 0x43d188 GetCommandLineA
 0x43d18c HeapReAlloc
 0x43d190 VirtualQuery
 0x43d194 GetSystemInfo
 0x43d198 VirtualProtect
 0x43d19c RtlUnwind
 0x43d1a0 GetSystemTimeAsFileTime
 0x43d1a4 LocalFree
 0x43d1a8 VirtualAlloc
 0x43d1ac VirtualFree
 0x43d1b0 IsProcessorFeaturePresent
 0x43d1b4 LoadLibraryA
 0x43d1b8 GetProcAddress
 0x43d1bc HeapAlloc
 0x43d1c0 GetProcessHeap
 0x43d1c4 HeapFree
 0x43d1c8 InterlockedCompareExchange
 0x43d1cc GetThreadLocale
 0x43d1d0 GetLocaleInfoA
 0x43d1d4 GetACP
 0x43d1d8 InterlockedExchange
 0x43d1dc FlushInstructionCache
 0x43d1e0 IsDBCSLeadByte
 0x43d1e4 CreateThread
 0x43d1e8 TerminateThread
 0x43d1ec lstrcmpiA
 0x43d1f0 lstrlenA
 0x43d1f4 InterlockedDecrement
 0x43d1f8 InterlockedIncrement
 0x43d1fc lstrlenW
 0x43d200 MoveFileExA
 0x43d204 GlobalLock
 0x43d208 GlobalUnlock
 0x43d20c GetCurrentProcess
 0x43d210 SetProcessWorkingSetSize
 0x43d214 FindFirstFileA
 0x43d218 FindNextFileA
 0x43d21c FindClose
 0x43d220 WideCharToMultiByte
 0x43d224 DeleteFileA
 0x43d228 GetVolumeInformationA
 0x43d22c GetVersionExA
 0x43d230 GetFileSize
 0x43d234 ReadFile
 0x43d238 CreateFileA
 0x43d23c GetLastError
 0x43d240 WriteFile
 0x43d244 MultiByteToWideChar
 0x43d248 CloseHandle
 0x43d24c GlobalAlloc
 0x43d250 FindResourceA
 0x43d254 LoadResource
 0x43d258 SizeofResource
 0x43d25c LockResource
 0x43d260 FreeResource
 0x43d264 lstrcpynA
 0x43d268 GetDateFormatA
 0x43d26c GetTimeFormatA
 0x43d270 GetTimeZoneInformation
 0x43d274 Sleep
 0x43d278 GetModuleFileNameA
 0x43d27c SetCurrentDirectoryA
 0x43d280 DeleteCriticalSection
 0x43d284 InitializeCriticalSection
 0x43d288 LeaveCriticalSection
 0x43d28c EnterCriticalSection
 0x43d290 RaiseException
 0x43d294 TlsAlloc
USER32.dll
 0x43d334 ScreenToClient
 0x43d338 InvalidateRgn
 0x43d33c SetCapture
 0x43d340 SetWindowLongA
 0x43d344 GetWindowLongA
 0x43d348 CreateWindowExA
 0x43d34c DestroyWindow
 0x43d350 SetWindowPos
 0x43d354 ShowWindow
 0x43d358 SendMessageA
 0x43d35c LoadIconA
 0x43d360 ReleaseDC
 0x43d364 FillRect
 0x43d368 GetDC
 0x43d36c SetTimer
 0x43d370 EnableWindow
 0x43d374 GetDlgItem
 0x43d378 SetDlgItemTextA
 0x43d37c IsChild
 0x43d380 SendDlgItemMessageA
 0x43d384 GetParent
 0x43d388 GetClassNameA
 0x43d38c ReleaseCapture
 0x43d390 CallWindowProcA
 0x43d394 DestroyAcceleratorTable
 0x43d398 GetWindow
 0x43d39c GetFocus
 0x43d3a0 GetDesktopWindow
 0x43d3a4 IsWindow
 0x43d3a8 GetClassInfoExA
 0x43d3ac LoadCursorA
 0x43d3b0 RegisterClassExA
 0x43d3b4 PostMessageA
 0x43d3b8 GetWindowRect
 0x43d3bc InsertMenuItemA
 0x43d3c0 FindWindowA
 0x43d3c4 GetKeyState
 0x43d3c8 SetWindowTextA
 0x43d3cc GetSystemMetrics
 0x43d3d0 SetActiveWindow
 0x43d3d4 EndPaint
 0x43d3d8 BeginPaint
 0x43d3dc LoadImageA
 0x43d3e0 GetClientRect
 0x43d3e4 PtInRect
 0x43d3e8 RedrawWindow
 0x43d3ec SetLayeredWindowAttributes
 0x43d3f0 KillTimer
 0x43d3f4 CharLowerA
 0x43d3f8 OffsetRect
 0x43d3fc InflateRect
 0x43d400 GetUpdateRect
 0x43d404 SetFocus
 0x43d408 GetWindowDC
 0x43d40c CreatePopupMenu
 0x43d410 ClientToScreen
 0x43d414 MoveWindow
 0x43d418 CreateAcceleratorTableA
 0x43d41c GetWindowTextA
 0x43d420 GetWindowTextLengthA
 0x43d424 RegisterWindowMessageA
 0x43d428 SystemParametersInfoA
 0x43d42c GetScrollInfo
 0x43d430 SetCursor
 0x43d434 GetDlgItemInt
 0x43d438 GetDlgCtrlID
 0x43d43c DialogBoxParamA
 0x43d440 CheckMenuItem
 0x43d444 GetMenuItemID
 0x43d448 TrackMouseEvent
 0x43d44c PostQuitMessage
 0x43d450 DispatchMessageA
 0x43d454 TranslateMessage
 0x43d458 GetMessageA
 0x43d45c LoadStringA
 0x43d460 MessageBoxA
 0x43d464 GetWindowInfo
 0x43d468 GetSysColor
 0x43d46c SetForegroundWindow
 0x43d470 TrackPopupMenu
 0x43d474 DefWindowProcA
 0x43d478 ValidateRect
 0x43d47c GetSysColorBrush
 0x43d480 GetMenuItemRect
 0x43d484 FrameRect
 0x43d488 CharNextA
 0x43d48c EndDialog
 0x43d490 DestroyMenu
 0x43d494 CopyRect
 0x43d498 OpenClipboard
 0x43d49c EmptyClipboard
 0x43d4a0 SetClipboardData
 0x43d4a4 CloseClipboard
 0x43d4a8 UnregisterClassA
 0x43d4ac LockWindowUpdate
 0x43d4b0 MessageBeep
 0x43d4b4 GetCursorPos
 0x43d4b8 SetScrollInfo
 0x43d4bc GetWindowPlacement
 0x43d4c0 RegisterHotKey
 0x43d4c4 UnregisterHotKey
 0x43d4c8 InvalidateRect
 0x43d4cc UpdateWindow
 0x43d4d0 DrawTextA
 0x43d4d4 GetMenuItemCount
GDI32.dll
 0x43d034 CreateRectRgn
 0x43d038 GetTextExtentPoint32A
 0x43d03c GetStockObject
 0x43d040 GetTextMetricsA
 0x43d044 TextOutA
 0x43d048 SetTextAlign
 0x43d04c CreateDIBitmap
 0x43d050 Polygon
 0x43d054 CreatePen
 0x43d058 SelectClipRgn
 0x43d05c EndPage
 0x43d060 CreatePatternBrush
 0x43d064 Rectangle
 0x43d068 SetTextColor
 0x43d06c GetCurrentObject
 0x43d070 EndDoc
 0x43d074 GetTextExtentExPointA
 0x43d078 GetDeviceCaps
 0x43d07c StartDocA
 0x43d080 BitBlt
 0x43d084 CreateRoundRectRgn
 0x43d088 DeleteObject
 0x43d08c SelectObject
 0x43d090 CreateFontA
 0x43d094 GetObjectA
 0x43d098 DeleteDC
 0x43d09c CreateSolidBrush
 0x43d0a0 CreateCompatibleBitmap
 0x43d0a4 CreateCompatibleDC
 0x43d0a8 StretchBlt
 0x43d0ac StartPage
 0x43d0b0 SetBkMode
 0x43d0b4 SetStretchBltMode
comdlg32.dll
 0x43d514 GetOpenFileNameA
 0x43d518 PrintDlgA
ADVAPI32.dll
 0x43d000 RegDeleteKeyA
 0x43d004 GetUserNameA
 0x43d008 RegEnumKeyExA
 0x43d00c RegQueryInfoKeyA
 0x43d010 RegCreateKeyExA
 0x43d014 RegSetValueExA
 0x43d018 RegOpenKeyExA
 0x43d01c RegQueryValueExA
 0x43d020 RegCloseKey
 0x43d024 RegDeleteValueA
SHELL32.dll
 0x43d2e4 SHGetSpecialFolderPathA
 0x43d2e8 ShellExecuteA
 0x43d2ec DragFinish
 0x43d2f0 DragQueryFileA
 0x43d2f4 Shell_NotifyIconA
ole32.dll
 0x43d548 CLSIDFromProgID
 0x43d54c CoGetClassObject
 0x43d550 OleLockRunning
 0x43d554 StringFromGUID2
 0x43d558 CoInitializeEx
 0x43d55c CoInitializeSecurity
 0x43d560 CoUninitialize
 0x43d564 CoSetProxyBlanket
 0x43d568 CoTaskMemFree
 0x43d56c CoCreateInstance
 0x43d570 CoTaskMemRealloc
 0x43d574 CoTaskMemAlloc
 0x43d578 CreateStreamOnHGlobal
 0x43d57c CLSIDFromString
 0x43d580 OleInitialize
 0x43d584 OleUninitialize
OLEAUT32.dll
 0x43d2b0 VarUI4FromStr
 0x43d2b4 VariantClear
 0x43d2b8 SysStringByteLen
 0x43d2bc GetErrorInfo
 0x43d2c0 SysAllocStringLen
 0x43d2c4 VariantInit
 0x43d2c8 OleCreateFontIndirect
 0x43d2cc LoadRegTypeLib
 0x43d2d0 SysAllocString
 0x43d2d4 SysFreeString
 0x43d2d8 SysStringLen
 0x43d2dc LoadTypeLib
WS2_32.dll
 0x43d4e4 closesocket
 0x43d4e8 connect
 0x43d4ec htonl
 0x43d4f0 htons
 0x43d4f4 socket
 0x43d4f8 gethostbyname
 0x43d4fc recv
 0x43d500 send
 0x43d504 setsockopt
 0x43d508 WSAStartup
 0x43d50c WSACleanup
gdiplus.dll
 0x43d520 GdipCreateBitmapFromStream
 0x43d524 GdipCreateBitmapFromStreamICM
 0x43d528 GdipCreateHBITMAPFromBitmap
 0x43d52c GdipDisposeImage
 0x43d530 GdiplusShutdown
 0x43d534 GdiplusStartup
 0x43d538 GdipAlloc
 0x43d53c GdipCloneImage
 0x43d540 GdipFree
WINMM.dll
 0x43d4dc PlaySoundA
COMCTL32.dll
 0x43d02c InitCommonControlsEx
MSIMG32.dll
 0x43d2a8 TransparentBlt
LIBEAY32.dll
 0x43d29c None
 0x43d2a0 None
SSLEAY32.dll
 0x43d2fc None
 0x43d300 None
 0x43d304 None
 0x43d308 None
 0x43d30c None
 0x43d310 None
 0x43d314 None
 0x43d318 None
 0x43d31c None
 0x43d320 None
 0x43d324 None
 0x43d328 None
 0x43d32c None

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure