Report - cust9.exe

Gen2 Gen1 ASPack Malicious Packer Malicious Library UPX PE64 PE File
ScreenShot
Created 2021.10.18 09:45 Machine s1_win7_x6401
Filename cust9.exe
Type PE32+ executable (GUI) x86-64, for MS Windows
AI Score
3
Behavior Score
2.0
ZERO API file : malware
VT API (file) 41 detected (Upatre, malicious, high confidence, Mikey, GenericRXAA, Unsafe, izhj, confidence, 100%, Eldorado, 0NA103JH21, Minerva, xjudi, ai score=100, kcloud, Phonzy, score, PasswordStealer, Hsiv, susgen)
md5 22f5d12116ee1c11f3173f977bafc744
sha256 fd4d1fc83330c5cf818e557ef882ca147ba98fee4128fe00bda07c6c2f79050a
ssdeep 12288:Tx1vJopzeLkTqhqeEmC7sOSafaei7fqBHf:3CzIkTgqeEVsOffasF
imphash 045715ac29c84a0e47dab339e337bc06
impfuzzy 192:wmAC25QJ2YMNnplhvre0Fs9eDVZUxIXspc4eFH26Kd3:wFQcBXlNv5DgxIXspc4eFH26Kd3
  Network IP location

Signature (4cnts)

Level Description
danger File has been identified by 41 AntiVirus engines on VirusTotal as malicious
notice The binary likely contains encrypted or compressed data indicative of a packer
info The file contains an unknown PE resource name possibly indicative of a packer
info This executable has a PDB path

Rules (8cnts)

Level Name Description Collection
danger Win32_Trojan_Gen_1_0904B0_Zero Win32 Trojan Emotet binaries (upload)
watch ASPack_Zero ASPack packed file binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch Malicious_Packer_Zero Malicious Packer binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE64 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)
info Win32_Trojan_Gen_2_0904B0_Zero Win32 Trojan Gen binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

SHELL32.dll
 0x140083000 None
 0x140083008 ShellAboutW
 0x140083010 SHGetSpecialFolderPathW
SHLWAPI.dll
 0x140083020 None
gdiplus.dll
 0x140083030 GdipGetImageGraphicsContext
 0x140083038 GdipDeleteGraphics
 0x140083040 GdipSetInterpolationMode
 0x140083048 GdipSetSmoothingMode
 0x140083050 GdipSetPageUnit
 0x140083058 GdipDrawLineI
 0x140083060 GdipDrawArcI
 0x140083068 GdipFillRectangleI
 0x140083070 GdipCloneImage
 0x140083078 GdipCreateBitmapFromScan0
 0x140083080 GdipDeletePen
 0x140083088 GdipCreateFromHDC
 0x140083090 GdipDrawImageRectI
 0x140083098 GdipCreateBitmapFromHBITMAP
 0x1400830a0 GdipCloneBitmapAreaI
 0x1400830a8 GdipCreatePen1
 0x1400830b0 GdipDisposeImage
 0x1400830b8 GdipDeleteBrush
 0x1400830c0 GdipAlloc
 0x1400830c8 GdipFree
 0x1400830d0 GdiplusShutdown
 0x1400830d8 GdiplusStartup
 0x1400830e0 GdipCreateHBITMAPFromBitmap
 0x1400830e8 GdipCreateSolidFill
ADVAPI32.dll
 0x1400830f8 RegEnumKeyExW
 0x140083100 RegOpenKeyExW
 0x140083108 RegEnumValueW
 0x140083110 RegGetValueW
 0x140083118 RegDeleteKeyW
 0x140083120 RegQueryInfoKeyW
 0x140083128 RegQueryValueExW
 0x140083130 RegSetValueExW
 0x140083138 EventUnregister
 0x140083140 EventRegister
 0x140083148 RegCloseKey
 0x140083150 RegCreateKeyExW
 0x140083158 EventWrite
OLEAUT32.dll
 0x140083168 SysStringLen
 0x140083170 SysAllocStringByteLen
 0x140083178 VariantClear
 0x140083180 VariantInit
 0x140083188 SysFreeString
 0x140083190 SysAllocString
UxTheme.dll
 0x1400831a0 IsThemeActive
ole32.dll
 0x1400831b0 CoUninitialize
 0x1400831b8 CoInitialize
 0x1400831c0 CoCreateInstance
COMCTL32.dll
 0x1400831d0 ImageList_Destroy
 0x1400831d8 ImageList_Create
 0x1400831e0 ImageList_Add
 0x1400831e8 None
 0x1400831f0 None
 0x1400831f8 None
 0x140083200 None
ntdll.dll
 0x140083210 WinSqmAddToStreamEx
 0x140083218 WinSqmAddToStream
KERNEL32.dll
 0x140083228 SetUnhandledExceptionFilter
 0x140083230 UnhandledExceptionFilter
 0x140083238 OutputDebugStringA
 0x140083240 RtlVirtualUnwind
 0x140083248 RtlLookupFunctionEntry
 0x140083250 RtlCaptureContext
 0x140083258 GetStartupInfoW
 0x140083260 GetCurrentProcess
 0x140083268 TerminateProcess
 0x140083270 QueryPerformanceCounter
 0x140083278 GetCurrentProcessId
 0x140083280 GetCurrentThreadId
 0x140083288 GetSystemTimeAsFileTime
 0x140083290 GetTickCount
 0x140083298 lstrlenA
 0x1400832a0 GetModuleHandleW
 0x1400832a8 SizeofResource
 0x1400832b0 LockResource
 0x1400832b8 LoadResource
 0x1400832c0 GetModuleFileNameW
 0x1400832c8 GetSystemTime
 0x1400832d0 WaitForSingleObject
 0x1400832d8 CreateEventW
 0x1400832e0 CreateThread
 0x1400832e8 ResetEvent
 0x1400832f0 SetEvent
 0x1400832f8 CloseHandle
 0x140083300 GlobalSize
 0x140083308 GlobalLock
 0x140083310 GlobalUnlock
 0x140083318 GlobalAlloc
 0x140083320 lstrcmpW
 0x140083328 MulDiv
 0x140083330 GlobalFindAtomW
 0x140083338 FindResourceW
 0x140083340 GetLastError
 0x140083348 MultiByteToWideChar
 0x140083350 GetLocalTime
 0x140083358 GetDateFormatW
 0x140083360 GetLocaleInfoW
 0x140083368 WritePrivateProfileStringW
 0x140083370 GetPrivateProfileStringW
 0x140083378 lstrcmpiW
 0x140083380 LoadLibraryW
 0x140083388 GetProcAddress
 0x140083390 GetLocaleInfoEx
 0x140083398 FreeLibrary
 0x1400833a0 LocalFree
 0x1400833a8 LocalAlloc
 0x1400833b0 LocalReAlloc
 0x1400833b8 GetProfileStringW
 0x1400833c0 lstrlenW
 0x1400833c8 CompareStringW
 0x1400833d0 RegisterApplicationRecoveryCallback
 0x1400833d8 ApplicationRecoveryInProgress
 0x1400833e0 Sleep
 0x1400833e8 ApplicationRecoveryFinished
 0x1400833f0 RegisterApplicationRestart
 0x1400833f8 GetTempFileNameW
 0x140083400 SystemTimeToFileTime
 0x140083408 CompareFileTime
 0x140083410 GetFileAttributesW
 0x140083418 FileTimeToSystemTime
 0x140083420 CreateFileW
 0x140083428 DeleteFileW
 0x140083430 LeaveCriticalSection
 0x140083438 DeleteCriticalSection
 0x140083440 SetLastError
 0x140083448 GetModuleHandleExW
 0x140083450 EnterCriticalSection
 0x140083458 InitializeCriticalSection
 0x140083460 RaiseException
 0x140083468 GetProcessHeap
 0x140083470 HeapSize
 0x140083478 HeapFree
 0x140083480 DelayLoadFailureHook
 0x140083488 ResolveDelayLoadedAPI
 0x140083490 HeapReAlloc
 0x140083498 HeapAlloc
 0x1400834a0 WideCharToMultiByte
 0x1400834a8 FindResourceExW
 0x1400834b0 HeapDestroy
USER32.dll
 0x1400834c0 OpenClipboard
 0x1400834c8 GetClipboardData
 0x1400834d0 InvalidateRect
 0x1400834d8 CloseClipboard
 0x1400834e0 EmptyClipboard
 0x1400834e8 SetClipboardData
 0x1400834f0 PostQuitMessage
 0x1400834f8 DefWindowProcW
 0x140083500 LoadAcceleratorsW
 0x140083508 InsertMenuItemW
 0x140083510 RegisterClassExW
 0x140083518 SetWindowPlacement
 0x140083520 SetForegroundWindow
 0x140083528 GetMessageW
 0x140083530 TranslateAcceleratorW
 0x140083538 GetMessageExtraInfo
 0x140083540 TranslateMessage
 0x140083548 DispatchMessageW
 0x140083550 GetKeyState
 0x140083558 IsDialogMessageW
 0x140083560 GetClassNameW
 0x140083568 GetDC
 0x140083570 ReleaseDC
 0x140083578 GetSystemMetrics
 0x140083580 GetWindowLongW
 0x140083588 EnumChildWindows
 0x140083590 DrawTextW
 0x140083598 SetPropW
 0x1400835a0 SystemParametersInfoW
 0x1400835a8 CheckRadioButton
 0x1400835b0 UpdateWindow
 0x1400835b8 SendDlgItemMessageW
 0x1400835c0 IsDlgButtonChecked
 0x1400835c8 MoveWindow
 0x1400835d0 SetDlgItemInt
 0x1400835d8 GetDlgItemInt
 0x1400835e0 FillRect
 0x1400835e8 GetNextDlgTabItem
 0x1400835f0 MonitorFromWindow
 0x1400835f8 GetMonitorInfoW
 0x140083600 OffsetRect
 0x140083608 EqualRect
 0x140083610 MonitorFromRect
 0x140083618 GetClassWord
 0x140083620 EnumDesktopWindows
 0x140083628 EnumDisplayMonitors
 0x140083630 IntersectRect
 0x140083638 CopyRect
 0x140083640 CreateDialogParamW
 0x140083648 GetFocus
 0x140083650 CreatePopupMenu
 0x140083658 TrackPopupMenu
 0x140083660 IsClipboardFormatAvailable
 0x140083668 CharNextA
 0x140083670 IsWindowEnabled
 0x140083678 PostMessageW
 0x140083680 GetWindowTextW
 0x140083688 GetWindowTextLengthW
 0x140083690 EnableWindow
 0x140083698 GetWindowLongPtrW
 0x1400836a0 SetWindowLongPtrW
 0x1400836a8 SetWindowLongW
 0x1400836b0 SetClassLongW
 0x1400836b8 SetWindowTextW
 0x1400836c0 GetWindowPlacement
 0x1400836c8 CheckMenuItem
 0x1400836d0 GetSysColor
 0x1400836d8 SetClassLongPtrW
 0x1400836e0 GetClassLongPtrW
 0x1400836e8 DrawMenuBar
 0x1400836f0 SetMenuItemInfoW
 0x1400836f8 AppendMenuW
 0x140083700 LoadStringW
 0x140083708 GetSubMenu
 0x140083710 RemoveMenu
 0x140083718 CheckMenuRadioItem
 0x140083720 SetFocus
 0x140083728 MapWindowPoints
 0x140083730 EnableMenuItem
 0x140083738 GetMenu
 0x140083740 GetClientRect
 0x140083748 ShowWindow
 0x140083750 CreateWindowExW
 0x140083758 DestroyWindow
 0x140083760 DialogBoxParamW
 0x140083768 EndDialog
 0x140083770 SetWindowPos
 0x140083778 GetDlgItem
 0x140083780 GetWindowRect
 0x140083788 SendMessageW
 0x140083790 MessageBeep
 0x140083798 LoadCursorW
 0x1400837a0 SetCursor
 0x1400837a8 LoadImageW
 0x1400837b0 UnregisterClassA
 0x1400837b8 GetProcessDefaultLayout
 0x1400837c0 GetMenuState
 0x1400837c8 GetParent
RPCRT4.dll
 0x1400837d8 RpcStringFreeW
 0x1400837e0 UuidToStringW
 0x1400837e8 UuidCreate
WINMM.dll
 0x1400837f8 timeGetTime
GDI32.dll
 0x140083808 CreateDIBSection
 0x140083810 GetStockObject
 0x140083818 SetBkColor
 0x140083820 SetBkMode
 0x140083828 CreatePatternBrush
 0x140083830 DeleteObject
 0x140083838 DeleteDC
 0x140083840 EqualRgn
 0x140083848 CombineRgn
 0x140083850 SetRectRgn
 0x140083858 CreateRectRgnIndirect
 0x140083860 CreateRectRgn
 0x140083868 CreateCompatibleBitmap
 0x140083870 GetRgnBox
 0x140083878 LineTo
 0x140083880 MoveToEx
 0x140083888 ExtCreatePen
 0x140083890 GetObjectW
 0x140083898 GetTextExtentPoint32W
 0x1400838a0 GetTextMetricsW
 0x1400838a8 CreateSolidBrush
 0x1400838b0 SetTextColor
 0x1400838b8 GetDeviceCaps
 0x1400838c0 CreateCompatibleDC
 0x1400838c8 CreateFontIndirectW
 0x1400838d0 SelectObject
 0x1400838d8 GetTextExtentPointW
msvcrt.dll
 0x1400838e8 difftime
 0x1400838f0 memmove
 0x1400838f8 memset
 0x140083900 __C_specific_handler
 0x140083908 ??0exception@@QEAA@AEBQEBDH@Z
 0x140083910 _callnewh
 0x140083918 _CxxThrowException
 0x140083920 __CxxFrameHandler3
 0x140083928 setlocale
 0x140083930 __pctype_func
 0x140083938 ___lc_handle_func
 0x140083940 ___lc_codepage_func
 0x140083948 memcpy
 0x140083950 ___mb_cur_max_func
 0x140083958 _errno
 0x140083960 __mb_cur_max
 0x140083968 __crtGetStringTypeW
 0x140083970 __crtLCMapStringW
 0x140083978 __uncaught_exception
 0x140083980 isspace
 0x140083988 tolower
 0x140083990 abort
 0x140083998 isalnum
 0x1400839a0 _XcptFilter
 0x1400839a8 _amsg_exit
 0x1400839b0 __getmainargs
 0x1400839b8 __set_app_type
 0x1400839c0 time
 0x1400839c8 _cexit
 0x1400839d0 _ismbblead
 0x1400839d8 __setusermatherr
 0x1400839e0 _initterm
 0x1400839e8 _acmdln
 0x1400839f0 _fmode
 0x1400839f8 _commode
 0x140083a00 ??1type_info@@UEAA@XZ
 0x140083a08 _lock
 0x140083a10 _unlock
 0x140083a18 __dllonexit
 0x140083a20 _onexit
 0x140083a28 ?terminate@@YAXXZ
 0x140083a30 mbstowcs_s
 0x140083a38 exit
 0x140083a40 isdigit
 0x140083a48 isxdigit
 0x140083a50 toupper
 0x140083a58 _purecall
 0x140083a60 malloc
 0x140083a68 ??0exception@@QEAA@XZ
 0x140083a70 memmove_s
 0x140083a78 ??0exception@@QEAA@AEBQEBD@Z
 0x140083a80 ??1exception@@UEAA@XZ
 0x140083a88 ?what@exception@@UEBAPEBDXZ
 0x140083a90 memcpy_s
 0x140083a98 ??0exception@@QEAA@AEBV0@@Z
 0x140083aa0 free
 0x140083aa8 isalpha
 0x140083ab0 wcstoul
 0x140083ab8 strcspn
 0x140083ac0 memchr
 0x140083ac8 _wcsrev
 0x140083ad0 strchr
 0x140083ad8 _strtoui64
 0x140083ae0 _strtoi64
 0x140083ae8 sprintf_s
 0x140083af0 _wtoi64
 0x140083af8 _i64tow_s
 0x140083b00 _wcsdup
 0x140083b08 localeconv
 0x140083b10 iswalpha
 0x140083b18 iswdigit
 0x140083b20 _wcslwr_s
 0x140083b28 _wcsnicmp
 0x140083b30 wcsncmp
 0x140083b38 _itow_s
 0x140083b40 calloc
 0x140083b48 wcschr
 0x140083b50 _wcsicmp
 0x140083b58 _itoa
 0x140083b60 _wtoi
 0x140083b68 _vsnwprintf
 0x140083b70 wcscat_s
 0x140083b78 wcscpy_s
 0x140083b80 _exit
 0x140083b88 wcstol
 0x140083b90 wcscmp

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure