Report - copp.exe

PWS Loki[b] Loki[m] UPX Malicious Library PE32 OS Processor Check PE File
ScreenShot
Created 2021.07.28 14:07 Machine s1_win7_x6402
Filename copp.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
5
Behavior Score
2.2
ZERO API file : malware
VT API (file)
md5 374fb48a959a96ce92ae0e4346763293
sha256 f2d2638afb528c7476c9ee8e83ddb20e686b0b05f53f2f966fd9eb962427f8aa
ssdeep 24576:1oJBu2XV04jnHW8VwBYcOa3sM6zlYzLhQ0zJ68VQWWRWqMZ:Su4jHmScOcsvWkq3Z
imphash d803cf4cabab38ad6ac8123e3c7a53dd
impfuzzy 96:oO0b11txj63OxfUv6u75tKN2Sm68eXTCdjAwhmypAhiO4uR83un:oO411txj63OxfUv6u7vJY2djO
  Network IP location

Signature (7cnts)

Level Description
watch Harvests credentials from local FTP client softwares
notice Allocates read-write-execute memory (usually to unpack itself)
notice The binary likely contains encrypted or compressed data indicative of a packer
info Checks amount of memory in system
info Checks if process is being debugged by a debugger
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The file contains an unknown PE resource name possibly indicative of a packer

Rules (6cnts)

Level Name Description Collection
danger Win32_PWS_Loki_Zero Win32 PWS Loki binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

GDI32.dll
 0x4b2cac CreateBitmap
 0x4b2cb0 CreateCompatibleBitmap
 0x4b2cb4 CreateCompatibleDC
 0x4b2cb8 CreateFontA
 0x4b2cbc CreateFontIndirectA
 0x4b2cc0 CreatePalette
 0x4b2cc4 CreatePen
 0x4b2cc8 CreateSolidBrush
 0x4b2ccc DeleteDC
 0x4b2cd0 DeleteObject
 0x4b2cd4 ExcludeClipRect
 0x4b2cd8 ExtTextOutA
 0x4b2cdc ExtTextOutW
 0x4b2ce0 GetBkMode
 0x4b2ce4 GetCharABCWidthsFloatA
 0x4b2ce8 GetCharWidth32A
 0x4b2cec GetCharWidth32W
 0x4b2cf0 GetCharWidthA
 0x4b2cf4 GetCharWidthW
 0x4b2cf8 GetCharacterPlacementW
 0x4b2cfc GetDeviceCaps
 0x4b2d00 GetObjectA
 0x4b2d04 GetPixel
 0x4b2d08 GetStockObject
 0x4b2d0c GetTextExtentExPointA
 0x4b2d10 GetTextExtentPoint32A
 0x4b2d14 GetTextMetricsA
 0x4b2d18 IntersectClipRect
 0x4b2d1c LineTo
 0x4b2d20 MoveToEx
 0x4b2d24 Polyline
 0x4b2d28 RealizePalette
 0x4b2d2c Rectangle
 0x4b2d30 SelectObject
 0x4b2d34 SelectPalette
 0x4b2d38 SetBkColor
 0x4b2d3c SetBkMode
 0x4b2d40 SetMapMode
 0x4b2d44 SetPaletteEntries
 0x4b2d48 SetPixel
 0x4b2d4c SetTextAlign
 0x4b2d50 SetTextColor
 0x4b2d54 TextOutA
 0x4b2d58 TranslateCharsetInfo
 0x4b2d5c UnrealizeObject
 0x4b2d60 UpdateColors
USER32.dll
 0x4b2d68 AppendMenuA
 0x4b2d6c BeginPaint
 0x4b2d70 CheckDlgButton
 0x4b2d74 CheckMenuItem
 0x4b2d78 CheckRadioButton
 0x4b2d7c CloseClipboard
 0x4b2d80 CreateCaret
 0x4b2d84 CreateDialogParamA
 0x4b2d88 CreateMenu
 0x4b2d8c CreatePopupMenu
 0x4b2d90 CreateWindowExA
 0x4b2d94 CreateWindowExW
 0x4b2d98 DefDlgProcA
 0x4b2d9c DefWindowProcA
 0x4b2da0 DefWindowProcW
 0x4b2da4 DeleteMenu
 0x4b2da8 DestroyCaret
 0x4b2dac DestroyIcon
 0x4b2db0 DestroyWindow
 0x4b2db4 DialogBoxParamA
 0x4b2db8 DispatchMessageA
 0x4b2dbc DispatchMessageW
 0x4b2dc0 DrawEdge
 0x4b2dc4 DrawIconEx
 0x4b2dc8 EmptyClipboard
 0x4b2dcc EnableMenuItem
 0x4b2dd0 EnableWindow
 0x4b2dd4 EndDialog
 0x4b2dd8 EndPaint
 0x4b2ddc FindWindowA
 0x4b2de0 FlashWindow
 0x4b2de4 GetCapture
 0x4b2de8 GetCaretBlinkTime
 0x4b2dec GetClientRect
 0x4b2df0 GetClipboardData
 0x4b2df4 GetClipboardOwner
 0x4b2df8 GetCursorPos
 0x4b2dfc GetDC
 0x4b2e00 GetDesktopWindow
 0x4b2e04 GetDlgItem
 0x4b2e08 GetDlgItemTextA
 0x4b2e0c GetDoubleClickTime
 0x4b2e10 GetForegroundWindow
 0x4b2e14 GetKeyboardLayout
 0x4b2e18 GetKeyboardState
 0x4b2e1c GetMessageA
 0x4b2e20 GetMessageTime
 0x4b2e24 GetParent
 0x4b2e28 GetQueueStatus
 0x4b2e2c GetScrollInfo
 0x4b2e30 GetSysColor
 0x4b2e34 GetSystemMenu
 0x4b2e38 GetSystemMetrics
 0x4b2e3c GetWindowLongA
 0x4b2e40 GetWindowPlacement
 0x4b2e44 GetWindowRect
 0x4b2e48 GetWindowTextA
 0x4b2e4c GetWindowTextLengthA
 0x4b2e50 HideCaret
 0x4b2e54 InsertMenuA
 0x4b2e58 InvalidateRect
 0x4b2e5c IsDialogMessageA
 0x4b2e60 IsDlgButtonChecked
 0x4b2e64 IsIconic
 0x4b2e68 IsWindow
 0x4b2e6c IsZoomed
 0x4b2e70 KillTimer
 0x4b2e74 LoadCursorA
 0x4b2e78 LoadIconA
 0x4b2e7c LoadImageA
 0x4b2e80 MapDialogRect
 0x4b2e84 MessageBeep
 0x4b2e88 MessageBoxA
 0x4b2e8c MessageBoxIndirectA
 0x4b2e90 MoveWindow
 0x4b2e94 MsgWaitForMultipleObjects
 0x4b2e98 OpenClipboard
 0x4b2e9c PeekMessageA
 0x4b2ea0 PeekMessageW
 0x4b2ea4 PostMessageA
 0x4b2ea8 PostQuitMessage
 0x4b2eac RegisterClassA
 0x4b2eb0 RegisterClassW
 0x4b2eb4 RegisterClipboardFormatA
 0x4b2eb8 RegisterWindowMessageA
 0x4b2ebc ReleaseCapture
 0x4b2ec0 ReleaseDC
 0x4b2ec4 ScreenToClient
 0x4b2ec8 SendDlgItemMessageA
 0x4b2ecc SendMessageA
 0x4b2ed0 SetActiveWindow
 0x4b2ed4 SetCapture
 0x4b2ed8 SetCaretPos
 0x4b2edc SetClassLongA
 0x4b2ee0 SetClipboardData
 0x4b2ee4 SetCursor
 0x4b2ee8 SetDlgItemTextA
 0x4b2eec SetFocus
 0x4b2ef0 SetForegroundWindow
 0x4b2ef4 SetKeyboardState
 0x4b2ef8 SetScrollInfo
 0x4b2efc SetTimer
 0x4b2f00 SetWindowLongA
 0x4b2f04 SetWindowPlacement
 0x4b2f08 SetWindowPos
 0x4b2f0c SetWindowTextA
 0x4b2f10 ShowCaret
 0x4b2f14 ShowCursor
 0x4b2f18 ShowWindow
 0x4b2f1c SystemParametersInfoA
 0x4b2f20 ToAsciiEx
 0x4b2f24 TrackPopupMenu
 0x4b2f28 TranslateMessage
 0x4b2f2c UpdateWindow
COMDLG32.dll
 0x4b2f34 ChooseColorA
 0x4b2f38 ChooseFontA
 0x4b2f3c GetOpenFileNameA
 0x4b2f40 GetSaveFileNameA
SHELL32.dll
 0x4b2f48 ShellExecuteA
ole32.dll
 0x4b2f50 CoCreateInstance
 0x4b2f54 CoInitialize
 0x4b2f58 CoUninitialize
IMM32.dll
 0x4b2f60 ImmGetCompositionStringW
 0x4b2f64 ImmGetContext
 0x4b2f68 ImmReleaseContext
 0x4b2f6c ImmSetCompositionFontA
 0x4b2f70 ImmSetCompositionWindow
ADVAPI32.dll
 0x4b2f78 AllocateAndInitializeSid
 0x4b2f7c CopySid
 0x4b2f80 EqualSid
 0x4b2f84 GetLengthSid
 0x4b2f88 GetUserNameA
 0x4b2f8c InitializeSecurityDescriptor
 0x4b2f90 RegCloseKey
 0x4b2f94 RegCreateKeyA
 0x4b2f98 RegCreateKeyExA
 0x4b2f9c RegDeleteKeyA
 0x4b2fa0 RegDeleteValueA
 0x4b2fa4 RegEnumKeyA
 0x4b2fa8 RegOpenKeyA
 0x4b2fac RegQueryValueExA
 0x4b2fb0 RegSetValueExA
 0x4b2fb4 SetSecurityDescriptorDacl
 0x4b2fb8 SetSecurityDescriptorOwner
KERNEL32.dll
 0x4b2fc0 Beep
 0x4b2fc4 ClearCommBreak
 0x4b2fc8 CloseHandle
 0x4b2fcc CompareStringW
 0x4b2fd0 ConnectNamedPipe
 0x4b2fd4 CreateEventA
 0x4b2fd8 CreateFileA
 0x4b2fdc CreateFileMappingA
 0x4b2fe0 CreateFileW
 0x4b2fe4 CreateMutexA
 0x4b2fe8 CreateNamedPipeA
 0x4b2fec CreatePipe
 0x4b2ff0 CreateProcessA
 0x4b2ff4 CreateThread
 0x4b2ff8 DecodePointer
 0x4b2ffc DeleteCriticalSection
 0x4b3000 DeleteFileA
 0x4b3004 EnterCriticalSection
 0x4b3008 ExitProcess
 0x4b300c FindClose
 0x4b3010 FindFirstFileA
 0x4b3014 FindFirstFileExA
 0x4b3018 FindNextFileA
 0x4b301c FindResourceA
 0x4b3020 FlushFileBuffers
 0x4b3024 FormatMessageA
 0x4b3028 FreeEnvironmentStringsW
 0x4b302c FreeLibrary
 0x4b3030 GetACP
 0x4b3034 GetCPInfo
 0x4b3038 GetCommState
 0x4b303c GetCommandLineA
 0x4b3040 GetCommandLineW
 0x4b3044 GetConsoleCP
 0x4b3048 GetConsoleMode
 0x4b304c GetCurrentDirectoryA
 0x4b3050 GetCurrentProcess
 0x4b3054 GetCurrentProcessId
 0x4b3058 GetCurrentThread
 0x4b305c GetCurrentThreadId
 0x4b3060 GetDateFormatW
 0x4b3064 GetEnvironmentStringsW
 0x4b3068 GetEnvironmentVariableA
 0x4b306c GetFileAttributesExA
 0x4b3070 GetFileType
 0x4b3074 GetLastError
 0x4b3078 GetLocalTime
 0x4b307c GetLocaleInfoA
 0x4b3080 GetModuleFileNameA
 0x4b3084 GetModuleFileNameW
 0x4b3088 GetModuleHandleA
 0x4b308c GetModuleHandleExW
 0x4b3090 GetModuleHandleW
 0x4b3094 GetOEMCP
 0x4b3098 GetOverlappedResult
 0x4b309c GetProcAddress
 0x4b30a0 GetProcessHeap
 0x4b30a4 GetProcessTimes
 0x4b30a8 GetStartupInfoW
 0x4b30ac GetStdHandle
 0x4b30b0 GetStringTypeW
 0x4b30b4 GetSystemDirectoryA
 0x4b30b8 GetSystemTimeAsFileTime
 0x4b30bc GetTempPathA
 0x4b30c0 GetThreadTimes
 0x4b30c4 GetTickCount
 0x4b30c8 GetTimeFormatW
 0x4b30cc GetTimeZoneInformation
 0x4b30d0 GetVersionExA
 0x4b30d4 GetWindowsDirectoryA
 0x4b30d8 GlobalAlloc
 0x4b30dc GlobalFree
 0x4b30e0 GlobalLock
 0x4b30e4 GlobalMemoryStatus
 0x4b30e8 GlobalUnlock
 0x4b30ec HeapAlloc
 0x4b30f0 HeapFree
 0x4b30f4 HeapReAlloc
 0x4b30f8 HeapSize
 0x4b30fc InitializeCriticalSectionAndSpinCount
 0x4b3100 InitializeSListHead
 0x4b3104 IsDBCSLeadByteEx
 0x4b3108 IsDebuggerPresent
 0x4b310c IsProcessorFeaturePresent
 0x4b3110 IsValidCodePage
 0x4b3114 LCMapStringW
 0x4b3118 LeaveCriticalSection
 0x4b311c LoadLibraryA
 0x4b3120 LoadLibraryExA
 0x4b3124 LoadLibraryExW
 0x4b3128 LoadResource
 0x4b312c LocalAlloc
 0x4b3130 LocalFileTimeToFileTime
 0x4b3134 LocalFree
 0x4b3138 LockResource
 0x4b313c MapViewOfFile
 0x4b3140 MulDiv
 0x4b3144 MultiByteToWideChar
 0x4b3148 OpenProcess
 0x4b314c OutputDebugStringW
 0x4b3150 QueryPerformanceCounter
 0x4b3154 RaiseException
 0x4b3158 ReadConsoleW
 0x4b315c ReadFile
 0x4b3160 ReleaseMutex
 0x4b3164 RtlUnwind
 0x4b3168 SetCommBreak
 0x4b316c SetCommState
 0x4b3170 SetCommTimeouts
 0x4b3174 SetCurrentDirectoryA
 0x4b3178 SetEndOfFile
 0x4b317c SetEnvironmentVariableA
 0x4b3180 SetEvent
 0x4b3184 SetFilePointerEx
 0x4b3188 SetHandleInformation
 0x4b318c SetLastError
 0x4b3190 SetStdHandle
 0x4b3194 SetUnhandledExceptionFilter
 0x4b3198 SizeofResource
 0x4b319c TerminateProcess
 0x4b31a0 TlsAlloc
 0x4b31a4 TlsFree
 0x4b31a8 TlsGetValue
 0x4b31ac TlsSetValue
 0x4b31b0 UnhandledExceptionFilter
 0x4b31b4 UnmapViewOfFile
 0x4b31b8 WaitForSingleObject
 0x4b31bc WaitForSingleObjectEx
 0x4b31c0 WaitNamedPipeA
 0x4b31c4 WideCharToMultiByte
 0x4b31c8 WriteConsoleW
 0x4b31cc WriteFile

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure