Report - MTB1056 Proforma.exe

UPX Malicious Library PE File PE32
ScreenShot
Created 2021.10.07 12:22 Machine s1_win7_x6402
Filename MTB1056 Proforma.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
2
Behavior Score
1.6
ZERO API file : clean
VT API (file) 33 detected (Scarsi, malicious, high confidence, Zusy, Artemis, Unsafe, Save, confidence, Rescoms, Eldorado, EQFQ, Remcos, MalwareX, AGEN, BadFile, Outbreak, Woreflint, score, ai score=86, Generic@ML, RDML, rimx9QxDXvHA5srCBmBBqA, EOBG, ZelphiF, YKW@a0bKWPii, RnkBend)
md5 c050088cde2c6e479d294c4eda274c78
sha256 662eecce48bec8dc6ebb8dc123713a3dfb97dc2514ddb3396d88cf855267f2bb
ssdeep 12288:LJNzf5G/0os4Hn6hgF8VCJ3fj9Ffin4uq8Sk:vhfos4Hn8dVU3fxFfin4t8Sk
imphash 384487a869f88e6d61619b7a3f81e432
impfuzzy 96:oO4fXYo3Me5c2buu27xSUvK9eesoWGXE7ZXhpuU8JS10+YdDwPOQCJ:oV3MSbuuaxSUvK9tso1XE7ZKG1Q+POQw
  Network IP location

Signature (4cnts)

Level Description
danger File has been identified by 33 AntiVirus engines on VirusTotal as malicious
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The executable uses a known packer
info The file contains an unknown PE resource name possibly indicative of a packer

Rules (4cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

oleaut32.dll
 0x46074c SysFreeString
 0x460750 SysReAllocStringLen
 0x460754 SysAllocStringLen
advapi32.dll
 0x46075c RegQueryValueExA
 0x460760 RegOpenKeyExA
 0x460764 RegCloseKey
user32.dll
 0x46076c GetKeyboardType
 0x460770 DestroyWindow
 0x460774 LoadStringA
 0x460778 MessageBoxA
 0x46077c CharNextA
kernel32.dll
 0x460784 GetACP
 0x460788 Sleep
 0x46078c VirtualFree
 0x460790 VirtualAlloc
 0x460794 GetTickCount
 0x460798 QueryPerformanceCounter
 0x46079c GetCurrentThreadId
 0x4607a0 InterlockedDecrement
 0x4607a4 InterlockedIncrement
 0x4607a8 VirtualQuery
 0x4607ac WideCharToMultiByte
 0x4607b0 MultiByteToWideChar
 0x4607b4 lstrlenA
 0x4607b8 lstrcpynA
 0x4607bc LoadLibraryExA
 0x4607c0 GetThreadLocale
 0x4607c4 GetStartupInfoA
 0x4607c8 GetProcAddress
 0x4607cc GetModuleHandleA
 0x4607d0 GetModuleFileNameA
 0x4607d4 GetLocaleInfoA
 0x4607d8 GetLastError
 0x4607dc GetCommandLineA
 0x4607e0 FreeLibrary
 0x4607e4 FindFirstFileA
 0x4607e8 FindClose
 0x4607ec ExitProcess
 0x4607f0 CompareStringA
 0x4607f4 WriteFile
 0x4607f8 UnhandledExceptionFilter
 0x4607fc SetFilePointer
 0x460800 SetEndOfFile
 0x460804 RtlUnwind
 0x460808 ReadFile
 0x46080c RaiseException
 0x460810 GetStdHandle
 0x460814 GetFileSize
 0x460818 GetFileType
 0x46081c CreateFileA
 0x460820 CloseHandle
kernel32.dll
 0x460828 TlsSetValue
 0x46082c TlsGetValue
 0x460830 LocalAlloc
 0x460834 GetModuleHandleA
user32.dll
 0x46083c CreateWindowExA
 0x460840 WindowFromPoint
 0x460844 WaitMessage
 0x460848 UpdateWindow
 0x46084c UnregisterClassA
 0x460850 UnhookWindowsHookEx
 0x460854 TranslateMessage
 0x460858 TranslateMDISysAccel
 0x46085c TrackPopupMenu
 0x460860 SystemParametersInfoA
 0x460864 ShowWindow
 0x460868 ShowScrollBar
 0x46086c ShowOwnedPopups
 0x460870 SetWindowsHookExA
 0x460874 SetWindowTextA
 0x460878 SetWindowPos
 0x46087c SetWindowPlacement
 0x460880 SetWindowLongW
 0x460884 SetWindowLongA
 0x460888 SetTimer
 0x46088c SetScrollRange
 0x460890 SetScrollPos
 0x460894 SetScrollInfo
 0x460898 SetRect
 0x46089c SetPropA
 0x4608a0 SetParent
 0x4608a4 SetMenuItemInfoA
 0x4608a8 SetMenu
 0x4608ac SetForegroundWindow
 0x4608b0 SetFocus
 0x4608b4 SetCursor
 0x4608b8 SetClassLongA
 0x4608bc SetCapture
 0x4608c0 SetActiveWindow
 0x4608c4 SendMessageW
 0x4608c8 SendMessageA
 0x4608cc ScrollWindow
 0x4608d0 ScreenToClient
 0x4608d4 RemovePropA
 0x4608d8 RemoveMenu
 0x4608dc ReleaseDC
 0x4608e0 ReleaseCapture
 0x4608e4 RegisterWindowMessageA
 0x4608e8 RegisterClipboardFormatA
 0x4608ec RegisterClassA
 0x4608f0 RedrawWindow
 0x4608f4 PtInRect
 0x4608f8 PostQuitMessage
 0x4608fc PostMessageA
 0x460900 PeekMessageW
 0x460904 PeekMessageA
 0x460908 OffsetRect
 0x46090c OemToCharA
 0x460910 MsgWaitForMultipleObjects
 0x460914 MessageBoxA
 0x460918 MapWindowPoints
 0x46091c MapVirtualKeyA
 0x460920 LoadStringA
 0x460924 LoadKeyboardLayoutA
 0x460928 LoadIconA
 0x46092c LoadCursorA
 0x460930 LoadBitmapA
 0x460934 KillTimer
 0x460938 IsZoomed
 0x46093c IsWindowVisible
 0x460940 IsWindowUnicode
 0x460944 IsWindowEnabled
 0x460948 IsWindow
 0x46094c IsRectEmpty
 0x460950 IsIconic
 0x460954 IsDialogMessageW
 0x460958 IsDialogMessageA
 0x46095c IsChild
 0x460960 InvalidateRect
 0x460964 IntersectRect
 0x460968 InsertMenuItemA
 0x46096c InsertMenuA
 0x460970 InflateRect
 0x460974 GetWindowThreadProcessId
 0x460978 GetWindowTextA
 0x46097c GetWindowRect
 0x460980 GetWindowPlacement
 0x460984 GetWindowLongW
 0x460988 GetWindowLongA
 0x46098c GetWindowDC
 0x460990 GetTopWindow
 0x460994 GetSystemMetrics
 0x460998 GetSystemMenu
 0x46099c GetSysColorBrush
 0x4609a0 GetSysColor
 0x4609a4 GetSubMenu
 0x4609a8 GetScrollRange
 0x4609ac GetScrollPos
 0x4609b0 GetScrollInfo
 0x4609b4 GetPropA
 0x4609b8 GetParent
 0x4609bc GetWindow
 0x4609c0 GetMessagePos
 0x4609c4 GetMenuStringA
 0x4609c8 GetMenuState
 0x4609cc GetMenuItemInfoA
 0x4609d0 GetMenuItemID
 0x4609d4 GetMenuItemCount
 0x4609d8 GetMenu
 0x4609dc GetLastActivePopup
 0x4609e0 GetKeyboardState
 0x4609e4 GetKeyboardLayoutNameA
 0x4609e8 GetKeyboardLayoutList
 0x4609ec GetKeyboardLayout
 0x4609f0 GetKeyState
 0x4609f4 GetKeyNameTextA
 0x4609f8 GetIconInfo
 0x4609fc GetForegroundWindow
 0x460a00 GetFocus
 0x460a04 GetDesktopWindow
 0x460a08 GetDCEx
 0x460a0c GetDC
 0x460a10 GetCursorPos
 0x460a14 GetCursor
 0x460a18 GetClientRect
 0x460a1c GetClassLongA
 0x460a20 GetClassInfoA
 0x460a24 GetCapture
 0x460a28 GetActiveWindow
 0x460a2c FrameRect
 0x460a30 FindWindowA
 0x460a34 FillRect
 0x460a38 EqualRect
 0x460a3c EnumWindows
 0x460a40 EnumThreadWindows
 0x460a44 EnumChildWindows
 0x460a48 EndPaint
 0x460a4c EnableWindow
 0x460a50 EnableScrollBar
 0x460a54 EnableMenuItem
 0x460a58 DrawTextA
 0x460a5c DrawMenuBar
 0x460a60 DrawIconEx
 0x460a64 DrawIcon
 0x460a68 DrawFrameControl
 0x460a6c DrawEdge
 0x460a70 DispatchMessageW
 0x460a74 DispatchMessageA
 0x460a78 DestroyWindow
 0x460a7c DestroyMenu
 0x460a80 DestroyIcon
 0x460a84 DestroyCursor
 0x460a88 DeleteMenu
 0x460a8c DefWindowProcA
 0x460a90 DefMDIChildProcA
 0x460a94 DefFrameProcA
 0x460a98 CreatePopupMenu
 0x460a9c CreateMenu
 0x460aa0 CreateIcon
 0x460aa4 ClientToScreen
 0x460aa8 CheckMenuItem
 0x460aac CallWindowProcA
 0x460ab0 CallNextHookEx
 0x460ab4 BeginPaint
 0x460ab8 CharNextA
 0x460abc CharLowerA
 0x460ac0 CharToOemA
 0x460ac4 AdjustWindowRectEx
 0x460ac8 ActivateKeyboardLayout
gdi32.dll
 0x460ad0 UnrealizeObject
 0x460ad4 StretchBlt
 0x460ad8 SetWindowOrgEx
 0x460adc SetViewportOrgEx
 0x460ae0 SetTextColor
 0x460ae4 SetStretchBltMode
 0x460ae8 SetROP2
 0x460aec SetPixel
 0x460af0 SetDIBColorTable
 0x460af4 SetBrushOrgEx
 0x460af8 SetBkMode
 0x460afc SetBkColor
 0x460b00 SelectPalette
 0x460b04 SelectObject
 0x460b08 SelectClipRgn
 0x460b0c SaveDC
 0x460b10 RestoreDC
 0x460b14 RectVisible
 0x460b18 RealizePalette
 0x460b1c PatBlt
 0x460b20 MoveToEx
 0x460b24 MaskBlt
 0x460b28 LineTo
 0x460b2c IntersectClipRect
 0x460b30 GetWindowOrgEx
 0x460b34 GetTextMetricsA
 0x460b38 GetTextExtentPoint32A
 0x460b3c GetSystemPaletteEntries
 0x460b40 GetStockObject
 0x460b44 GetRgnBox
 0x460b48 GetPixelFormat
 0x460b4c GetPixel
 0x460b50 GetPaletteEntries
 0x460b54 GetObjectA
 0x460b58 GetGraphicsMode
 0x460b5c GetDeviceCaps
 0x460b60 GetDIBits
 0x460b64 GetDIBColorTable
 0x460b68 GetDCOrgEx
 0x460b6c GetDCPenColor
 0x460b70 GetDCBrushColor
 0x460b74 GetCurrentPositionEx
 0x460b78 GetClipBox
 0x460b7c GetBrushOrgEx
 0x460b80 GetBkMode
 0x460b84 GetBitmapBits
 0x460b88 ExcludeClipRect
 0x460b8c DeleteObject
 0x460b90 DeleteDC
 0x460b94 CreateSolidBrush
 0x460b98 CreatePenIndirect
 0x460b9c CreatePalette
 0x460ba0 CreateHalftonePalette
 0x460ba4 CreateFontIndirectA
 0x460ba8 CreateDIBitmap
 0x460bac CreateDIBSection
 0x460bb0 CreateCompatibleDC
 0x460bb4 CreateCompatibleBitmap
 0x460bb8 CreateBrushIndirect
 0x460bbc CreateBitmap
 0x460bc0 BitBlt
version.dll
 0x460bc8 VerQueryValueA
 0x460bcc GetFileVersionInfoSizeA
 0x460bd0 GetFileVersionInfoA
kernel32.dll
 0x460bd8 lstrcpyA
 0x460bdc WriteFile
 0x460be0 WaitForSingleObject
 0x460be4 VirtualQuery
 0x460be8 VirtualProtect
 0x460bec VirtualAlloc
 0x460bf0 SizeofResource
 0x460bf4 SetThreadLocale
 0x460bf8 SetFilePointer
 0x460bfc SetEvent
 0x460c00 SetErrorMode
 0x460c04 SetEndOfFile
 0x460c08 ResetEvent
 0x460c0c ReadFile
 0x460c10 MulDiv
 0x460c14 LockResource
 0x460c18 LoadResource
 0x460c1c LoadLibraryA
 0x460c20 LeaveCriticalSection
 0x460c24 InitializeCriticalSection
 0x460c28 GlobalFindAtomA
 0x460c2c GlobalDeleteAtom
 0x460c30 GlobalAddAtomA
 0x460c34 GetVersionExA
 0x460c38 GetVersion
 0x460c3c GetTickCount
 0x460c40 GetThreadLocale
 0x460c44 GetStdHandle
 0x460c48 GetProcAddress
 0x460c4c GetModuleHandleA
 0x460c50 GetModuleFileNameA
 0x460c54 GetLocaleInfoA
 0x460c58 GetLocalTime
 0x460c5c GetLastError
 0x460c60 GetFullPathNameA
 0x460c64 GetFileAttributesA
 0x460c68 GetDiskFreeSpaceA
 0x460c6c GetDateFormatA
 0x460c70 GetCurrentThreadId
 0x460c74 GetCurrentProcessId
 0x460c78 GetCPInfo
 0x460c7c FreeResource
 0x460c80 InterlockedExchange
 0x460c84 FreeLibrary
 0x460c88 FormatMessageA
 0x460c8c FindResourceA
 0x460c90 EnumCalendarInfoA
 0x460c94 EnterCriticalSection
 0x460c98 DeleteCriticalSection
 0x460c9c CreateThread
 0x460ca0 CreateFileA
 0x460ca4 CreateEventA
 0x460ca8 CompareStringA
 0x460cac CloseHandle
advapi32.dll
 0x460cb4 RegQueryValueExA
 0x460cb8 RegOpenKeyExA
 0x460cbc RegFlushKey
 0x460cc0 RegCloseKey
kernel32.dll
 0x460cc8 Sleep
oleaut32.dll
 0x460cd0 SafeArrayPtrOfIndex
 0x460cd4 SafeArrayGetUBound
 0x460cd8 SafeArrayGetLBound
 0x460cdc SafeArrayCreate
 0x460ce0 VariantChangeType
 0x460ce4 VariantCopy
 0x460ce8 VariantClear
 0x460cec VariantInit
comctl32.dll
 0x460cf4 _TrackMouseEvent
 0x460cf8 ImageList_SetIconSize
 0x460cfc ImageList_GetIconSize
 0x460d00 ImageList_Write
 0x460d04 ImageList_Read
 0x460d08 ImageList_DragShowNolock
 0x460d0c ImageList_DragMove
 0x460d10 ImageList_DragLeave
 0x460d14 ImageList_DragEnter
 0x460d18 ImageList_EndDrag
 0x460d1c ImageList_BeginDrag
 0x460d20 ImageList_Remove
 0x460d24 ImageList_DrawEx
 0x460d28 ImageList_Draw
 0x460d2c ImageList_GetBkColor
 0x460d30 ImageList_SetBkColor
 0x460d34 ImageList_Add
 0x460d38 ImageList_GetImageCount
 0x460d3c ImageList_Destroy
 0x460d40 ImageList_Create
Amsi
 0x460d48 AmsiOpenSession
URL
 0x460d50 InetIsOffline

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure