Report - 198.exe

Malicious Library UPX PE File PE32 OS Processor Check
ScreenShot
Created 2023.10.20 07:29 Machine s1_win7_x6403
Filename 198.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
8
Behavior Score
0.4
ZERO API file : clean
VT API (file)
md5 0171e926fc187d40081567eeb2b2ef27
sha256 4ca7d34dddff55f6781ab90e06fa64b6225202d6f99a847a5f713d547cfde277
ssdeep 3072:VS81hDGDsanYN9EUP5fEbaQMrGBwi00L1pNGcaK/TBfCcnAgsHsVC7b7:sKGDsaYN9TumCBwwbNV/TBqcMb7
imphash 04754536767d250d5353f62256c28828
impfuzzy 192:w5CBVjBD5QCXq+TDBCcOG+t4tnJgVjlKG1TBwFJxih8fFk73bBvk7FGg7Q9:w+5Q0EcOG+g2E2Cf6vkRZU9
  Network IP location

Signature (1cnts)

Level Description
notice The binary likely contains encrypted or compressed data indicative of a packer

Rules (5cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

USER32.dll
 0x4261f4 GetMenuItemRect
 0x4261f8 MenuItemFromPoint
 0x4261fc DragObject
 0x426200 DragDetect
 0x426204 DrawIcon
 0x426208 GrayStringA
 0x42620c DrawStateA
 0x426210 UpdateWindow
 0x426214 SetActiveWindow
 0x426218 PaintDesktop
 0x42621c AllowSetForegroundWindow
 0x426220 GetDCEx
 0x426224 GetWindowDC
 0x426228 BeginPaint
 0x42622c EndPaint
 0x426230 GetUpdateRect
 0x426234 GetWindowRgn
 0x426238 GetWindowRgnBox
 0x42623c ExcludeUpdateRgn
 0x426240 InvalidateRect
 0x426244 LockWindowUpdate
 0x426248 ScrollWindowEx
 0x42624c SetScrollPos
 0x426250 SetScrollRange
 0x426254 ShowScrollBar
 0x426258 EnableScrollBar
 0x42625c EnumPropsExA
 0x426260 GetWindowTextLengthA
 0x426264 GetClientRect
 0x426268 GetWindowRect
 0x42626c AdjustWindowRect
 0x426270 AdjustWindowRectExForDpi
 0x426274 SetWindowContextHelpId
 0x426278 GetWindowContextHelpId
 0x42627c SetMenuContextHelpId
 0x426280 MessageBoxA
 0x426284 ShowCursor
 0x426288 SetCursorPos
 0x42628c SetCursor
 0x426290 GetPhysicalCursorPos
 0x426294 SetCaretBlinkTime
 0x426298 HideCaret
 0x42629c ShowCaret
 0x4262a0 SetCaretPos
 0x4262a4 ClientToScreen
 0x4262a8 ScreenToClient
 0x4262ac LogicalToPhysicalPoint
 0x4262b0 PhysicalToLogicalPoint
 0x4262b4 LogicalToPhysicalPointForPerMonitorDPI
 0x4262b8 MapWindowPoints
 0x4262bc WindowFromPoint
 0x4262c0 ChildWindowFromPoint
 0x4262c4 GetSysColor
 0x4262c8 SetSysColors
 0x4262cc InvertRect
 0x4262d0 SetRectEmpty
 0x4262d4 InflateRect
 0x4262d8 OffsetRect
 0x4262dc IsRectEmpty
 0x4262e0 EqualRect
 0x4262e4 PtInRect
 0x4262e8 GetWindowWord
 0x4262ec SetWindowWord
 0x4262f0 GetWindowLongA
 0x4262f4 SetWindowLongA
 0x4262f8 GetClassWord
 0x4262fc SetClassWord
 0x426300 GetClassLongA
 0x426304 GetProcessDefaultLayout
 0x426308 SetProcessDefaultLayout
 0x42630c GetDesktopWindow
 0x426310 FindWindowA
 0x426314 FindWindowExA
 0x426318 RegisterShellHookWindow
 0x42631c GetClassNameA
 0x426320 GetTopWindow
 0x426324 GetWindow
 0x426328 GetMenuItemInfoA
 0x42632c LoadCursorFromFileA
 0x426330 CreateCursor
 0x426334 DestroyCursor
 0x426338 CreateIconFromResourceEx
 0x42633c CopyImage
 0x426340 MapDialogRect
 0x426344 DlgDirSelectExA
 0x426348 DlgDirListComboBoxA
 0x42634c DlgDirSelectComboBoxExA
 0x426350 SetScrollInfo
 0x426354 GetScrollInfo
 0x426358 DefFrameProcA
 0x42635c ArrangeIconicWindows
 0x426360 TileWindows
 0x426364 CascadeWindows
 0x426368 GetGuiResources
 0x42636c EnumDisplaySettingsA
 0x426370 EnumDisplaySettingsExA
 0x426374 SetMenuDefaultItem
 0x426378 DisplayConfigGetDeviceInfo
 0x42637c SystemParametersInfoA
 0x426380 SoundSentry
 0x426384 SetLastErrorEx
 0x426388 InternalGetWindowText
 0x42638c CancelShutdown
 0x426390 MonitorFromPoint
 0x426394 MonitorFromRect
 0x426398 MonitorFromWindow
 0x42639c IsWinEventHookInstalled
 0x4263a0 GetGUIThreadInfo
 0x4263a4 BlockInput
 0x4263a8 SetProcessDPIAware
 0x4263ac SetThreadDpiAwarenessContext
 0x4263b0 GetAwarenessFromDpiAwarenessContext
 0x4263b4 GetDpiFromDpiAwarenessContext
 0x4263b8 IsValidDpiAwarenessContext
 0x4263bc GetSystemDpiForProcess
 0x4263c0 SetProcessDpiAwarenessContext
 0x4263c4 SetThreadDpiHostingBehavior
 0x4263c8 GetThreadDpiHostingBehavior
 0x4263cc GetTitleBarInfo
 0x4263d0 GetMenuBarInfo
 0x4263d4 RegisterRawInputDevices
 0x4263d8 GetRegisteredRawInputDevices
 0x4263dc GetRawInputDeviceList
 0x4263e0 GetPointerDevice
 0x4263e4 GetPointerDeviceRects
 0x4263e8 GetPointerDeviceCursors
 0x4263ec GetRawPointerDeviceData
 0x4263f0 ChangeWindowMessageFilter
 0x4263f4 ChangeWindowMessageFilterEx
 0x4263f8 GetGestureInfo
 0x4263fc GetGestureExtraArgs
 0x426400 CloseGestureInfoHandle
 0x426404 ShutdownBlockReasonCreate
 0x426408 ShutdownBlockReasonQuery
 0x42640c ShutdownBlockReasonDestroy
 0x426410 GetCurrentInputMessageSource
 0x426414 GetCIMSSM
 0x426418 SetDisplayAutoRotationPreferences
 0x42641c IsImmersiveProcess
 0x426420 DdeSetQualityOfService
 0x426424 ReuseDDElParam
 0x426428 DdeInitializeA
 0x42642c DdeDisconnect
 0x426430 DdeSetUserHandle
 0x426434 DdeAbandonTransaction
 0x426438 DdeImpersonateClient
 0x42643c DdeNameService
 0x426440 DdeClientTransaction
 0x426444 DdeAddData
 0x426448 DdeGetData
 0x42644c DdeAccessData
 0x426450 DdeUnaccessData
 0x426454 DdeFreeDataHandle
 0x426458 DdeCreateStringHandleA
 0x42645c DdeKeepStringHandle
 0x426460 DdeCmpStringHandles
 0x426464 InsertMenuItemA
 0x426468 EndMenu
 0x42646c GetMenuInfo
 0x426470 CalculatePopupWindowPosition
 0x426474 TrackPopupMenuEx
 0x426478 GetMenuCheckMarkDimensions
 0x42647c SetMenuItemBitmaps
 0x426480 DeleteMenu
 0x426484 RemoveMenu
 0x426488 ModifyMenuA
 0x42648c GetMenuItemID
 0x426490 DestroyMenu
 0x426494 CreatePopupMenu
 0x426498 DrawMenuBar
 0x42649c GetMenuStringA
 0x4264a0 HiliteMenuItem
 0x4264a4 SetMenu
 0x4264a8 GetMenu
 0x4264ac LoadMenuIndirectA
 0x4264b0 GetSystemMetricsForDpi
 0x4264b4 TranslateAcceleratorA
 0x4264b8 CopyAcceleratorTableA
 0x4264bc SetCoalescableTimer
 0x4264c0 MsgWaitForMultipleObjects
 0x4264c4 ReleaseCapture
 0x4264c8 GetCapture
 0x4264cc GetQueueStatus
 0x4264d0 MapVirtualKeyA
 0x4264d4 GetLastInputInfo
 0x4264d8 GetPointerInputTransform
 0x4264dc EvaluateProximityToPolygon
 0x4264e0 EvaluateProximityToRect
 0x4264e4 EnableMouseInPointer
 0x4264e8 UnregisterPointerInputTargetEx
 0x4264ec RegisterPointerInputTarget
 0x4264f0 SkipPointerFrameMessages
 0x4264f4 GetMenuDefaultItem
 0x4264f8 GetPointerFramePenInfo
 0x4264fc GetPointerPenInfoHistory
 0x426500 QueryDisplayConfig
 0x426504 SetMenuItemInfoA
 0x426508 GetPointerFrameTouchInfoHistory
 0x42650c GetPointerTouchInfo
 0x426510 GetPointerFrameInfo
 0x426514 GetPointerInfo
 0x426518 GetPointerType
 0x42651c InitializeTouchInjection
 0x426520 UnregisterTouchWindow
 0x426524 RegisterTouchWindow
 0x426528 VkKeyScanExA
 0x42652c VkKeyScanA
 0x426530 ToUnicode
 0x426534 ToAsciiEx
 0x426538 GetKeyNameTextA
 0x42653c SetKeyboardState
 0x426540 GetKBCodePage
 0x426544 GetFocus
 0x426548 GetActiveWindow
 0x42654c SetFocus
 0x426550 IsCharLowerA
 0x426554 CharNextA
 0x426558 CharUpperBuffW
 0x42655c CharUpperBuffA
 0x426560 CharUpperA
 0x426564 OemToCharBuffA
 0x426568 OemToCharA
 0x42656c RemoveClipboardFormatListener
 0x426570 AddClipboardFormatListener
 0x426574 GetOpenClipboardWindow
 0x426578 IsClipboardFormatAvailable
 0x42657c EmptyClipboard
 0x426580 GetClipboardFormatNameA
 0x426584 CountClipboardFormats
 0x426588 ChangeClipboardChain
 0x42658c SetClipboardViewer
 0x426590 SetDialogDpiChangeBehavior
 0x426594 GetDialogControlDpiChangeBehavior
 0x426598 DefDlgProcA
 0x42659c GetDialogBaseUnits
 0x4265a0 GetDlgCtrlID
 0x4265a4 IsDlgButtonChecked
 0x4265a8 GetDlgItemTextA
 0x4265ac GetDlgItemInt
 0x4265b0 EndDialog
 0x4265b4 DialogBoxIndirectParamA
 0x4265b8 DialogBoxParamA
 0x4265bc CreateDialogParamA
 0x4265c0 IsZoomed
 0x4265c4 EndDeferWindowPos
 0x4265c8 DeferWindowPos
 0x4265cc SetWindowDisplayAffinity
 0x4265d0 GetWindowDisplayAffinity
 0x4265d4 SetWindowPlacement
 0x4265d8 SetWindowPos
 0x4265dc OpenIcon
 0x4265e0 ShowOwnedPopups
 0x4265e4 SetLayeredWindowAttributes
 0x4265e8 PrintWindow
 0x4265ec GetLayeredWindowAttributes
 0x4265f0 UpdateLayeredWindow
 0x4265f4 ShowWindow
 0x4265f8 IsChild
 0x4265fc IsMenu
 0x426600 GetClassInfoExA
 0x426604 GetClassInfoA
 0x426608 UnregisterClassA
 0x42660c RegisterClassA
 0x426610 InSendMessageEx
 0x426614 InSendMessage
 0x426618 CallWindowProcA
 0x42661c PostQuitMessage
 0x426620 DefWindowProcA
 0x426624 AttachThreadInput
 0x426628 PostThreadMessageA
 0x42662c PostMessageA
 0x426630 UnregisterPowerSettingNotification
 0x426634 RegisterDeviceNotificationA
 0x426638 IsWow64Message
 0x42663c GetMessagePos
 0x426640 SwapMouseButton
 0x426644 ExitWindowsEx
 0x426648 RegisterHotKey
 0x42664c PeekMessageA
 0x426650 SetMessageQueue
 0x426654 TranslateMessage
 0x426658 GetMessageA
 0x42665c DrawFrameControl
 0x426660 SetUserObjectInformationA
 0x426664 GetProcessWindowStation
 0x426668 SetProcessWindowStation
 0x42666c CloseWindowStation
 0x426670 CreateWindowStationA
 0x426674 CloseDesktop
 0x426678 SetThreadDesktop
 0x42667c EnumDesktopsA
 0x426680 OpenInputDesktop
 0x426684 OpenDesktopA
 0x426688 CreateDesktopA
 0x42668c GetKeyboardLayout
 0x426690 GetKeyboardLayoutNameA
 0x426694 UnloadKeyboardLayout
 0x426698 CallNextHookEx
 0x42669c LoadStringA
KERNEL32.dll
 0x42608c LoadLibraryExW
 0x426090 FreeLibrary
 0x426094 TlsFree
 0x426098 TlsSetValue
 0x42609c TlsGetValue
 0x4260a0 TlsAlloc
 0x4260a4 InitializeCriticalSectionAndSpinCount
 0x4260a8 DeleteCriticalSection
 0x4260ac LeaveCriticalSection
 0x4260b0 EnterCriticalSection
 0x4260b4 SetLastError
 0x4260b8 GetLastError
 0x4260bc GetFileType
 0x4260c0 GetStartupInfoW
 0x4260c4 IsDebuggerPresent
 0x4260c8 InitializeSListHead
 0x4260cc GetSystemTimeAsFileTime
 0x4260d0 GetCurrentThreadId
 0x4260d4 QueryPerformanceCounter
 0x4260d8 IsProcessorFeaturePresent
 0x4260dc TerminateProcess
 0x4260e0 GetCurrentProcess
 0x4260e4 SetUnhandledExceptionFilter
 0x4260e8 UnhandledExceptionFilter
 0x4260ec CreateFileW
 0x4260f0 SetFilePointerEx
 0x4260f4 ExitProcess
 0x4260f8 GetModuleHandleExW
 0x4260fc GetConsoleMode
 0x426100 GetConsoleOutputCP
 0x426104 GetStdHandle
 0x426108 GetModuleFileNameW
 0x42610c LCMapStringW
 0x426110 SetStdHandle
 0x426114 FindClose
 0x426118 FindFirstFileExW
 0x42611c IsValidCodePage
 0x426120 GetACP
 0x426124 GetOEMCP
 0x426128 GetCPInfo
 0x42612c GetCommandLineA
 0x426130 GetCommandLineW
 0x426134 GetEnvironmentStringsW
 0x426138 RtlUnwind
 0x42613c FreeEnvironmentStringsW
 0x426140 GetProcessHeap
 0x426144 WriteConsoleW
 0x426148 HeapSize
 0x42614c RaiseException
 0x426150 DecodePointer
 0x426154 VirtualProtect
 0x426158 VirtualAlloc
 0x42615c WideCharToMultiByte
 0x426160 MultiByteToWideChar
 0x426164 MoveFileW
 0x426168 FormatMessageA
 0x42616c LocalAlloc
 0x426170 LoadLibraryA
 0x426174 GetProcAddress
 0x426178 GetModuleHandleW
 0x42617c GetModuleHandleA
 0x426180 GetModuleFileNameA
 0x426184 GetTickCount
 0x426188 GetSystemInfo
 0x42618c GetProcessId
 0x426190 SetThreadPriority
 0x426194 SwitchToThread
 0x426198 GetCurrentProcessId
 0x42619c CreateMutexW
 0x4261a0 HeapFree
 0x4261a4 HeapAlloc
 0x4261a8 HeapCreate
 0x4261ac DisconnectNamedPipe
 0x4261b0 DuplicateHandle
 0x4261b4 CloseHandle
 0x4261b8 OutputDebugStringA
 0x4261bc WriteFile
 0x4261c0 SetFilePointer
 0x4261c4 SetFileAttributesW
 0x4261c8 GetFileAttributesW
 0x4261cc FlushFileBuffers
 0x4261d0 FindNextFileW
 0x4261d4 FindFirstFileW
 0x4261d8 CreateFileA
 0x4261dc CreateDirectoryA
 0x4261e0 HeapReAlloc
 0x4261e4 GetStringTypeW
ADVAPI32.dll
 0x426000 CloseEventLog
SHELL32.dll
 0x4261ec SHCreateProcessAsUserW
ole32.dll
 0x4266a4 CoInitializeSecurity
 0x4266a8 CoInitializeEx
 0x4266ac CoCreateInstance
 0x4266b0 HWND_UserMarshal
GDI32.dll
 0x426008 Arc
 0x42600c CloseMetaFile
 0x426010 CopyMetaFileA
 0x426014 CreateBitmapIndirect
 0x426018 CreateBrushIndirect
 0x42601c CreateCompatibleDC
 0x426020 CreateDCA
 0x426024 CreateDIBitmap
 0x426028 CreateDIBPatternBrushPt
 0x42602c CreateEllipticRgnIndirect
 0x426030 CreateFontA
 0x426034 CreateICA
 0x426038 CreatePalette
 0x42603c CreatePolyPolygonRgn
 0x426040 CreatePatternBrush
 0x426044 CreateRectRgnIndirect
 0x426048 CreateRoundRectRgn
 0x42604c CreateScalableFontResourceA
 0x426050 DeleteDC
 0x426054 DeleteObject
 0x426058 GetDeviceCaps
 0x42605c AddFontMemResourceEx
 0x426060 CreateFontIndirectExA
 0x426064 CopyEnhMetaFileA
 0x426068 AngleArc
 0x42606c CombineTransform
 0x426070 AbortPath
 0x426074 BeginPath
 0x426078 CloseFigure
 0x42607c GetObjectW
 0x426080 CreateColorSpaceA
 0x426084 Chord

EAT(Export Address Table) Library



Similarity measure (PE file only) - Checking for service failure