Report - Vyhakaweykhdlxdskadtnsbyrarglkacvy.exe

UPX Malicious Library PE32 PE File
ScreenShot
Created 2022.04.13 17:41 Machine s1_win7_x6403
Filename Vyhakaweykhdlxdskadtnsbyrarglkacvy.exe
Type PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
AI Score
5
Behavior Score
2.0
ZERO API file : malware
VT API (file) 17 detected (Unsafe, MalPbs, gen1, malicious, high confidence, Dico, RATX, Infected, moderate, score, Sabsik, Artemis, Limpopo, susgen, ZelphiF, 9G0@aCeXv6ci)
md5 f437e68bcfe259663e8d3366bdd44b6c
sha256 3ba7ad2a718413ab6d36dd156bbdd5ac1bcca860f039b14c4cb4382aee58bc88
ssdeep 12288:nL7vh24ii6f8UmV9cSzr2VcLVJ8evldpWmSwjWxgJaTAYBBXK3cUbBgQrS5pZJ5Q:n/5RK09Hf2mhJ8edbSwjs5TJBTwYb
imphash e70ebf13be6a24042d117ba668cc8eb8
impfuzzy 192:ot3MDeuucUSUvMK9ELojXEAk7RfvVG1uTFUPbOQHS:E3RcU9fv1uxUPbOQy
  Network IP location

Signature (6cnts)

Level Description
watch File has been identified by 17 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The executable uses a known packer

Rules (4cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (2cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
cutting-tools.in US PUBLIC-DOMAIN-REGISTRY 162.215.240.160 malware
162.215.240.160 US PUBLIC-DOMAIN-REGISTRY 162.215.240.160 mailcious

Suricata ids

PE API

IAT(Import Address Table) Library

oleaut32.dll
 0x497858 SysFreeString
 0x49785c SysReAllocStringLen
 0x497860 SysAllocStringLen
advapi32.dll
 0x497868 RegQueryValueExA
 0x49786c RegOpenKeyExA
 0x497870 RegCloseKey
user32.dll
 0x497878 GetKeyboardType
 0x49787c DestroyWindow
 0x497880 LoadStringA
 0x497884 MessageBoxA
 0x497888 CharNextA
kernel32.dll
 0x497890 GetACP
 0x497894 Sleep
 0x497898 VirtualFree
 0x49789c VirtualAlloc
 0x4978a0 GetTickCount
 0x4978a4 QueryPerformanceCounter
 0x4978a8 GetCurrentThreadId
 0x4978ac InterlockedDecrement
 0x4978b0 InterlockedIncrement
 0x4978b4 VirtualQuery
 0x4978b8 WideCharToMultiByte
 0x4978bc MultiByteToWideChar
 0x4978c0 lstrlenA
 0x4978c4 lstrcpynA
 0x4978c8 LoadLibraryExA
 0x4978cc GetThreadLocale
 0x4978d0 GetStartupInfoA
 0x4978d4 GetProcAddress
 0x4978d8 GetModuleHandleA
 0x4978dc GetModuleFileNameA
 0x4978e0 GetLocaleInfoA
 0x4978e4 GetCommandLineA
 0x4978e8 FreeLibrary
 0x4978ec FindFirstFileA
 0x4978f0 FindClose
 0x4978f4 ExitProcess
 0x4978f8 CompareStringA
 0x4978fc WriteFile
 0x497900 UnhandledExceptionFilter
 0x497904 RtlUnwind
 0x497908 RaiseException
 0x49790c GetStdHandle
kernel32.dll
 0x497914 TlsSetValue
 0x497918 TlsGetValue
 0x49791c LocalAlloc
 0x497920 GetModuleHandleA
user32.dll
 0x497928 CreateWindowExA
 0x49792c WindowFromPoint
 0x497930 WaitMessage
 0x497934 UpdateWindow
 0x497938 UnregisterClassA
 0x49793c UnionRect
 0x497940 UnhookWindowsHookEx
 0x497944 TranslateMessage
 0x497948 TranslateMDISysAccel
 0x49794c TrackPopupMenu
 0x497950 SystemParametersInfoA
 0x497954 ShowWindow
 0x497958 ShowScrollBar
 0x49795c ShowOwnedPopups
 0x497960 ShowCaret
 0x497964 SetWindowsHookExA
 0x497968 SetWindowPos
 0x49796c SetWindowPlacement
 0x497970 SetWindowLongW
 0x497974 SetWindowLongA
 0x497978 SetTimer
 0x49797c SetScrollRange
 0x497980 SetScrollPos
 0x497984 SetScrollInfo
 0x497988 SetRectEmpty
 0x49798c SetRect
 0x497990 SetPropA
 0x497994 SetParent
 0x497998 SetMenuItemInfoA
 0x49799c SetMenu
 0x4979a0 SetForegroundWindow
 0x4979a4 SetFocus
 0x4979a8 SetCursor
 0x4979ac SetClipboardData
 0x4979b0 SetClassLongA
 0x4979b4 SetCapture
 0x4979b8 SetActiveWindow
 0x4979bc SendMessageW
 0x4979c0 SendMessageA
 0x4979c4 ScrollWindow
 0x4979c8 ScreenToClient
 0x4979cc RemovePropA
 0x4979d0 RemoveMenu
 0x4979d4 ReleaseDC
 0x4979d8 ReleaseCapture
 0x4979dc RegisterWindowMessageA
 0x4979e0 RegisterClipboardFormatA
 0x4979e4 RegisterClassExA
 0x4979e8 RegisterClassA
 0x4979ec RedrawWindow
 0x4979f0 PtInRect
 0x4979f4 PostQuitMessage
 0x4979f8 PostMessageA
 0x4979fc PeekMessageW
 0x497a00 PeekMessageA
 0x497a04 OpenClipboard
 0x497a08 OffsetRect
 0x497a0c OemToCharA
 0x497a10 NotifyWinEvent
 0x497a14 MessageBoxA
 0x497a18 MessageBeep
 0x497a1c MapWindowPoints
 0x497a20 MapVirtualKeyA
 0x497a24 LoadStringA
 0x497a28 LoadKeyboardLayoutA
 0x497a2c LoadImageA
 0x497a30 LoadIconA
 0x497a34 LoadCursorA
 0x497a38 LoadBitmapA
 0x497a3c KillTimer
 0x497a40 IsZoomed
 0x497a44 IsWindowVisible
 0x497a48 IsWindowUnicode
 0x497a4c IsWindowEnabled
 0x497a50 IsWindow
 0x497a54 IsRectEmpty
 0x497a58 IsIconic
 0x497a5c IsDialogMessageW
 0x497a60 IsDialogMessageA
 0x497a64 IsChild
 0x497a68 InvalidateRect
 0x497a6c IntersectRect
 0x497a70 InsertMenuItemA
 0x497a74 InsertMenuA
 0x497a78 InflateRect
 0x497a7c HideCaret
 0x497a80 GetWindowThreadProcessId
 0x497a84 GetWindowTextA
 0x497a88 GetWindowRect
 0x497a8c GetWindowPlacement
 0x497a90 GetWindowLongW
 0x497a94 GetWindowLongA
 0x497a98 GetWindowDC
 0x497a9c GetTopWindow
 0x497aa0 GetSystemMetrics
 0x497aa4 GetSystemMenu
 0x497aa8 GetSysColorBrush
 0x497aac GetSysColor
 0x497ab0 GetSubMenu
 0x497ab4 GetScrollRange
 0x497ab8 GetScrollPos
 0x497abc GetScrollInfo
 0x497ac0 GetPropA
 0x497ac4 GetParent
 0x497ac8 GetWindow
 0x497acc GetMessagePos
 0x497ad0 GetMessageA
 0x497ad4 GetMenuStringA
 0x497ad8 GetMenuState
 0x497adc GetMenuItemInfoA
 0x497ae0 GetMenuItemID
 0x497ae4 GetMenuItemCount
 0x497ae8 GetMenu
 0x497aec GetLastActivePopup
 0x497af0 GetKeyboardState
 0x497af4 GetKeyboardLayoutNameA
 0x497af8 GetKeyboardLayoutList
 0x497afc GetKeyboardLayout
 0x497b00 GetKeyState
 0x497b04 GetKeyNameTextA
 0x497b08 GetIconInfo
 0x497b0c GetForegroundWindow
 0x497b10 GetFocus
 0x497b14 GetDesktopWindow
 0x497b18 GetDCEx
 0x497b1c GetDC
 0x497b20 GetCursorPos
 0x497b24 GetCursor
 0x497b28 GetClipboardData
 0x497b2c GetClientRect
 0x497b30 GetClassLongA
 0x497b34 GetClassInfoA
 0x497b38 GetCapture
 0x497b3c GetActiveWindow
 0x497b40 FrameRect
 0x497b44 FindWindowA
 0x497b48 FillRect
 0x497b4c EqualRect
 0x497b50 EnumWindows
 0x497b54 EnumThreadWindows
 0x497b58 EnumChildWindows
 0x497b5c EndPaint
 0x497b60 EnableWindow
 0x497b64 EnableScrollBar
 0x497b68 EnableMenuItem
 0x497b6c EmptyClipboard
 0x497b70 DrawTextA
 0x497b74 DrawStateA
 0x497b78 DrawMenuBar
 0x497b7c DrawIconEx
 0x497b80 DrawIcon
 0x497b84 DrawFrameControl
 0x497b88 DrawEdge
 0x497b8c DispatchMessageW
 0x497b90 DispatchMessageA
 0x497b94 DestroyWindow
 0x497b98 DestroyMenu
 0x497b9c DestroyIcon
 0x497ba0 DestroyCursor
 0x497ba4 DeleteMenu
 0x497ba8 DefWindowProcA
 0x497bac DefMDIChildProcA
 0x497bb0 DefFrameProcA
 0x497bb4 CreatePopupMenu
 0x497bb8 CreateMenu
 0x497bbc CreateIcon
 0x497bc0 CopyImage
 0x497bc4 CloseClipboard
 0x497bc8 ClientToScreen
 0x497bcc CheckMenuItem
 0x497bd0 CharNextW
 0x497bd4 CallWindowProcA
 0x497bd8 CallNextHookEx
 0x497bdc BeginPaint
 0x497be0 CharNextA
 0x497be4 CharLowerBuffA
 0x497be8 CharLowerA
 0x497bec CharUpperBuffA
 0x497bf0 CharToOemA
 0x497bf4 AdjustWindowRectEx
 0x497bf8 ActivateKeyboardLayout
gdi32.dll
 0x497c00 UnrealizeObject
 0x497c04 StretchBlt
 0x497c08 SetWindowOrgEx
 0x497c0c SetWinMetaFileBits
 0x497c10 SetViewportOrgEx
 0x497c14 SetTextColor
 0x497c18 SetStretchBltMode
 0x497c1c SetROP2
 0x497c20 SetPixel
 0x497c24 SetMapMode
 0x497c28 SetEnhMetaFileBits
 0x497c2c SetDIBColorTable
 0x497c30 SetBrushOrgEx
 0x497c34 SetBkMode
 0x497c38 SetBkColor
 0x497c3c SetBitmapBits
 0x497c40 SelectPalette
 0x497c44 SelectObject
 0x497c48 SaveDC
 0x497c4c RestoreDC
 0x497c50 Rectangle
 0x497c54 RectVisible
 0x497c58 RealizePalette
 0x497c5c Polyline
 0x497c60 Polygon
 0x497c64 PlayEnhMetaFile
 0x497c68 PatBlt
 0x497c6c MoveToEx
 0x497c70 MaskBlt
 0x497c74 LineTo
 0x497c78 IntersectClipRect
 0x497c7c GetWindowOrgEx
 0x497c80 GetWinMetaFileBits
 0x497c84 GetTextMetricsA
 0x497c88 GetTextExtentPointA
 0x497c8c GetTextExtentPoint32A
 0x497c90 GetSystemPaletteEntries
 0x497c94 GetStockObject
 0x497c98 GetRgnBox
 0x497c9c GetPolyFillMode
 0x497ca0 GetPixel
 0x497ca4 GetPaletteEntries
 0x497ca8 GetObjectA
 0x497cac GetMapMode
 0x497cb0 GetEnhMetaFilePaletteEntries
 0x497cb4 GetEnhMetaFileHeader
 0x497cb8 GetEnhMetaFileBits
 0x497cbc GetDeviceCaps
 0x497cc0 GetDIBits
 0x497cc4 GetDIBColorTable
 0x497cc8 GetDCOrgEx
 0x497ccc GetDCPenColor
 0x497cd0 GetDCBrushColor
 0x497cd4 GetCurrentPositionEx
 0x497cd8 GetClipBox
 0x497cdc GetBrushOrgEx
 0x497ce0 GetBkColor
 0x497ce4 GetBitmapBits
 0x497ce8 GdiFlush
 0x497cec ExcludeClipRect
 0x497cf0 DeleteObject
 0x497cf4 DeleteEnhMetaFile
 0x497cf8 DeleteDC
 0x497cfc CreateSolidBrush
 0x497d00 CreatePenIndirect
 0x497d04 CreatePalette
 0x497d08 CreateHalftonePalette
 0x497d0c CreateFontIndirectA
 0x497d10 CreateFontA
 0x497d14 CreateDIBitmap
 0x497d18 CreateDIBSection
 0x497d1c CreateCompatibleDC
 0x497d20 CreateCompatibleBitmap
 0x497d24 CreateBrushIndirect
 0x497d28 CreateBitmap
 0x497d2c CopyEnhMetaFileA
 0x497d30 BitBlt
version.dll
 0x497d38 VerQueryValueA
 0x497d3c GetFileVersionInfoSizeA
 0x497d40 GetFileVersionInfoA
kernel32.dll
 0x497d48 lstrcpyA
 0x497d4c WriteFile
 0x497d50 WideCharToMultiByte
 0x497d54 WaitForSingleObject
 0x497d58 VirtualQuery
 0x497d5c VirtualProtect
 0x497d60 VirtualAlloc
 0x497d64 SizeofResource
 0x497d68 SetThreadLocale
 0x497d6c SetFilePointer
 0x497d70 SetEvent
 0x497d74 SetErrorMode
 0x497d78 SetEndOfFile
 0x497d7c ResetEvent
 0x497d80 ReadFile
 0x497d84 MultiByteToWideChar
 0x497d88 MulDiv
 0x497d8c LockResource
 0x497d90 LoadResource
 0x497d94 LoadLibraryA
 0x497d98 LeaveCriticalSection
 0x497d9c InitializeCriticalSection
 0x497da0 GlobalUnlock
 0x497da4 GlobalReAlloc
 0x497da8 GlobalHandle
 0x497dac GlobalLock
 0x497db0 GlobalFree
 0x497db4 GlobalFindAtomA
 0x497db8 GlobalDeleteAtom
 0x497dbc GlobalAlloc
 0x497dc0 GlobalAddAtomA
 0x497dc4 GetVersionExA
 0x497dc8 GetVersion
 0x497dcc GetTickCount
 0x497dd0 GetThreadLocale
 0x497dd4 GetStdHandle
 0x497dd8 GetProcAddress
 0x497ddc GetModuleHandleA
 0x497de0 GetModuleFileNameA
 0x497de4 GetLocaleInfoA
 0x497de8 GetLocalTime
 0x497dec GetLastError
 0x497df0 GetFullPathNameA
 0x497df4 GetFileAttributesA
 0x497df8 GetDiskFreeSpaceA
 0x497dfc GetDateFormatA
 0x497e00 GetCurrentThreadId
 0x497e04 GetCurrentProcessId
 0x497e08 GetCPInfo
 0x497e0c FreeResource
 0x497e10 InterlockedExchange
 0x497e14 FreeLibrary
 0x497e18 FormatMessageA
 0x497e1c FindResourceA
 0x497e20 EnumCalendarInfoA
 0x497e24 EnterCriticalSection
 0x497e28 DeleteFileA
 0x497e2c DeleteCriticalSection
 0x497e30 CreateThread
 0x497e34 CreateFileA
 0x497e38 CreateEventA
 0x497e3c CompareStringA
 0x497e40 CloseHandle
advapi32.dll
 0x497e48 RegQueryValueExA
 0x497e4c RegOpenKeyExA
 0x497e50 RegFlushKey
 0x497e54 RegCreateKeyExA
 0x497e58 RegCloseKey
winmm.dll
 0x497e60 sndPlaySoundA
 0x497e64 PlaySoundA
shell32.dll
 0x497e6c ShellExecuteA
oleaut32.dll
 0x497e74 GetErrorInfo
 0x497e78 VariantInit
 0x497e7c SysFreeString
ole32.dll
 0x497e84 CoUninitialize
 0x497e88 CoInitialize
kernel32.dll
 0x497e90 Sleep
oleaut32.dll
 0x497e98 SafeArrayPtrOfIndex
 0x497e9c SafeArrayPutElement
 0x497ea0 SafeArrayGetElement
 0x497ea4 SafeArrayUnaccessData
 0x497ea8 SafeArrayAccessData
 0x497eac SafeArrayGetUBound
 0x497eb0 SafeArrayGetLBound
 0x497eb4 SafeArrayCreate
 0x497eb8 VariantChangeType
 0x497ebc VariantCopyInd
 0x497ec0 VariantCopy
 0x497ec4 VariantClear
 0x497ec8 VariantInit
comctl32.dll
 0x497ed0 _TrackMouseEvent
 0x497ed4 ImageList_SetIconSize
 0x497ed8 ImageList_GetIconSize
 0x497edc ImageList_Write
 0x497ee0 ImageList_Read
 0x497ee4 ImageList_GetDragImage
 0x497ee8 ImageList_DragShowNolock
 0x497eec ImageList_DragMove
 0x497ef0 ImageList_DragLeave
 0x497ef4 ImageList_DragEnter
 0x497ef8 ImageList_EndDrag
 0x497efc ImageList_BeginDrag
 0x497f00 ImageList_Remove
 0x497f04 ImageList_DrawEx
 0x497f08 ImageList_Replace
 0x497f0c ImageList_Draw
 0x497f10 ImageList_GetBkColor
 0x497f14 ImageList_SetBkColor
 0x497f18 ImageList_Add
 0x497f1c ImageList_GetImageCount
 0x497f20 ImageList_Destroy
 0x497f24 ImageList_Create
oleacc.dll
 0x497f2c LresultFromObject

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure