Report - server.exe

PE File PE32
ScreenShot
Created 2021.06.24 23:48 Machine s1_win7_x6401
Filename server.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
5
Behavior Score
1.2
ZERO API file : clean
VT API (file)
md5 3702ad7cc7ea7c7333c67896a78ec921
sha256 68a0604d6a5338e5e76380dd45cf06469db18baad72f83675623ba4bccd2bd29
ssdeep 24576:tMsvlcRdvYjnhQrs2kI7wP37P+BgXSPJ5KIbH4SQ2ZGG:tFvlAiyok8P7+0IJwIDYG
imphash 1ed28589ba0c58a6400a125c47a41359
impfuzzy 192:P3EF9gG1aomjbuuAbSUvK9aqooqEse72POQRB1zj:P3SH1SAQ9oPPOQj1zj
  Network IP location

Signature (4cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice Foreign language identified in PE resource
info Checks amount of memory in system
info The executable contains unknown PE section names indicative of a packer (could be a false positive)

Rules (2cnts)

Level Name Description Collection
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x473168 DeleteCriticalSection
 0x47316c LeaveCriticalSection
 0x473170 EnterCriticalSection
 0x473174 InitializeCriticalSection
 0x473178 VirtualFree
 0x47317c VirtualAlloc
 0x473180 LocalFree
 0x473184 LocalAlloc
 0x473188 GetVersion
 0x47318c GetCurrentThreadId
 0x473190 InterlockedDecrement
 0x473194 InterlockedIncrement
 0x473198 VirtualQuery
 0x47319c WideCharToMultiByte
 0x4731a0 MultiByteToWideChar
 0x4731a4 lstrlenA
 0x4731a8 lstrcpynA
 0x4731ac LoadLibraryExA
 0x4731b0 GetThreadLocale
 0x4731b4 GetStartupInfoA
 0x4731b8 GetProcAddress
 0x4731bc GetModuleHandleA
 0x4731c0 GetModuleFileNameA
 0x4731c4 GetLocaleInfoA
 0x4731c8 GetLastError
 0x4731cc GetCommandLineA
 0x4731d0 FreeLibrary
 0x4731d4 FindFirstFileA
 0x4731d8 FindClose
 0x4731dc ExitProcess
 0x4731e0 ExitThread
 0x4731e4 CreateThread
 0x4731e8 WriteFile
 0x4731ec UnhandledExceptionFilter
 0x4731f0 SetFilePointer
 0x4731f4 SetEndOfFile
 0x4731f8 RtlUnwind
 0x4731fc ReadFile
 0x473200 RaiseException
 0x473204 GetStdHandle
 0x473208 GetFileSize
 0x47320c GetFileType
 0x473210 CreateFileA
 0x473214 CloseHandle
user32.dll
 0x47321c GetKeyboardType
 0x473220 LoadStringA
 0x473224 MessageBoxA
 0x473228 CharNextA
advapi32.dll
 0x473230 RegQueryValueExA
 0x473234 RegOpenKeyExA
 0x473238 RegCloseKey
oleaut32.dll
 0x473240 SysFreeString
 0x473244 SysReAllocStringLen
 0x473248 SysAllocStringLen
kernel32.dll
 0x473250 TlsSetValue
 0x473254 TlsGetValue
 0x473258 LocalAlloc
 0x47325c GetModuleHandleA
advapi32.dll
 0x473264 RegSetValueExA
 0x473268 RegQueryValueExA
 0x47326c RegOpenKeyExA
 0x473270 RegFlushKey
 0x473274 RegCreateKeyExA
 0x473278 RegCloseKey
kernel32.dll
 0x473280 lstrcpyA
 0x473284 WriteFile
 0x473288 WaitForSingleObject
 0x47328c VirtualQuery
 0x473290 VirtualAlloc
 0x473294 Sleep
 0x473298 SizeofResource
 0x47329c SetThreadPriority
 0x4732a0 SetThreadLocale
 0x4732a4 SetProcessWorkingSetSize
 0x4732a8 SetFilePointer
 0x4732ac SetEvent
 0x4732b0 SetErrorMode
 0x4732b4 SetEndOfFile
 0x4732b8 ResumeThread
 0x4732bc ResetEvent
 0x4732c0 ReadFile
 0x4732c4 OpenProcess
 0x4732c8 MulDiv
 0x4732cc LockResource
 0x4732d0 LoadResource
 0x4732d4 LoadLibraryA
 0x4732d8 LeaveCriticalSection
 0x4732dc InitializeCriticalSection
 0x4732e0 GlobalUnlock
 0x4732e4 GlobalReAlloc
 0x4732e8 GlobalHandle
 0x4732ec GlobalLock
 0x4732f0 GlobalFree
 0x4732f4 GlobalFindAtomA
 0x4732f8 GlobalDeleteAtom
 0x4732fc GlobalAlloc
 0x473300 GlobalAddAtomA
 0x473304 GetVersionExA
 0x473308 GetVersion
 0x47330c GetTickCount
 0x473310 GetThreadLocale
 0x473314 GetSystemInfo
 0x473318 GetStringTypeExA
 0x47331c GetStdHandle
 0x473320 GetProcAddress
 0x473324 GetModuleHandleA
 0x473328 GetModuleFileNameA
 0x47332c GetLocaleInfoA
 0x473330 GetLocalTime
 0x473334 GetLastError
 0x473338 GetFullPathNameA
 0x47333c GetExitCodeThread
 0x473340 GetDiskFreeSpaceA
 0x473344 GetDateFormatA
 0x473348 GetCurrentThreadId
 0x47334c GetCurrentProcessId
 0x473350 GetCPInfo
 0x473354 GetACP
 0x473358 FreeResource
 0x47335c InterlockedIncrement
 0x473360 InterlockedExchange
 0x473364 InterlockedDecrement
 0x473368 FreeLibrary
 0x47336c FormatMessageA
 0x473370 FindResourceA
 0x473374 FindFirstFileA
 0x473378 FindClose
 0x47337c FileTimeToLocalFileTime
 0x473380 FileTimeToDosDateTime
 0x473384 EnumCalendarInfoA
 0x473388 EnterCriticalSection
 0x47338c DeleteCriticalSection
 0x473390 CreateThread
 0x473394 CreateFileA
 0x473398 CreateEventA
 0x47339c CompareStringA
 0x4733a0 CloseHandle
version.dll
 0x4733a8 VerQueryValueA
 0x4733ac GetFileVersionInfoSizeA
 0x4733b0 GetFileVersionInfoA
gdi32.dll
 0x4733b8 UnrealizeObject
 0x4733bc StretchBlt
 0x4733c0 SetWindowOrgEx
 0x4733c4 SetWinMetaFileBits
 0x4733c8 SetViewportOrgEx
 0x4733cc SetTextColor
 0x4733d0 SetStretchBltMode
 0x4733d4 SetROP2
 0x4733d8 SetPixel
 0x4733dc SetEnhMetaFileBits
 0x4733e0 SetDIBColorTable
 0x4733e4 SetBrushOrgEx
 0x4733e8 SetBkMode
 0x4733ec SetBkColor
 0x4733f0 SelectPalette
 0x4733f4 SelectObject
 0x4733f8 SaveDC
 0x4733fc RestoreDC
 0x473400 Rectangle
 0x473404 RectVisible
 0x473408 RealizePalette
 0x47340c Polyline
 0x473410 PlayEnhMetaFile
 0x473414 PatBlt
 0x473418 MoveToEx
 0x47341c MaskBlt
 0x473420 LineTo
 0x473424 IntersectClipRect
 0x473428 GetWindowOrgEx
 0x47342c GetWinMetaFileBits
 0x473430 GetTextMetricsA
 0x473434 GetTextExtentPoint32A
 0x473438 GetSystemPaletteEntries
 0x47343c GetStockObject
 0x473440 GetPixel
 0x473444 GetPaletteEntries
 0x473448 GetObjectA
 0x47344c GetEnhMetaFilePaletteEntries
 0x473450 GetEnhMetaFileHeader
 0x473454 GetEnhMetaFileBits
 0x473458 GetDeviceCaps
 0x47345c GetDIBits
 0x473460 GetDIBColorTable
 0x473464 GetDCOrgEx
 0x473468 GetCurrentPositionEx
 0x47346c GetClipBox
 0x473470 GetBrushOrgEx
 0x473474 GetBitmapBits
 0x473478 GdiFlush
 0x47347c ExcludeClipRect
 0x473480 DeleteObject
 0x473484 DeleteEnhMetaFile
 0x473488 DeleteDC
 0x47348c CreateSolidBrush
 0x473490 CreatePenIndirect
 0x473494 CreatePalette
 0x473498 CreateHalftonePalette
 0x47349c CreateFontIndirectA
 0x4734a0 CreateDIBitmap
 0x4734a4 CreateDIBSection
 0x4734a8 CreateCompatibleDC
 0x4734ac CreateCompatibleBitmap
 0x4734b0 CreateBrushIndirect
 0x4734b4 CreateBitmap
 0x4734b8 CopyEnhMetaFileA
 0x4734bc BitBlt
user32.dll
 0x4734c4 CreateWindowExA
 0x4734c8 mouse_event
 0x4734cc keybd_event
 0x4734d0 WindowFromPoint
 0x4734d4 WinHelpA
 0x4734d8 WaitMessage
 0x4734dc UpdateWindow
 0x4734e0 UnregisterClassA
 0x4734e4 UnhookWindowsHookEx
 0x4734e8 TranslateMessage
 0x4734ec TranslateMDISysAccel
 0x4734f0 TrackPopupMenu
 0x4734f4 SystemParametersInfoA
 0x4734f8 ShowWindow
 0x4734fc ShowScrollBar
 0x473500 ShowOwnedPopups
 0x473504 ShowCursor
 0x473508 SetWindowsHookExA
 0x47350c SetWindowTextA
 0x473510 SetWindowPos
 0x473514 SetWindowPlacement
 0x473518 SetWindowLongA
 0x47351c SetTimer
 0x473520 SetScrollRange
 0x473524 SetScrollPos
 0x473528 SetScrollInfo
 0x47352c SetRect
 0x473530 SetPropA
 0x473534 SetParent
 0x473538 SetMenuItemInfoA
 0x47353c SetMenu
 0x473540 SetForegroundWindow
 0x473544 SetFocus
 0x473548 SetCursorPos
 0x47354c SetCursor
 0x473550 SetClassLongA
 0x473554 SetCapture
 0x473558 SetActiveWindow
 0x47355c SendMessageA
 0x473560 ScrollWindow
 0x473564 ScreenToClient
 0x473568 RemovePropA
 0x47356c RemoveMenu
 0x473570 ReleaseDC
 0x473574 ReleaseCapture
 0x473578 RegisterWindowMessageA
 0x47357c RegisterClipboardFormatA
 0x473580 RegisterClassA
 0x473584 RedrawWindow
 0x473588 PtInRect
 0x47358c PostQuitMessage
 0x473590 PostMessageA
 0x473594 PeekMessageA
 0x473598 OffsetRect
 0x47359c OemToCharA
 0x4735a0 MsgWaitForMultipleObjects
 0x4735a4 MessageBoxA
 0x4735a8 MapWindowPoints
 0x4735ac MapVirtualKeyA
 0x4735b0 LoadStringA
 0x4735b4 LoadKeyboardLayoutA
 0x4735b8 LoadIconA
 0x4735bc LoadCursorA
 0x4735c0 LoadBitmapA
 0x4735c4 KillTimer
 0x4735c8 IsZoomed
 0x4735cc IsWindowVisible
 0x4735d0 IsWindowEnabled
 0x4735d4 IsWindow
 0x4735d8 IsRectEmpty
 0x4735dc IsIconic
 0x4735e0 IsDialogMessageA
 0x4735e4 IsChild
 0x4735e8 InvalidateRect
 0x4735ec IntersectRect
 0x4735f0 InsertMenuItemA
 0x4735f4 InsertMenuA
 0x4735f8 InflateRect
 0x4735fc GetWindowThreadProcessId
 0x473600 GetWindowTextA
 0x473604 GetWindowRect
 0x473608 GetWindowPlacement
 0x47360c GetWindowLongA
 0x473610 GetWindowDC
 0x473614 GetTopWindow
 0x473618 GetSystemMetrics
 0x47361c GetSystemMenu
 0x473620 GetSysColorBrush
 0x473624 GetSysColor
 0x473628 GetSubMenu
 0x47362c GetScrollRange
 0x473630 GetScrollPos
 0x473634 GetScrollInfo
 0x473638 GetPropA
 0x47363c GetParent
 0x473640 GetWindow
 0x473644 GetMenuStringA
 0x473648 GetMenuState
 0x47364c GetMenuItemInfoA
 0x473650 GetMenuItemID
 0x473654 GetMenuItemCount
 0x473658 GetMenu
 0x47365c GetLastActivePopup
 0x473660 GetKeyboardState
 0x473664 GetKeyboardLayoutList
 0x473668 GetKeyboardLayout
 0x47366c GetKeyState
 0x473670 GetKeyNameTextA
 0x473674 GetIconInfo
 0x473678 GetForegroundWindow
 0x47367c GetFocus
 0x473680 GetDesktopWindow
 0x473684 GetDCEx
 0x473688 GetDC
 0x47368c GetCursorPos
 0x473690 GetCursor
 0x473694 GetClipboardData
 0x473698 GetClientRect
 0x47369c GetClassNameA
 0x4736a0 GetClassInfoA
 0x4736a4 GetCapture
 0x4736a8 GetActiveWindow
 0x4736ac FrameRect
 0x4736b0 FindWindowA
 0x4736b4 FillRect
 0x4736b8 EqualRect
 0x4736bc EnumWindows
 0x4736c0 EnumThreadWindows
 0x4736c4 EndPaint
 0x4736c8 EnableWindow
 0x4736cc EnableScrollBar
 0x4736d0 EnableMenuItem
 0x4736d4 DrawTextA
 0x4736d8 DrawMenuBar
 0x4736dc DrawIconEx
 0x4736e0 DrawIcon
 0x4736e4 DrawFrameControl
 0x4736e8 DrawEdge
 0x4736ec DispatchMessageA
 0x4736f0 DestroyWindow
 0x4736f4 DestroyMenu
 0x4736f8 DestroyIcon
 0x4736fc DestroyCursor
 0x473700 DeleteMenu
 0x473704 DefWindowProcA
 0x473708 DefMDIChildProcA
 0x47370c DefFrameProcA
 0x473710 CreatePopupMenu
 0x473714 CreateMenu
 0x473718 CreateIcon
 0x47371c ClientToScreen
 0x473720 CheckMenuItem
 0x473724 CallWindowProcA
 0x473728 CallNextHookEx
 0x47372c BeginPaint
 0x473730 CharNextA
 0x473734 CharLowerBuffA
 0x473738 CharLowerA
 0x47373c CharUpperBuffA
 0x473740 CharToOemA
 0x473744 AdjustWindowRectEx
 0x473748 ActivateKeyboardLayout
kernel32.dll
 0x473750 Sleep
oleaut32.dll
 0x473758 SafeArrayPtrOfIndex
 0x47375c SafeArrayGetUBound
 0x473760 SafeArrayGetLBound
 0x473764 SafeArrayCreate
 0x473768 VariantChangeType
 0x47376c VariantCopy
 0x473770 VariantClear
 0x473774 VariantInit
comctl32.dll
 0x47377c ImageList_SetIconSize
 0x473780 ImageList_GetIconSize
 0x473784 ImageList_Write
 0x473788 ImageList_Read
 0x47378c ImageList_GetDragImage
 0x473790 ImageList_DragShowNolock
 0x473794 ImageList_SetDragCursorImage
 0x473798 ImageList_DragMove
 0x47379c ImageList_DragLeave
 0x4737a0 ImageList_DragEnter
 0x4737a4 ImageList_EndDrag
 0x4737a8 ImageList_BeginDrag
 0x4737ac ImageList_Remove
 0x4737b0 ImageList_DrawEx
 0x4737b4 ImageList_Draw
 0x4737b8 ImageList_GetBkColor
 0x4737bc ImageList_SetBkColor
 0x4737c0 ImageList_ReplaceIcon
 0x4737c4 ImageList_Add
 0x4737c8 ImageList_GetImageCount
 0x4737cc ImageList_Destroy
 0x4737d0 ImageList_Create
shell32.dll
 0x4737d8 ShellExecuteA
URLMON.DLL
 0x4737e0 URLDownloadToFileA
wsock32.dll
 0x4737e8 WSACleanup
 0x4737ec WSAStartup
 0x4737f0 WSAGetLastError
 0x4737f4 WSACancelAsyncRequest
 0x4737f8 WSAAsyncGetServByName
 0x4737fc WSAAsyncGetHostByName
 0x473800 WSAAsyncSelect
 0x473804 getservbyname
 0x473808 gethostbyname
 0x47380c socket
 0x473810 setsockopt
 0x473814 send
 0x473818 select
 0x47381c recv
 0x473820 ntohs
 0x473824 listen
 0x473828 ioctlsocket
 0x47382c inet_addr
 0x473830 htons
 0x473834 getsockopt
 0x473838 connect
 0x47383c closesocket
 0x473840 ind
 0x473844 accept
USER32.DLL
 0x47384c BlockInput

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure