Report - Akjnagosfmwanr.exe

Malicious Library UPX PE File PE32 MZP Format
ScreenShot
Created 2023.09.21 10:29 Machine s1_win7_x6403
Filename Akjnagosfmwanr.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
4
Behavior Score
2.6
ZERO API file : clean
VT API (file) 44 detected (AIDetectMalware, Noon, malicious, high confidence, Zusy, Artemis, Save, ModiLoader, confidence, 100%, Strictor, PSWStealer, Eldorado, Attribute, HighConfidence, score, bewy, DropperX, DownLoader46, Delf, Detected, Remcos, R570879, TScope, ai score=84, unsafe, Chgt, CLASSIC, susgen, Formbook)
md5 047324921fcd5ca64134a367d389e900
sha256 34a8af0af0e818443b87f59fcbb5c10af500f1b45c9b3d1e7d6aecc494d009f5
ssdeep 12288:eo1mZWdG+Q25wOymUo04zNbv/dY/gmfXJJG2uZX8H5ZravCBhOX:e0pG+F53ycRVv/eIKGfZX8H5tav6s
imphash f44d2d08aa3f7e0759f9441d70198a12
impfuzzy 192:334+G1dDmibuuSrSUvK9RqoaqEfeSPOQXp:33y1XSA9LiPOQ5
  Network IP location

Signature (6cnts)

Level Description
danger File has been identified by 44 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The executable uses a known packer

Rules (5cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (1cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
wedhstinwell.online Unknown clean

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x4f9154 DeleteCriticalSection
 0x4f9158 LeaveCriticalSection
 0x4f915c EnterCriticalSection
 0x4f9160 InitializeCriticalSection
 0x4f9164 VirtualFree
 0x4f9168 VirtualAlloc
 0x4f916c LocalFree
 0x4f9170 LocalAlloc
 0x4f9174 GetTickCount
 0x4f9178 QueryPerformanceCounter
 0x4f917c GetVersion
 0x4f9180 GetCurrentThreadId
 0x4f9184 InterlockedDecrement
 0x4f9188 InterlockedIncrement
 0x4f918c VirtualQuery
 0x4f9190 WideCharToMultiByte
 0x4f9194 MultiByteToWideChar
 0x4f9198 lstrlenA
 0x4f919c lstrcpynA
 0x4f91a0 LoadLibraryExA
 0x4f91a4 GetThreadLocale
 0x4f91a8 GetStartupInfoA
 0x4f91ac GetProcAddress
 0x4f91b0 GetModuleHandleA
 0x4f91b4 GetModuleFileNameA
 0x4f91b8 GetLocaleInfoA
 0x4f91bc GetCommandLineA
 0x4f91c0 FreeLibrary
 0x4f91c4 FindFirstFileA
 0x4f91c8 FindClose
 0x4f91cc ExitProcess
 0x4f91d0 WriteFile
 0x4f91d4 UnhandledExceptionFilter
 0x4f91d8 RtlUnwind
 0x4f91dc RaiseException
 0x4f91e0 GetStdHandle
user32.dll
 0x4f91e8 GetKeyboardType
 0x4f91ec LoadStringA
 0x4f91f0 MessageBoxA
 0x4f91f4 CharNextA
advapi32.dll
 0x4f91fc RegQueryValueExA
 0x4f9200 RegOpenKeyExA
 0x4f9204 RegCloseKey
oleaut32.dll
 0x4f920c SysFreeString
 0x4f9210 SysReAllocStringLen
 0x4f9214 SysAllocStringLen
kernel32.dll
 0x4f921c TlsSetValue
 0x4f9220 TlsGetValue
 0x4f9224 LocalAlloc
 0x4f9228 GetModuleHandleA
advapi32.dll
 0x4f9230 RegQueryValueExA
 0x4f9234 RegOpenKeyExA
 0x4f9238 RegCloseKey
kernel32.dll
 0x4f9240 lstrcpyA
 0x4f9244 WriteFile
 0x4f9248 WaitForSingleObject
 0x4f924c VirtualQuery
 0x4f9250 VirtualProtect
 0x4f9254 VirtualAlloc
 0x4f9258 Sleep
 0x4f925c SizeofResource
 0x4f9260 SetThreadLocale
 0x4f9264 SetFilePointer
 0x4f9268 SetEvent
 0x4f926c SetErrorMode
 0x4f9270 SetEndOfFile
 0x4f9274 ResetEvent
 0x4f9278 ReadFile
 0x4f927c MultiByteToWideChar
 0x4f9280 MulDiv
 0x4f9284 LockResource
 0x4f9288 LoadResource
 0x4f928c LoadLibraryExA
 0x4f9290 LoadLibraryA
 0x4f9294 LeaveCriticalSection
 0x4f9298 InitializeCriticalSection
 0x4f929c GlobalUnlock
 0x4f92a0 GlobalSize
 0x4f92a4 GlobalReAlloc
 0x4f92a8 GlobalHandle
 0x4f92ac GlobalLock
 0x4f92b0 GlobalFree
 0x4f92b4 GlobalFindAtomA
 0x4f92b8 GlobalDeleteAtom
 0x4f92bc GlobalAlloc
 0x4f92c0 GlobalAddAtomA
 0x4f92c4 GetVersionExA
 0x4f92c8 GetVersion
 0x4f92cc GetUserDefaultLCID
 0x4f92d0 GetTickCount
 0x4f92d4 GetThreadLocale
 0x4f92d8 GetSystemInfo
 0x4f92dc GetStringTypeExA
 0x4f92e0 GetStdHandle
 0x4f92e4 GetProcAddress
 0x4f92e8 GetModuleHandleA
 0x4f92ec GetModuleFileNameA
 0x4f92f0 GetLocaleInfoA
 0x4f92f4 GetLocalTime
 0x4f92f8 GetLastError
 0x4f92fc GetFullPathNameA
 0x4f9300 GetDiskFreeSpaceA
 0x4f9304 GetDateFormatA
 0x4f9308 GetCurrentThreadId
 0x4f930c GetCurrentProcessId
 0x4f9310 GetCurrentProcess
 0x4f9314 GetCPInfo
 0x4f9318 GetACP
 0x4f931c FreeResource
 0x4f9320 InterlockedExchange
 0x4f9324 FreeLibrary
 0x4f9328 FormatMessageA
 0x4f932c FlushFileBuffers
 0x4f9330 FindResourceA
 0x4f9334 EnumCalendarInfoA
 0x4f9338 EnterCriticalSection
 0x4f933c DeleteCriticalSection
 0x4f9340 CreateThread
 0x4f9344 CreateFileA
 0x4f9348 CreateEventA
 0x4f934c CompareStringA
 0x4f9350 CloseHandle
version.dll
 0x4f9358 VerQueryValueA
 0x4f935c GetFileVersionInfoSizeA
 0x4f9360 GetFileVersionInfoA
gdi32.dll
 0x4f9368 UnrealizeObject
 0x4f936c StretchBlt
 0x4f9370 SetWindowOrgEx
 0x4f9374 SetWinMetaFileBits
 0x4f9378 SetViewportOrgEx
 0x4f937c SetTextColor
 0x4f9380 SetStretchBltMode
 0x4f9384 SetROP2
 0x4f9388 SetPixel
 0x4f938c SetEnhMetaFileBits
 0x4f9390 SetDIBColorTable
 0x4f9394 SetBrushOrgEx
 0x4f9398 SetBkMode
 0x4f939c SetBkColor
 0x4f93a0 SelectPalette
 0x4f93a4 SelectObject
 0x4f93a8 SaveDC
 0x4f93ac RestoreDC
 0x4f93b0 RectVisible
 0x4f93b4 RealizePalette
 0x4f93b8 PlayEnhMetaFile
 0x4f93bc PatBlt
 0x4f93c0 MoveToEx
 0x4f93c4 MaskBlt
 0x4f93c8 LineTo
 0x4f93cc IntersectClipRect
 0x4f93d0 GetWindowOrgEx
 0x4f93d4 GetWinMetaFileBits
 0x4f93d8 GetTextMetricsA
 0x4f93dc GetTextExtentPoint32A
 0x4f93e0 GetSystemPaletteEntries
 0x4f93e4 GetStockObject
 0x4f93e8 GetPixel
 0x4f93ec GetPaletteEntries
 0x4f93f0 GetObjectA
 0x4f93f4 GetEnhMetaFilePaletteEntries
 0x4f93f8 GetEnhMetaFileHeader
 0x4f93fc GetEnhMetaFileDescriptionA
 0x4f9400 GetEnhMetaFileBits
 0x4f9404 GetDeviceCaps
 0x4f9408 GetDIBits
 0x4f940c GetDIBColorTable
 0x4f9410 GetDCOrgEx
 0x4f9414 GetCurrentPositionEx
 0x4f9418 GetClipBox
 0x4f941c GetBrushOrgEx
 0x4f9420 GetBitmapBits
 0x4f9424 GdiFlush
 0x4f9428 ExcludeClipRect
 0x4f942c DeleteObject
 0x4f9430 DeleteEnhMetaFile
 0x4f9434 DeleteDC
 0x4f9438 CreateSolidBrush
 0x4f943c CreatePenIndirect
 0x4f9440 CreatePalette
 0x4f9444 CreateHalftonePalette
 0x4f9448 CreateFontIndirectA
 0x4f944c CreateEnhMetaFileA
 0x4f9450 CreateDIBitmap
 0x4f9454 CreateDIBSection
 0x4f9458 CreateCompatibleDC
 0x4f945c CreateCompatibleBitmap
 0x4f9460 CreateBrushIndirect
 0x4f9464 CreateBitmap
 0x4f9468 CopyEnhMetaFileA
 0x4f946c CloseEnhMetaFile
 0x4f9470 BitBlt
user32.dll
 0x4f9478 CreateWindowExA
 0x4f947c WindowFromPoint
 0x4f9480 WinHelpA
 0x4f9484 WaitMessage
 0x4f9488 UpdateWindow
 0x4f948c UnregisterClassA
 0x4f9490 UnhookWindowsHookEx
 0x4f9494 TranslateMessage
 0x4f9498 TranslateMDISysAccel
 0x4f949c TrackPopupMenu
 0x4f94a0 SystemParametersInfoA
 0x4f94a4 ShowWindow
 0x4f94a8 ShowScrollBar
 0x4f94ac ShowOwnedPopups
 0x4f94b0 ShowCursor
 0x4f94b4 SetWindowsHookExA
 0x4f94b8 SetWindowPos
 0x4f94bc SetWindowPlacement
 0x4f94c0 SetWindowLongA
 0x4f94c4 SetTimer
 0x4f94c8 SetScrollRange
 0x4f94cc SetScrollPos
 0x4f94d0 SetScrollInfo
 0x4f94d4 SetRect
 0x4f94d8 SetPropA
 0x4f94dc SetParent
 0x4f94e0 SetMenuItemInfoA
 0x4f94e4 SetMenu
 0x4f94e8 SetForegroundWindow
 0x4f94ec SetFocus
 0x4f94f0 SetCursor
 0x4f94f4 SetClassLongA
 0x4f94f8 SetCapture
 0x4f94fc SetActiveWindow
 0x4f9500 SendMessageA
 0x4f9504 ScrollWindow
 0x4f9508 ScreenToClient
 0x4f950c RemovePropA
 0x4f9510 RemoveMenu
 0x4f9514 ReleaseDC
 0x4f9518 ReleaseCapture
 0x4f951c RegisterWindowMessageA
 0x4f9520 RegisterClipboardFormatA
 0x4f9524 RegisterClassA
 0x4f9528 RedrawWindow
 0x4f952c PtInRect
 0x4f9530 PostQuitMessage
 0x4f9534 PostMessageA
 0x4f9538 PeekMessageA
 0x4f953c OffsetRect
 0x4f9540 OemToCharA
 0x4f9544 MessageBoxA
 0x4f9548 MapWindowPoints
 0x4f954c MapVirtualKeyA
 0x4f9550 LoadStringA
 0x4f9554 LoadKeyboardLayoutA
 0x4f9558 LoadIconA
 0x4f955c LoadCursorA
 0x4f9560 LoadBitmapA
 0x4f9564 KillTimer
 0x4f9568 IsZoomed
 0x4f956c IsWindowVisible
 0x4f9570 IsWindowEnabled
 0x4f9574 IsWindow
 0x4f9578 IsRectEmpty
 0x4f957c IsIconic
 0x4f9580 IsDialogMessageA
 0x4f9584 IsChild
 0x4f9588 InvalidateRect
 0x4f958c IntersectRect
 0x4f9590 InsertMenuItemA
 0x4f9594 InsertMenuA
 0x4f9598 InflateRect
 0x4f959c GetWindowThreadProcessId
 0x4f95a0 GetWindowTextA
 0x4f95a4 GetWindowRect
 0x4f95a8 GetWindowPlacement
 0x4f95ac GetWindowLongA
 0x4f95b0 GetWindowDC
 0x4f95b4 GetTopWindow
 0x4f95b8 GetSystemMetrics
 0x4f95bc GetSystemMenu
 0x4f95c0 GetSysColorBrush
 0x4f95c4 GetSysColor
 0x4f95c8 GetSubMenu
 0x4f95cc GetScrollRange
 0x4f95d0 GetScrollPos
 0x4f95d4 GetScrollInfo
 0x4f95d8 GetPropA
 0x4f95dc GetParent
 0x4f95e0 GetWindow
 0x4f95e4 GetMessageTime
 0x4f95e8 GetMenuStringA
 0x4f95ec GetMenuState
 0x4f95f0 GetMenuItemInfoA
 0x4f95f4 GetMenuItemID
 0x4f95f8 GetMenuItemCount
 0x4f95fc GetMenu
 0x4f9600 GetLastActivePopup
 0x4f9604 GetKeyboardState
 0x4f9608 GetKeyboardLayoutList
 0x4f960c GetKeyboardLayout
 0x4f9610 GetKeyState
 0x4f9614 GetKeyNameTextA
 0x4f9618 GetIconInfo
 0x4f961c GetForegroundWindow
 0x4f9620 GetFocus
 0x4f9624 GetDesktopWindow
 0x4f9628 GetDCEx
 0x4f962c GetDC
 0x4f9630 GetCursorPos
 0x4f9634 GetCursor
 0x4f9638 GetClipboardData
 0x4f963c GetClientRect
 0x4f9640 GetClassNameA
 0x4f9644 GetClassInfoA
 0x4f9648 GetCaretPos
 0x4f964c GetCapture
 0x4f9650 GetActiveWindow
 0x4f9654 FrameRect
 0x4f9658 FindWindowA
 0x4f965c FillRect
 0x4f9660 EqualRect
 0x4f9664 EnumWindows
 0x4f9668 EnumThreadWindows
 0x4f966c EndPaint
 0x4f9670 EnableWindow
 0x4f9674 EnableScrollBar
 0x4f9678 EnableMenuItem
 0x4f967c DrawTextA
 0x4f9680 DrawMenuBar
 0x4f9684 DrawIconEx
 0x4f9688 DrawIcon
 0x4f968c DrawFrameControl
 0x4f9690 DrawEdge
 0x4f9694 DispatchMessageA
 0x4f9698 DestroyWindow
 0x4f969c DestroyMenu
 0x4f96a0 DestroyIcon
 0x4f96a4 DestroyCursor
 0x4f96a8 DeleteMenu
 0x4f96ac DefWindowProcA
 0x4f96b0 DefMDIChildProcA
 0x4f96b4 DefFrameProcA
 0x4f96b8 CreatePopupMenu
 0x4f96bc CreateMenu
 0x4f96c0 CreateIcon
 0x4f96c4 ClientToScreen
 0x4f96c8 CheckMenuItem
 0x4f96cc CallWindowProcA
 0x4f96d0 CallNextHookEx
 0x4f96d4 BeginPaint
 0x4f96d8 CharNextA
 0x4f96dc CharLowerBuffA
 0x4f96e0 CharLowerA
 0x4f96e4 CharToOemA
 0x4f96e8 AdjustWindowRectEx
 0x4f96ec ActivateKeyboardLayout
kernel32.dll
 0x4f96f4 Sleep
oleaut32.dll
 0x4f96fc SafeArrayPtrOfIndex
 0x4f9700 SafeArrayGetUBound
 0x4f9704 SafeArrayGetLBound
 0x4f9708 SafeArrayCreate
 0x4f970c VariantChangeType
 0x4f9710 VariantCopy
 0x4f9714 VariantClear
 0x4f9718 VariantInit
ole32.dll
 0x4f9720 CreateStreamOnHGlobal
 0x4f9724 IsAccelerator
 0x4f9728 OleDraw
 0x4f972c OleSetMenuDescriptor
 0x4f9730 CoCreateInstance
 0x4f9734 CoGetClassObject
 0x4f9738 CoUninitialize
 0x4f973c CoInitialize
 0x4f9740 IsEqualGUID
oleaut32.dll
 0x4f9748 GetErrorInfo
 0x4f974c SysFreeString
comctl32.dll
 0x4f9754 ImageList_SetIconSize
 0x4f9758 ImageList_GetIconSize
 0x4f975c ImageList_Write
 0x4f9760 ImageList_Read
 0x4f9764 ImageList_GetDragImage
 0x4f9768 ImageList_DragShowNolock
 0x4f976c ImageList_SetDragCursorImage
 0x4f9770 ImageList_DragMove
 0x4f9774 ImageList_DragLeave
 0x4f9778 ImageList_DragEnter
 0x4f977c ImageList_EndDrag
 0x4f9780 ImageList_BeginDrag
 0x4f9784 ImageList_Remove
 0x4f9788 ImageList_DrawEx
 0x4f978c ImageList_Draw
 0x4f9790 ImageList_GetBkColor
 0x4f9794 ImageList_SetBkColor
 0x4f9798 ImageList_ReplaceIcon
 0x4f979c ImageList_Add
 0x4f97a0 ImageList_SetImageCount
 0x4f97a4 ImageList_GetImageCount
 0x4f97a8 ImageList_Destroy
 0x4f97ac ImageList_Create
uRL
 0x4f97b4 AddMIMEFileTypesPS

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure