Report - cat.php

Generic Malware Malicious Packer Malicious Library UPX PE File DLL PE64
ScreenShot
Created 2022.03.12 22:50 Machine s1_win7_x6401
Filename cat.php
Type PE32+ executable (DLL) (GUI) x86-64, for MS Windows
AI Score
6
Behavior Score
2.8
ZERO API file : malware
VT API (file)
md5 1a5df93142ccad861ae2a1adbb571d0e
sha256 5351b008bbc4c1b1073dc419143cfd7a0cabc15f796563155e0b579cd080373d
ssdeep 24576:p1PghBzKWN1zjpjLJ1RxfawzZA2UDF/WYVO0dD:pVax1zBLnfNZA2UDgYE01
imphash a62a4e55e145a922e3a860d82c01e587
impfuzzy 192:5tDvIpSvmfzXgUxkY60ezYcncncSvWPpK/4QPUO5:DAp/67RzYaYMpc4QPUO5
  Network IP location

Signature (7cnts)

Level Description
danger Connects to an IP address that is no longer responding to requests (legitimate services will remain up-and-running usually)
notice Allocates read-write-execute memory (usually to unpack itself)
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
notice The binary likely contains encrypted or compressed data indicative of a packer
info Checks if process is being debugged by a debugger
info Queries for the computername
info The file contains an unknown PE resource name possibly indicative of a packer

Rules (7cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch Malicious_Packer_Zero Malicious Packer binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsDLL (no description) binaries (upload)
info IsPE64 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (2cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
benokij.com US HOSTKEY-USA 139.60.161.165 clean
139.60.161.165 US HOSTKEY-USA 139.60.161.165 clean

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.dll
 0x1800761d0 RtlLookupFunctionEntry
 0x1800761d8 RtlUnwindEx
 0x1800761e0 HeapFree
 0x1800761e8 HeapAlloc
 0x1800761f0 RtlPcToFileHeader
 0x1800761f8 TerminateProcess
 0x180076200 UnhandledExceptionFilter
 0x180076208 SetUnhandledExceptionFilter
 0x180076210 IsDebuggerPresent
 0x180076218 RtlVirtualUnwind
 0x180076220 RtlCaptureContext
 0x180076228 GetSystemTimeAsFileTime
 0x180076230 FlsSetValue
 0x180076238 GetCommandLineA
 0x180076240 HeapReAlloc
 0x180076248 HeapQueryInformation
 0x180076250 HeapSize
 0x180076258 VirtualProtect
 0x180076260 VirtualAlloc
 0x180076268 GetSystemInfo
 0x180076270 VirtualQuery
 0x180076278 EncodePointer
 0x180076280 DecodePointer
 0x180076288 FlsGetValue
 0x180076290 FlsFree
 0x180076298 FlsAlloc
 0x1800762a0 HeapSetInformation
 0x1800762a8 HeapCreate
 0x1800762b0 HeapDestroy
 0x1800762b8 GetStdHandle
 0x1800762c0 GetModuleFileNameA
 0x1800762c8 GetACP
 0x1800762d0 GetOEMCP
 0x1800762d8 IsValidCodePage
 0x1800762e0 GetDateFormatA
 0x1800762e8 GetTimeFormatA
 0x1800762f0 SetHandleCount
 0x1800762f8 GetFileType
 0x180076300 GetStartupInfoA
 0x180076308 FreeEnvironmentStringsA
 0x180076310 GetEnvironmentStrings
 0x180076318 FreeEnvironmentStringsW
 0x180076320 GetEnvironmentStringsW
 0x180076328 QueryPerformanceCounter
 0x180076330 InitializeCriticalSectionAndSpinCount
 0x180076338 GetTimeZoneInformation
 0x180076340 LCMapStringA
 0x180076348 LCMapStringW
 0x180076350 GetStringTypeA
 0x180076358 GetStringTypeW
 0x180076360 GetLocaleInfoA
 0x180076368 GetConsoleCP
 0x180076370 GetConsoleMode
 0x180076378 SetStdHandle
 0x180076380 WriteConsoleA
 0x180076388 GetConsoleOutputCP
 0x180076390 WriteConsoleW
 0x180076398 CreateFileA
 0x1800763a0 SetEnvironmentVariableA
 0x1800763a8 GetFileTime
 0x1800763b0 GetFileSizeEx
 0x1800763b8 GetFileAttributesW
 0x1800763c0 FileTimeToLocalFileTime
 0x1800763c8 lstrlenA
 0x1800763d0 CreateFileW
 0x1800763d8 GetFullPathNameW
 0x1800763e0 GetVolumeInformationW
 0x1800763e8 FindFirstFileW
 0x1800763f0 FindClose
 0x1800763f8 GetCurrentProcess
 0x180076400 DuplicateHandle
 0x180076408 GetFileSize
 0x180076410 SetEndOfFile
 0x180076418 UnlockFile
 0x180076420 LockFile
 0x180076428 FlushFileBuffers
 0x180076430 SetFilePointer
 0x180076438 WriteFile
 0x180076440 ReadFile
 0x180076448 GetThreadLocale
 0x180076450 DeleteCriticalSection
 0x180076458 LocalReAlloc
 0x180076460 TlsSetValue
 0x180076468 GlobalHandle
 0x180076470 GlobalReAlloc
 0x180076478 TlsAlloc
 0x180076480 InitializeCriticalSection
 0x180076488 EnterCriticalSection
 0x180076490 TlsGetValue
 0x180076498 LeaveCriticalSection
 0x1800764a0 LocalAlloc
 0x1800764a8 GlobalFlags
 0x1800764b0 GetProfileIntW
 0x1800764b8 FileTimeToSystemTime
 0x1800764c0 CopyFileW
 0x1800764c8 GlobalSize
 0x1800764d0 FormatMessageW
 0x1800764d8 LocalFree
 0x1800764e0 MulDiv
 0x1800764e8 GlobalFindAtomW
 0x1800764f0 CompareStringW
 0x1800764f8 LoadLibraryA
 0x180076500 GetVersionExA
 0x180076508 GetTickCount
 0x180076510 GetPrivateProfileStringW
 0x180076518 lstrlenW
 0x180076520 WritePrivateProfileStringW
 0x180076528 FreeResource
 0x180076530 GetCurrentProcessId
 0x180076538 GlobalAddAtomW
 0x180076540 CloseHandle
 0x180076548 GlobalDeleteAtom
 0x180076550 GetCurrentThread
 0x180076558 GetCurrentThreadId
 0x180076560 ConvertDefaultLocale
 0x180076568 EnumResourceLanguagesW
 0x180076570 lstrcmpA
 0x180076578 GetLocaleInfoW
 0x180076580 CompareStringA
 0x180076588 lstrcmpW
 0x180076590 WideCharToMultiByte
 0x180076598 Sleep
 0x1800765a0 GlobalAlloc
 0x1800765a8 GlobalLock
 0x1800765b0 GlobalUnlock
 0x1800765b8 GlobalFree
 0x1800765c0 lstrcpynW
 0x1800765c8 FreeLibrary
 0x1800765d0 GetVersionExW
 0x1800765d8 MultiByteToWideChar
 0x1800765e0 RaiseException
 0x1800765e8 DebugBreak
 0x1800765f0 LoadResource
 0x1800765f8 LockResource
 0x180076600 SizeofResource
 0x180076608 FindResourceW
 0x180076610 GetModuleHandleW
 0x180076618 LoadLibraryW
 0x180076620 GetProcAddress
 0x180076628 GetLastError
 0x180076630 SetLastError
 0x180076638 GetCommandLineW
 0x180076640 lstrcatW
 0x180076648 GetModuleFileNameW
 0x180076650 CreateProcessW
 0x180076658 GetCPInfo
 0x180076660 ExitProcess
USER32.dll
 0x180076728 InvalidateRgn
 0x180076730 GetNextDlgGroupItem
 0x180076738 MessageBeep
 0x180076740 IsRectEmpty
 0x180076748 WindowFromPoint
 0x180076750 DestroyMenu
 0x180076758 EndPaint
 0x180076760 BeginPaint
 0x180076768 GetWindowDC
 0x180076770 ClientToScreen
 0x180076778 GrayStringW
 0x180076780 DrawTextExW
 0x180076788 TabbedTextOutW
 0x180076790 ShowWindow
 0x180076798 MoveWindow
 0x1800767a0 SetWindowTextW
 0x1800767a8 IsDialogMessageW
 0x1800767b0 RegisterWindowMessageW
 0x1800767b8 SendDlgItemMessageA
 0x1800767c0 SendDlgItemMessageW
 0x1800767c8 WinHelpW
 0x1800767d0 IsChild
 0x1800767d8 GetCapture
 0x1800767e0 GetClassNameW
 0x1800767e8 GetClassLongPtrW
 0x1800767f0 SetPropW
 0x1800767f8 GetPropW
 0x180076800 RemovePropW
 0x180076808 SetFocus
 0x180076810 GetWindowTextLengthW
 0x180076818 GetWindowTextW
 0x180076820 GetTopWindow
 0x180076828 GetWindowLongPtrW
 0x180076830 SetWindowLongPtrW
 0x180076838 CopyAcceleratorTableW
 0x180076840 GetMessageTime
 0x180076848 MapWindowPoints
 0x180076850 TrackPopupMenu
 0x180076858 SetMenu
 0x180076860 GetScrollRange
 0x180076868 GetScrollPos
 0x180076870 SetForegroundWindow
 0x180076878 GetSubMenu
 0x180076880 GetMenuItemID
 0x180076888 CreateWindowExW
 0x180076890 GetClassInfoExW
 0x180076898 GetClassInfoW
 0x1800768a0 RegisterClassW
 0x1800768a8 AdjustWindowRectEx
 0x1800768b0 GetDlgCtrlID
 0x1800768b8 DefWindowProcW
 0x1800768c0 CallWindowProcW
 0x1800768c8 GetMenu
 0x1800768d0 SetWindowLongW
 0x1800768d8 IntersectRect
 0x1800768e0 SystemParametersInfoA
 0x1800768e8 GetWindowPlacement
 0x1800768f0 SetWindowContextHelpId
 0x1800768f8 MapDialogRect
 0x180076900 SetWindowPos
 0x180076908 RegisterClipboardFormatW
 0x180076910 SetActiveWindow
 0x180076918 CreateDialogIndirectParamW
 0x180076920 DestroyWindow
 0x180076928 IsWindow
 0x180076930 GetDlgItem
 0x180076938 GetNextDlgTabItem
 0x180076940 EndDialog
 0x180076948 GetWindowThreadProcessId
 0x180076950 GetWindowLongW
 0x180076958 GetSystemMetrics
 0x180076960 DrawIcon
 0x180076968 AppendMenuW
 0x180076970 SendMessageW
 0x180076978 GetLastActivePopup
 0x180076980 IsWindowEnabled
 0x180076988 MessageBoxW
 0x180076990 SetCursor
 0x180076998 SetWindowsHookExW
 0x1800769a0 CallNextHookEx
 0x1800769a8 GetMessageW
 0x1800769b0 TranslateMessage
 0x1800769b8 DispatchMessageW
 0x1800769c0 GetActiveWindow
 0x1800769c8 IsWindowVisible
 0x1800769d0 PeekMessageW
 0x1800769d8 GetCursorPos
 0x1800769e0 ValidateRect
 0x1800769e8 CharNextW
 0x1800769f0 PostThreadMessageW
 0x1800769f8 CharUpperW
 0x180076a00 GetSysColorBrush
 0x180076a08 SetMenuItemBitmaps
 0x180076a10 GetMenuCheckMarkDimensions
 0x180076a18 LoadCursorW
 0x180076a20 ReleaseCapture
 0x180076a28 SetCapture
 0x180076a30 UnhookWindowsHookEx
 0x180076a38 SetRect
 0x180076a40 GetSystemMenu
 0x180076a48 IsIconic
 0x180076a50 GetClientRect
 0x180076a58 EnableWindow
 0x180076a60 LoadIconW
 0x180076a68 GetFocus
 0x180076a70 PostMessageW
 0x180076a78 GetDC
 0x180076a80 ReleaseDC
 0x180076a88 UpdateWindow
 0x180076a90 InvalidateRect
 0x180076a98 GetWindow
 0x180076aa0 GetParent
 0x180076aa8 PtInRect
 0x180076ab0 InflateRect
 0x180076ab8 OffsetRect
 0x180076ac0 FillRect
 0x180076ac8 GetWindowRect
 0x180076ad0 GetSysColor
 0x180076ad8 GetDesktopWindow
 0x180076ae0 GetKeyState
 0x180076ae8 GetMessagePos
 0x180076af0 SetClipboardData
 0x180076af8 CloseClipboard
 0x180076b00 EmptyClipboard
 0x180076b08 DrawTextW
 0x180076b10 CreatePopupMenu
 0x180076b18 GetMenuItemCount
 0x180076b20 ScreenToClient
 0x180076b28 OpenClipboard
 0x180076b30 CopyRect
 0x180076b38 EqualRect
 0x180076b40 DrawFocusRect
 0x180076b48 PostQuitMessage
 0x180076b50 CheckMenuItem
 0x180076b58 EnableMenuItem
 0x180076b60 GetMenuState
 0x180076b68 ModifyMenuW
 0x180076b70 LoadBitmapW
 0x180076b78 GetForegroundWindow
GDI32.dll
 0x180076078 ExtSelectClipRgn
 0x180076080 DeleteDC
 0x180076088 GetStockObject
 0x180076090 GetDeviceCaps
 0x180076098 CreatePen
 0x1800760a0 CreateSolidBrush
 0x1800760a8 CopyMetaFileW
 0x1800760b0 GetMapMode
 0x1800760b8 GetBkColor
 0x1800760c0 GetTextColor
 0x1800760c8 GetRgnBox
 0x1800760d0 ScaleWindowExtEx
 0x1800760d8 SetWindowExtEx
 0x1800760e0 ScaleViewportExtEx
 0x1800760e8 SetViewportExtEx
 0x1800760f0 OffsetViewportOrgEx
 0x1800760f8 SetViewportOrgEx
 0x180076100 SelectObject
 0x180076108 Escape
 0x180076110 ExtTextOutW
 0x180076118 TextOutW
 0x180076120 RectVisible
 0x180076128 GetTextExtentPoint32W
 0x180076130 GetWindowExtEx
 0x180076138 GetViewportExtEx
 0x180076140 MoveToEx
 0x180076148 LineTo
 0x180076150 SetMapMode
 0x180076158 RestoreDC
 0x180076160 SaveDC
 0x180076168 SetBkColor
 0x180076170 SetTextColor
 0x180076178 GetClipBox
 0x180076180 CreateRectRgnIndirect
 0x180076188 CreateBitmap
 0x180076190 DeleteObject
 0x180076198 CreateFontIndirectW
 0x1800761a0 CreateCompatibleDC
 0x1800761a8 CreateCompatibleBitmap
 0x1800761b0 GetCurrentObject
 0x1800761b8 GetObjectW
 0x1800761c0 PtVisible
COMDLG32.dll
 0x180076068 GetFileTitleW
WINSPOOL.DRV
 0x180076b88 DocumentPropertiesW
 0x180076b90 ClosePrinter
 0x180076b98 OpenPrinterW
ADVAPI32.dll
 0x180076000 RegCreateKeyExW
 0x180076008 RegDeleteValueW
 0x180076010 RegSetValueExW
 0x180076018 RegCloseKey
 0x180076020 RegQueryValueW
 0x180076028 RegOpenKeyW
 0x180076030 RegEnumKeyW
 0x180076038 RegDeleteKeyW
 0x180076040 RegOpenKeyExW
 0x180076048 RegQueryValueExW
SHELL32.dll
 0x1800766f0 ShellExecuteW
COMCTL32.dll
 0x180076058 None
SHLWAPI.dll
 0x180076700 PathFindFileNameW
 0x180076708 PathStripToRootW
 0x180076710 PathIsUNCW
 0x180076718 PathFindExtensionW
oledlg.dll
 0x180076c60 OleUIBusyW
ole32.dll
 0x180076ba8 CreateStreamOnHGlobal
 0x180076bb0 CreateILockBytesOnHGlobal
 0x180076bb8 StgCreateDocfileOnILockBytes
 0x180076bc0 StgOpenStorageOnILockBytes
 0x180076bc8 CoRegisterMessageFilter
 0x180076bd0 CoRevokeClassObject
 0x180076bd8 CoGetClassObject
 0x180076be0 RevokeDragDrop
 0x180076be8 CoLockObjectExternal
 0x180076bf0 RegisterDragDrop
 0x180076bf8 OleFlushClipboard
 0x180076c00 OleIsCurrentClipboard
 0x180076c08 OleDuplicateData
 0x180076c10 CoTaskMemAlloc
 0x180076c18 ReleaseStgMedium
 0x180076c20 CoTaskMemFree
 0x180076c28 CLSIDFromString
 0x180076c30 CLSIDFromProgID
 0x180076c38 OleInitialize
 0x180076c40 CoFreeUnusedLibraries
 0x180076c48 OleUninitialize
 0x180076c50 DoDragDrop
OLEAUT32.dll
 0x180076670 SystemTimeToVariantTime
 0x180076678 VarBstrFromDate
 0x180076680 SysFreeString
 0x180076688 VarUdateFromDate
 0x180076690 VarDateFromStr
 0x180076698 SysAllocStringLen
 0x1800766a0 VariantClear
 0x1800766a8 VariantChangeType
 0x1800766b0 VariantInit
 0x1800766b8 SysStringLen
 0x1800766c0 OleCreateFontIndirect
 0x1800766c8 SafeArrayDestroy
 0x1800766d0 SysAllocString
 0x1800766d8 VariantCopy
 0x1800766e0 VariantTimeToSystemTime

EAT(Export Address Table) Library

0x1800074f0 zFijxQxKeyxOddj


Similarity measure (PE file only) - Checking for service failure