Report - 2

UPX DLL PE32 PE File
ScreenShot
Created 2023.04.25 07:34 Machine s1_win7_x6403
Filename 2
Type PE32 executable (DLL) (console) Intel 80386, for MS Windows
AI Score
1
Behavior Score
1.4
ZERO API file : clean
VT API (file)
md5 9b776e3f4d86ccb06d787012eae66c09
sha256 935adf3f245f0e4e5e3e0d79a04e758de081d5a165b118df7038764ec38c2f6f
ssdeep 3072:y0oWwSUTRjn/6XZHApSHMhOpOMdINWzI6rSZeamGQzqhQnyCTSa8hYEbqXdfNGhB:WljnbpQuMewlrSZqGja8UG+j0q4v
imphash 3f4fc0c267a8853d2a78e06cced37d98
impfuzzy 6:pWv42gJwduYYygJ2Z+OYMETOGrOHMREcJ8iPEcJ37+OxXh4e3xUAZVebpje:zZwd9YTds3wXJXPXJqORhlvZ8Ne
  Network IP location

Signature (5cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice The binary likely contains encrypted or compressed data indicative of a packer
info Checks if process is being debugged by a debugger
info One or more processes crashed
info This executable has a PDB path

Rules (4cnts)

Level Name Description Collection
watch UPX_Zero UPX packed file binaries (upload)
info IsDLL (no description) binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.dll
 0x55937000 WriteFile
 0x55937004 GetStdHandle
 0x55937008 ReadFile
 0x5593700c InterlockedExchange
 0x55937010 Sleep
 0x55937014 InterlockedCompareExchange
 0x55937018 TerminateProcess
 0x5593701c GetCurrentProcess
 0x55937020 UnhandledExceptionFilter
 0x55937024 SetUnhandledExceptionFilter
 0x55937028 IsDebuggerPresent
 0x5593702c DisableThreadLibraryCalls
 0x55937030 QueryPerformanceCounter
 0x55937034 GetTickCount
 0x55937038 GetCurrentThreadId
 0x5593703c GetCurrentProcessId
 0x55937040 GetSystemTimeAsFileTime

EAT(Export Address Table) Library

0x559229f6 I?0?$WeakImplHelper1@VXAbortChannel@task@star@sun@com@@@cppu@@QAE@ABV01@@Z
0x559223ac I?0?$WeakImplHelper1@VXAbortChannel@task@star@sun@com@@@cppu@@QAE@XZ
0x55922a26 I?0AbortChannel@dp_misc@@QAE@ABV01@@Z
0x55922978 I?0AbortChannel@dp_misc@@QAE@XZ
0x559276b2 I?0DescriptionInfoset@dp_misc@@QAE@ABV01@@Z
0x5592a8fe I?0DescriptionInfoset@dp_misc@@QAE@ABV?$Reference@VXComponentContext@uno@star@sun@com@@@uno@star@sun@com@@ABV?$Reference@VXNode@dom@xml@star@sun@com@@@3456@@Z
0x55926cfd I?0SimpleLicenseAttributes@dp_misc@@QAE@ABU01@@Z
0x55926cb5 I?0SimpleLicenseAttributes@dp_misc@@QAE@XZ
0x55921664 I?1?$WeakImplHelper1@VXAbortChannel@task@star@sun@com@@@cppu@@UAE@XZ
0x559223cd I?1AbortChannel@dp_misc@@UAE@XZ
0x5592797d I?1DescriptionInfoset@dp_misc@@QAE@XZ
0x55926cdc I?1SimpleLicenseAttributes@dp_misc@@QAE@XZ
0x5592583f I?4?$StaticWithInit@$$CBVOUString@rtl@@UStrTitle@dp_misc@@U34@$$CBV12@@rtl@@QAEAAV01@ABV01@@Z
0x55922a21 I?4?$WeakImplHelper1@VXAbortChannel@task@star@sun@com@@@cppu@@QAEAAV01@ABV01@@Z
0x5592312a I?4AbortChannel@dp_misc@@QAEAAV01@ABV01@@Z
0x55928ef5 I?4DescriptionInfoset@dp_misc@@QAEAAV01@ABV01@@Z
0x55926d35 I?4SimpleLicenseAttributes@dp_misc@@QAEAAU01@ABU01@@Z
0x55925844 I?4StrTitle@dp_misc@@QAEAAU01@ABU01@@Z
0x5592586c I?RStrTitle@dp_misc@@QAE?BVOUString@rtl@@XZ
0x5593771c I?_7AbortChannel@dp_misc@@6BOWeakObject@cppu@@@
0x559376f0 I?_7AbortChannel@dp_misc@@6BXAbortChannel@task@star@sun@com@@@
0x55937704 I?_7AbortChannel@dp_misc@@6BXTypeProvider@lang@star@sun@com@@@
0x55921fbe ITRACE@dp_misc@@YAXABVOString@rtl@@@Z
0x55921fbd ITRACE@dp_misc@@YAXABVOUString@rtl@@@Z
0x55921fd9 Iacquire@?$WeakImplHelper1@VXAbortChannel@task@star@sun@com@@@cppu@@UAAXXZ
0x5592c9ef Icheck@Dependencies@dp_misc@@YA?AV?$Sequence@V?$Reference@VXElement@dom@xml@star@sun@com@@@uno@star@sun@com@@@uno@star@sun@com@@ABVDescriptionInfoset@2@@Z
0x5592b46e IcheckBlacklist@DescriptionInfoset@dp_misc@@ABEXXZ
0x559279cc IcheckBlacklistVersion@DescriptionInfoset@dp_misc@@ABE_NVOUString@rtl@@ABV?$Sequence@VOUString@rtl@@@uno@star@sun@com@@@Z
0x55926a89 IcompareVersions@dp_misc@@YA?AW4Order@1@ABVOUString@rtl@@0@Z
0x55926352 Icreate_folder@dp_misc@@YA_NPAVContent@ucbhelper@@ABVOUString@rtl@@ABV?$Reference@VXCommandEnvironment@ucb@star@sun@com@@@uno@star@sun@com@@_N@Z
0x55925afd Icreate_ucb_content@dp_misc@@YA_NPAVContent@ucbhelper@@ABVOUString@rtl@@ABV?$Reference@VXCommandEnvironment@ucb@star@sun@com@@@uno@star@sun@com@@_N@Z
0x55925b90 Ierase_path@dp_misc@@YA_NABVOUString@rtl@@ABV?$Reference@VXCommandEnvironment@ucb@star@sun@com@@@uno@star@sun@com@@_N@Z
0x55923ea8 IexpandUnoRcTerm@dp_misc@@YA?AVOUString@rtl@@ABV23@@Z
0x55923eee IexpandUnoRcUrl@dp_misc@@YA?AVOUString@rtl@@ABV23@@Z
0x55924c10 IgenerateIdentifier@dp_misc@@YA?AVOUString@rtl@@ABV?$optional@VOUString@rtl@@@boost@@ABV23@@Z
0x55924ad4 IgenerateLegacyIdentifier@dp_misc@@YA?AVOUString@rtl@@ABV23@@Z
0x55922e06 IgenerateRandomPipeId@dp_misc@@YA?AVOUString@rtl@@XZ
0x559262af Iget@?$StaticWithInit@$$CBVOUString@rtl@@UStrTitle@dp_misc@@U34@$$CBV12@@rtl@@SAABVOUString@2@XZ
0x559229e1 Iget@AbortChannel@dp_misc@@SAPAV12@ABV?$Reference@VXAbortChannel@task@star@sun@com@@@uno@star@sun@com@@@Z
0x559287f8 IgetChildWithDefaultLocale@DescriptionInfoset@dp_misc@@ABE?AV?$Reference@VXNode@dom@xml@star@sun@com@@@uno@star@sun@com@@ABV34567@@Z
0x5592bc20 IgetDependencies@DescriptionInfoset@dp_misc@@QBE?AV?$Reference@VXNodeList@dom@xml@star@sun@com@@@uno@star@sun@com@@XZ
0x5592ac24 IgetDescriptionInfoset@dp_misc@@YA?AVDescriptionInfoset@1@ABVOUString@rtl@@@Z
0x5592c2e8 IgetErrorText@Dependencies@dp_misc@@YA?AVOUString@rtl@@ABV?$Reference@VXElement@dom@xml@star@sun@com@@@uno@star@sun@com@@@Z
0x5592e2ae IgetExtensionDefaultUpdateURL@dp_misc@@YA?AVOUString@rtl@@XZ
0x5592f157 IgetExtensionWithHighestVersion@dp_misc@@YA?AV?$Reference@VXPackage@deployment@star@sun@com@@@uno@star@sun@com@@ABV?$Sequence@V?$Reference@VXPackage@deployment@star@sun@com@@@uno@star@sun@com@@@3456@@Z
0x5592e3fb IgetHighestVersion@dp_misc@@YA?AVOUString@rtl@@ABV23@000@Z
0x559298b2 IgetIconURL@DescriptionInfoset@dp_misc@@QBE?AVOUString@rtl@@E@Z
0x5592b41a IgetIdentifier@DescriptionInfoset@dp_misc@@QBE?AV?$optional@VOUString@rtl@@@boost@@XZ
0x55924b4b IgetIdentifier@dp_misc@@YA?AVOUString@rtl@@ABV?$Reference@VXPackage@deployment@star@sun@com@@@uno@star@sun@com@@@Z
0x55923e3c IgetImplementationId@?$WeakImplHelper1@VXAbortChannel@task@star@sun@com@@@cppu@@UAA?AV?$Sequence@C@uno@star@sun@com@@XZ
0x55929252 IgetLocalizedChild@DescriptionInfoset@dp_misc@@ABE?AV?$Reference@VXNode@dom@xml@star@sun@com@@@uno@star@sun@com@@ABVOUString@rtl@@@Z
0x55921000 IgetLocalizedDescriptionURL@DescriptionInfoset@dp_misc@@QBE?AVOUString@rtl@@XZ
0x55929c98 IgetLocalizedDisplayName@DescriptionInfoset@dp_misc@@QBE?AVOUString@rtl@@XZ
0x5592945a IgetLocalizedHREFAttrFromChild@DescriptionInfoset@dp_misc@@ABE?AVOUString@rtl@@ABV34@PA_N@Z
0x55929ddc IgetLocalizedLicenseURL@DescriptionInfoset@dp_misc@@QBE?AVOUString@rtl@@XZ
0x559299db IgetLocalizedPublisherNameAndURL@DescriptionInfoset@dp_misc@@QBE?AU?$pair@VOUString@rtl@@V12@@std@@XZ
0x55929c42 IgetLocalizedReleaseNotesURL@DescriptionInfoset@dp_misc@@QBE?AVOUString@rtl@@XZ
0x5592ad5b IgetLocalizedUpdateWebsiteURL@DescriptionInfoset@dp_misc@@QBE?AV?$optional@VOUString@rtl@@@boost@@XZ
0x55928184 IgetNodeValueFromExpression@DescriptionInfoset@dp_misc@@ABE?AVOUString@rtl@@ABV34@@Z
0x55924811 IgetOfficeLocale@dp_misc@@YA?AULocale@lang@star@sun@com@@XZ
0x55924845 IgetOfficeLocaleString@dp_misc@@YA?AVOUString@rtl@@XZ
0x55930b74 IgetOnlineUpdateInfos@dp_misc@@YA?AV?$map@VOUString@rtl@@UUpdateInfo@dp_misc@@U?$less@VOUString@rtl@@@std@@V?$allocator@U?$pair@$$CBVOUString@rtl@@UUpdateInfo@dp_misc@@@std@@@6@@std@@ABV?$Reference@VXComponentContext@uno@star@sun@com@@@uno@star@sun@com@@ABV?$Reference@VXExtensionManager@deployment@star@sun@com@@@5678@ABV?$Reference@VXUpdateInformationProvider@deployment@star@sun@com@@@5678@PBV?$vector@V?$Reference@VXPackage@deployment@star@sun@com@@@uno@star@sun@com@@V?$allocator@V?$Reference@VXPackage@depl
0x5592ae83 IgetOptionalValue@DescriptionInfoset@dp_misc@@ABE?AV?$optional@VOUString@rtl@@@boost@@ABVOUString@rtl@@@Z
0x5592e07d IgetPlatformString@dp_misc@@YAABVOUString@rtl@@XZ
0x55924984 IgetResourceString@dp_misc@@YA?AVString@@G@Z
0x5592afaf IgetSimpleLicenseAttributes@DescriptionInfoset@dp_misc@@QBE?AV?$optional@USimpleLicenseAttributes@dp_misc@@@boost@@XZ
0x5592c00d IgetSupportedPlaforms@DescriptionInfoset@dp_misc@@QBE?AV?$Sequence@VOUString@rtl@@@uno@star@sun@com@@XZ
0x55923e08 IgetTypes@?$WeakImplHelper1@VXAbortChannel@task@star@sun@com@@@cppu@@UAA?AV?$Sequence@VType@uno@star@sun@com@@@uno@star@sun@com@@XZ
0x5592985e IgetUpdateDownloadUrls@DescriptionInfoset@dp_misc@@QBE?AV?$Sequence@VOUString@rtl@@@uno@star@sun@com@@XZ
0x5592980a IgetUpdateInformationUrls@DescriptionInfoset@dp_misc@@QBE?AV?$Sequence@VOUString@rtl@@@uno@star@sun@com@@XZ
0x55929146 IgetUrls@DescriptionInfoset@dp_misc@@ABE?AV?$Sequence@VOUString@rtl@@@uno@star@sun@com@@ABVOUString@rtl@@@Z
0x55928287 IgetVersion@DescriptionInfoset@dp_misc@@QBE?AVOUString@rtl@@XZ
0x55926d59 IhasDescription@DescriptionInfoset@dp_misc@@QBE_NXZ
0x5592df8d IhasValidPlatform@dp_misc@@YA_NABV?$Sequence@VOUString@rtl@@@uno@star@sun@com@@@Z
0x55925396 IinteractContinuation@dp_misc@@YA_NABVAny@uno@star@sun@com@@ABVType@3456@ABV?$Reference@VXCommandEnvironment@ucb@star@sun@com@@@3456@PA_N3@Z
0x55921660 IisAborted@AbortChannel@dp_misc@@QBE_NXZ
0x5592e392 IisUpdateSharedExtension@dp_misc@@YA?AW4UPDATE_SOURCE@1@_NABVOUString@rtl@@11@Z
0x5592e2f5 IisUpdateUserExtension@dp_misc@@YA?AW4UPDATE_SOURCE@1@_NABVOUString@rtl@@111@Z
0x55921da2 ImakeRcTerm@dp_misc@@YA?AVOUString@rtl@@ABV23@@Z
0x5592250d ImakeURL@dp_misc@@YA?AVOUString@rtl@@ABV23@0@Z
0x55922689 ImakeURLAppendSysPathSegment@dp_misc@@YA?AVOUString@rtl@@ABV23@0@Z
0x559283c2 ImatchCountryAndLanguage@DescriptionInfoset@dp_misc@@ABE?AV?$Reference@VXNode@dom@xml@star@sun@com@@@uno@star@sun@com@@ABV34567@ABULocale@lang@567@@Z
0x559282db ImatchFullLocale@DescriptionInfoset@dp_misc@@ABE?AV?$Reference@VXNode@dom@xml@star@sun@com@@@uno@star@sun@com@@ABV34567@ABVOUString@rtl@@@Z
0x55928611 ImatchLanguage@DescriptionInfoset@dp_misc@@ABE?AV?$Reference@VXNode@dom@xml@star@sun@com@@@uno@star@sun@com@@ABV34567@ABULocale@lang@567@@Z
0x559233f3 Ioffice_is_running@dp_misc@@YA_NXZ
0x5592e082 Iplatform_fits@dp_misc@@YA_NABVOUString@rtl@@@Z
0x55923dca IqueryInterface@?$WeakImplHelper1@VXAbortChannel@task@star@sun@com@@@cppu@@UAA?AVAny@uno@star@sun@com@@ABVType@4567@@Z
0x55922c7a IraiseProcess@dp_misc@@YAPAXABVOUString@rtl@@ABV?$Sequence@VOUString@rtl@@@uno@star@sun@com@@@Z
0x55921f0e IreadConsole@dp_misc@@YA?AVOUString@rtl@@XZ
0x55925e3b IreadFile@dp_misc@@YA?AVByteSequence@rtl@@AAVContent@ucbhelper@@@Z
0x55925ed8 IreadLine@dp_misc@@YA_NPAVOUString@rtl@@ABV23@AAVContent@ucbhelper@@G@Z
0x559267de IreadProperties@dp_misc@@YA_NAAV?$list@U?$pair@VOUString@rtl@@V12@@std@@V?$allocator@U?$pair@VOUString@rtl@@V12@@std@@@2@@std@@AAVContent@ucbhelper@@@Z
0x55921fe2 Irelease@?$WeakImplHelper1@VXAbortChannel@task@star@sun@com@@@cppu@@UAAXXZ
0x55923950 IresolveUnoURL@dp_misc@@YA?AV?$Reference@VXInterface@uno@star@sun@com@@@uno@star@sun@com@@ABVOUString@rtl@@ABV?$Reference@VXComponentContext@uno@star@sun@com@@@3456@PAVAbortChannel@1@@Z
0x5592501a IsendAbort@AbortChannel@dp_misc@@UAAXXZ
0x55923a5e IsyncRepositories@dp_misc@@YAXABV?$Reference@VXCommandEnvironment@ucb@star@sun@com@@@uno@star@sun@com@@@Z
0x559245bd ItoLocale@dp_misc@@YA?AULocale@lang@star@sun@com@@ABVOUString@rtl@@@Z
0x55921ec6 IwriteConsole@dp_misc@@YAXABVOString@rtl@@@Z
0x55921eae IwriteConsole@dp_misc@@YAXABVOUString@rtl@@@Z
0x55921ef6 IwriteConsoleError@dp_misc@@YAXABVOString@rtl@@@Z
0x55921ede IwriteConsoleError@dp_misc@@YAXABVOUString@rtl@@@Z
0x55929e32 Motd


Similarity measure (PE file only) - Checking for service failure