Report - mypc.exe

Malicious Library UPX PE File OS Processor Check PE32
ScreenShot
Created 2021.11.18 14:11 Machine s1_win7_x6401
Filename mypc.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
9
Behavior Score
2.4
ZERO API file : clean
VT API (file) 30 detected (Bulz, malicious, high confidence, score, Artemis, Save, Attribute, HighConfidence, Kryptik, AGen, FileRepMalware, Generic@ML, RDML, BjOeFJdlSqOIP3absrS6kg, Gen8, ai score=89, KVMH008, kcloud, Sabsik, TrickBot, ZexaF, aAW@aunZHPmi, susgen)
md5 5ca007dbd88522738eab36ecbf8cc230
sha256 96b98b0b77a3e458bfbdf84bc7c05b73d592e5fd6f8691742ac7c463489ac26b
ssdeep 24576:qA864/5Nhq4nm2/u0I8tquax5IoFlGP/TRRr6Si210iOBauD5HgpAFqb1chWOM7:qDLwObI8s2C3Gd7
imphash b9005a59919df3b1340483e40896aaf6
impfuzzy 48:rspRBVZ+Kcp6tSS1mzVRfA3S5EDF/KAn6g/XSv09CjKsJyXxgzGSY+nB6UR/H:rspn9cp6tSS1mhRWHHwb
  Network IP location

Signature (6cnts)

Level Description
danger File has been identified by 30 AntiVirus engines on VirusTotal as malicious
notice A process attempted to delay the analysis task.
notice Executes one or more WMI queries
info Queries for the computername
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info This executable has a PDB path

Rules (5cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.dll
 0x8071000 GetModuleFileNameA
 0x8071004 SetLastError
 0x8071008 GetModuleHandleExW
 0x807100c InitializeCriticalSectionEx
 0x8071010 WaitForSingleObject
 0x8071014 UnmapViewOfFile
 0x8071018 Sleep
 0x807101c GetLastError
 0x8071020 CloseHandle
 0x8071024 RaiseException
 0x8071028 DecodePointer
 0x807102c DeleteCriticalSection
 0x8071030 CreateEventA
 0x8071034 MultiByteToWideChar
 0x8071038 WideCharToMultiByte
 0x807103c SetEndOfFile
 0x8071040 GetConsoleCP
 0x8071044 FlushFileBuffers
 0x8071048 CreateFileW
 0x807104c SetStdHandle
 0x8071050 GetProcessHeap
 0x8071054 FreeEnvironmentStringsW
 0x8071058 GetEnvironmentStringsW
 0x807105c GetCommandLineW
 0x8071060 GetCommandLineA
 0x8071064 GetOEMCP
 0x8071068 IsValidCodePage
 0x807106c FindNextFileA
 0x8071070 FindFirstFileExA
 0x8071074 FindClose
 0x8071078 EnumSystemLocalesW
 0x807107c GetUserDefaultLCID
 0x8071080 IsValidLocale
 0x8071084 HeapReAlloc
 0x8071088 HeapSize
 0x807108c HeapFree
 0x8071090 HeapAlloc
 0x8071094 GetFileType
 0x8071098 ReadConsoleW
 0x807109c GetConsoleMode
 0x80710a0 SetFilePointerEx
 0x80710a4 EnterCriticalSection
 0x80710a8 LeaveCriticalSection
 0x80710ac InitializeCriticalSectionAndSpinCount
 0x80710b0 CreateEventW
 0x80710b4 SwitchToThread
 0x80710b8 TlsAlloc
 0x80710bc TlsGetValue
 0x80710c0 TlsSetValue
 0x80710c4 TlsFree
 0x80710c8 GetSystemTimeAsFileTime
 0x80710cc GetModuleHandleW
 0x80710d0 GetProcAddress
 0x80710d4 EncodePointer
 0x80710d8 LCMapStringW
 0x80710dc GetLocaleInfoW
 0x80710e0 GetStringTypeW
 0x80710e4 GetCPInfo
 0x80710e8 IsDebuggerPresent
 0x80710ec OutputDebugStringW
 0x80710f0 SetEvent
 0x80710f4 ResetEvent
 0x80710f8 WaitForSingleObjectEx
 0x80710fc InitializeSListHead
 0x8071100 UnhandledExceptionFilter
 0x8071104 SetUnhandledExceptionFilter
 0x8071108 GetStartupInfoW
 0x807110c IsProcessorFeaturePresent
 0x8071110 QueryPerformanceCounter
 0x8071114 GetCurrentProcessId
 0x8071118 GetCurrentThreadId
 0x807111c GetCurrentProcess
 0x8071120 TerminateProcess
 0x8071124 RtlUnwind
 0x8071128 InterlockedPushEntrySList
 0x807112c FreeLibrary
 0x8071130 LoadLibraryExW
 0x8071134 ReadFile
 0x8071138 ExitProcess
 0x807113c GetStdHandle
 0x8071140 WriteFile
 0x8071144 GetACP
 0x8071148 WriteConsoleW
USER32.dll
 0x8071160 GetAsyncKeyState
 0x8071164 EndPaint
 0x8071168 BeginPaint
 0x807116c GetCursorPos
 0x8071170 GetMessageW
 0x8071174 DefWindowProcW
 0x8071178 PostMessageW
 0x807117c DestroyWindow
 0x8071180 CreateWindowExW
 0x8071184 EndDialog
 0x8071188 RegisterClassExW
 0x807118c UpdateWindow
 0x8071190 LoadStringW
 0x8071194 ShowWindow
 0x8071198 LoadAcceleratorsW
 0x807119c DispatchMessageW
 0x80711a0 SetTimer
 0x80711a4 SetLayeredWindowAttributes
 0x80711a8 TranslateAcceleratorW
 0x80711ac TranslateMessage
 0x80711b0 LoadIconW
 0x80711b4 LoadCursorW
 0x80711b8 PostQuitMessage
 0x80711bc DialogBoxParamW
ole32.dll
 0x80711c4 CoCreateInstance
 0x80711c8 CoInitializeSecurity
 0x80711cc CoInitializeEx
OLEAUT32.dll
 0x8071150 SysAllocStringLen
 0x8071154 SysAllocString
 0x8071158 SysFreeString

EAT(Export Address Table) Library

0x494a0 ??0?$codecvt_null@_W@archive@boost@@QAE@I@Z
0x44514 ??0?$singleton@V?$extended_type_info_typeid@Uexecutables@@@serialization@boost@@@serialization@boost@@IAE@XZ
0x44514 ??0?$singleton@V?$extended_type_info_typeid@Ustorage@@@serialization@boost@@@serialization@boost@@IAE@XZ
0x44514 ??0?$singleton@V?$extended_type_info_typeid@V?$vector@V?$vector@_KV?$allocator@_K@std@@@std@@V?$allocator@V?$vector@_KV?$allocator@_K@std@@@std@@@2@@std@@@serialization@boost@@@serialization@boost@@IAE@XZ
0x44514 ??0?$singleton@V?$extended_type_info_typeid@V?$vector@_KV?$allocator@_K@std@@@std@@@serialization@boost@@@serialization@boost@@IAE@XZ
0x41430 ??1?$codecvt_null@_W@archive@boost@@UAE@XZ
0x41aaf ??_F?$codecvt_null@_W@archive@boost@@QAEXXZ
0x41aa7 ?do_always_noconv@?$codecvt_null@_W@archive@boost@@EBE_NXZ
0x41aa3 ?do_encoding@?$codecvt_null@_W@archive@boost@@EBEHXZ
0x49630 ?do_in@?$codecvt_null@_W@archive@boost@@EBEHAAU_Mbstatet@@PBD1AAPBDPA_W3AAPA_W@Z
0x41aaa ?do_max_length@?$codecvt_null@_W@archive@boost@@EBEHXZ
0x496a0 ?do_out@?$codecvt_null@_W@archive@boost@@EBEHAAU_Mbstatet@@PB_W1AAPB_WPAD3AAPAD@Z
0x443a3 ?get_const_instance@?$singleton@V?$extended_type_info_typeid@Uexecutables@@@serialization@boost@@@serialization@boost@@SAABV?$extended_type_info_typeid@Uexecutables@@@23@XZ
0x46c7d ?get_const_instance@?$singleton@V?$extended_type_info_typeid@Ustorage@@@serialization@boost@@@serialization@boost@@SAABV?$extended_type_info_typeid@Ustorage@@@23@XZ
0x46f22 ?get_const_instance@?$singleton@V?$extended_type_info_typeid@V?$vector@V?$vector@_KV?$allocator@_K@std@@@std@@V?$allocator@V?$vector@_KV?$allocator@_K@std@@@std@@@2@@std@@@serialization@boost@@@serialization@boost@@SAABV?$extended_type_info_typeid@V?$vector@V?$vector@_KV?$allocator@_K@std@@@std@@V?$allocator@V?$vector@_KV?$allocator@_K@std@@@std@@@2@@std@@@23@XZ
0x4753a ?get_const_instance@?$singleton@V?$extended_type_info_typeid@V?$vector@_KV?$allocator@_K@std@@@std@@@serialization@boost@@@serialization@boost@@SAABV?$extended_type_info_typeid@V?$vector@_KV?$allocator@_K@std@@@std@@@23@XZ
0x44288 ?get_const_instance@?$singleton@V?$iserializer@Vtext_iarchive@archive@boost@@Uexecutables@@@detail@archive@boost@@@serialization@boost@@SAABV?$iserializer@Vtext_iarchive@archive@boost@@Uexecutables@@@detail@archive@3@XZ
0x46b84 ?get_const_instance@?$singleton@V?$iserializer@Vtext_iarchive@archive@boost@@Ustorage@@@detail@archive@boost@@@serialization@boost@@SAABV?$iserializer@Vtext_iarchive@archive@boost@@Ustorage@@@detail@archive@3@XZ
0x46e36 ?get_const_instance@?$singleton@V?$iserializer@Vtext_iarchive@archive@boost@@V?$vector@V?$vector@_KV?$allocator@_K@std@@@std@@V?$allocator@V?$vector@_KV?$allocator@_K@std@@@std@@@2@@std@@@detail@archive@boost@@@serialization@boost@@SAABV?$iserializer@Vtext_iarchive@archive@boost@@V?$vector@V?$vector@_KV?$allocator@_K@std@@@std@@V?$allocator@V?$vector@_KV?$allocator@_K@std@@@std@@@2@@std@@@detail@archive@3@XZ
0x47441 ?get_const_instance@?$singleton@V?$iserializer@Vtext_iarchive@archive@boost@@V?$vector@_KV?$allocator@_K@std@@@std@@@detail@archive@boost@@@serialization@boost@@SAABV?$iserializer@Vtext_iarchive@archive@boost@@V?$vector@_KV?$allocator@_K@std@@@std@@@detail@archive@3@XZ
0x49790 ?get_const_instance@?$singleton@V?$map@Vtext_iarchive@archive@boost@@@extra_detail@detail@archive@boost@@@serialization@boost@@SAABV?$map@Vtext_iarchive@archive@boost@@@extra_detail@detail@archive@3@XZ
0x4b320 ?get_const_instance@?$singleton@V?$multiset@PBVextended_type_info@serialization@boost@@Ukey_compare@detail@23@V?$allocator@PBVextended_type_info@serialization@boost@@@std@@@std@@@serialization@boost@@SAABV?$multiset@PBVextended_type_info@serialization@boost@@Ukey_compare@detail@23@V?$allocator@PBVextended_type_info@serialization@boost@@@std@@@std@@XZ
0x4ae70 ?get_const_instance@?$singleton@V?$multiset@PBVextended_type_info_typeid_0@typeid_system@serialization@boost@@Utype_compare@234@V?$allocator@PBVextended_type_info_typeid_0@typeid_system@serialization@boost@@@std@@@std@@@serialization@boost@@SAABV?$multiset@PBVextended_type_info_typeid_0@typeid_system@serialization@boost@@Utype_compare@234@V?$allocator@PBVextended_type_info_typeid_0@typeid_system@serialization@boost@@@std@@@std@@XZ
0x41ab7 ?get_lock@singleton_module@serialization@boost@@AAEAA_NXZ
0x49790 ?get_mutable_instance@?$singleton@V?$map@Vtext_iarchive@archive@boost@@@extra_detail@detail@archive@boost@@@serialization@boost@@SAAAV?$map@Vtext_iarchive@archive@boost@@@extra_detail@detail@archive@3@XZ
0x4b320 ?get_mutable_instance@?$singleton@V?$multiset@PBVextended_type_info@serialization@boost@@Ukey_compare@detail@23@V?$allocator@PBVextended_type_info@serialization@boost@@@std@@@std@@@serialization@boost@@SAAAV?$multiset@PBVextended_type_info@serialization@boost@@Ukey_compare@detail@23@V?$allocator@PBVextended_type_info@serialization@boost@@@std@@@std@@XZ
0x4ae70 ?get_mutable_instance@?$singleton@V?$multiset@PBVextended_type_info_typeid_0@typeid_system@serialization@boost@@Utype_compare@234@V?$allocator@PBVextended_type_info_typeid_0@typeid_system@serialization@boost@@@std@@@std@@@serialization@boost@@SAAAV?$multiset@PBVextended_type_info_typeid_0@typeid_system@serialization@boost@@Utype_compare@234@V?$allocator@PBVextended_type_info_typeid_0@typeid_system@serialization@boost@@@std@@@std@@XZ
0x49850 ?is_destroyed@?$singleton@V?$map@Vtext_iarchive@archive@boost@@@extra_detail@detail@archive@boost@@@serialization@boost@@SA_NXZ
0x4b3e0 ?is_destroyed@?$singleton@V?$multiset@PBVextended_type_info@serialization@boost@@Ukey_compare@detail@23@V?$allocator@PBVextended_type_info@serialization@boost@@@std@@@std@@@serialization@boost@@SA_NXZ
0x4af30 ?is_destroyed@?$singleton@V?$multiset@PBVextended_type_info_typeid_0@typeid_system@serialization@boost@@Utype_compare@234@V?$allocator@PBVextended_type_info_typeid_0@typeid_system@serialization@boost@@@std@@@std@@@serialization@boost@@SA_NXZ
0x41acd ?is_locked@singleton_module@serialization@boost@@QAE_NXZ
0x44517 ?load_object_data@?$iserializer@Vtext_iarchive@archive@boost@@Uexecutables@@@detail@archive@boost@@UBEXAAVbasic_iarchive@234@PAXI@Z
0x46dad ?load_object_data@?$iserializer@Vtext_iarchive@archive@boost@@Ustorage@@@detail@archive@boost@@UBEXAAVbasic_iarchive@234@PAXI@Z
0x47052 ?load_object_data@?$iserializer@Vtext_iarchive@archive@boost@@V?$vector@V?$vector@_KV?$allocator@_K@std@@@std@@V?$allocator@V?$vector@_KV?$allocator@_K@std@@@std@@@2@@std@@@detail@archive@boost@@UBEXAAVbasic_iarchive@234@PAXI@Z
0x4766a ?load_object_data@?$iserializer@Vtext_iarchive@archive@boost@@V?$vector@_KV?$allocator@_K@std@@@std@@@detail@archive@boost@@UBEXAAVbasic_iarchive@234@PAXI@Z
0x822cc94 ?lock@?1??get_lock@singleton_module@serialization@boost@@AAEAA_NXZ@4_NA
0x41abd ?lock@singleton_module@serialization@boost@@QAEXXZ
0x41ac5 ?unlock@singleton_module@serialization@boost@@QAEXXZ


Similarity measure (PE file only) - Checking for service failure