Report - 1.exe

Generic Malware PE File PE32
ScreenShot
Created 2021.07.06 10:00 Machine s1_win7_x6401
Filename 1.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
2
Behavior Score
4.2
ZERO API file : malware
VT API (file) 44 detected (AIDetect, malware2, Bsymem, GenericKD, Unsafe, Save, Attribute, HighConfidence, EPIZ, Malicious, MalwareX, DownLoader40, R002C0DG521, Static AI, Malicious PE, anqje, ai score=87, Bunitucrypt, 1G1WENW, score, Qbot, GenericRXAA, BScope, Scar, Generic@ML, RDML, qfDad7TmDLok08Pi3, KzKw, susgen, ZelphiF, GGW@ay91i1bi, GdSda, HgIASX0A)
md5 03b05d8cc99932a1a6e476927be4e70a
sha256 ef9e7a24f9c512ed4ea4d194b4c25398b85f0458fa7b1224d6108e0845d8c5d2
ssdeep 12288:lfGBwJKPjWbG7fFxI9SteBSBG6DOIjfsi:lOaoqyJxI9TYBx5
imphash 909039a7a37e69bf5b6549b85d4f558b
impfuzzy 192:f3mNk1Q9buuSrSUvK9RqooqE6pCPbOQpM:f3R1kSA9LkPbOQm
  Network IP location

Signature (9cnts)

Level Description
danger File has been identified by 44 AntiVirus engines on VirusTotal as malicious
watch Communicates with host for which no DNS query was performed
watch Installs itself for autorun at Windows startup
notice Allocates read-write-execute memory (usually to unpack itself)
notice Creates hidden or system file
notice Queries the disk size which could be used to detect virtual machine with small fixed size or dynamic allocation
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The executable uses a known packer
info The file contains an unknown PE resource name possibly indicative of a packer

Rules (3cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (1cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
185.215.113.32 Unknown 185.215.113.32 mailcious

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x46f154 DeleteCriticalSection
 0x46f158 LeaveCriticalSection
 0x46f15c EnterCriticalSection
 0x46f160 InitializeCriticalSection
 0x46f164 VirtualFree
 0x46f168 VirtualAlloc
 0x46f16c LocalFree
 0x46f170 LocalAlloc
 0x46f174 GetVersion
 0x46f178 GetCurrentThreadId
 0x46f17c InterlockedDecrement
 0x46f180 InterlockedIncrement
 0x46f184 VirtualQuery
 0x46f188 WideCharToMultiByte
 0x46f18c MultiByteToWideChar
 0x46f190 lstrlenA
 0x46f194 lstrcpynA
 0x46f198 LoadLibraryExA
 0x46f19c GetThreadLocale
 0x46f1a0 GetStartupInfoA
 0x46f1a4 GetProcAddress
 0x46f1a8 GetModuleHandleA
 0x46f1ac GetModuleFileNameA
 0x46f1b0 GetLocaleInfoA
 0x46f1b4 GetCommandLineA
 0x46f1b8 FreeLibrary
 0x46f1bc FindFirstFileA
 0x46f1c0 FindClose
 0x46f1c4 ExitProcess
 0x46f1c8 WriteFile
 0x46f1cc UnhandledExceptionFilter
 0x46f1d0 RtlUnwind
 0x46f1d4 RaiseException
 0x46f1d8 GetStdHandle
user32.dll
 0x46f1e0 GetKeyboardType
 0x46f1e4 LoadStringA
 0x46f1e8 MessageBoxA
 0x46f1ec CharNextA
advapi32.dll
 0x46f1f4 RegQueryValueExA
 0x46f1f8 RegOpenKeyExA
 0x46f1fc RegCloseKey
oleaut32.dll
 0x46f204 SysFreeString
 0x46f208 SysReAllocStringLen
 0x46f20c SysAllocStringLen
kernel32.dll
 0x46f214 TlsSetValue
 0x46f218 TlsGetValue
 0x46f21c LocalAlloc
 0x46f220 GetModuleHandleA
advapi32.dll
 0x46f228 RegQueryValueExA
 0x46f22c RegOpenKeyExA
 0x46f230 RegCloseKey
kernel32.dll
 0x46f238 lstrcpyA
 0x46f23c WriteFile
 0x46f240 WinExec
 0x46f244 WaitForSingleObject
 0x46f248 VirtualQuery
 0x46f24c VirtualAllocEx
 0x46f250 VirtualAlloc
 0x46f254 Sleep
 0x46f258 SizeofResource
 0x46f25c SetThreadLocale
 0x46f260 SetFilePointer
 0x46f264 SetEvent
 0x46f268 SetErrorMode
 0x46f26c SetEndOfFile
 0x46f270 ResetEvent
 0x46f274 ReadFile
 0x46f278 MultiByteToWideChar
 0x46f27c MulDiv
 0x46f280 LockResource
 0x46f284 LoadResource
 0x46f288 LoadLibraryA
 0x46f28c LeaveCriticalSection
 0x46f290 InitializeCriticalSection
 0x46f294 GlobalUnlock
 0x46f298 GlobalReAlloc
 0x46f29c GlobalHandle
 0x46f2a0 GlobalLock
 0x46f2a4 GlobalFree
 0x46f2a8 GlobalFindAtomA
 0x46f2ac GlobalDeleteAtom
 0x46f2b0 GlobalAlloc
 0x46f2b4 GlobalAddAtomA
 0x46f2b8 GetVersionExA
 0x46f2bc GetVersion
 0x46f2c0 GetTickCount
 0x46f2c4 GetThreadLocale
 0x46f2c8 GetSystemInfo
 0x46f2cc GetStringTypeExA
 0x46f2d0 GetStdHandle
 0x46f2d4 GetProcAddress
 0x46f2d8 GetModuleHandleA
 0x46f2dc GetModuleFileNameA
 0x46f2e0 GetLocaleInfoA
 0x46f2e4 GetLocalTime
 0x46f2e8 GetLastError
 0x46f2ec GetFullPathNameA
 0x46f2f0 GetDiskFreeSpaceA
 0x46f2f4 GetDateFormatA
 0x46f2f8 GetCurrentThreadId
 0x46f2fc GetCurrentProcessId
 0x46f300 GetCPInfo
 0x46f304 GetACP
 0x46f308 FreeResource
 0x46f30c InterlockedExchange
 0x46f310 FreeLibrary
 0x46f314 FormatMessageA
 0x46f318 FindResourceA
 0x46f31c EnumCalendarInfoA
 0x46f320 EnterCriticalSection
 0x46f324 DeleteCriticalSection
 0x46f328 CreateThread
 0x46f32c CreateFileA
 0x46f330 CreateEventA
 0x46f334 CompareStringA
 0x46f338 CloseHandle
version.dll
 0x46f340 VerQueryValueA
 0x46f344 GetFileVersionInfoSizeA
 0x46f348 GetFileVersionInfoA
gdi32.dll
 0x46f350 UnrealizeObject
 0x46f354 StretchBlt
 0x46f358 SetWindowOrgEx
 0x46f35c SetViewportOrgEx
 0x46f360 SetTextColor
 0x46f364 SetStretchBltMode
 0x46f368 SetROP2
 0x46f36c SetPixel
 0x46f370 SetDIBColorTable
 0x46f374 SetBrushOrgEx
 0x46f378 SetBkMode
 0x46f37c SetBkColor
 0x46f380 SelectPalette
 0x46f384 SelectObject
 0x46f388 SaveDC
 0x46f38c RestoreDC
 0x46f390 RectVisible
 0x46f394 RealizePalette
 0x46f398 PatBlt
 0x46f39c MoveToEx
 0x46f3a0 MaskBlt
 0x46f3a4 LineTo
 0x46f3a8 IntersectClipRect
 0x46f3ac GetWindowOrgEx
 0x46f3b0 GetTextMetricsA
 0x46f3b4 GetTextExtentPoint32A
 0x46f3b8 GetTextColor
 0x46f3bc GetSystemPaletteEntries
 0x46f3c0 GetStockObject
 0x46f3c4 GetPixel
 0x46f3c8 GetPaletteEntries
 0x46f3cc GetObjectA
 0x46f3d0 GetGraphicsMode
 0x46f3d4 GetDeviceCaps
 0x46f3d8 GetDIBits
 0x46f3dc GetDIBColorTable
 0x46f3e0 GetDCOrgEx
 0x46f3e4 GetCurrentPositionEx
 0x46f3e8 GetClipBox
 0x46f3ec GetBrushOrgEx
 0x46f3f0 GetBitmapBits
 0x46f3f4 ExcludeClipRect
 0x46f3f8 DeleteObject
 0x46f3fc DeleteDC
 0x46f400 CreateSolidBrush
 0x46f404 CreatePenIndirect
 0x46f408 CreatePalette
 0x46f40c CreateHalftonePalette
 0x46f410 CreateFontIndirectA
 0x46f414 CreateDIBitmap
 0x46f418 CreateDIBSection
 0x46f41c CreateCompatibleDC
 0x46f420 CreateCompatibleBitmap
 0x46f424 CreateBrushIndirect
 0x46f428 CreateBitmap
 0x46f42c BitBlt
 0x46f430 AddFontResourceA
user32.dll
 0x46f438 CreateWindowExA
 0x46f43c WindowFromPoint
 0x46f440 WinHelpA
 0x46f444 WaitMessage
 0x46f448 UpdateWindow
 0x46f44c UnregisterClassA
 0x46f450 UnhookWindowsHookEx
 0x46f454 TranslateMessage
 0x46f458 TranslateMDISysAccel
 0x46f45c TrackPopupMenu
 0x46f460 SystemParametersInfoA
 0x46f464 ShowWindow
 0x46f468 ShowScrollBar
 0x46f46c ShowOwnedPopups
 0x46f470 ShowCursor
 0x46f474 SetWindowsHookExA
 0x46f478 SetWindowPos
 0x46f47c SetWindowPlacement
 0x46f480 SetWindowLongA
 0x46f484 SetTimer
 0x46f488 SetScrollRange
 0x46f48c SetScrollPos
 0x46f490 SetScrollInfo
 0x46f494 SetRect
 0x46f498 SetPropA
 0x46f49c SetParent
 0x46f4a0 SetMenuItemInfoA
 0x46f4a4 SetMenu
 0x46f4a8 SetForegroundWindow
 0x46f4ac SetFocus
 0x46f4b0 SetCursor
 0x46f4b4 SetClassLongA
 0x46f4b8 SetCapture
 0x46f4bc SetActiveWindow
 0x46f4c0 SendMessageA
 0x46f4c4 ScrollWindow
 0x46f4c8 ScreenToClient
 0x46f4cc RemovePropA
 0x46f4d0 RemoveMenu
 0x46f4d4 ReleaseDC
 0x46f4d8 ReleaseCapture
 0x46f4dc RegisterWindowMessageA
 0x46f4e0 RegisterClipboardFormatA
 0x46f4e4 RegisterClassA
 0x46f4e8 RedrawWindow
 0x46f4ec PtInRect
 0x46f4f0 PostQuitMessage
 0x46f4f4 PostMessageA
 0x46f4f8 PeekMessageA
 0x46f4fc OffsetRect
 0x46f500 OemToCharA
 0x46f504 MessageBoxA
 0x46f508 MapWindowPoints
 0x46f50c MapVirtualKeyA
 0x46f510 LoadStringA
 0x46f514 LoadKeyboardLayoutA
 0x46f518 LoadIconA
 0x46f51c LoadCursorA
 0x46f520 LoadBitmapA
 0x46f524 KillTimer
 0x46f528 IsZoomed
 0x46f52c IsWindowVisible
 0x46f530 IsWindowEnabled
 0x46f534 IsWindow
 0x46f538 IsRectEmpty
 0x46f53c IsIconic
 0x46f540 IsDialogMessageA
 0x46f544 IsChild
 0x46f548 InvalidateRect
 0x46f54c IntersectRect
 0x46f550 InsertMenuItemA
 0x46f554 InsertMenuA
 0x46f558 InflateRect
 0x46f55c GetWindowThreadProcessId
 0x46f560 GetWindowTextA
 0x46f564 GetWindowRect
 0x46f568 GetWindowPlacement
 0x46f56c GetWindowLongA
 0x46f570 GetWindowDC
 0x46f574 GetTopWindow
 0x46f578 GetSystemMetrics
 0x46f57c GetSystemMenu
 0x46f580 GetSysColorBrush
 0x46f584 GetSysColor
 0x46f588 GetSubMenu
 0x46f58c GetScrollRange
 0x46f590 GetScrollPos
 0x46f594 GetScrollInfo
 0x46f598 GetPropA
 0x46f59c GetParent
 0x46f5a0 GetWindow
 0x46f5a4 GetMenuStringA
 0x46f5a8 GetMenuState
 0x46f5ac GetMenuItemInfoA
 0x46f5b0 GetMenuItemID
 0x46f5b4 GetMenuItemCount
 0x46f5b8 GetMenu
 0x46f5bc GetLastActivePopup
 0x46f5c0 GetKeyboardState
 0x46f5c4 GetKeyboardLayoutList
 0x46f5c8 GetKeyboardLayout
 0x46f5cc GetKeyState
 0x46f5d0 GetKeyNameTextA
 0x46f5d4 GetIconInfo
 0x46f5d8 GetForegroundWindow
 0x46f5dc GetFocus
 0x46f5e0 GetDesktopWindow
 0x46f5e4 GetDCEx
 0x46f5e8 GetDC
 0x46f5ec GetCursorPos
 0x46f5f0 GetCursor
 0x46f5f4 GetClientRect
 0x46f5f8 GetClassNameA
 0x46f5fc GetClassInfoA
 0x46f600 GetCapture
 0x46f604 GetActiveWindow
 0x46f608 FrameRect
 0x46f60c FindWindowA
 0x46f610 FillRect
 0x46f614 EqualRect
 0x46f618 EnumWindows
 0x46f61c EnumThreadWindows
 0x46f620 EndPaint
 0x46f624 EnableWindow
 0x46f628 EnableScrollBar
 0x46f62c EnableMenuItem
 0x46f630 DrawTextA
 0x46f634 DrawMenuBar
 0x46f638 DrawIconEx
 0x46f63c DrawIcon
 0x46f640 DrawFrameControl
 0x46f644 DrawEdge
 0x46f648 DispatchMessageA
 0x46f64c DestroyWindow
 0x46f650 DestroyMenu
 0x46f654 DestroyIcon
 0x46f658 DestroyCursor
 0x46f65c DeleteMenu
 0x46f660 DefWindowProcA
 0x46f664 DefMDIChildProcA
 0x46f668 DefFrameProcA
 0x46f66c CreatePopupMenu
 0x46f670 CreateMenu
 0x46f674 CreateIcon
 0x46f678 ClientToScreen
 0x46f67c CheckMenuItem
 0x46f680 CallWindowProcA
 0x46f684 CallNextHookEx
 0x46f688 BeginPaint
 0x46f68c CharNextA
 0x46f690 CharLowerA
 0x46f694 CharUpperBuffA
 0x46f698 CharToOemA
 0x46f69c AdjustWindowRectEx
 0x46f6a0 ActivateKeyboardLayout
kernel32.dll
 0x46f6a8 Sleep
oleaut32.dll
 0x46f6b0 SafeArrayPtrOfIndex
 0x46f6b4 SafeArrayPutElement
 0x46f6b8 SafeArrayGetElement
 0x46f6bc SafeArrayUnaccessData
 0x46f6c0 SafeArrayAccessData
 0x46f6c4 SafeArrayGetUBound
 0x46f6c8 SafeArrayGetLBound
 0x46f6cc SafeArrayCreate
 0x46f6d0 VariantChangeType
 0x46f6d4 VariantCopyInd
 0x46f6d8 VariantCopy
 0x46f6dc VariantClear
 0x46f6e0 VariantInit
ole32.dll
 0x46f6e8 OleUninitialize
 0x46f6ec OleInitialize
 0x46f6f0 CoCreateInstance
 0x46f6f4 CoUninitialize
 0x46f6f8 CoInitialize
oleaut32.dll
 0x46f700 CreateErrorInfo
 0x46f704 GetErrorInfo
 0x46f708 SetErrorInfo
 0x46f70c SysFreeString
comctl32.dll
 0x46f714 ImageList_SetIconSize
 0x46f718 ImageList_GetIconSize
 0x46f71c ImageList_Write
 0x46f720 ImageList_Read
 0x46f724 ImageList_GetDragImage
 0x46f728 ImageList_DragShowNolock
 0x46f72c ImageList_SetDragCursorImage
 0x46f730 ImageList_DragMove
 0x46f734 ImageList_DragLeave
 0x46f738 ImageList_DragEnter
 0x46f73c ImageList_EndDrag
 0x46f740 ImageList_BeginDrag
 0x46f744 ImageList_Remove
 0x46f748 ImageList_DrawEx
 0x46f74c ImageList_Draw
 0x46f750 ImageList_GetBkColor
 0x46f754 ImageList_SetBkColor
 0x46f758 ImageList_ReplaceIcon
 0x46f75c ImageList_Add
 0x46f760 ImageList_GetImageCount
 0x46f764 ImageList_Destroy
 0x46f768 ImageList_Create
user32.dll
 0x46f770 DdeCmpStringHandles
 0x46f774 DdeFreeStringHandle
 0x46f778 DdeQueryStringA
 0x46f77c DdeCreateStringHandleA
 0x46f780 DdeGetLastError
 0x46f784 DdeFreeDataHandle
 0x46f788 DdeUnaccessData
 0x46f78c DdeAccessData
 0x46f790 DdeCreateDataHandle
 0x46f794 DdeClientTransaction
 0x46f798 DdeNameService
 0x46f79c DdePostAdvise
 0x46f7a0 DdeSetUserHandle
 0x46f7a4 DdeQueryConvInfo
 0x46f7a8 DdeDisconnect
 0x46f7ac DdeConnect
 0x46f7b0 DdeUninitialize
 0x46f7b4 DdeInitializeA

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure