Report - Owpxkxlhneicvr.scr

Malicious Library UPX PE File PE32 MZP Format URL Format
ScreenShot
Created 2023.09.20 18:01 Machine s1_win7_x6403
Filename Owpxkxlhneicvr.scr
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
4
Behavior Score
3.6
ZERO API file : clean
VT API (file) 20 detected (AIDetectMalware, malicious, high confidence, ModiLoader, Eldorado, Attribute, HighConfidence, Remcos, DropperX, Detected, R575480, unsafe, CLASSIC, Formbook, confidence)
md5 79b7474ded312cda4a0bd477ddf78378
sha256 3880c8403a1377ae8bbcc6f782e51839364c9e2e9e29ea9a02d011eeefd51d69
ssdeep 12288:QQGIc/IHeXIZ7dF+Xa4IkmeQ+rp6pBBFKxdLIJuVvFTqlCtop7p7R8H9xvUincHL:Q3Ic+ZzOFcfDcchpd+Y0MSiy
imphash 48b10491a087916b8cdb741cb4ec7517
impfuzzy 192:334+k1sT1/ibuucxSUvK9y3oaqvRo72POQXd:33Q1sGcq9/jPOQN
  Network IP location

Signature (9cnts)

Level Description
warning File has been identified by 20 AntiVirus engines on VirusTotal as malicious
watch Creates a windows hook that monitors keyboard input (keylogger)
notice A process attempted to delay the analysis task.
notice Allocates read-write-execute memory (usually to unpack itself)
notice HTTP traffic contains suspicious features which may be indicative of malware related traffic
notice Performs some HTTP requests
info Checks amount of memory in system
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The executable uses a known packer

Rules (11cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (download)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (download)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (download)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (download)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info PE_Header_Zero PE File Signature binaries (download)
info PE_Header_Zero PE File Signature binaries (upload)
info url_file_format Microsoft Windows Internet Shortcut File Format binaries (download)

Network (7cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://geoplugin.net/json.gp NL Schuberg Philis B.V. 178.237.33.50 clean
http://troubletorn.ydns.eu/x/yaztdtgfd/Owpxkxlhnei Unknown 193.42.32.61 clean
tornado.ydns.eu Unknown 193.42.32.61 mailcious
geoplugin.net NL Schuberg Philis B.V. 178.237.33.50 clean
troubletorn.ydns.eu Unknown 193.42.32.61 clean
178.237.33.50 NL Schuberg Philis B.V. 178.237.33.50 clean
193.42.32.61 Unknown 193.42.32.61 mailcious

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x51a168 DeleteCriticalSection
 0x51a16c LeaveCriticalSection
 0x51a170 EnterCriticalSection
 0x51a174 InitializeCriticalSection
 0x51a178 VirtualFree
 0x51a17c VirtualAlloc
 0x51a180 LocalFree
 0x51a184 LocalAlloc
 0x51a188 GetTickCount
 0x51a18c QueryPerformanceCounter
 0x51a190 GetVersion
 0x51a194 GetCurrentThreadId
 0x51a198 InterlockedDecrement
 0x51a19c InterlockedIncrement
 0x51a1a0 VirtualQuery
 0x51a1a4 WideCharToMultiByte
 0x51a1a8 MultiByteToWideChar
 0x51a1ac lstrlenA
 0x51a1b0 lstrcpynA
 0x51a1b4 LoadLibraryExA
 0x51a1b8 GetThreadLocale
 0x51a1bc GetStartupInfoA
 0x51a1c0 GetProcAddress
 0x51a1c4 GetModuleHandleA
 0x51a1c8 GetModuleFileNameA
 0x51a1cc GetLocaleInfoA
 0x51a1d0 GetCommandLineA
 0x51a1d4 FreeLibrary
 0x51a1d8 FindFirstFileA
 0x51a1dc FindClose
 0x51a1e0 ExitProcess
 0x51a1e4 WriteFile
 0x51a1e8 UnhandledExceptionFilter
 0x51a1ec RtlUnwind
 0x51a1f0 RaiseException
 0x51a1f4 GetStdHandle
user32.dll
 0x51a1fc GetKeyboardType
 0x51a200 LoadStringA
 0x51a204 MessageBoxA
 0x51a208 CharNextA
advapi32.dll
 0x51a210 RegQueryValueExA
 0x51a214 RegOpenKeyExA
 0x51a218 RegCloseKey
oleaut32.dll
 0x51a220 SysFreeString
 0x51a224 SysReAllocStringLen
 0x51a228 SysAllocStringLen
kernel32.dll
 0x51a230 TlsSetValue
 0x51a234 TlsGetValue
 0x51a238 LocalAlloc
 0x51a23c GetModuleHandleA
advapi32.dll
 0x51a244 RegQueryValueExA
 0x51a248 RegOpenKeyExA
 0x51a24c RegCloseKey
kernel32.dll
 0x51a254 lstrcpyA
 0x51a258 WriteFile
 0x51a25c WaitForSingleObject
 0x51a260 VirtualQuery
 0x51a264 VirtualProtect
 0x51a268 VirtualAlloc
 0x51a26c Sleep
 0x51a270 SizeofResource
 0x51a274 SetThreadLocale
 0x51a278 SetFilePointer
 0x51a27c SetEvent
 0x51a280 SetErrorMode
 0x51a284 SetEndOfFile
 0x51a288 ResetEvent
 0x51a28c ReadFile
 0x51a290 MultiByteToWideChar
 0x51a294 MulDiv
 0x51a298 LockResource
 0x51a29c LoadResource
 0x51a2a0 LoadLibraryExA
 0x51a2a4 LoadLibraryA
 0x51a2a8 LeaveCriticalSection
 0x51a2ac InitializeCriticalSection
 0x51a2b0 GlobalUnlock
 0x51a2b4 GlobalSize
 0x51a2b8 GlobalReAlloc
 0x51a2bc GlobalHandle
 0x51a2c0 GlobalLock
 0x51a2c4 GlobalFree
 0x51a2c8 GlobalFindAtomA
 0x51a2cc GlobalDeleteAtom
 0x51a2d0 GlobalAlloc
 0x51a2d4 GlobalAddAtomA
 0x51a2d8 GetVersionExA
 0x51a2dc GetVersion
 0x51a2e0 GetUserDefaultLCID
 0x51a2e4 GetTickCount
 0x51a2e8 GetThreadLocale
 0x51a2ec GetSystemInfo
 0x51a2f0 GetStringTypeExA
 0x51a2f4 GetStdHandle
 0x51a2f8 GetProcAddress
 0x51a2fc GetModuleHandleA
 0x51a300 GetModuleFileNameA
 0x51a304 GetLocaleInfoA
 0x51a308 GetLocalTime
 0x51a30c GetLastError
 0x51a310 GetFullPathNameA
 0x51a314 GetDiskFreeSpaceA
 0x51a318 GetDateFormatA
 0x51a31c GetCurrentThreadId
 0x51a320 GetCurrentProcessId
 0x51a324 GetCPInfo
 0x51a328 GetACP
 0x51a32c FreeResource
 0x51a330 InterlockedExchange
 0x51a334 FreeLibrary
 0x51a338 FormatMessageA
 0x51a33c FindResourceA
 0x51a340 FindFirstFileA
 0x51a344 FindClose
 0x51a348 FileTimeToLocalFileTime
 0x51a34c FileTimeToDosDateTime
 0x51a350 EnumCalendarInfoA
 0x51a354 EnterCriticalSection
 0x51a358 DeleteFileA
 0x51a35c DeleteCriticalSection
 0x51a360 CreateThread
 0x51a364 CreateFileA
 0x51a368 CreateEventA
 0x51a36c CompareStringA
 0x51a370 CloseHandle
version.dll
 0x51a378 VerQueryValueA
 0x51a37c GetFileVersionInfoSizeA
 0x51a380 GetFileVersionInfoA
gdi32.dll
 0x51a388 UnrealizeObject
 0x51a38c StretchBlt
 0x51a390 SetWindowOrgEx
 0x51a394 SetWinMetaFileBits
 0x51a398 SetViewportOrgEx
 0x51a39c SetTextColor
 0x51a3a0 SetStretchBltMode
 0x51a3a4 SetROP2
 0x51a3a8 SetPixel
 0x51a3ac SetEnhMetaFileBits
 0x51a3b0 SetDIBColorTable
 0x51a3b4 SetBrushOrgEx
 0x51a3b8 SetBkMode
 0x51a3bc SetBkColor
 0x51a3c0 SelectPalette
 0x51a3c4 SelectObject
 0x51a3c8 SaveDC
 0x51a3cc RestoreDC
 0x51a3d0 Rectangle
 0x51a3d4 RectVisible
 0x51a3d8 RealizePalette
 0x51a3dc Polyline
 0x51a3e0 Polygon
 0x51a3e4 PlayEnhMetaFile
 0x51a3e8 PatBlt
 0x51a3ec MoveToEx
 0x51a3f0 MaskBlt
 0x51a3f4 LineTo
 0x51a3f8 IntersectClipRect
 0x51a3fc GetWindowOrgEx
 0x51a400 GetWinMetaFileBits
 0x51a404 GetTextMetricsA
 0x51a408 GetTextExtentPointA
 0x51a40c GetTextExtentPoint32A
 0x51a410 GetSystemPaletteEntries
 0x51a414 GetStockObject
 0x51a418 GetPixel
 0x51a41c GetPaletteEntries
 0x51a420 GetObjectA
 0x51a424 GetEnhMetaFilePaletteEntries
 0x51a428 GetEnhMetaFileHeader
 0x51a42c GetEnhMetaFileDescriptionA
 0x51a430 GetEnhMetaFileBits
 0x51a434 GetDeviceCaps
 0x51a438 GetDIBits
 0x51a43c GetDIBColorTable
 0x51a440 GetDCOrgEx
 0x51a444 GetCurrentPositionEx
 0x51a448 GetClipBox
 0x51a44c GetBrushOrgEx
 0x51a450 GetBitmapBits
 0x51a454 GdiFlush
 0x51a458 ExcludeClipRect
 0x51a45c DeleteObject
 0x51a460 DeleteEnhMetaFile
 0x51a464 DeleteDC
 0x51a468 CreateSolidBrush
 0x51a46c CreatePenIndirect
 0x51a470 CreatePalette
 0x51a474 CreateHalftonePalette
 0x51a478 CreateFontIndirectA
 0x51a47c CreateEnhMetaFileA
 0x51a480 CreateDIBitmap
 0x51a484 CreateDIBSection
 0x51a488 CreateCompatibleDC
 0x51a48c CreateCompatibleBitmap
 0x51a490 CreateBrushIndirect
 0x51a494 CreateBitmap
 0x51a498 CopyEnhMetaFileA
 0x51a49c CloseEnhMetaFile
 0x51a4a0 BitBlt
user32.dll
 0x51a4a8 CreateWindowExA
 0x51a4ac WindowFromPoint
 0x51a4b0 WinHelpA
 0x51a4b4 WaitMessage
 0x51a4b8 UpdateWindow
 0x51a4bc UnregisterClassA
 0x51a4c0 UnhookWindowsHookEx
 0x51a4c4 TranslateMessage
 0x51a4c8 TranslateMDISysAccel
 0x51a4cc TrackPopupMenu
 0x51a4d0 SystemParametersInfoA
 0x51a4d4 ShowWindow
 0x51a4d8 ShowScrollBar
 0x51a4dc ShowOwnedPopups
 0x51a4e0 ShowCursor
 0x51a4e4 ShowCaret
 0x51a4e8 SetWindowsHookExA
 0x51a4ec SetWindowPos
 0x51a4f0 SetWindowPlacement
 0x51a4f4 SetWindowLongA
 0x51a4f8 SetTimer
 0x51a4fc SetScrollRange
 0x51a500 SetScrollPos
 0x51a504 SetScrollInfo
 0x51a508 SetRect
 0x51a50c SetPropA
 0x51a510 SetParent
 0x51a514 SetMenuItemInfoA
 0x51a518 SetMenu
 0x51a51c SetForegroundWindow
 0x51a520 SetFocus
 0x51a524 SetCursor
 0x51a528 SetClipboardData
 0x51a52c SetClassLongA
 0x51a530 SetCapture
 0x51a534 SetActiveWindow
 0x51a538 SendMessageA
 0x51a53c ScrollWindow
 0x51a540 ScreenToClient
 0x51a544 RemovePropA
 0x51a548 RemoveMenu
 0x51a54c ReleaseDC
 0x51a550 ReleaseCapture
 0x51a554 RegisterWindowMessageA
 0x51a558 RegisterClipboardFormatA
 0x51a55c RegisterClassA
 0x51a560 RedrawWindow
 0x51a564 PtInRect
 0x51a568 PostQuitMessage
 0x51a56c PostMessageA
 0x51a570 PeekMessageA
 0x51a574 OpenClipboard
 0x51a578 OffsetRect
 0x51a57c OemToCharA
 0x51a580 MessageBoxA
 0x51a584 MessageBeep
 0x51a588 MapWindowPoints
 0x51a58c MapVirtualKeyA
 0x51a590 LoadStringA
 0x51a594 LoadKeyboardLayoutA
 0x51a598 LoadIconA
 0x51a59c LoadCursorA
 0x51a5a0 LoadBitmapA
 0x51a5a4 KillTimer
 0x51a5a8 IsZoomed
 0x51a5ac IsWindowVisible
 0x51a5b0 IsWindowEnabled
 0x51a5b4 IsWindow
 0x51a5b8 IsRectEmpty
 0x51a5bc IsIconic
 0x51a5c0 IsDialogMessageA
 0x51a5c4 IsChild
 0x51a5c8 InvalidateRect
 0x51a5cc IntersectRect
 0x51a5d0 InsertMenuItemA
 0x51a5d4 InsertMenuA
 0x51a5d8 InflateRect
 0x51a5dc HideCaret
 0x51a5e0 GetWindowThreadProcessId
 0x51a5e4 GetWindowTextA
 0x51a5e8 GetWindowRect
 0x51a5ec GetWindowPlacement
 0x51a5f0 GetWindowLongA
 0x51a5f4 GetWindowDC
 0x51a5f8 GetTopWindow
 0x51a5fc GetSystemMetrics
 0x51a600 GetSystemMenu
 0x51a604 GetSysColorBrush
 0x51a608 GetSysColor
 0x51a60c GetSubMenu
 0x51a610 GetScrollRange
 0x51a614 GetScrollPos
 0x51a618 GetScrollInfo
 0x51a61c GetPropA
 0x51a620 GetParent
 0x51a624 GetWindow
 0x51a628 GetMessageTime
 0x51a62c GetMenuStringA
 0x51a630 GetMenuState
 0x51a634 GetMenuItemInfoA
 0x51a638 GetMenuItemID
 0x51a63c GetMenuItemCount
 0x51a640 GetMenu
 0x51a644 GetLastActivePopup
 0x51a648 GetKeyboardState
 0x51a64c GetKeyboardLayoutList
 0x51a650 GetKeyboardLayout
 0x51a654 GetKeyState
 0x51a658 GetKeyNameTextA
 0x51a65c GetIconInfo
 0x51a660 GetGUIThreadInfo
 0x51a664 GetForegroundWindow
 0x51a668 GetFocus
 0x51a66c GetDesktopWindow
 0x51a670 GetDCEx
 0x51a674 GetDC
 0x51a678 GetCursorPos
 0x51a67c GetCursor
 0x51a680 GetClipboardData
 0x51a684 GetClientRect
 0x51a688 GetClassNameA
 0x51a68c GetClassInfoA
 0x51a690 GetCapture
 0x51a694 GetActiveWindow
 0x51a698 FrameRect
 0x51a69c FindWindowA
 0x51a6a0 FillRect
 0x51a6a4 EqualRect
 0x51a6a8 EnumWindows
 0x51a6ac EnumThreadWindows
 0x51a6b0 EndPaint
 0x51a6b4 EnableWindow
 0x51a6b8 EnableScrollBar
 0x51a6bc EnableMenuItem
 0x51a6c0 EmptyClipboard
 0x51a6c4 DrawTextA
 0x51a6c8 DrawStateA
 0x51a6cc DrawMenuBar
 0x51a6d0 DrawIconEx
 0x51a6d4 DrawIcon
 0x51a6d8 DrawFrameControl
 0x51a6dc DrawEdge
 0x51a6e0 DispatchMessageA
 0x51a6e4 DestroyWindow
 0x51a6e8 DestroyMenu
 0x51a6ec DestroyIcon
 0x51a6f0 DestroyCursor
 0x51a6f4 DeleteMenu
 0x51a6f8 DefWindowProcA
 0x51a6fc DefMDIChildProcA
 0x51a700 DefFrameProcA
 0x51a704 CreatePopupMenu
 0x51a708 CreateMenu
 0x51a70c CreateIcon
 0x51a710 CloseClipboard
 0x51a714 ClientToScreen
 0x51a718 CheckMenuItem
 0x51a71c CallWindowProcA
 0x51a720 CallNextHookEx
 0x51a724 BeginPaint
 0x51a728 CharNextA
 0x51a72c CharLowerBuffA
 0x51a730 CharLowerA
 0x51a734 CharUpperBuffA
 0x51a738 CharToOemA
 0x51a73c AdjustWindowRectEx
 0x51a740 ActivateKeyboardLayout
kernel32.dll
 0x51a748 Sleep
oleaut32.dll
 0x51a750 SafeArrayPtrOfIndex
 0x51a754 SafeArrayGetUBound
 0x51a758 SafeArrayGetLBound
 0x51a75c SafeArrayCreate
 0x51a760 VariantChangeType
 0x51a764 VariantCopy
 0x51a768 VariantClear
 0x51a76c VariantInit
ole32.dll
 0x51a774 CreateStreamOnHGlobal
 0x51a778 IsAccelerator
 0x51a77c OleDraw
 0x51a780 OleSetMenuDescriptor
 0x51a784 CoCreateInstance
 0x51a788 CoGetClassObject
 0x51a78c CoUninitialize
 0x51a790 CoInitialize
 0x51a794 IsEqualGUID
oleaut32.dll
 0x51a79c GetErrorInfo
 0x51a7a0 SysFreeString
comctl32.dll
 0x51a7a8 ImageList_SetIconSize
 0x51a7ac ImageList_GetIconSize
 0x51a7b0 ImageList_Write
 0x51a7b4 ImageList_Read
 0x51a7b8 ImageList_GetDragImage
 0x51a7bc ImageList_DragShowNolock
 0x51a7c0 ImageList_SetDragCursorImage
 0x51a7c4 ImageList_DragMove
 0x51a7c8 ImageList_DragLeave
 0x51a7cc ImageList_DragEnter
 0x51a7d0 ImageList_EndDrag
 0x51a7d4 ImageList_BeginDrag
 0x51a7d8 ImageList_Remove
 0x51a7dc ImageList_DrawEx
 0x51a7e0 ImageList_Replace
 0x51a7e4 ImageList_Draw
 0x51a7e8 ImageList_GetBkColor
 0x51a7ec ImageList_SetBkColor
 0x51a7f0 ImageList_ReplaceIcon
 0x51a7f4 ImageList_Add
 0x51a7f8 ImageList_SetImageCount
 0x51a7fc ImageList_GetImageCount
 0x51a800 ImageList_Destroy
 0x51a804 ImageList_Create
winmm.dll
 0x51a80c sndPlaySoundA
uRL
 0x51a814 AddMIMEFileTypesPS

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure