Report - rere.exe

PWS Loki[b] Loki[m] UPX PE File PE64 OS Processor Check
ScreenShot
Created 2021.07.19 17:54 Machine s1_win7_x6401
Filename rere.exe
Type PE32+ executable (GUI) x86-64, for MS Windows
AI Score
5
Behavior Score
2.0
ZERO API file : clean
VT API (file) 3 detected (LFYS, ASMalwS, Rozena)
md5 734b3fcc06d0a0eda6b83de9165636ac
sha256 13d8429d500e20be8588f250449f70a6e8f8f34df9423b2897fd33bbb8712c5f
ssdeep 24576:gHd6lUVuUP3ElxHDu1lD4XtAGIHB+g7lpynB:gHdLug3EHHAkXKfB3vS
imphash 13235f12bec0089819abb93d2e545004
impfuzzy 96:oE0b11txz/B3OxfUvDaS375tKN2Sm68BX0CUjAwhmypAhiObGvR8lu5:oE411txz/B3OxfUvDaS37vJ55UjMk
  Network IP location

Signature (7cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice File has been identified by 3 AntiVirus engines on VirusTotal as malicious
notice The binary likely contains encrypted or compressed data indicative of a packer
info Checks amount of memory in system
info Checks if process is being debugged by a debugger
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The file contains an unknown PE resource name possibly indicative of a packer

Rules (5cnts)

Level Name Description Collection
danger Win32_PWS_Loki_Zero Win32 PWS Loki binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE64 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

GDI32.dll
 0x1400d2c98 CreateBitmap
 0x1400d2ca0 CreateCompatibleBitmap
 0x1400d2ca8 CreateCompatibleDC
 0x1400d2cb0 CreateFontA
 0x1400d2cb8 CreateFontIndirectA
 0x1400d2cc0 CreatePalette
 0x1400d2cc8 CreatePen
 0x1400d2cd0 CreateSolidBrush
 0x1400d2cd8 DeleteDC
 0x1400d2ce0 DeleteObject
 0x1400d2ce8 ExcludeClipRect
 0x1400d2cf0 ExtTextOutA
 0x1400d2cf8 ExtTextOutW
 0x1400d2d00 GetBkMode
 0x1400d2d08 GetCharABCWidthsFloatA
 0x1400d2d10 GetCharWidth32A
 0x1400d2d18 GetCharWidth32W
 0x1400d2d20 GetCharWidthA
 0x1400d2d28 GetCharWidthW
 0x1400d2d30 GetCharacterPlacementW
 0x1400d2d38 GetDeviceCaps
 0x1400d2d40 GetObjectA
 0x1400d2d48 GetOutlineTextMetricsA
 0x1400d2d50 GetPixel
 0x1400d2d58 GetStockObject
 0x1400d2d60 GetTextExtentExPointA
 0x1400d2d68 GetTextExtentPoint32A
 0x1400d2d70 GetTextMetricsA
 0x1400d2d78 IntersectClipRect
 0x1400d2d80 LineTo
 0x1400d2d88 MoveToEx
 0x1400d2d90 Polyline
 0x1400d2d98 RealizePalette
 0x1400d2da0 Rectangle
 0x1400d2da8 SelectObject
 0x1400d2db0 SelectPalette
 0x1400d2db8 SetBkColor
 0x1400d2dc0 SetBkMode
 0x1400d2dc8 SetMapMode
 0x1400d2dd0 SetPaletteEntries
 0x1400d2dd8 SetPixel
 0x1400d2de0 SetTextAlign
 0x1400d2de8 SetTextColor
 0x1400d2df0 TextOutA
 0x1400d2df8 TranslateCharsetInfo
 0x1400d2e00 UnrealizeObject
 0x1400d2e08 UpdateColors
USER32.dll
 0x1400d2e18 AppendMenuA
 0x1400d2e20 BeginPaint
 0x1400d2e28 CheckDlgButton
 0x1400d2e30 CheckMenuItem
 0x1400d2e38 CheckRadioButton
 0x1400d2e40 CloseClipboard
 0x1400d2e48 CreateCaret
 0x1400d2e50 CreateDialogParamA
 0x1400d2e58 CreateMenu
 0x1400d2e60 CreatePopupMenu
 0x1400d2e68 CreateWindowExA
 0x1400d2e70 CreateWindowExW
 0x1400d2e78 DefDlgProcA
 0x1400d2e80 DefWindowProcA
 0x1400d2e88 DefWindowProcW
 0x1400d2e90 DeleteMenu
 0x1400d2e98 DestroyCaret
 0x1400d2ea0 DestroyIcon
 0x1400d2ea8 DestroyWindow
 0x1400d2eb0 DialogBoxParamA
 0x1400d2eb8 DispatchMessageA
 0x1400d2ec0 DispatchMessageW
 0x1400d2ec8 DrawEdge
 0x1400d2ed0 DrawIconEx
 0x1400d2ed8 EmptyClipboard
 0x1400d2ee0 EnableMenuItem
 0x1400d2ee8 EnableWindow
 0x1400d2ef0 EndDialog
 0x1400d2ef8 EndPaint
 0x1400d2f00 FindWindowA
 0x1400d2f08 FlashWindow
 0x1400d2f10 GetCapture
 0x1400d2f18 GetCaretBlinkTime
 0x1400d2f20 GetClientRect
 0x1400d2f28 GetClipboardData
 0x1400d2f30 GetClipboardOwner
 0x1400d2f38 GetCursorPos
 0x1400d2f40 GetDC
 0x1400d2f48 GetDesktopWindow
 0x1400d2f50 GetDlgItem
 0x1400d2f58 GetDlgItemTextA
 0x1400d2f60 GetDoubleClickTime
 0x1400d2f68 GetForegroundWindow
 0x1400d2f70 GetKeyboardLayout
 0x1400d2f78 GetKeyboardState
 0x1400d2f80 GetMessageA
 0x1400d2f88 GetMessageTime
 0x1400d2f90 GetParent
 0x1400d2f98 GetQueueStatus
 0x1400d2fa0 GetScrollInfo
 0x1400d2fa8 GetSysColor
 0x1400d2fb0 GetSysColorBrush
 0x1400d2fb8 GetSystemMenu
 0x1400d2fc0 GetSystemMetrics
 0x1400d2fc8 GetWindowLongPtrA
 0x1400d2fd0 GetWindowPlacement
 0x1400d2fd8 GetWindowRect
 0x1400d2fe0 GetWindowTextA
 0x1400d2fe8 GetWindowTextLengthA
 0x1400d2ff0 HideCaret
 0x1400d2ff8 InsertMenuA
 0x1400d3000 InvalidateRect
 0x1400d3008 IsDialogMessageA
 0x1400d3010 IsDlgButtonChecked
 0x1400d3018 IsIconic
 0x1400d3020 IsWindow
 0x1400d3028 IsZoomed
 0x1400d3030 KillTimer
 0x1400d3038 LoadCursorA
 0x1400d3040 LoadIconA
 0x1400d3048 LoadImageA
 0x1400d3050 MapDialogRect
 0x1400d3058 MessageBeep
 0x1400d3060 MessageBoxA
 0x1400d3068 MessageBoxIndirectA
 0x1400d3070 MoveWindow
 0x1400d3078 MsgWaitForMultipleObjects
 0x1400d3080 OffsetRect
 0x1400d3088 OpenClipboard
 0x1400d3090 PeekMessageA
 0x1400d3098 PeekMessageW
 0x1400d30a0 PostMessageA
 0x1400d30a8 PostQuitMessage
 0x1400d30b0 RegisterClassA
 0x1400d30b8 RegisterClassW
 0x1400d30c0 RegisterClipboardFormatA
 0x1400d30c8 RegisterWindowMessageA
 0x1400d30d0 ReleaseCapture
 0x1400d30d8 ReleaseDC
 0x1400d30e0 ScreenToClient
 0x1400d30e8 SendDlgItemMessageA
 0x1400d30f0 SendMessageA
 0x1400d30f8 SetActiveWindow
 0x1400d3100 SetCapture
 0x1400d3108 SetCaretPos
 0x1400d3110 SetClassLongPtrA
 0x1400d3118 SetClipboardData
 0x1400d3120 SetCursor
 0x1400d3128 SetDlgItemTextA
 0x1400d3130 SetFocus
 0x1400d3138 SetForegroundWindow
 0x1400d3140 SetKeyboardState
 0x1400d3148 SetScrollInfo
 0x1400d3150 SetTimer
 0x1400d3158 SetWindowLongPtrA
 0x1400d3160 SetWindowPlacement
 0x1400d3168 SetWindowPos
 0x1400d3170 SetWindowTextA
 0x1400d3178 ShowCaret
 0x1400d3180 ShowCursor
 0x1400d3188 ShowWindow
 0x1400d3190 SystemParametersInfoA
 0x1400d3198 ToAsciiEx
 0x1400d31a0 TrackPopupMenu
 0x1400d31a8 TranslateMessage
 0x1400d31b0 UpdateWindow
COMDLG32.dll
 0x1400d31c0 ChooseColorA
 0x1400d31c8 ChooseFontA
 0x1400d31d0 GetOpenFileNameA
 0x1400d31d8 GetSaveFileNameA
SHELL32.dll
 0x1400d31e8 ShellExecuteA
ole32.dll
 0x1400d31f8 CoCreateInstance
 0x1400d3200 CoInitialize
 0x1400d3208 CoUninitialize
IMM32.dll
 0x1400d3218 ImmGetCompositionStringW
 0x1400d3220 ImmGetContext
 0x1400d3228 ImmReleaseContext
 0x1400d3230 ImmSetCompositionFontA
 0x1400d3238 ImmSetCompositionWindow
ADVAPI32.dll
 0x1400d3248 AllocateAndInitializeSid
 0x1400d3250 CopySid
 0x1400d3258 EqualSid
 0x1400d3260 GetLengthSid
 0x1400d3268 GetUserNameA
 0x1400d3270 InitializeSecurityDescriptor
 0x1400d3278 RegCloseKey
 0x1400d3280 RegCreateKeyA
 0x1400d3288 RegCreateKeyExA
 0x1400d3290 RegDeleteKeyA
 0x1400d3298 RegDeleteValueA
 0x1400d32a0 RegEnumKeyA
 0x1400d32a8 RegOpenKeyA
 0x1400d32b0 RegQueryValueExA
 0x1400d32b8 RegSetValueExA
 0x1400d32c0 SetSecurityDescriptorDacl
 0x1400d32c8 SetSecurityDescriptorOwner
KERNEL32.dll
 0x1400d32d8 Beep
 0x1400d32e0 ClearCommBreak
 0x1400d32e8 CloseHandle
 0x1400d32f0 CompareStringW
 0x1400d32f8 ConnectNamedPipe
 0x1400d3300 CreateEventA
 0x1400d3308 CreateFileA
 0x1400d3310 CreateFileMappingA
 0x1400d3318 CreateFileW
 0x1400d3320 CreateMutexA
 0x1400d3328 CreateNamedPipeA
 0x1400d3330 CreatePipe
 0x1400d3338 CreateProcessA
 0x1400d3340 CreateThread
 0x1400d3348 DeleteCriticalSection
 0x1400d3350 DeleteFileA
 0x1400d3358 EncodePointer
 0x1400d3360 EnterCriticalSection
 0x1400d3368 ExitProcess
 0x1400d3370 FindClose
 0x1400d3378 FindFirstFileA
 0x1400d3380 FindFirstFileExW
 0x1400d3388 FindNextFileA
 0x1400d3390 FindNextFileW
 0x1400d3398 FindResourceA
 0x1400d33a0 FlushFileBuffers
 0x1400d33a8 FormatMessageA
 0x1400d33b0 FreeEnvironmentStringsW
 0x1400d33b8 FreeLibrary
 0x1400d33c0 GetACP
 0x1400d33c8 GetCPInfo
 0x1400d33d0 GetCommState
 0x1400d33d8 GetCommandLineA
 0x1400d33e0 GetCommandLineW
 0x1400d33e8 GetConsoleCP
 0x1400d33f0 GetConsoleMode
 0x1400d33f8 GetCurrentDirectoryA
 0x1400d3400 GetCurrentProcess
 0x1400d3408 GetCurrentProcessId
 0x1400d3410 GetCurrentThread
 0x1400d3418 GetCurrentThreadId
 0x1400d3420 GetDateFormatW
 0x1400d3428 GetEnvironmentStringsW
 0x1400d3430 GetEnvironmentVariableA
 0x1400d3438 GetFileAttributesExA
 0x1400d3440 GetFileType
 0x1400d3448 GetLastError
 0x1400d3450 GetLocalTime
 0x1400d3458 GetLocaleInfoA
 0x1400d3460 GetModuleFileNameA
 0x1400d3468 GetModuleFileNameW
 0x1400d3470 GetModuleHandleA
 0x1400d3478 GetModuleHandleExW
 0x1400d3480 GetModuleHandleW
 0x1400d3488 GetOEMCP
 0x1400d3490 GetOverlappedResult
 0x1400d3498 GetProcAddress
 0x1400d34a0 GetProcessHeap
 0x1400d34a8 GetProcessTimes
 0x1400d34b0 GetStartupInfoW
 0x1400d34b8 GetStdHandle
 0x1400d34c0 GetStringTypeW
 0x1400d34c8 GetSystemDirectoryA
 0x1400d34d0 GetSystemTimeAsFileTime
 0x1400d34d8 GetTempPathA
 0x1400d34e0 GetThreadTimes
 0x1400d34e8 GetTickCount
 0x1400d34f0 GetTimeFormatW
 0x1400d34f8 GetTimeZoneInformation
 0x1400d3500 GetVersionExA
 0x1400d3508 GetWindowsDirectoryA
 0x1400d3510 GlobalAlloc
 0x1400d3518 GlobalFree
 0x1400d3520 GlobalLock
 0x1400d3528 GlobalMemoryStatus
 0x1400d3530 GlobalUnlock
 0x1400d3538 HeapAlloc
 0x1400d3540 HeapFree
 0x1400d3548 HeapReAlloc
 0x1400d3550 HeapSize
 0x1400d3558 InitializeCriticalSectionAndSpinCount
 0x1400d3560 InitializeSListHead
 0x1400d3568 IsDBCSLeadByteEx
 0x1400d3570 IsDebuggerPresent
 0x1400d3578 IsProcessorFeaturePresent
 0x1400d3580 IsValidCodePage
 0x1400d3588 LCMapStringW
 0x1400d3590 LeaveCriticalSection
 0x1400d3598 LoadLibraryA
 0x1400d35a0 LoadLibraryExA
 0x1400d35a8 LoadLibraryExW
 0x1400d35b0 LoadResource
 0x1400d35b8 LocalAlloc
 0x1400d35c0 LocalFileTimeToFileTime
 0x1400d35c8 LocalFree
 0x1400d35d0 LockResource
 0x1400d35d8 MapViewOfFile
 0x1400d35e0 MulDiv
 0x1400d35e8 MultiByteToWideChar
 0x1400d35f0 OpenProcess
 0x1400d35f8 OutputDebugStringW
 0x1400d3600 QueryPerformanceCounter
 0x1400d3608 RaiseException
 0x1400d3610 ReadConsoleW
 0x1400d3618 ReadFile
 0x1400d3620 ReleaseMutex
 0x1400d3628 RtlCaptureContext
 0x1400d3630 RtlLookupFunctionEntry
 0x1400d3638 RtlPcToFileHeader
 0x1400d3640 RtlUnwindEx
 0x1400d3648 RtlVirtualUnwind
 0x1400d3650 SetCommBreak
 0x1400d3658 SetCommState
 0x1400d3660 SetCommTimeouts
 0x1400d3668 SetCurrentDirectoryA
 0x1400d3670 SetEndOfFile
 0x1400d3678 SetEnvironmentVariableW
 0x1400d3680 SetEvent
 0x1400d3688 SetFilePointerEx
 0x1400d3690 SetHandleInformation
 0x1400d3698 SetLastError
 0x1400d36a0 SetStdHandle
 0x1400d36a8 SetUnhandledExceptionFilter
 0x1400d36b0 SizeofResource
 0x1400d36b8 TerminateProcess
 0x1400d36c0 TlsAlloc
 0x1400d36c8 TlsFree
 0x1400d36d0 TlsGetValue
 0x1400d36d8 TlsSetValue
 0x1400d36e0 UnhandledExceptionFilter
 0x1400d36e8 UnmapViewOfFile
 0x1400d36f0 WaitForSingleObject
 0x1400d36f8 WaitNamedPipeA
 0x1400d3700 WideCharToMultiByte
 0x1400d3708 WriteConsoleW
 0x1400d3710 WriteFile

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure