Report - pub3.exe

Malicious Library UPX PE File OS Processor Check PE32
ScreenShot
Created 2021.11.02 11:38 Machine s1_win7_x6403
Filename pub3.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
7
Behavior Score
2.2
ZERO API file : clean
VT API (file) 21 detected (AIDetect, malware1, malicious, high confidence, Save, confidence, 100%, Hacktool, Kryptik, Eldorado, Fragtor, score, Artemis, ET#90%, RDMK, cmRtazrxtj4MeT1LRNaZ5p80xlyz, Static AI, Malicious PE, Unsafe, ZexaF, ju0@aeGO@KeG)
md5 220979c6ad45de9d933fc57a73840204
sha256 19104fc4be7e31e36c9602a861b28f2b6ed4ba28eb03b9bd01069ffbd6eff470
ssdeep 1536:E3Q1HnPu+xv90AL0w+hhRqUzeaenv6/lPthX1UFSjqISR4RQZ34aQuk2oCkNhUft:XHP1V0mq9KiZ1FZPRnaXroCeh
imphash ed38ab5cc3f4fd753cddd79c6cfea0fc
impfuzzy 24:bhEq+fqWS+IIFD0OR/uAkhS1OovCZt5cpluiRv9jIgJ3In4FNS5jM6L3n:CG+NRMjt5cpsS9zZjSfL3
  Network IP location

Signature (6cnts)

Level Description
warning File has been identified by 21 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice The binary likely contains encrypted or compressed data indicative of a packer
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The file contains an unknown PE resource name possibly indicative of a packer
info This executable has a PDB path

Rules (5cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.dll
 0x418000 HeapReAlloc
 0x418004 LoadResource
 0x418008 HeapAlloc
 0x41800c SetMailslotInfo
 0x418010 GetEnvironmentStringsW
 0x418014 SetConsoleScreenBufferSize
 0x418018 SetEvent
 0x41801c GetTickCount
 0x418020 TlsSetValue
 0x418024 FindResourceExA
 0x418028 GlobalAlloc
 0x41802c LoadLibraryW
 0x418030 InitAtomTable
 0x418034 FindNextVolumeW
 0x418038 WriteConsoleW
 0x41803c CreateActCtxA
 0x418040 BindIoCompletionCallback
 0x418044 GetProcAddress
 0x418048 VirtualAlloc
 0x41804c BeginUpdateResourceW
 0x418050 PrepareTape
 0x418054 GetAtomNameA
 0x418058 LoadLibraryA
 0x41805c WriteConsoleA
 0x418060 SetEnvironmentVariableA
 0x418064 GetModuleFileNameA
 0x418068 FindFirstChangeNotificationA
 0x41806c GetProcessAffinityMask
 0x418070 AddConsoleAliasA
 0x418074 CreateFileW
 0x418078 HeapSize
 0x41807c DecodePointer
 0x418080 EncodePointer
 0x418084 GetCommandLineA
 0x418088 HeapSetInformation
 0x41808c GetStartupInfoW
 0x418090 IsProcessorFeaturePresent
 0x418094 ReadFile
 0x418098 UnhandledExceptionFilter
 0x41809c SetUnhandledExceptionFilter
 0x4180a0 IsDebuggerPresent
 0x4180a4 TerminateProcess
 0x4180a8 GetCurrentProcess
 0x4180ac EnterCriticalSection
 0x4180b0 LeaveCriticalSection
 0x4180b4 InitializeCriticalSectionAndSpinCount
 0x4180b8 RtlUnwind
 0x4180bc SetHandleCount
 0x4180c0 GetStdHandle
 0x4180c4 GetFileType
 0x4180c8 DeleteCriticalSection
 0x4180cc GetLastError
 0x4180d0 SetFilePointer
 0x4180d4 TlsAlloc
 0x4180d8 TlsGetValue
 0x4180dc TlsFree
 0x4180e0 InterlockedIncrement
 0x4180e4 GetModuleHandleW
 0x4180e8 SetLastError
 0x4180ec GetCurrentThreadId
 0x4180f0 InterlockedDecrement
 0x4180f4 HeapFree
 0x4180f8 CloseHandle
 0x4180fc ExitProcess
 0x418100 WriteFile
 0x418104 GetModuleFileNameW
 0x418108 FreeEnvironmentStringsW
 0x41810c WideCharToMultiByte
 0x418110 HeapCreate
 0x418114 QueryPerformanceCounter
 0x418118 GetCurrentProcessId
 0x41811c GetSystemTimeAsFileTime
 0x418120 MultiByteToWideChar
 0x418124 Sleep
 0x418128 GetCPInfo
 0x41812c GetACP
 0x418130 GetOEMCP
 0x418134 IsValidCodePage
 0x418138 CreateFileA
 0x41813c SetStdHandle
 0x418140 GetConsoleCP
 0x418144 GetConsoleMode
 0x418148 FlushFileBuffers
 0x41814c RaiseException
 0x418150 LCMapStringW
 0x418154 GetStringTypeW
 0x418158 SetEndOfFile
 0x41815c GetProcessHeap
USER32.dll
 0x418164 GetCursorPos

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure