Report - HelpPane.exe

Gen2 Gen1 Malicious Packer Malicious Library UPX PE64 PE File
ScreenShot
Created 2021.11.11 20:08 Machine s1_win7_x6401
Filename HelpPane.exe
Type PE32+ executable (GUI) x86-64, for MS Windows
AI Score Not founds Behavior Score
0.6
ZERO API file : clean
VT API (file)
md5 7e8faec2e175c8b45b6d380a6a4c9503
sha256 42c2c94edf6f5e2e75556f455039cacd8a23bc825e8beef864b8572c3007db5a
ssdeep 12288:DGrARa7TAPZfMiuU9YAioFOVdgnFoA7aXKPXPiXuHNHGb6bH/zx/GCLW/nh/X:DBwmZ33qAioFmymA7
imphash a71b59777fdf47eb06d8f9729f3bf423
impfuzzy 192:C2u6S2rWi2+JW/56JFIe8tLXCqJXmkQ/pH2gVecQv7y:to+JKkWtLXCCXmkQ/pH2gDQv7y
  Network IP location

Signature (3cnts)

Level Description
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The file contains an unknown PE resource name possibly indicative of a packer
info This executable has a PDB path

Rules (7cnts)

Level Name Description Collection
danger Win32_Trojan_Gen_1_0904B0_Zero Win32 Trojan Emotet binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch Malicious_Packer_Zero Malicious Packer binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE64 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)
info Win32_Trojan_Gen_2_0904B0_Zero Win32 Trojan Gen binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

ADVAPI32.dll
 0x14005ee40 RegisterTraceGuidsW
 0x14005ee48 GetTraceEnableLevel
 0x14005ee50 GetTraceEnableFlags
 0x14005ee58 GetTraceLoggerHandle
 0x14005ee60 TraceEvent
 0x14005ee68 RegOpenKeyW
 0x14005ee70 RegQueryValueExW
 0x14005ee78 RegCloseKey
 0x14005ee80 RegQueryInfoKeyW
 0x14005ee88 RegEnumKeyExW
 0x14005ee90 RegOpenKeyExW
 0x14005ee98 RegSetValueExW
 0x14005eea0 RegCreateKeyExW
 0x14005eea8 RegDeleteValueW
 0x14005eeb0 UnregisterTraceGuids
 0x14005eeb8 EventUnregister
 0x14005eec0 EventRegister
 0x14005eec8 EventSetInformation
 0x14005eed0 EventWriteTransfer
 0x14005eed8 RegGetValueW
 0x14005eee0 EqualSid
 0x14005eee8 OpenThreadToken
 0x14005eef0 OpenProcessToken
 0x14005eef8 GetTokenInformation
 0x14005ef00 GetSidLengthRequired
 0x14005ef08 InitializeSid
 0x14005ef10 IsValidSid
 0x14005ef18 GetSidSubAuthority
 0x14005ef20 GetLengthSid
 0x14005ef28 CopySid
 0x14005ef30 SetSecurityDescriptorDacl
 0x14005ef38 AllocateAndInitializeSid
 0x14005ef40 SetEntriesInAclW
 0x14005ef48 FreeSid
 0x14005ef50 InitializeSecurityDescriptor
KERNEL32.dll
 0x14005efe8 PostQueuedCompletionStatus
 0x14005eff0 GetSystemInfo
 0x14005eff8 CreateIoCompletionPort
 0x14005f000 CreateEventW
 0x14005f008 ProcessIdToSessionId
 0x14005f010 GetCurrentProcessId
 0x14005f018 GetExitCodeThread
 0x14005f020 TerminateThread
 0x14005f028 LoadLibraryExW
 0x14005f030 lstrcmpiW
 0x14005f038 CreateMutexW
 0x14005f040 GetSystemDirectoryW
 0x14005f048 SetCurrentDirectoryW
 0x14005f050 HeapSetInformation
 0x14005f058 ReleaseMutex
 0x14005f060 HeapAlloc
 0x14005f068 GetProcessHeap
 0x14005f070 HeapFree
 0x14005f078 GetCurrentThreadId
 0x14005f080 GetModuleFileNameA
 0x14005f088 DebugBreak
 0x14005f090 IsDebuggerPresent
 0x14005f098 OutputDebugStringW
 0x14005f0a0 AcquireSRWLockExclusive
 0x14005f0a8 ReleaseSRWLockExclusive
 0x14005f0b0 ResetEvent
 0x14005f0b8 ReleaseSRWLockShared
 0x14005f0c0 ReleaseSemaphore
 0x14005f0c8 SetThreadpoolTimer
 0x14005f0d0 WaitForThreadpoolTimerCallbacks
 0x14005f0d8 CloseThreadpoolTimer
 0x14005f0e0 WaitForSingleObjectEx
 0x14005f0e8 InitializeCriticalSectionEx
 0x14005f0f0 OpenSemaphoreW
 0x14005f0f8 CreateThreadpoolTimer
 0x14005f100 GetFileAttributesW
 0x14005f108 GetPackagesByPackageFamily
 0x14005f110 GetCurrentThread
 0x14005f118 CompareStringW
 0x14005f120 InitOnceBeginInitialize
 0x14005f128 InitOnceComplete
 0x14005f130 CreateMutexExW
 0x14005f138 CreateSemaphoreExW
 0x14005f140 CreateThread
 0x14005f148 ResumeThread
 0x14005f150 MulDiv
 0x14005f158 WaitForMultipleObjects
 0x14005f160 GetCurrentProcess
 0x14005f168 LocalAlloc
 0x14005f170 GlobalFree
 0x14005f178 GlobalAlloc
 0x14005f180 DelayLoadFailureHook
 0x14005f188 GetQueuedCompletionStatus
 0x14005f190 SetEvent
 0x14005f198 WaitForSingleObject
 0x14005f1a0 GetLastError
 0x14005f1a8 CloseHandle
 0x14005f1b0 LocalFree
 0x14005f1b8 FormatMessageW
 0x14005f1c0 MultiByteToWideChar
 0x14005f1c8 LoadLibraryW
 0x14005f1d0 FreeLibrary
 0x14005f1d8 AcquireSRWLockShared
 0x14005f1e0 ResolveDelayLoadedAPI
 0x14005f1e8 SetLastError
 0x14005f1f0 GetModuleFileNameW
 0x14005f1f8 InitializeCriticalSection
 0x14005f200 ExpandEnvironmentStringsW
 0x14005f208 FindResourceExW
 0x14005f210 LoadResource
 0x14005f218 LockResource
 0x14005f220 SizeofResource
 0x14005f228 GetProcessMitigationPolicy
 0x14005f230 OpenEventW
 0x14005f238 GetUserPreferredUILanguages
 0x14005f240 GetProductInfo
 0x14005f248 OutputDebugStringA
 0x14005f250 HeapSize
 0x14005f258 HeapReAlloc
 0x14005f260 HeapDestroy
 0x14005f268 GetTickCount
 0x14005f270 RaiseException
 0x14005f278 DeleteCriticalSection
 0x14005f280 LeaveCriticalSection
 0x14005f288 EnterCriticalSection
 0x14005f290 GetModuleHandleW
 0x14005f298 GetProcAddress
 0x14005f2a0 GetVersionExW
 0x14005f2a8 GetModuleHandleExW
 0x14005f2b0 VirtualFree
 0x14005f2b8 VirtualAlloc
 0x14005f2c0 LoadLibraryExA
 0x14005f2c8 EncodePointer
 0x14005f2d0 DecodePointer
 0x14005f2d8 FlushInstructionCache
 0x14005f2e0 InterlockedPushEntrySList
 0x14005f2e8 InterlockedPopEntrySList
 0x14005f2f0 Sleep
 0x14005f2f8 GetStartupInfoW
 0x14005f300 UnhandledExceptionFilter
 0x14005f308 SetUnhandledExceptionFilter
 0x14005f310 TerminateProcess
 0x14005f318 WakeAllConditionVariable
 0x14005f320 SleepConditionVariableSRW
 0x14005f328 QueryPerformanceCounter
 0x14005f330 GetSystemTimeAsFileTime
GDI32.dll
 0x14005ef98 GetTextExtentPoint32W
 0x14005efa0 SelectObject
 0x14005efa8 GetDeviceCaps
 0x14005efb0 GetStockObject
 0x14005efb8 CreateFontIndirectW
 0x14005efc0 GetObjectW
 0x14005efc8 SetTextColor
 0x14005efd0 SetBkMode
 0x14005efd8 DeleteObject
USER32.dll
 0x14005f428 EnableWindow
 0x14005f430 IsDlgButtonChecked
 0x14005f438 CheckDlgButton
 0x14005f440 GetDlgItem
 0x14005f448 ShowWindow
 0x14005f450 ReleaseDC
 0x14005f458 GetDC
 0x14005f460 GetProcessDefaultLayout
 0x14005f468 MonitorFromPoint
 0x14005f470 GetWindowRect
 0x14005f478 GetMonitorInfoW
 0x14005f480 MonitorFromRect
 0x14005f488 GetWindowPlacement
 0x14005f490 IsIconic
 0x14005f498 IsZoomed
 0x14005f4a0 SetCursor
 0x14005f4a8 LockWindowUpdate
 0x14005f4b0 PostQuitMessage
 0x14005f4b8 GetDlgItemTextW
 0x14005f4c0 SystemParametersInfoW
 0x14005f4c8 DestroyIcon
 0x14005f4d0 DispatchMessageW
 0x14005f4d8 UnregisterClassA
 0x14005f4e0 BringWindowToTop
 0x14005f4e8 GetMessageW
 0x14005f4f0 LoadAcceleratorsW
 0x14005f4f8 CharNextW
 0x14005f500 PostMessageW
 0x14005f508 KillTimer
 0x14005f510 SetTimer
 0x14005f518 MessageBoxW
 0x14005f520 SetActiveWindow
 0x14005f528 GetKeyState
 0x14005f530 SetWindowTextW
 0x14005f538 DestroyMenu
 0x14005f540 DialogBoxParamW
 0x14005f548 TrackPopupMenuEx
 0x14005f550 ClientToScreen
 0x14005f558 EnableMenuItem
 0x14005f560 CheckMenuRadioItem
 0x14005f568 InvalidateRect
 0x14005f570 LoadMenuW
 0x14005f578 GetSubMenu
 0x14005f580 CallWindowProcW
 0x14005f588 GetWindowLongPtrW
 0x14005f590 SetWindowLongPtrW
 0x14005f598 RegisterClassExW
 0x14005f5a0 EndDialog
 0x14005f5a8 TranslateAcceleratorW
 0x14005f5b0 SetDlgItemTextW
 0x14005f5b8 GetSystemMetrics
 0x14005f5c0 TranslateMessage
 0x14005f5c8 LoadCursorW
 0x14005f5d0 GetClassInfoExW
 0x14005f5d8 DefWindowProcW
 0x14005f5e0 CreateWindowExW
 0x14005f5e8 SetFocus
 0x14005f5f0 IsWindowVisible
 0x14005f5f8 IsWindowEnabled
 0x14005f600 MoveWindow
 0x14005f608 AdjustWindowRectEx
 0x14005f610 GetMenu
 0x14005f618 GetWindowLongW
 0x14005f620 SetWindowPos
 0x14005f628 GetSysColorBrush
 0x14005f630 GetSysColor
 0x14005f638 SendMessageW
 0x14005f640 GetClientRect
 0x14005f648 GetParent
msvcrt.dll
 0x14005f668 memcpy
 0x14005f670 memcmp
 0x14005f678 __CxxFrameHandler3
 0x14005f680 __C_specific_handler
 0x14005f688 _wcsnicmp
 0x14005f690 memcpy_s
 0x14005f698 memset
 0x14005f6a0 _wcsicmp
 0x14005f6a8 iswspace
 0x14005f6b0 _purecall
 0x14005f6b8 free
 0x14005f6c0 vswprintf_s
 0x14005f6c8 _vscwprintf
 0x14005f6d0 _wcslwr_s
 0x14005f6d8 _resetstkoflw
 0x14005f6e0 memmove_s
 0x14005f6e8 __set_app_type
 0x14005f6f0 malloc
 0x14005f6f8 wcscpy_s
 0x14005f700 wcscat_s
 0x14005f708 _vsnwprintf
 0x14005f710 towupper
 0x14005f718 wcsstr
 0x14005f720 calloc
 0x14005f728 _beginthreadex
 0x14005f730 _onexit
 0x14005f738 __dllonexit
 0x14005f740 _unlock
 0x14005f748 _lock
 0x14005f750 realloc
 0x14005f758 _errno
 0x14005f760 ??1type_info@@UEAA@XZ
 0x14005f768 ?terminate@@YAXXZ
 0x14005f770 _commode
 0x14005f778 _fmode
 0x14005f780 _wcmdln
 0x14005f788 _initterm
 0x14005f790 __setusermatherr
 0x14005f798 _cexit
 0x14005f7a0 _exit
 0x14005f7a8 exit
 0x14005f7b0 wcscmp
 0x14005f7b8 __wgetmainargs
 0x14005f7c0 _amsg_exit
 0x14005f7c8 _XcptFilter
 0x14005f7d0 _CxxThrowException
 0x14005f7d8 _callnewh
 0x14005f7e0 ??0exception@@QEAA@AEBQEBDH@Z
 0x14005f7e8 _wtoi
 0x14005f7f0 _itow_s
 0x14005f7f8 swprintf_s
 0x14005f800 _vsnprintf_s
 0x14005f808 ??0exception@@QEAA@XZ
 0x14005f810 ??0exception@@QEAA@AEBQEBD@Z
 0x14005f818 ??1exception@@UEAA@XZ
 0x14005f820 ?what@exception@@UEBAPEBDXZ
 0x14005f828 ??0exception@@QEAA@AEBV0@@Z
 0x14005f830 wcsncpy_s
 0x14005f838 wcschr
COMCTL32.dll
 0x14005ef60 None
 0x14005ef68 InitCommonControlsEx
 0x14005ef70 None
 0x14005ef78 None
 0x14005ef80 ImageList_LoadImageW
 0x14005ef88 ImageList_Destroy
ole32.dll
 0x14005f888 CoTaskMemRealloc
 0x14005f890 CoTaskMemFree
 0x14005f898 CoInitialize
 0x14005f8a0 CoUninitialize
 0x14005f8a8 CoCreateInstance
 0x14005f8b0 CoTaskMemAlloc
 0x14005f8b8 CoGetMalloc
 0x14005f8c0 OleInitialize
 0x14005f8c8 CoInitializeSecurity
 0x14005f8d0 CoRegisterClassObject
 0x14005f8d8 CoResumeClassObjects
 0x14005f8e0 CoRevokeClassObject
 0x14005f8e8 OleUninitialize
 0x14005f8f0 CoImpersonateClient
 0x14005f8f8 CoRevertToSelf
 0x14005f900 PropVariantClear
OLEAUT32.dll
 0x14005f340 SysAllocString
 0x14005f348 VariantClear
 0x14005f350 VariantInit
 0x14005f358 SysStringLen
 0x14005f360 LoadRegTypeLib
 0x14005f368 LoadTypeLib
 0x14005f370 SysFreeString
 0x14005f378 SysAllocStringLen
 0x14005f380 VariantCopy
 0x14005f388 SysStringByteLen
 0x14005f390 SysAllocStringByteLen
 0x14005f398 VarUI4FromStr
 0x14005f3a0 LoadTypeLibEx
 0x14005f3a8 VarBstrCat
 0x14005f3b0 DispCallFunc
SHELL32.dll
 0x14005f3c0 SHGetPropertyStoreForWindow
 0x14005f3c8 ShellExecuteW
SHLWAPI.dll
 0x14005f3d8 UrlEscapeW
 0x14005f3e0 SHGetValueW
 0x14005f3e8 None
 0x14005f3f0 SHRegGetValueW
 0x14005f3f8 SHStrDupW
 0x14005f400 None
 0x14005f408 UrlUnescapeW
SLWGA.dll
 0x14005f418 SLIsGenuineLocal
ntdll.dll
 0x14005f848 RtlCaptureContext
 0x14005f850 RtlLookupFunctionEntry
 0x14005f858 RtlVirtualUnwind
 0x14005f860 NtOpenProcessToken
 0x14005f868 NtQueryInformationToken
 0x14005f870 NtClose
 0x14005f878 NtOpenThreadToken
api-ms-win-core-path-l1-1-0.dll
 0x14005f658 PathCchAppend

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure