Report - stub_186.exe

UPX Malicious Library Antivirus OS Processor Check PE File PE32
ScreenShot
Created 2023.07.06 20:25 Machine s1_win7_x6401
Filename stub_186.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
3
Behavior Score
1.2
ZERO API
VT API (file)
md5 0f3a69075e511390b5fdb4687f47ea0b
sha256 693cace37b4b6fed2ca67906c7a4b1c11273110561a207a222aa4e62fb4a184a
ssdeep 49152:neGqC5kz7oT/A4/Zg55JUdaowPMpbRG8w0xn+pan3MLeMMMMMMEe0pTz:eGSQE48KIow+bRG8w0IckeMMMMMMEe09
imphash 7ec95b75325cb92234bce540f91117d0
impfuzzy 192:9ZuF9heMCYWkAi6waXNaivgUGbG9O2DUl/Q3+M:8WMCXkAWdiH93/
  Network IP location

Signature (5cnts)

Level Description
notice Foreign language identified in PE resource
info Checks amount of memory in system
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The file contains an unknown PE resource name possibly indicative of a packer
info This executable has a PDB path

Rules (6cnts)

Level Name Description Collection
watch Antivirus Contains references to security software binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (2cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
apache.org US FASTLY 151.101.2.132
151.101.2.132 US FASTLY 151.101.2.132

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.dll
 0x50f120 GetShortPathNameW
 0x50f124 GetLongPathNameW
 0x50f128 GetFileType
 0x50f12c GetStdHandle
 0x50f130 FlushFileBuffers
 0x50f134 GetFileTime
 0x50f138 GetDiskFreeSpaceExW
 0x50f13c GetVersionExW
 0x50f140 GetCurrentDirectoryW
 0x50f144 GetFullPathNameW
 0x50f148 FoldStringW
 0x50f14c LoadResource
 0x50f150 SizeofResource
 0x50f154 FindResourceW
 0x50f158 LoadLibraryExW
 0x50f15c CompareStringA
 0x50f160 GetCurrentThread
 0x50f164 SetThreadPriority
 0x50f168 SetThreadExecutionState
 0x50f16c GetSystemDirectoryW
 0x50f170 SetCurrentDirectoryW
 0x50f174 GetFullPathNameA
 0x50f178 SetPriorityClass
 0x50f17c GetProcessAffinityMask
 0x50f180 CreateThread
 0x50f184 InitializeCriticalSection
 0x50f188 EnterCriticalSection
 0x50f18c LeaveCriticalSection
 0x50f190 DeleteCriticalSection
 0x50f194 SetEvent
 0x50f198 ResetEvent
 0x50f19c ReleaseSemaphore
 0x50f1a0 CreateEventW
 0x50f1a4 CreateSemaphoreW
 0x50f1a8 GetSystemTime
 0x50f1ac TzSpecificLocalTimeToSystemTime
 0x50f1b0 GetCPInfo
 0x50f1b4 IsDBCSLeadByte
 0x50f1b8 WideCharToMultiByte
 0x50f1bc CompareStringW
 0x50f1c0 GetModuleHandleExW
 0x50f1c4 GetCompressedFileSizeW
 0x50f1c8 EnumResourceNamesW
 0x50f1cc EnumResourceLanguagesW
 0x50f1d0 BeginUpdateResourceW
 0x50f1d4 UpdateResourceW
 0x50f1d8 EndUpdateResourceW
 0x50f1dc GetLocaleInfoW
 0x50f1e0 GetNumberFormatW
 0x50f1e4 GetLogicalDrives
 0x50f1e8 SuspendThread
 0x50f1ec ResumeThread
 0x50f1f0 GetCurrentThreadId
 0x50f1f4 CopyFileW
 0x50f1f8 GetThreadPriority
 0x50f1fc SetErrorMode
 0x50f200 BackupSeek
 0x50f204 WaitForMultipleObjects
 0x50f208 MulDiv
 0x50f20c CompareFileTime
 0x50f210 FindNextChangeNotification
 0x50f214 HeapSize
 0x50f218 GetProcessHeap
 0x50f21c SetEnvironmentVariableA
 0x50f220 FreeEnvironmentStringsW
 0x50f224 GetEnvironmentStringsW
 0x50f228 GetCommandLineA
 0x50f22c IsValidCodePage
 0x50f230 FindNextFileA
 0x50f234 FindFirstFileExA
 0x50f238 GetStringTypeW
 0x50f23c WriteConsoleW
 0x50f240 SetStdHandle
 0x50f244 LCMapStringW
 0x50f248 HeapReAlloc
 0x50f24c GetModuleFileNameA
 0x50f250 ExitProcess
 0x50f254 GetConsoleCP
 0x50f258 ReadConsoleW
 0x50f25c GetConsoleMode
 0x50f260 SetFilePointerEx
 0x50f264 FreeLibraryAndExitThread
 0x50f268 ExitThread
 0x50f26c QueryPerformanceFrequency
 0x50f270 EncodePointer
 0x50f274 TlsFree
 0x50f278 TlsSetValue
 0x50f27c TlsGetValue
 0x50f280 TlsAlloc
 0x50f284 InitializeCriticalSectionAndSpinCount
 0x50f288 RaiseException
 0x50f28c RtlUnwind
 0x50f290 InitializeSListHead
 0x50f294 QueryPerformanceCounter
 0x50f298 GetStartupInfoW
 0x50f29c IsDebuggerPresent
 0x50f2a0 WaitForSingleObjectEx
 0x50f2a4 IsProcessorFeaturePresent
 0x50f2a8 TerminateProcess
 0x50f2ac SetUnhandledExceptionFilter
 0x50f2b0 UnhandledExceptionFilter
 0x50f2b4 BackupRead
 0x50f2b8 DeviceIoControl
 0x50f2bc FormatMessageW
 0x50f2c0 LocalFree
 0x50f2c4 GetFileInformationByHandle
 0x50f2c8 GetTickCount
 0x50f2cc GetLocalTime
 0x50f2d0 FindCloseChangeNotification
 0x50f2d4 FindFirstChangeNotificationW
 0x50f2d8 ExpandEnvironmentStringsW
 0x50f2dc SystemTimeToFileTime
 0x50f2e0 SystemTimeToTzSpecificLocalTime
 0x50f2e4 FindNextFileW
 0x50f2e8 GetDiskFreeSpaceW
 0x50f2ec CreateHardLinkW
 0x50f2f0 SetLastError
 0x50f2f4 DosDateTimeToFileTime
 0x50f2f8 LocalFileTimeToFileTime
 0x50f2fc HeapFree
 0x50f300 HeapAlloc
 0x50f304 HeapDestroy
 0x50f308 HeapCreate
 0x50f30c DeleteFileW
 0x50f310 SetFileAttributesW
 0x50f314 CreateFileW
 0x50f318 RemoveDirectoryW
 0x50f31c CreateDirectoryW
 0x50f320 LoadLibraryW
 0x50f324 GetSystemTimeAsFileTime
 0x50f328 SetFileTime
 0x50f32c SetFilePointer
 0x50f330 SetEndOfFile
 0x50f334 ReadFile
 0x50f338 WriteFile
 0x50f33c GetFileSize
 0x50f340 FreeLibrary
 0x50f344 MoveFileW
 0x50f348 GetCPInfoExW
 0x50f34c GetOEMCP
 0x50f350 GetACP
 0x50f354 GetVolumeInformationW
 0x50f358 DecodePointer
 0x50f35c GetDriveTypeW
 0x50f360 Sleep
 0x50f364 GetCurrentProcessId
 0x50f368 GetCurrentProcess
 0x50f36c CreateMutexW
 0x50f370 ReleaseMutex
 0x50f374 GetLastError
 0x50f378 GlobalFree
 0x50f37c GlobalUnlock
 0x50f380 GlobalLock
 0x50f384 GlobalSize
 0x50f388 GlobalAlloc
 0x50f38c MultiByteToWideChar
 0x50f390 GetVersionExA
 0x50f394 GetModuleHandleW
 0x50f398 GetProcAddress
 0x50f39c GetTempPathW
 0x50f3a0 OpenFileMappingW
 0x50f3a4 CreateFileMappingW
 0x50f3a8 UnmapViewOfFile
 0x50f3ac MapViewOfFile
 0x50f3b0 CloseHandle
 0x50f3b4 WaitForSingleObject
 0x50f3b8 GetCommandLineW
 0x50f3bc GetModuleFileNameW
 0x50f3c0 GetDateFormatW
 0x50f3c4 GetTimeFormatW
 0x50f3c8 FindFirstFileW
 0x50f3cc FileTimeToSystemTime
 0x50f3d0 FileTimeToLocalFileTime
 0x50f3d4 FindClose
 0x50f3d8 GetPriorityClass
 0x50f3dc GetFileAttributesW
USER32.dll
 0x50f44c BringWindowToTop
 0x50f450 DispatchMessageW
 0x50f454 TranslateMessage
 0x50f458 GetMessageW
 0x50f45c RegisterWindowMessageW
 0x50f460 FindWindowExW
 0x50f464 MessageBoxW
 0x50f468 CreateIcon
 0x50f46c EnumWindows
 0x50f470 SetForegroundWindow
 0x50f474 IsCharAlphaW
 0x50f478 FlashWindow
 0x50f47c CopyRect
 0x50f480 RegisterClassExW
 0x50f484 GetSysColor
 0x50f488 ValidateRect
 0x50f48c CopyImage
 0x50f490 FillRect
 0x50f494 DrawIconEx
 0x50f498 SystemParametersInfoW
 0x50f49c GetSystemMenu
 0x50f4a0 KillTimer
 0x50f4a4 SetTimer
 0x50f4a8 MessageBoxIndirectW
 0x50f4ac CharLowerW
 0x50f4b0 CharUpperW
 0x50f4b4 ExitWindowsEx
 0x50f4b8 CharLowerA
 0x50f4bc LoadStringW
 0x50f4c0 GetWindow
 0x50f4c4 SetProcessDefaultLayout
 0x50f4c8 OemToCharBuffA
 0x50f4cc OemToCharA
 0x50f4d0 GetComboBoxInfo
 0x50f4d4 RedrawWindow
 0x50f4d8 MessageBeep
 0x50f4dc CharToOemA
 0x50f4e0 CreateDialogIndirectParamW
 0x50f4e4 SetClipboardData
 0x50f4e8 CloseClipboard
 0x50f4ec OpenClipboard
 0x50f4f0 PeekMessageW
 0x50f4f4 EnableMenuItem
 0x50f4f8 CheckMenuItem
 0x50f4fc GetFocus
 0x50f500 MoveWindow
 0x50f504 LoadImageW
 0x50f508 GetClientRect
 0x50f50c GetWindowTextLengthW
 0x50f510 EndPaint
 0x50f514 BeginPaint
 0x50f518 UpdateWindow
 0x50f51c AppendMenuW
 0x50f520 GetMenuItemCount
 0x50f524 DrawMenuBar
 0x50f528 wsprintfW
 0x50f52c ScreenToClient
 0x50f530 ClientToScreen
 0x50f534 CallWindowProcW
 0x50f538 PtInRect
 0x50f53c SetMenuItemInfoW
 0x50f540 GetMenuItemInfoW
 0x50f544 InsertMenuItemW
 0x50f548 TrackPopupMenu
 0x50f54c DeleteMenu
 0x50f550 GetMenuState
 0x50f554 GetLastActivePopup
 0x50f558 TranslateAcceleratorW
 0x50f55c GetMenuItemID
 0x50f560 SetMenu
 0x50f564 LoadMenuW
 0x50f568 LoadAcceleratorsW
 0x50f56c GetClipboardData
 0x50f570 IsChild
 0x50f574 RegisterClassW
 0x50f578 PostQuitMessage
 0x50f57c LoadIconW
 0x50f580 LoadBitmapW
 0x50f584 SetScrollRange
 0x50f588 SetScrollPos
 0x50f58c ScrollWindowEx
 0x50f590 CreateDialogParamW
 0x50f594 PostThreadMessageW
 0x50f598 IsDialogMessageW
 0x50f59c SendMessageW
 0x50f5a0 DefWindowProcW
 0x50f5a4 CreateWindowExW
 0x50f5a8 DestroyWindow
 0x50f5ac SetFocus
 0x50f5b0 GetWindowTextW
 0x50f5b4 GetWindowLongW
 0x50f5b8 SetWindowLongW
 0x50f5bc SetWindowPos
 0x50f5c0 GetWindowPlacement
 0x50f5c4 SetWindowPlacement
 0x50f5c8 GetIconInfo
 0x50f5cc CreateIconIndirect
 0x50f5d0 FindWindowW
 0x50f5d4 RemovePropW
 0x50f5d8 GetPropW
 0x50f5dc SetPropW
 0x50f5e0 GetForegroundWindow
 0x50f5e4 EmptyClipboard
 0x50f5e8 InsertMenuW
 0x50f5ec GetSubMenu
 0x50f5f0 DestroyMenu
 0x50f5f4 CreatePopupMenu
 0x50f5f8 GetMenu
 0x50f5fc IsWindow
 0x50f600 WaitForInputIdle
 0x50f604 IsWindowVisible
 0x50f608 DialogBoxParamW
 0x50f60c EndDialog
 0x50f610 LoadCursorW
 0x50f614 GetWindowThreadProcessId
 0x50f618 WindowFromPoint
 0x50f61c SetCursor
 0x50f620 GetKeyState
 0x50f624 RegisterClipboardFormatW
 0x50f628 SystemParametersInfoA
 0x50f62c GetDesktopWindow
 0x50f630 IntersectRect
 0x50f634 GetCursorPos
 0x50f638 SetWindowTextW
 0x50f63c ReleaseDC
 0x50f640 GetDC
 0x50f644 GetSystemMetrics
 0x50f648 EnableWindow
 0x50f64c IsIconic
 0x50f650 IsWindowEnabled
 0x50f654 IsDlgButtonChecked
 0x50f658 GetDlgItemInt
 0x50f65c SetDlgItemInt
 0x50f660 CharToOemBuffA
 0x50f664 ShowWindow
 0x50f668 GetClassNameW
 0x50f66c EnumChildWindows
 0x50f670 InvalidateRect
 0x50f674 PostMessageW
 0x50f678 CheckDlgButton
 0x50f67c DestroyIcon
 0x50f680 GetParent
 0x50f684 MapWindowPoints
 0x50f688 GetWindowRect
 0x50f68c SendDlgItemMessageW
 0x50f690 GetDlgItemTextW
 0x50f694 SetDlgItemTextW
 0x50f698 GetDlgItem
 0x50f69c CharToOemBuffW
GDI32.dll
 0x50f098 TextOutA
 0x50f09c CreatePatternBrush
 0x50f0a0 MoveToEx
 0x50f0a4 SetPixel
 0x50f0a8 Rectangle
 0x50f0ac LineTo
 0x50f0b0 GetTextExtentPoint32W
 0x50f0b4 CreateDIBSection
 0x50f0b8 DPtoLP
 0x50f0bc StretchBlt
 0x50f0c0 SetMapMode
 0x50f0c4 GetMapMode
 0x50f0c8 GetDeviceCaps
 0x50f0cc CreateCompatibleBitmap
 0x50f0d0 CreateBitmap
 0x50f0d4 ExtTextOutW
 0x50f0d8 SetBkColor
 0x50f0dc BitBlt
 0x50f0e0 GetObjectW
 0x50f0e4 GetPixel
 0x50f0e8 DeleteDC
 0x50f0ec CreateCompatibleDC
 0x50f0f0 Polyline
 0x50f0f4 Polygon
 0x50f0f8 TextOutW
 0x50f0fc SetTextColor
 0x50f100 CreateSolidBrush
 0x50f104 CreatePen
 0x50f108 GetTextFaceW
 0x50f10c GetTextMetricsW
 0x50f110 SelectObject
 0x50f114 DeleteObject
 0x50f118 CreateFontW
COMDLG32.dll
 0x50f084 ChooseFontW
 0x50f088 GetOpenFileNameW
 0x50f08c GetSaveFileNameW
 0x50f090 CommDlgExtendedError
ADVAPI32.dll
 0x50f000 FreeSid
 0x50f004 AccessCheck
 0x50f008 OpenProcessToken
 0x50f00c MapGenericMask
 0x50f010 GetFileSecurityW
 0x50f014 RegCloseKey
 0x50f018 RegOpenKeyExW
 0x50f01c IsTextUnicode
 0x50f020 RegSetValueExW
 0x50f024 RegEnumValueW
 0x50f028 RegEnumKeyExW
 0x50f02c RegDeleteValueW
 0x50f030 RegDeleteKeyW
 0x50f034 RegCreateKeyExW
 0x50f038 CheckTokenMembership
 0x50f03c DuplicateToken
 0x50f040 AllocateAndInitializeSid
 0x50f044 SetFileSecurityW
 0x50f048 GetSecurityDescriptorLength
 0x50f04c CryptGenRandom
 0x50f050 CryptReleaseContext
 0x50f054 CryptAcquireContextW
 0x50f058 LookupPrivilegeValueW
 0x50f05c AdjustTokenPrivileges
 0x50f060 RegQueryValueExW
SHELL32.dll
 0x50f3f0 SHGetFolderLocation
 0x50f3f4 SHGetPathFromIDListW
 0x50f3f8 SHGetDesktopFolder
 0x50f3fc FindExecutableW
 0x50f400 DragFinish
 0x50f404 DragQueryFileW
 0x50f408 Shell_NotifyIconW
 0x50f40c DragAcceptFiles
 0x50f410 ShellExecuteW
 0x50f414 SHGetSpecialFolderLocation
 0x50f418 None
 0x50f41c SHAddToRecentDocs
 0x50f420 SHFileOperationW
 0x50f424 SHGetFolderPathW
 0x50f428 ShellExecuteExW
 0x50f42c SHBrowseForFolderW
 0x50f430 SHGetMalloc
 0x50f434 SHChangeNotify
 0x50f438 SHGetFileInfoW
ole32.dll
 0x50f6b0 OleUninitialize
 0x50f6b4 OleInitialize
 0x50f6b8 CLSIDFromString
 0x50f6bc CoTaskMemAlloc
 0x50f6c0 CoInitializeEx
 0x50f6c4 CoTaskMemFree
 0x50f6c8 CoCreateInstance
 0x50f6cc OleSetClipboard
 0x50f6d0 DoDragDrop
 0x50f6d4 CreateStreamOnHGlobal
OLEAUT32.dll
 0x50f3e4 VariantClear
 0x50f3e8 SysAllocString
SHLWAPI.dll
 0x50f440 SHAutoComplete
 0x50f444 StrCmpLogicalW
COMCTL32.dll
 0x50f068 CreateStatusWindowW
 0x50f06c None
 0x50f070 ImageList_Create
 0x50f074 ImageList_ReplaceIcon
 0x50f078 InitCommonControlsEx
 0x50f07c PropertySheetW
UxTheme.dll
 0x50f6a4 IsAppThemed
 0x50f6a8 IsThemeActive

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure