Report - sepcon.exe

UPX Malicious Library PE File PE32
ScreenShot
Created 2021.09.17 10:07 Machine s1_win7_x6402
Filename sepcon.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
6
Behavior Score
3.2
ZERO API file : malware
VT API (file) 42 detected (AIDetect, malware2, BestaFera, malicious, high confidence, Remcos, FMYX, Unsafe, TrojanBanker, ZelphiF, XGW@ayAvTvci, Delf, Eldorado, Attribute, HighConfidence, Fareit, FDBI, Static AI, Suspicious PE, score, ai score=88, Generic@ML, RDML, L8MonyRrYqmibrbhxdZXDg, GenKryptik, EKLE, GdSda)
md5 8b932daa6b317c6baef47bf2a2646e38
sha256 570cdd6d574979da5f8f63d5469a03fb0ec1ca4e59e02a51839ddec78353a90a
ssdeep 24576:W0WE0AyOVWoKcwdZ2GIZHrIzvlZwXI7Dyj3SaH+MJu:W0WEoQhudZx
imphash 91f41270d021c09d2e59583bf5cdff98
impfuzzy 192:334nk1QDDQbuuArSUvK9RqoaqyKeSPOQXi:33d1bAA9LzPOQy
  Network IP location

Signature (8cnts)

Level Description
danger File has been identified by 42 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
notice Performs some HTTP requests
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The executable uses a known packer
info The file contains an unknown PE resource name possibly indicative of a packer

Rules (4cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (3cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
https://cdn.discordapp.com/attachments/856925952004063242/887741718500368394/Wqoqmxwsxttksdzrkzpmhvyndcocgqt Unknown 162.159.133.233 clean
cdn.discordapp.com Unknown 162.159.129.233 malware
162.159.133.233 Unknown 162.159.133.233 malware

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x465154 DeleteCriticalSection
 0x465158 LeaveCriticalSection
 0x46515c EnterCriticalSection
 0x465160 InitializeCriticalSection
 0x465164 VirtualFree
 0x465168 VirtualAlloc
 0x46516c LocalFree
 0x465170 LocalAlloc
 0x465174 GetTickCount
 0x465178 QueryPerformanceCounter
 0x46517c GetVersion
 0x465180 GetCurrentThreadId
 0x465184 InterlockedDecrement
 0x465188 InterlockedIncrement
 0x46518c VirtualQuery
 0x465190 WideCharToMultiByte
 0x465194 MultiByteToWideChar
 0x465198 lstrlenA
 0x46519c lstrcpynA
 0x4651a0 LoadLibraryExA
 0x4651a4 GetThreadLocale
 0x4651a8 GetStartupInfoA
 0x4651ac GetProcAddress
 0x4651b0 GetModuleHandleA
 0x4651b4 GetModuleFileNameA
 0x4651b8 GetLocaleInfoA
 0x4651bc GetLastError
 0x4651c0 GetCommandLineA
 0x4651c4 FreeLibrary
 0x4651c8 FindFirstFileA
 0x4651cc FindClose
 0x4651d0 ExitProcess
 0x4651d4 WriteFile
 0x4651d8 UnhandledExceptionFilter
 0x4651dc SetFilePointer
 0x4651e0 SetEndOfFile
 0x4651e4 RtlUnwind
 0x4651e8 ReadFile
 0x4651ec RaiseException
 0x4651f0 GetStdHandle
 0x4651f4 GetFileSize
 0x4651f8 GetFileType
 0x4651fc CreateFileA
 0x465200 CloseHandle
user32.dll
 0x465208 GetKeyboardType
 0x46520c LoadStringA
 0x465210 MessageBoxA
 0x465214 CharNextA
advapi32.dll
 0x46521c RegQueryValueExA
 0x465220 RegOpenKeyExA
 0x465224 RegCloseKey
oleaut32.dll
 0x46522c SysFreeString
 0x465230 SysReAllocStringLen
 0x465234 SysAllocStringLen
kernel32.dll
 0x46523c TlsSetValue
 0x465240 TlsGetValue
 0x465244 LocalAlloc
 0x465248 GetModuleHandleA
advapi32.dll
 0x465250 RegQueryValueExA
 0x465254 RegOpenKeyExA
 0x465258 RegCloseKey
kernel32.dll
 0x465260 lstrcpyA
 0x465264 lstrcmpiA
 0x465268 WriteFile
 0x46526c WaitForSingleObject
 0x465270 VirtualQuery
 0x465274 VirtualProtect
 0x465278 VirtualAlloc
 0x46527c Sleep
 0x465280 SizeofResource
 0x465284 SetThreadLocale
 0x465288 SetFilePointer
 0x46528c SetEvent
 0x465290 SetErrorMode
 0x465294 SetEndOfFile
 0x465298 ResetEvent
 0x46529c ReadFile
 0x4652a0 MultiByteToWideChar
 0x4652a4 MulDiv
 0x4652a8 LockResource
 0x4652ac LoadResource
 0x4652b0 LoadLibraryA
 0x4652b4 LeaveCriticalSection
 0x4652b8 InitializeCriticalSection
 0x4652bc GlobalUnlock
 0x4652c0 GlobalSize
 0x4652c4 GlobalReAlloc
 0x4652c8 GlobalHandle
 0x4652cc GlobalLock
 0x4652d0 GlobalFree
 0x4652d4 GlobalFindAtomA
 0x4652d8 GlobalDeleteAtom
 0x4652dc GlobalAlloc
 0x4652e0 GlobalAddAtomA
 0x4652e4 GetVersionExA
 0x4652e8 GetVersion
 0x4652ec GetUserDefaultLCID
 0x4652f0 GetTickCount
 0x4652f4 GetThreadLocale
 0x4652f8 GetSystemInfo
 0x4652fc GetStringTypeExA
 0x465300 GetStdHandle
 0x465304 GetProcAddress
 0x465308 GetModuleHandleA
 0x46530c GetModuleFileNameA
 0x465310 GetLocaleInfoA
 0x465314 GetLocalTime
 0x465318 GetLastError
 0x46531c GetFullPathNameA
 0x465320 GetDiskFreeSpaceA
 0x465324 GetDateFormatA
 0x465328 GetCurrentThreadId
 0x46532c GetCurrentProcessId
 0x465330 GetCPInfo
 0x465334 GetACP
 0x465338 FreeResource
 0x46533c InterlockedExchange
 0x465340 FreeLibrary
 0x465344 FormatMessageA
 0x465348 FindResourceA
 0x46534c EnumCalendarInfoA
 0x465350 EnterCriticalSection
 0x465354 DeleteCriticalSection
 0x465358 CreateThread
 0x46535c CreateFileA
 0x465360 CreateEventA
 0x465364 CompareStringA
 0x465368 CloseHandle
version.dll
 0x465370 VerQueryValueA
 0x465374 GetFileVersionInfoSizeA
 0x465378 GetFileVersionInfoA
gdi32.dll
 0x465380 UnrealizeObject
 0x465384 StretchBlt
 0x465388 SetWindowOrgEx
 0x46538c SetWinMetaFileBits
 0x465390 SetViewportOrgEx
 0x465394 SetTextColor
 0x465398 SetStretchBltMode
 0x46539c SetROP2
 0x4653a0 SetPixel
 0x4653a4 SetEnhMetaFileBits
 0x4653a8 SetDIBColorTable
 0x4653ac SetBrushOrgEx
 0x4653b0 SetBkMode
 0x4653b4 SetBkColor
 0x4653b8 SelectPalette
 0x4653bc SelectObject
 0x4653c0 SaveDC
 0x4653c4 RestoreDC
 0x4653c8 RectVisible
 0x4653cc RealizePalette
 0x4653d0 PlayEnhMetaFile
 0x4653d4 PatBlt
 0x4653d8 MoveToEx
 0x4653dc MaskBlt
 0x4653e0 LineTo
 0x4653e4 IntersectClipRect
 0x4653e8 GetWindowOrgEx
 0x4653ec GetWinMetaFileBits
 0x4653f0 GetTextMetricsA
 0x4653f4 GetTextExtentPoint32A
 0x4653f8 GetSystemPaletteEntries
 0x4653fc GetStockObject
 0x465400 GetPixel
 0x465404 GetPaletteEntries
 0x465408 GetObjectA
 0x46540c GetMapMode
 0x465410 GetGraphicsMode
 0x465414 GetEnhMetaFilePaletteEntries
 0x465418 GetEnhMetaFileHeader
 0x46541c GetEnhMetaFileDescriptionA
 0x465420 GetEnhMetaFileBits
 0x465424 GetDeviceCaps
 0x465428 GetDIBits
 0x46542c GetDIBColorTable
 0x465430 GetDCOrgEx
 0x465434 GetDCPenColor
 0x465438 GetCurrentPositionEx
 0x46543c GetClipBox
 0x465440 GetBrushOrgEx
 0x465444 GetBkColor
 0x465448 GetBitmapBits
 0x46544c ExtTextOutA
 0x465450 ExcludeClipRect
 0x465454 DeleteObject
 0x465458 DeleteEnhMetaFile
 0x46545c DeleteDC
 0x465460 CreateSolidBrush
 0x465464 CreatePenIndirect
 0x465468 CreatePalette
 0x46546c CreateHalftonePalette
 0x465470 CreateFontIndirectA
 0x465474 CreateEnhMetaFileA
 0x465478 CreateDIBitmap
 0x46547c CreateDIBSection
 0x465480 CreateCompatibleDC
 0x465484 CreateCompatibleBitmap
 0x465488 CreateBrushIndirect
 0x46548c CreateBitmap
 0x465490 CopyEnhMetaFileA
 0x465494 CloseEnhMetaFile
 0x465498 BitBlt
user32.dll
 0x4654a0 CreateWindowExA
 0x4654a4 WindowFromPoint
 0x4654a8 WinHelpA
 0x4654ac WaitMessage
 0x4654b0 UpdateWindow
 0x4654b4 UnregisterClassA
 0x4654b8 UnhookWindowsHookEx
 0x4654bc TranslateMessage
 0x4654c0 TranslateMDISysAccel
 0x4654c4 TrackPopupMenu
 0x4654c8 SystemParametersInfoA
 0x4654cc ShowWindow
 0x4654d0 ShowScrollBar
 0x4654d4 ShowOwnedPopups
 0x4654d8 ShowCursor
 0x4654dc SetWindowsHookExA
 0x4654e0 SetWindowTextA
 0x4654e4 SetWindowPos
 0x4654e8 SetWindowPlacement
 0x4654ec SetWindowLongA
 0x4654f0 SetTimer
 0x4654f4 SetScrollRange
 0x4654f8 SetScrollPos
 0x4654fc SetScrollInfo
 0x465500 SetRect
 0x465504 SetPropA
 0x465508 SetParent
 0x46550c SetMenuItemInfoA
 0x465510 SetMenu
 0x465514 SetForegroundWindow
 0x465518 SetFocus
 0x46551c SetCursor
 0x465520 SetClassLongA
 0x465524 SetCapture
 0x465528 SetActiveWindow
 0x46552c SendMessageA
 0x465530 ScrollWindow
 0x465534 ScreenToClient
 0x465538 RemovePropA
 0x46553c RemoveMenu
 0x465540 ReleaseDC
 0x465544 ReleaseCapture
 0x465548 RegisterWindowMessageA
 0x46554c RegisterClipboardFormatA
 0x465550 RegisterClassA
 0x465554 RedrawWindow
 0x465558 PtInRect
 0x46555c PostQuitMessage
 0x465560 PostMessageA
 0x465564 PeekMessageA
 0x465568 OffsetRect
 0x46556c OemToCharA
 0x465570 MessageBoxA
 0x465574 MapWindowPoints
 0x465578 MapVirtualKeyA
 0x46557c LoadStringA
 0x465580 LoadKeyboardLayoutA
 0x465584 LoadIconA
 0x465588 LoadCursorA
 0x46558c LoadBitmapA
 0x465590 KillTimer
 0x465594 IsZoomed
 0x465598 IsWindowVisible
 0x46559c IsWindowEnabled
 0x4655a0 IsWindow
 0x4655a4 IsRectEmpty
 0x4655a8 IsIconic
 0x4655ac IsDialogMessageA
 0x4655b0 IsChild
 0x4655b4 InvalidateRect
 0x4655b8 IntersectRect
 0x4655bc InsertMenuItemA
 0x4655c0 InsertMenuA
 0x4655c4 InflateRect
 0x4655c8 GetWindowThreadProcessId
 0x4655cc GetWindowTextA
 0x4655d0 GetWindowRect
 0x4655d4 GetWindowPlacement
 0x4655d8 GetWindowLongA
 0x4655dc GetWindowDC
 0x4655e0 GetTopWindow
 0x4655e4 GetSystemMetrics
 0x4655e8 GetSystemMenu
 0x4655ec GetSysColorBrush
 0x4655f0 GetSysColor
 0x4655f4 GetSubMenu
 0x4655f8 GetScrollRange
 0x4655fc GetScrollPos
 0x465600 GetScrollInfo
 0x465604 GetPropA
 0x465608 GetParent
 0x46560c GetWindow
 0x465610 GetMessageTime
 0x465614 GetMenuStringA
 0x465618 GetMenuState
 0x46561c GetMenuItemInfoA
 0x465620 GetMenuItemID
 0x465624 GetMenuItemCount
 0x465628 GetMenu
 0x46562c GetLastActivePopup
 0x465630 GetKeyboardState
 0x465634 GetKeyboardLayoutList
 0x465638 GetKeyboardLayout
 0x46563c GetKeyState
 0x465640 GetKeyNameTextA
 0x465644 GetIconInfo
 0x465648 GetForegroundWindow
 0x46564c GetFocus
 0x465650 GetDlgItem
 0x465654 GetDesktopWindow
 0x465658 GetDCEx
 0x46565c GetDC
 0x465660 GetCursorPos
 0x465664 GetCursor
 0x465668 GetClipboardData
 0x46566c GetClientRect
 0x465670 GetClassNameA
 0x465674 GetClassInfoA
 0x465678 GetCapture
 0x46567c GetActiveWindow
 0x465680 FrameRect
 0x465684 FindWindowA
 0x465688 FillRect
 0x46568c EqualRect
 0x465690 EnumWindows
 0x465694 EnumThreadWindows
 0x465698 EndPaint
 0x46569c EnableWindow
 0x4656a0 EnableScrollBar
 0x4656a4 EnableMenuItem
 0x4656a8 DrawTextA
 0x4656ac DrawMenuBar
 0x4656b0 DrawIconEx
 0x4656b4 DrawIcon
 0x4656b8 DrawFrameControl
 0x4656bc DrawFocusRect
 0x4656c0 DrawEdge
 0x4656c4 DispatchMessageA
 0x4656c8 DestroyWindow
 0x4656cc DestroyMenu
 0x4656d0 DestroyIcon
 0x4656d4 DestroyCursor
 0x4656d8 DeleteMenu
 0x4656dc DefWindowProcA
 0x4656e0 DefMDIChildProcA
 0x4656e4 DefFrameProcA
 0x4656e8 CreatePopupMenu
 0x4656ec CreateMenu
 0x4656f0 CreateIcon
 0x4656f4 ClientToScreen
 0x4656f8 CheckMenuItem
 0x4656fc CallWindowProcA
 0x465700 CallNextHookEx
 0x465704 BeginPaint
 0x465708 CharNextA
 0x46570c CharLowerBuffA
 0x465710 CharLowerA
 0x465714 CharToOemA
 0x465718 AdjustWindowRectEx
 0x46571c ActivateKeyboardLayout
kernel32.dll
 0x465724 Sleep
oleaut32.dll
 0x46572c SafeArrayPtrOfIndex
 0x465730 SafeArrayGetUBound
 0x465734 SafeArrayGetLBound
 0x465738 SafeArrayCreate
 0x46573c VariantChangeType
 0x465740 VariantCopy
 0x465744 VariantClear
 0x465748 VariantInit
ole32.dll
 0x465750 CreateStreamOnHGlobal
 0x465754 IsAccelerator
 0x465758 OleDraw
 0x46575c OleSetMenuDescriptor
 0x465760 CoCreateInstance
 0x465764 CoGetClassObject
 0x465768 CoUninitialize
 0x46576c CoInitialize
 0x465770 IsEqualGUID
oleaut32.dll
 0x465778 GetErrorInfo
 0x46577c SysFreeString
comctl32.dll
 0x465784 ImageList_SetIconSize
 0x465788 ImageList_GetIconSize
 0x46578c ImageList_Write
 0x465790 ImageList_Read
 0x465794 ImageList_GetDragImage
 0x465798 ImageList_DragShowNolock
 0x46579c ImageList_SetDragCursorImage
 0x4657a0 ImageList_DragMove
 0x4657a4 ImageList_DragLeave
 0x4657a8 ImageList_DragEnter
 0x4657ac ImageList_EndDrag
 0x4657b0 ImageList_BeginDrag
 0x4657b4 ImageList_Remove
 0x4657b8 ImageList_DrawEx
 0x4657bc ImageList_Draw
 0x4657c0 ImageList_GetBkColor
 0x4657c4 ImageList_SetBkColor
 0x4657c8 ImageList_ReplaceIcon
 0x4657cc ImageList_Add
 0x4657d0 ImageList_SetImageCount
 0x4657d4 ImageList_GetImageCount
 0x4657d8 ImageList_Destroy
 0x4657dc ImageList_Create
 0x4657e0 InitCommonControls
comdlg32.dll
 0x4657e8 GetOpenFileNameA

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure