Report - ss.exe

UPX Malicious Library MZP Format PE32 PE File
ScreenShot
Created 2023.03.29 17:35 Machine s1_win7_x6401
Filename ss.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
4
Behavior Score
3.0
ZERO API file : clean
VT API (file)
md5 efd45307df4754e7facbb561fb091721
sha256 6a2c84aa44e56953f4e2af1e6eb79c80997695ad74db5b80a17e2134feff946a
ssdeep 12288:zPDiJJG05qrVujzjkv45nG2JoGhkgGt4z9MqCb4jyKrxo6EbpYx0:rmb3GVsfkv4I2Wi0t4s4jPG6Eb
imphash 97097c6816d59e0e343951d5da613aa6
impfuzzy 192:f30Nk1QnmqbuuSrSUvK9R6ooqEKe7CPbOQ0N:f3L1MSA9HvPbOQ2
  Network IP location

Signature (7cnts)

Level Description
danger Connects to an IP address that is no longer responding to requests (legitimate services will remain up-and-running usually)
watch Communicates with host for which no DNS query was performed
notice A process created a hidden window
notice Allocates read-write-execute memory (usually to unpack itself)
info Checks amount of memory in system
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The file contains an unknown PE resource name possibly indicative of a packer

Rules (5cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (1cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
206.188.197.143 US NETWORK-SOLUTIONS-HOSTING 206.188.197.143 clean

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x463154 DeleteCriticalSection
 0x463158 LeaveCriticalSection
 0x46315c EnterCriticalSection
 0x463160 InitializeCriticalSection
 0x463164 VirtualFree
 0x463168 VirtualAlloc
 0x46316c LocalFree
 0x463170 LocalAlloc
 0x463174 GetVersion
 0x463178 GetCurrentThreadId
 0x46317c InterlockedDecrement
 0x463180 InterlockedIncrement
 0x463184 VirtualQuery
 0x463188 WideCharToMultiByte
 0x46318c MultiByteToWideChar
 0x463190 lstrlenA
 0x463194 lstrcpynA
 0x463198 LoadLibraryExA
 0x46319c GetThreadLocale
 0x4631a0 GetStartupInfoA
 0x4631a4 GetProcAddress
 0x4631a8 GetModuleHandleA
 0x4631ac GetModuleFileNameA
 0x4631b0 GetLocaleInfoA
 0x4631b4 GetCommandLineA
 0x4631b8 FreeLibrary
 0x4631bc FindFirstFileA
 0x4631c0 FindClose
 0x4631c4 ExitProcess
 0x4631c8 WriteFile
 0x4631cc UnhandledExceptionFilter
 0x4631d0 RtlUnwind
 0x4631d4 RaiseException
 0x4631d8 GetStdHandle
user32.dll
 0x4631e0 GetKeyboardType
 0x4631e4 LoadStringA
 0x4631e8 MessageBoxA
 0x4631ec CharNextA
advapi32.dll
 0x4631f4 RegQueryValueExA
 0x4631f8 RegOpenKeyExA
 0x4631fc RegCloseKey
oleaut32.dll
 0x463204 SysFreeString
 0x463208 SysReAllocStringLen
 0x46320c SysAllocStringLen
kernel32.dll
 0x463214 TlsSetValue
 0x463218 TlsGetValue
 0x46321c LocalAlloc
 0x463220 GetModuleHandleA
advapi32.dll
 0x463228 RegQueryValueExA
 0x46322c RegOpenKeyExA
 0x463230 RegCloseKey
kernel32.dll
 0x463238 lstrcpyA
 0x46323c WriteFile
 0x463240 WaitForSingleObject
 0x463244 VirtualQuery
 0x463248 VirtualAlloc
 0x46324c Sleep
 0x463250 SizeofResource
 0x463254 SetThreadLocale
 0x463258 SetFilePointer
 0x46325c SetEvent
 0x463260 SetErrorMode
 0x463264 SetEndOfFile
 0x463268 ResetEvent
 0x46326c ReadFile
 0x463270 MultiByteToWideChar
 0x463274 MulDiv
 0x463278 LockResource
 0x46327c LoadResource
 0x463280 LoadLibraryA
 0x463284 LeaveCriticalSection
 0x463288 InitializeCriticalSection
 0x46328c GlobalUnlock
 0x463290 GlobalReAlloc
 0x463294 GlobalHandle
 0x463298 GlobalLock
 0x46329c GlobalFree
 0x4632a0 GlobalFindAtomA
 0x4632a4 GlobalDeleteAtom
 0x4632a8 GlobalAlloc
 0x4632ac GlobalAddAtomA
 0x4632b0 GetVersionExA
 0x4632b4 GetVersion
 0x4632b8 GetTickCount
 0x4632bc GetThreadLocale
 0x4632c0 GetSystemInfo
 0x4632c4 GetStringTypeExA
 0x4632c8 GetStdHandle
 0x4632cc GetProcAddress
 0x4632d0 GetModuleHandleA
 0x4632d4 GetModuleFileNameA
 0x4632d8 GetLocaleInfoA
 0x4632dc GetLocalTime
 0x4632e0 GetLastError
 0x4632e4 GetFullPathNameA
 0x4632e8 GetDiskFreeSpaceA
 0x4632ec GetDateFormatA
 0x4632f0 GetCurrentThreadId
 0x4632f4 GetCurrentProcessId
 0x4632f8 GetCPInfo
 0x4632fc GetACP
 0x463300 FreeResource
 0x463304 InterlockedExchange
 0x463308 FreeLibrary
 0x46330c FormatMessageA
 0x463310 FindResourceA
 0x463314 EnumCalendarInfoA
 0x463318 EnterCriticalSection
 0x46331c DeleteCriticalSection
 0x463320 CreateThread
 0x463324 CreateFileA
 0x463328 CreateEventA
 0x46332c CompareStringA
 0x463330 CloseHandle
version.dll
 0x463338 VerQueryValueA
 0x46333c GetFileVersionInfoSizeA
 0x463340 GetFileVersionInfoA
gdi32.dll
 0x463348 UnrealizeObject
 0x46334c StrokePath
 0x463350 StretchBlt
 0x463354 SetWindowOrgEx
 0x463358 SetWinMetaFileBits
 0x46335c SetViewportOrgEx
 0x463360 SetTextColor
 0x463364 SetStretchBltMode
 0x463368 SetROP2
 0x46336c SetPixel
 0x463370 SetEnhMetaFileBits
 0x463374 SetDIBColorTable
 0x463378 SetBrushOrgEx
 0x46337c SetBkMode
 0x463380 SetBkColor
 0x463384 SelectPalette
 0x463388 SelectObject
 0x46338c SaveDC
 0x463390 RestoreDC
 0x463394 Rectangle
 0x463398 RectVisible
 0x46339c RealizePalette
 0x4633a0 PlayEnhMetaFile
 0x4633a4 PatBlt
 0x4633a8 MoveToEx
 0x4633ac MaskBlt
 0x4633b0 LineTo
 0x4633b4 IntersectClipRect
 0x4633b8 GetWindowOrgEx
 0x4633bc GetWinMetaFileBits
 0x4633c0 GetTextMetricsA
 0x4633c4 GetTextExtentPoint32A
 0x4633c8 GetSystemPaletteEntries
 0x4633cc GetStockObject
 0x4633d0 GetPixel
 0x4633d4 GetPaletteEntries
 0x4633d8 GetObjectA
 0x4633dc GetEnhMetaFilePaletteEntries
 0x4633e0 GetEnhMetaFileHeader
 0x4633e4 GetEnhMetaFileBits
 0x4633e8 GetDeviceCaps
 0x4633ec GetDIBits
 0x4633f0 GetDIBColorTable
 0x4633f4 GetDCOrgEx
 0x4633f8 GetCurrentPositionEx
 0x4633fc GetClipBox
 0x463400 GetBrushOrgEx
 0x463404 GetBitmapBits
 0x463408 ExcludeClipRect
 0x46340c DeleteObject
 0x463410 DeleteEnhMetaFile
 0x463414 DeleteDC
 0x463418 CreateSolidBrush
 0x46341c CreatePenIndirect
 0x463420 CreatePalette
 0x463424 CreateHalftonePalette
 0x463428 CreateFontIndirectA
 0x46342c CreateDIBitmap
 0x463430 CreateDIBSection
 0x463434 CreateCompatibleDC
 0x463438 CreateCompatibleBitmap
 0x46343c CreateBrushIndirect
 0x463440 CreateBitmap
 0x463444 CopyEnhMetaFileA
 0x463448 BitBlt
user32.dll
 0x463450 CreateWindowExA
 0x463454 WindowFromPoint
 0x463458 WinHelpA
 0x46345c WaitMessage
 0x463460 UpdateWindow
 0x463464 UnregisterClassA
 0x463468 UnhookWindowsHookEx
 0x46346c TranslateMessage
 0x463470 TranslateMDISysAccel
 0x463474 TrackPopupMenu
 0x463478 SystemParametersInfoA
 0x46347c ShowWindow
 0x463480 ShowScrollBar
 0x463484 ShowOwnedPopups
 0x463488 ShowCursor
 0x46348c SetWindowsHookExA
 0x463490 SetWindowPos
 0x463494 SetWindowPlacement
 0x463498 SetWindowLongA
 0x46349c SetTimer
 0x4634a0 SetScrollRange
 0x4634a4 SetScrollPos
 0x4634a8 SetScrollInfo
 0x4634ac SetRect
 0x4634b0 SetPropA
 0x4634b4 SetParent
 0x4634b8 SetMenuItemInfoA
 0x4634bc SetMenu
 0x4634c0 SetForegroundWindow
 0x4634c4 SetFocus
 0x4634c8 SetCursor
 0x4634cc SetClassLongA
 0x4634d0 SetCapture
 0x4634d4 SetActiveWindow
 0x4634d8 SendMessageA
 0x4634dc ScrollWindow
 0x4634e0 ScreenToClient
 0x4634e4 RemovePropA
 0x4634e8 RemoveMenu
 0x4634ec ReleaseDC
 0x4634f0 ReleaseCapture
 0x4634f4 RegisterWindowMessageA
 0x4634f8 RegisterClipboardFormatA
 0x4634fc RegisterClassA
 0x463500 RedrawWindow
 0x463504 PtInRect
 0x463508 PostQuitMessage
 0x46350c PostMessageA
 0x463510 PeekMessageA
 0x463514 OffsetRect
 0x463518 OemToCharA
 0x46351c MessageBoxA
 0x463520 MapWindowPoints
 0x463524 MapVirtualKeyA
 0x463528 LoadStringA
 0x46352c LoadKeyboardLayoutA
 0x463530 LoadIconA
 0x463534 LoadCursorA
 0x463538 LoadBitmapA
 0x46353c KillTimer
 0x463540 IsZoomed
 0x463544 IsWindowVisible
 0x463548 IsWindowEnabled
 0x46354c IsWindow
 0x463550 IsRectEmpty
 0x463554 IsIconic
 0x463558 IsDialogMessageA
 0x46355c IsChild
 0x463560 IsCharLowerA
 0x463564 InvalidateRect
 0x463568 IntersectRect
 0x46356c InsertMenuItemA
 0x463570 InsertMenuA
 0x463574 InflateRect
 0x463578 GetWindowThreadProcessId
 0x46357c GetWindowTextA
 0x463580 GetWindowRect
 0x463584 GetWindowPlacement
 0x463588 GetWindowLongA
 0x46358c GetWindowDC
 0x463590 GetTopWindow
 0x463594 GetSystemMetrics
 0x463598 GetSystemMenu
 0x46359c GetSysColorBrush
 0x4635a0 GetSysColor
 0x4635a4 GetSubMenu
 0x4635a8 GetScrollRange
 0x4635ac GetScrollPos
 0x4635b0 GetScrollInfo
 0x4635b4 GetPropA
 0x4635b8 GetParent
 0x4635bc GetWindow
 0x4635c0 GetMenuStringA
 0x4635c4 GetMenuState
 0x4635c8 GetMenuItemInfoA
 0x4635cc GetMenuItemID
 0x4635d0 GetMenuItemCount
 0x4635d4 GetMenu
 0x4635d8 GetLastActivePopup
 0x4635dc GetKeyboardState
 0x4635e0 GetKeyboardLayoutList
 0x4635e4 GetKeyboardLayout
 0x4635e8 GetKeyState
 0x4635ec GetKeyNameTextA
 0x4635f0 GetIconInfo
 0x4635f4 GetForegroundWindow
 0x4635f8 GetFocus
 0x4635fc GetDesktopWindow
 0x463600 GetDCEx
 0x463604 GetDC
 0x463608 GetCursorPos
 0x46360c GetCursor
 0x463610 GetClipboardData
 0x463614 GetClientRect
 0x463618 GetClassNameA
 0x46361c GetClassInfoA
 0x463620 GetCapture
 0x463624 GetActiveWindow
 0x463628 FrameRect
 0x46362c FindWindowA
 0x463630 FillRect
 0x463634 EqualRect
 0x463638 EnumWindows
 0x46363c EnumThreadWindows
 0x463640 EndPaint
 0x463644 EnableWindow
 0x463648 EnableScrollBar
 0x46364c EnableMenuItem
 0x463650 DrawTextA
 0x463654 DrawMenuBar
 0x463658 DrawIconEx
 0x46365c DrawIcon
 0x463660 DrawFrameControl
 0x463664 DrawFocusRect
 0x463668 DrawEdge
 0x46366c DispatchMessageA
 0x463670 DestroyWindow
 0x463674 DestroyMenu
 0x463678 DestroyIcon
 0x46367c DestroyCursor
 0x463680 DeleteMenu
 0x463684 DefWindowProcA
 0x463688 DefMDIChildProcA
 0x46368c DefFrameProcA
 0x463690 CreatePopupMenu
 0x463694 CreateMenu
 0x463698 CreateIcon
 0x46369c ClientToScreen
 0x4636a0 CheckMenuItem
 0x4636a4 CallWindowProcA
 0x4636a8 CallNextHookEx
 0x4636ac BeginPaint
 0x4636b0 CharNextA
 0x4636b4 CharLowerBuffA
 0x4636b8 CharLowerA
 0x4636bc CharUpperBuffA
 0x4636c0 CharToOemA
 0x4636c4 AdjustWindowRectEx
 0x4636c8 ActivateKeyboardLayout
kernel32.dll
 0x4636d0 Sleep
oleaut32.dll
 0x4636d8 SafeArrayPtrOfIndex
 0x4636dc SafeArrayPutElement
 0x4636e0 SafeArrayGetElement
 0x4636e4 SafeArrayUnaccessData
 0x4636e8 SafeArrayAccessData
 0x4636ec SafeArrayGetUBound
 0x4636f0 SafeArrayGetLBound
 0x4636f4 SafeArrayCreate
 0x4636f8 VariantChangeType
 0x4636fc VariantCopyInd
 0x463700 VariantCopy
 0x463704 VariantClear
 0x463708 VariantInit
ole32.dll
 0x463710 CoUninitialize
 0x463714 CoInitialize
oleaut32.dll
 0x46371c GetErrorInfo
 0x463720 SysFreeString
comctl32.dll
 0x463728 ImageList_SetIconSize
 0x46372c ImageList_GetIconSize
 0x463730 ImageList_Write
 0x463734 ImageList_Read
 0x463738 ImageList_GetDragImage
 0x46373c ImageList_DragShowNolock
 0x463740 ImageList_SetDragCursorImage
 0x463744 ImageList_DragMove
 0x463748 ImageList_DragLeave
 0x46374c ImageList_DragEnter
 0x463750 ImageList_EndDrag
 0x463754 ImageList_BeginDrag
 0x463758 ImageList_Remove
 0x46375c ImageList_DrawEx
 0x463760 ImageList_Replace
 0x463764 ImageList_Draw
 0x463768 ImageList_GetBkColor
 0x46376c ImageList_SetBkColor
 0x463770 ImageList_ReplaceIcon
 0x463774 ImageList_Add
 0x463778 ImageList_GetImageCount
 0x46377c ImageList_Destroy
 0x463780 ImageList_Create
shell32.dll
 0x463788 ShellExecuteExA

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure