Report - 1.exe

Malicious Library UPX OS Processor Check MZP Format PE File PE64
ScreenShot
Created 2023.09.07 19:02 Machine s1_win7_x6403
Filename 1.exe
Type PE32+ executable (GUI) x86-64, for MS Windows
AI Score
3
Behavior Score
0.4
ZERO API file : mailcious
VT API (file)
md5 ff06438321dc9f8b1dadfe3fecb1df92
sha256 5059cddaa044258fb64b4b49f7d3ecca0a2520da05e4ee44c706fc82014ad438
ssdeep 49152:Mgh98D4xlsAOPmUIkUI8RUyvhoDCfVC0fLqaNl1XvGTx/S5rcW8jXNO:aa71fYO
imphash 7495bfccd8e07c22237460b8d82e6387
impfuzzy 192:NW/dqwUu5dCgTGxBWTOwIkuTQdO7LlcgOl9TFIVxuyEO:NaEPqTO1TQdOXOl9p5O
  Network IP location

Signature (2cnts)

Level Description
info Checks amount of memory in system
info The executable contains unknown PE section names indicative of a packer (could be a false positive)

Rules (6cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE64 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (2cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
mayo.edu US MAYO 129.176.1.88 clean
129.176.1.88 US MAYO 129.176.1.88 clean

Suricata ids

PE API

IAT(Import Address Table) Library

winspool.drv
 0x77b0e8 DocumentPropertiesW
 0x77b0f0 ClosePrinter
 0x77b0f8 OpenPrinterW
 0x77b100 GetDefaultPrinterW
 0x77b108 EnumPrintersW
comdlg32.dll
 0x77b118 FindTextW
comctl32.dll
 0x77b128 ImageList_GetImageInfo
 0x77b130 FlatSB_SetScrollInfo
 0x77b138 ImageList_DragMove
 0x77b140 ImageList_Destroy
 0x77b148 _TrackMouseEvent
 0x77b150 ImageList_DragShowNolock
 0x77b158 ImageList_Add
 0x77b160 FlatSB_SetScrollProp
 0x77b168 ImageList_GetDragImage
 0x77b170 ImageList_Create
 0x77b178 ImageList_EndDrag
 0x77b180 ImageList_DrawEx
 0x77b188 ImageList_SetImageCount
 0x77b190 FlatSB_GetScrollPos
 0x77b198 FlatSB_SetScrollPos
 0x77b1a0 InitializeFlatSB
 0x77b1a8 ImageList_Copy
 0x77b1b0 FlatSB_GetScrollInfo
 0x77b1b8 ImageList_Write
 0x77b1c0 ImageList_DrawIndirect
 0x77b1c8 ImageList_SetBkColor
 0x77b1d0 ImageList_GetBkColor
 0x77b1d8 ImageList_BeginDrag
 0x77b1e0 ImageList_GetIcon
 0x77b1e8 ImageList_Replace
 0x77b1f0 ImageList_GetImageCount
 0x77b1f8 ImageList_DragEnter
 0x77b200 ImageList_GetIconSize
 0x77b208 ImageList_SetIconSize
 0x77b210 ImageList_Read
 0x77b218 ImageList_DragLeave
 0x77b220 ImageList_LoadImageW
 0x77b228 ImageList_Draw
 0x77b230 ImageList_Remove
 0x77b238 ImageList_ReplaceIcon
 0x77b240 ImageList_SetOverlayImage
shell32.dll
 0x77b250 Shell_NotifyIconW
user32.dll
 0x77b260 CopyImage
 0x77b268 CreateWindowExW
 0x77b270 GetMenuItemInfoW
 0x77b278 SetMenuItemInfoW
 0x77b280 DefFrameProcW
 0x77b288 GetDCEx
 0x77b290 PeekMessageW
 0x77b298 MonitorFromWindow
 0x77b2a0 GetDlgCtrlID
 0x77b2a8 SetTimer
 0x77b2b0 WindowFromPoint
 0x77b2b8 BeginPaint
 0x77b2c0 RegisterClipboardFormatW
 0x77b2c8 FrameRect
 0x77b2d0 MapVirtualKeyW
 0x77b2d8 IsWindowUnicode
 0x77b2e0 RegisterWindowMessageW
 0x77b2e8 FillRect
 0x77b2f0 GetMenuStringW
 0x77b2f8 DispatchMessageW
 0x77b300 CreateAcceleratorTableW
 0x77b308 SendMessageA
 0x77b310 DefMDIChildProcW
 0x77b318 EnumWindows
 0x77b320 GetClassInfoW
 0x77b328 ShowOwnedPopups
 0x77b330 GetSystemMenu
 0x77b338 GetScrollRange
 0x77b340 SetScrollPos
 0x77b348 GetScrollPos
 0x77b350 GetActiveWindow
 0x77b358 SetActiveWindow
 0x77b360 DrawEdge
 0x77b368 GetKeyboardLayoutList
 0x77b370 LoadBitmapW
 0x77b378 DrawFocusRect
 0x77b380 EnumChildWindows
 0x77b388 GetScrollBarInfo
 0x77b390 ReleaseCapture
 0x77b398 UnhookWindowsHookEx
 0x77b3a0 LoadCursorW
 0x77b3a8 GetCapture
 0x77b3b0 SetCapture
 0x77b3b8 CreatePopupMenu
 0x77b3c0 ScrollWindow
 0x77b3c8 ShowCaret
 0x77b3d0 GetMenuItemID
 0x77b3d8 GetLastActivePopup
 0x77b3e0 CharLowerBuffW
 0x77b3e8 GetSystemMetrics
 0x77b3f0 PostMessageW
 0x77b3f8 DrawMenuBar
 0x77b400 SetParent
 0x77b408 IsZoomed
 0x77b410 CharUpperBuffW
 0x77b418 GetClientRect
 0x77b420 IsChild
 0x77b428 GetClassLongPtrW
 0x77b430 SetClassLongPtrW
 0x77b438 ClientToScreen
 0x77b440 GetClipboardData
 0x77b448 SetClipboardData
 0x77b450 SetWindowPlacement
 0x77b458 IsIconic
 0x77b460 CallNextHookEx
 0x77b468 GetMonitorInfoW
 0x77b470 ShowWindow
 0x77b478 CheckMenuItem
 0x77b480 CharUpperW
 0x77b488 DefWindowProcW
 0x77b490 GetForegroundWindow
 0x77b498 SetForegroundWindow
 0x77b4a0 GetWindowTextW
 0x77b4a8 EnableWindow
 0x77b4b0 DestroyWindow
 0x77b4b8 IsDialogMessageW
 0x77b4c0 EndMenu
 0x77b4c8 RegisterClassW
 0x77b4d0 CharNextW
 0x77b4d8 GetWindowThreadProcessId
 0x77b4e0 RedrawWindow
 0x77b4e8 GetDC
 0x77b4f0 GetFocus
 0x77b4f8 SetFocus
 0x77b500 EndPaint
 0x77b508 ReleaseDC
 0x77b510 MsgWaitForMultipleObjectsEx
 0x77b518 LoadKeyboardLayoutW
 0x77b520 ActivateKeyboardLayout
 0x77b528 GetParent
 0x77b530 DrawTextW
 0x77b538 SetScrollRange
 0x77b540 MonitorFromRect
 0x77b548 InsertMenuItemW
 0x77b550 PeekMessageA
 0x77b558 GetPropW
 0x77b560 MessageBoxW
 0x77b568 MessageBeep
 0x77b570 SetPropW
 0x77b578 RemovePropW
 0x77b580 UpdateWindow
 0x77b588 GetSubMenu
 0x77b590 MsgWaitForMultipleObjects
 0x77b598 DestroyMenu
 0x77b5a0 DestroyIcon
 0x77b5a8 SetWindowsHookExW
 0x77b5b0 EmptyClipboard
 0x77b5b8 IsWindowVisible
 0x77b5c0 DispatchMessageA
 0x77b5c8 UnregisterClassW
 0x77b5d0 GetTopWindow
 0x77b5d8 SendMessageW
 0x77b5e0 AdjustWindowRectEx
 0x77b5e8 DrawIcon
 0x77b5f0 IsWindow
 0x77b5f8 EnumThreadWindows
 0x77b600 InvalidateRect
 0x77b608 GetKeyboardState
 0x77b610 DrawFrameControl
 0x77b618 ScreenToClient
 0x77b620 GetWindowLongPtrW
 0x77b628 SetWindowLongPtrW
 0x77b630 SendMessageTimeoutW
 0x77b638 BringWindowToTop
 0x77b640 SetCursor
 0x77b648 CreateIcon
 0x77b650 CreateMenu
 0x77b658 LoadStringW
 0x77b660 CharLowerW
 0x77b668 SetWindowRgn
 0x77b670 SetWindowPos
 0x77b678 GetMenuItemCount
 0x77b680 RemoveMenu
 0x77b688 GetSysColorBrush
 0x77b690 GetKeyboardLayoutNameW
 0x77b698 GetWindowDC
 0x77b6a0 TranslateMessage
 0x77b6a8 OpenClipboard
 0x77b6b0 DrawTextExW
 0x77b6b8 MapWindowPoints
 0x77b6c0 EnumDisplayMonitors
 0x77b6c8 CallWindowProcW
 0x77b6d0 CloseClipboard
 0x77b6d8 DestroyCursor
 0x77b6e0 GetScrollInfo
 0x77b6e8 SetWindowTextW
 0x77b6f0 GetMessageExtraInfo
 0x77b6f8 EnableScrollBar
 0x77b700 GetSysColor
 0x77b708 TrackPopupMenu
 0x77b710 CopyIcon
 0x77b718 DrawIconEx
 0x77b720 PostQuitMessage
 0x77b728 GetClassNameW
 0x77b730 ShowScrollBar
 0x77b738 EnableMenuItem
 0x77b740 GetIconInfo
 0x77b748 GetMessagePos
 0x77b750 SetScrollInfo
 0x77b758 GetKeyNameTextW
 0x77b760 GetDesktopWindow
 0x77b768 GetCursorPos
 0x77b770 SetCursorPos
 0x77b778 HideCaret
 0x77b780 GetMenu
 0x77b788 GetMenuState
 0x77b790 SetMenu
 0x77b798 SetRect
 0x77b7a0 GetKeyState
 0x77b7a8 FindWindowExW
 0x77b7b0 MonitorFromPoint
 0x77b7b8 SystemParametersInfoW
 0x77b7c0 LoadIconW
 0x77b7c8 GetCursor
 0x77b7d0 GetWindow
 0x77b7d8 GetWindowRect
 0x77b7e0 InsertMenuW
 0x77b7e8 KillTimer
 0x77b7f0 WaitMessage
 0x77b7f8 IsWindowEnabled
 0x77b800 IsDialogMessageA
 0x77b808 TranslateMDISysAccel
 0x77b810 GetWindowPlacement
 0x77b818 CreateIconIndirect
 0x77b820 FindWindowW
 0x77b828 DeleteMenu
 0x77b830 GetKeyboardLayout
version.dll
 0x77b840 GetFileVersionInfoSizeW
 0x77b848 VerQueryValueW
 0x77b850 GetFileVersionInfoW
oleaut32.dll
 0x77b860 SysFreeString
 0x77b868 VariantClear
 0x77b870 VariantInit
 0x77b878 GetErrorInfo
 0x77b880 SysReAllocStringLen
 0x77b888 SafeArrayCreate
 0x77b890 SysAllocStringLen
 0x77b898 SafeArrayPtrOfIndex
 0x77b8a0 SafeArrayGetUBound
 0x77b8a8 SafeArrayGetLBound
 0x77b8b0 VariantCopy
 0x77b8b8 VariantChangeType
advapi32.dll
 0x77b8c8 RegSetValueExW
 0x77b8d0 CryptExportKey
 0x77b8d8 RegConnectRegistryW
 0x77b8e0 CryptDecrypt
 0x77b8e8 CryptDestroyKey
 0x77b8f0 CryptEncrypt
 0x77b8f8 CryptImportKey
 0x77b900 CryptDestroyHash
 0x77b908 RegQueryInfoKeyW
 0x77b910 RegUnLoadKeyW
 0x77b918 CryptReleaseContext
 0x77b920 RegSaveKeyW
 0x77b928 RegReplaceKeyW
 0x77b930 RegCreateKeyExW
 0x77b938 CryptAcquireContextW
 0x77b940 CryptDeriveKey
 0x77b948 RegLoadKeyW
 0x77b950 RegEnumKeyExW
 0x77b958 RegDeleteKeyW
 0x77b960 CryptGenKey
 0x77b968 RegOpenKeyExW
 0x77b970 RegDeleteValueW
 0x77b978 RegFlushKey
 0x77b980 RegEnumValueW
 0x77b988 RegQueryValueExW
 0x77b990 RegCloseKey
 0x77b998 CryptHashData
 0x77b9a0 CryptCreateHash
 0x77b9a8 RegRestoreKeyW
netapi32.dll
 0x77b9b8 NetWkstaGetInfo
 0x77b9c0 NetApiBufferFree
kernel32.dll
 0x77b9d0 RtlUnwindEx
 0x77b9d8 GetACP
 0x77b9e0 CloseHandle
 0x77b9e8 LocalFree
 0x77b9f0 GetCurrentProcessId
 0x77b9f8 SizeofResource
 0x77ba00 VirtualProtect
 0x77ba08 QueryPerformanceFrequency
 0x77ba10 IsDebuggerPresent
 0x77ba18 VirtualFree
 0x77ba20 GetFullPathNameW
 0x77ba28 ExitProcess
 0x77ba30 HeapAlloc
 0x77ba38 GetCPInfoExW
 0x77ba40 RtlUnwind
 0x77ba48 GetCPInfo
 0x77ba50 EnumSystemLocalesW
 0x77ba58 GetStdHandle
 0x77ba60 GetModuleHandleW
 0x77ba68 FreeLibrary
 0x77ba70 TryEnterCriticalSection
 0x77ba78 GetDllDirectoryW
 0x77ba80 SetDllDirectoryW
 0x77ba88 HeapDestroy
 0x77ba90 ReadFile
 0x77ba98 GetLastError
 0x77baa0 GetModuleFileNameW
 0x77baa8 SetLastError
 0x77bab0 GlobalAlloc
 0x77bab8 GlobalUnlock
 0x77bac0 FindResourceW
 0x77bac8 CreateThread
 0x77bad0 CompareStringW
 0x77bad8 MapViewOfFile
 0x77bae0 LoadLibraryA
 0x77bae8 ResetEvent
 0x77baf0 MulDiv
 0x77baf8 FreeResource
 0x77bb00 GetVersion
 0x77bb08 RaiseException
 0x77bb10 GlobalAddAtomW
 0x77bb18 FormatMessageW
 0x77bb20 SwitchToThread
 0x77bb28 GetExitCodeThread
 0x77bb30 GetCurrentThread
 0x77bb38 LoadLibraryExW
 0x77bb40 LockResource
 0x77bb48 GetCurrentThreadId
 0x77bb50 GetShortPathNameW
 0x77bb58 UnhandledExceptionFilter
 0x77bb60 VirtualQuery
 0x77bb68 GlobalFindAtomW
 0x77bb70 VirtualQueryEx
 0x77bb78 GlobalFree
 0x77bb80 Sleep
 0x77bb88 EnterCriticalSection
 0x77bb90 SetFilePointer
 0x77bb98 LoadResource
 0x77bba0 SuspendThread
 0x77bba8 GetTickCount
 0x77bbb0 GetStartupInfoW
 0x77bbb8 GlobalDeleteAtom
 0x77bbc0 GetFileAttributesW
 0x77bbc8 GetCurrentDirectoryW
 0x77bbd0 SetCurrentDirectoryW
 0x77bbd8 InitializeCriticalSection
 0x77bbe0 GetThreadPriority
 0x77bbe8 GetCurrentProcess
 0x77bbf0 SetThreadPriority
 0x77bbf8 GlobalLock
 0x77bc00 VirtualAlloc
 0x77bc08 GetSystemInfo
 0x77bc10 GetCommandLineW
 0x77bc18 DuplicateHandle
 0x77bc20 LeaveCriticalSection
 0x77bc28 GetProcAddress
 0x77bc30 ResumeThread
 0x77bc38 GetVersionExW
 0x77bc40 VerifyVersionInfoW
 0x77bc48 HeapCreate
 0x77bc50 GetDiskFreeSpaceW
 0x77bc58 VerSetConditionMask
 0x77bc60 FindFirstFileW
 0x77bc68 GetUserDefaultUILanguage
 0x77bc70 UnmapViewOfFile
 0x77bc78 lstrlenW
 0x77bc80 CompareStringA
 0x77bc88 QueryPerformanceCounter
 0x77bc90 SetEndOfFile
 0x77bc98 HeapFree
 0x77bca0 WideCharToMultiByte
 0x77bca8 FindClose
 0x77bcb0 MultiByteToWideChar
 0x77bcb8 LoadLibraryW
 0x77bcc0 SetEvent
 0x77bcc8 CreateFileW
 0x77bcd0 GetLocaleInfoW
 0x77bcd8 EnumResourceNamesW
 0x77bce0 GetLocalTime
 0x77bce8 WaitForSingleObject
 0x77bcf0 WriteFile
 0x77bcf8 CreateFileMappingW
 0x77bd00 ExitThread
 0x77bd08 DeleteCriticalSection
 0x77bd10 GetDateFormatW
 0x77bd18 TlsGetValue
 0x77bd20 SetErrorMode
 0x77bd28 IsValidLocale
 0x77bd30 TlsSetValue
 0x77bd38 GetSystemDefaultUILanguage
 0x77bd40 EnumCalendarInfoW
 0x77bd48 LocalAlloc
 0x77bd50 CreateEventW
 0x77bd58 WaitForMultipleObjectsEx
 0x77bd60 SetThreadLocale
 0x77bd68 GetThreadLocale
ole32.dll
 0x77bd78 IsEqualGUID
 0x77bd80 OleInitialize
 0x77bd88 OleUninitialize
 0x77bd90 CoInitialize
 0x77bd98 CoCreateInstance
 0x77bda0 CoUninitialize
 0x77bda8 CoTaskMemFree
 0x77bdb0 CoTaskMemAlloc
gdi32.dll
 0x77bdc0 Pie
 0x77bdc8 SetBkMode
 0x77bdd0 CreateCompatibleBitmap
 0x77bdd8 GetEnhMetaFileHeader
 0x77bde0 RectVisible
 0x77bde8 AngleArc
 0x77bdf0 SetAbortProc
 0x77bdf8 SetTextColor
 0x77be00 StretchBlt
 0x77be08 RoundRect
 0x77be10 RestoreDC
 0x77be18 SetRectRgn
 0x77be20 GetTextMetricsW
 0x77be28 GetWindowOrgEx
 0x77be30 CreatePalette
 0x77be38 PolyBezierTo
 0x77be40 CreateICW
 0x77be48 CreateDCW
 0x77be50 GetStockObject
 0x77be58 CreateSolidBrush
 0x77be60 Polygon
 0x77be68 MoveToEx
 0x77be70 PlayEnhMetaFile
 0x77be78 Ellipse
 0x77be80 StartPage
 0x77be88 GetBitmapBits
 0x77be90 StartDocW
 0x77be98 GetSystemPaletteEntries
 0x77bea0 GetEnhMetaFileBits
 0x77bea8 AbortDoc
 0x77beb0 GetEnhMetaFilePaletteEntries
 0x77beb8 CreatePenIndirect
 0x77bec0 CreateFontIndirectW
 0x77bec8 PolyBezier
 0x77bed0 EndDoc
 0x77bed8 GetObjectW
 0x77bee0 GetWinMetaFileBits
 0x77bee8 SetROP2
 0x77bef0 GetEnhMetaFileDescriptionW
 0x77bef8 ArcTo
 0x77bf00 Arc
 0x77bf08 SelectPalette
 0x77bf10 ExcludeClipRect
 0x77bf18 MaskBlt
 0x77bf20 SetWindowOrgEx
 0x77bf28 EndPage
 0x77bf30 DeleteEnhMetaFile
 0x77bf38 Chord
 0x77bf40 SetDIBits
 0x77bf48 SetViewportOrgEx
 0x77bf50 CreateRectRgn
 0x77bf58 RealizePalette
 0x77bf60 SetDIBColorTable
 0x77bf68 GetDIBColorTable
 0x77bf70 CreateBrushIndirect
 0x77bf78 PatBlt
 0x77bf80 SetEnhMetaFileBits
 0x77bf88 Rectangle
 0x77bf90 SaveDC
 0x77bf98 DeleteDC
 0x77bfa0 FrameRgn
 0x77bfa8 BitBlt
 0x77bfb0 GetDeviceCaps
 0x77bfb8 GetTextExtentPoint32W
 0x77bfc0 GetClipBox
 0x77bfc8 IntersectClipRect
 0x77bfd0 Polyline
 0x77bfd8 CreateBitmap
 0x77bfe0 SetWinMetaFileBits
 0x77bfe8 GetStretchBltMode
 0x77bff0 CreateDIBitmap
 0x77bff8 SetStretchBltMode
 0x77c000 GetDIBits
 0x77c008 CreateDIBSection
 0x77c010 LineTo
 0x77c018 GetRgnBox
 0x77c020 EnumFontsW
 0x77c028 CreateHalftonePalette
 0x77c030 SelectObject
 0x77c038 DeleteObject
 0x77c040 ExtFloodFill
 0x77c048 UnrealizeObject
 0x77c050 CopyEnhMetaFileW
 0x77c058 SetBkColor
 0x77c060 CreateCompatibleDC
 0x77c068 GetBrushOrgEx
 0x77c070 GetCurrentPositionEx
 0x77c078 GetTextExtentPointW
 0x77c080 ExtTextOutW
 0x77c088 SetBrushOrgEx
 0x77c090 GetPixel
 0x77c098 GdiFlush
 0x77c0a0 SetPixel
 0x77c0a8 EnumFontFamiliesExW
 0x77c0b0 StretchDIBits
 0x77c0b8 GetPaletteEntries

EAT(Export Address Table) Library

0x543310 TMethodImplementationIntercept
0x41a1d0 __dbk_fcall_wrapper
0x773290 dbkFCallWrapperAddr


Similarity measure (PE file only) - Checking for service failure