Report - 2.exe

Malicious Library UPX PE File PE32 MZP Format
ScreenShot
Created 2023.10.24 07:46 Machine s1_win7_x6403
Filename 2.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
5
Behavior Score
0.4
ZERO API file : mailcious
VT API (file)
md5 ad122be61ff9f19db11fd4ff53178d09
sha256 bb0e63a06e2e6607acc23172ca564b74f804e1b9aef7968b801c5a5b4e4422ca
ssdeep 12288:bRgcdrhCHwfbv7rHMUtXe44Lzyneqtxn+9WXH3ML:bmqewfbv7IwOlLzyneqtxmWXH8
imphash f5fcef2eacb86c1adad598b65c67a3ca
impfuzzy 192:f30qk1QJbuuSrSUvK9RqooqeUurEPOQ0i:f3e1+SA9Lw4POQD
  Network IP location

Signature (2cnts)

Level Description
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The file contains an unknown PE resource name possibly indicative of a packer

Rules (5cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (1cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
tetromask.site Unknown clean

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x1005a154 DeleteCriticalSection
 0x1005a158 LeaveCriticalSection
 0x1005a15c EnterCriticalSection
 0x1005a160 InitializeCriticalSection
 0x1005a164 VirtualFree
 0x1005a168 VirtualAlloc
 0x1005a16c LocalFree
 0x1005a170 LocalAlloc
 0x1005a174 GetVersion
 0x1005a178 GetCurrentThreadId
 0x1005a17c InterlockedDecrement
 0x1005a180 InterlockedIncrement
 0x1005a184 VirtualQuery
 0x1005a188 WideCharToMultiByte
 0x1005a18c MultiByteToWideChar
 0x1005a190 lstrlenA
 0x1005a194 lstrcpynA
 0x1005a198 LoadLibraryExA
 0x1005a19c GetThreadLocale
 0x1005a1a0 GetStartupInfoA
 0x1005a1a4 GetProcAddress
 0x1005a1a8 GetModuleHandleA
 0x1005a1ac GetModuleFileNameA
 0x1005a1b0 GetLocaleInfoA
 0x1005a1b4 GetCommandLineA
 0x1005a1b8 FreeLibrary
 0x1005a1bc FindFirstFileA
 0x1005a1c0 FindClose
 0x1005a1c4 ExitProcess
 0x1005a1c8 WriteFile
 0x1005a1cc UnhandledExceptionFilter
 0x1005a1d0 RtlUnwind
 0x1005a1d4 RaiseException
 0x1005a1d8 GetStdHandle
user32.dll
 0x1005a1e0 GetKeyboardType
 0x1005a1e4 LoadStringA
 0x1005a1e8 MessageBoxA
 0x1005a1ec CharNextA
advapi32.dll
 0x1005a1f4 RegQueryValueExA
 0x1005a1f8 RegOpenKeyExA
 0x1005a1fc RegCloseKey
oleaut32.dll
 0x1005a204 SysFreeString
 0x1005a208 SysReAllocStringLen
 0x1005a20c SysAllocStringLen
kernel32.dll
 0x1005a214 TlsSetValue
 0x1005a218 TlsGetValue
 0x1005a21c LocalAlloc
 0x1005a220 GetModuleHandleA
advapi32.dll
 0x1005a228 RegQueryValueExA
 0x1005a22c RegOpenKeyExA
 0x1005a230 RegCloseKey
kernel32.dll
 0x1005a238 lstrcpyA
 0x1005a23c WriteFile
 0x1005a240 WaitForSingleObject
 0x1005a244 VirtualQuery
 0x1005a248 VirtualAlloc
 0x1005a24c Sleep
 0x1005a250 SizeofResource
 0x1005a254 SetThreadLocale
 0x1005a258 SetFilePointer
 0x1005a25c SetEvent
 0x1005a260 SetErrorMode
 0x1005a264 SetEndOfFile
 0x1005a268 ResetEvent
 0x1005a26c ReadFile
 0x1005a270 MultiByteToWideChar
 0x1005a274 MulDiv
 0x1005a278 LockResource
 0x1005a27c LoadResource
 0x1005a280 LoadLibraryA
 0x1005a284 LeaveCriticalSection
 0x1005a288 InitializeCriticalSection
 0x1005a28c GlobalUnlock
 0x1005a290 GlobalReAlloc
 0x1005a294 GlobalHandle
 0x1005a298 GlobalLock
 0x1005a29c GlobalFree
 0x1005a2a0 GlobalFindAtomA
 0x1005a2a4 GlobalDeleteAtom
 0x1005a2a8 GlobalAlloc
 0x1005a2ac GlobalAddAtomA
 0x1005a2b0 GetVersionExA
 0x1005a2b4 GetVersion
 0x1005a2b8 GetTickCount
 0x1005a2bc GetThreadLocale
 0x1005a2c0 GetTempPathA
 0x1005a2c4 GetSystemInfo
 0x1005a2c8 GetStringTypeExA
 0x1005a2cc GetStdHandle
 0x1005a2d0 GetProcAddress
 0x1005a2d4 GetModuleHandleA
 0x1005a2d8 GetModuleFileNameA
 0x1005a2dc GetLocaleInfoA
 0x1005a2e0 GetLocalTime
 0x1005a2e4 GetLastError
 0x1005a2e8 GetFullPathNameA
 0x1005a2ec GetFileSize
 0x1005a2f0 GetDiskFreeSpaceA
 0x1005a2f4 GetDateFormatA
 0x1005a2f8 GetCurrentThreadId
 0x1005a2fc GetCurrentProcessId
 0x1005a300 GetCPInfo
 0x1005a304 GetACP
 0x1005a308 FreeResource
 0x1005a30c InterlockedExchange
 0x1005a310 FreeLibrary
 0x1005a314 FormatMessageA
 0x1005a318 FindResourceA
 0x1005a31c EnumCalendarInfoA
 0x1005a320 EnterCriticalSection
 0x1005a324 DeleteCriticalSection
 0x1005a328 CreateThread
 0x1005a32c CreateFileA
 0x1005a330 CreateEventA
 0x1005a334 CompareStringA
 0x1005a338 CloseHandle
version.dll
 0x1005a340 VerQueryValueA
 0x1005a344 GetFileVersionInfoSizeA
 0x1005a348 GetFileVersionInfoA
gdi32.dll
 0x1005a350 UnrealizeObject
 0x1005a354 StretchBlt
 0x1005a358 SetWindowOrgEx
 0x1005a35c SetViewportOrgEx
 0x1005a360 SetTextColor
 0x1005a364 SetStretchBltMode
 0x1005a368 SetROP2
 0x1005a36c SetPixel
 0x1005a370 SetMetaRgn
 0x1005a374 SetDIBColorTable
 0x1005a378 SetBrushOrgEx
 0x1005a37c SetBkMode
 0x1005a380 SetBkColor
 0x1005a384 SelectPalette
 0x1005a388 SelectObject
 0x1005a38c SaveDC
 0x1005a390 RestoreDC
 0x1005a394 RectVisible
 0x1005a398 RealizePalette
 0x1005a39c PathToRegion
 0x1005a3a0 PatBlt
 0x1005a3a4 MoveToEx
 0x1005a3a8 MaskBlt
 0x1005a3ac LineTo
 0x1005a3b0 IntersectClipRect
 0x1005a3b4 GetWindowOrgEx
 0x1005a3b8 GetTextMetricsA
 0x1005a3bc GetTextExtentPoint32A
 0x1005a3c0 GetTextColor
 0x1005a3c4 GetTextCharset
 0x1005a3c8 GetTextCharacterExtra
 0x1005a3cc GetSystemPaletteEntries
 0x1005a3d0 GetStockObject
 0x1005a3d4 GetPixelFormat
 0x1005a3d8 GetPixel
 0x1005a3dc GetPaletteEntries
 0x1005a3e0 GetObjectA
 0x1005a3e4 GetDeviceCaps
 0x1005a3e8 GetDIBits
 0x1005a3ec GetDIBColorTable
 0x1005a3f0 GetDCOrgEx
 0x1005a3f4 GetCurrentPositionEx
 0x1005a3f8 GetClipBox
 0x1005a3fc GetBrushOrgEx
 0x1005a400 GetBitmapBits
 0x1005a404 ExcludeClipRect
 0x1005a408 DeleteObject
 0x1005a40c DeleteDC
 0x1005a410 CreateSolidBrush
 0x1005a414 CreatePenIndirect
 0x1005a418 CreatePalette
 0x1005a41c CreateHalftonePalette
 0x1005a420 CreateFontIndirectA
 0x1005a424 CreateDIBitmap
 0x1005a428 CreateDIBSection
 0x1005a42c CreateCompatibleDC
 0x1005a430 CreateCompatibleBitmap
 0x1005a434 CreateBrushIndirect
 0x1005a438 CreateBitmap
 0x1005a43c BitBlt
user32.dll
 0x1005a444 CreateWindowExA
 0x1005a448 WindowFromPoint
 0x1005a44c WinHelpA
 0x1005a450 WaitMessage
 0x1005a454 UpdateWindow
 0x1005a458 UnregisterClassA
 0x1005a45c UnhookWindowsHookEx
 0x1005a460 TranslateMessage
 0x1005a464 TranslateMDISysAccel
 0x1005a468 TrackPopupMenu
 0x1005a46c SystemParametersInfoA
 0x1005a470 ShowWindow
 0x1005a474 ShowScrollBar
 0x1005a478 ShowOwnedPopups
 0x1005a47c ShowCursor
 0x1005a480 SetWindowsHookExA
 0x1005a484 SetWindowPos
 0x1005a488 SetWindowPlacement
 0x1005a48c SetWindowLongA
 0x1005a490 SetTimer
 0x1005a494 SetScrollRange
 0x1005a498 SetScrollPos
 0x1005a49c SetScrollInfo
 0x1005a4a0 SetRect
 0x1005a4a4 SetPropA
 0x1005a4a8 SetParent
 0x1005a4ac SetMenuItemInfoA
 0x1005a4b0 SetMenu
 0x1005a4b4 SetForegroundWindow
 0x1005a4b8 SetFocus
 0x1005a4bc SetCursor
 0x1005a4c0 SetClassLongA
 0x1005a4c4 SetCapture
 0x1005a4c8 SetActiveWindow
 0x1005a4cc SendMessageA
 0x1005a4d0 ScrollWindow
 0x1005a4d4 ScreenToClient
 0x1005a4d8 RemovePropA
 0x1005a4dc RemoveMenu
 0x1005a4e0 ReleaseDC
 0x1005a4e4 ReleaseCapture
 0x1005a4e8 RegisterWindowMessageA
 0x1005a4ec RegisterClipboardFormatA
 0x1005a4f0 RegisterClassA
 0x1005a4f4 RedrawWindow
 0x1005a4f8 PtInRect
 0x1005a4fc PostQuitMessage
 0x1005a500 PostMessageA
 0x1005a504 PeekMessageA
 0x1005a508 OffsetRect
 0x1005a50c OemToCharA
 0x1005a510 MessageBoxA
 0x1005a514 MapWindowPoints
 0x1005a518 MapVirtualKeyA
 0x1005a51c LoadStringA
 0x1005a520 LoadKeyboardLayoutA
 0x1005a524 LoadIconA
 0x1005a528 LoadCursorA
 0x1005a52c LoadBitmapA
 0x1005a530 KillTimer
 0x1005a534 IsZoomed
 0x1005a538 IsWindowVisible
 0x1005a53c IsWindowEnabled
 0x1005a540 IsWindow
 0x1005a544 IsRectEmpty
 0x1005a548 IsIconic
 0x1005a54c IsDialogMessageA
 0x1005a550 IsChild
 0x1005a554 InvalidateRect
 0x1005a558 IntersectRect
 0x1005a55c InsertMenuItemA
 0x1005a560 InsertMenuA
 0x1005a564 InflateRect
 0x1005a568 GetWindowThreadProcessId
 0x1005a56c GetWindowTextA
 0x1005a570 GetWindowRect
 0x1005a574 GetWindowPlacement
 0x1005a578 GetWindowLongA
 0x1005a57c GetWindowDC
 0x1005a580 GetTopWindow
 0x1005a584 GetSystemMetrics
 0x1005a588 GetSystemMenu
 0x1005a58c GetSysColorBrush
 0x1005a590 GetSysColor
 0x1005a594 GetSubMenu
 0x1005a598 GetScrollRange
 0x1005a59c GetScrollPos
 0x1005a5a0 GetScrollInfo
 0x1005a5a4 GetPropA
 0x1005a5a8 GetParent
 0x1005a5ac GetWindow
 0x1005a5b0 GetMenuStringA
 0x1005a5b4 GetMenuState
 0x1005a5b8 GetMenuItemInfoA
 0x1005a5bc GetMenuItemID
 0x1005a5c0 GetMenuItemCount
 0x1005a5c4 GetMenu
 0x1005a5c8 GetLastActivePopup
 0x1005a5cc GetKeyboardState
 0x1005a5d0 GetKeyboardLayoutList
 0x1005a5d4 GetKeyboardLayout
 0x1005a5d8 GetKeyState
 0x1005a5dc GetKeyNameTextA
 0x1005a5e0 GetIconInfo
 0x1005a5e4 GetForegroundWindow
 0x1005a5e8 GetFocus
 0x1005a5ec GetDoubleClickTime
 0x1005a5f0 GetDialogBaseUnits
 0x1005a5f4 GetDesktopWindow
 0x1005a5f8 GetDCEx
 0x1005a5fc GetDC
 0x1005a600 GetCursorPos
 0x1005a604 GetCursor
 0x1005a608 GetClipboardViewer
 0x1005a60c GetClipboardOwner
 0x1005a610 GetClipboardSequenceNumber
 0x1005a614 GetClientRect
 0x1005a618 GetClassNameA
 0x1005a61c GetClassInfoA
 0x1005a620 GetCaretBlinkTime
 0x1005a624 GetCapture
 0x1005a628 GetActiveWindow
 0x1005a62c FrameRect
 0x1005a630 FindWindowA
 0x1005a634 FillRect
 0x1005a638 EqualRect
 0x1005a63c EnumWindows
 0x1005a640 EnumThreadWindows
 0x1005a644 EndPaint
 0x1005a648 EnableWindow
 0x1005a64c EnableScrollBar
 0x1005a650 EnableMenuItem
 0x1005a654 DrawTextA
 0x1005a658 DrawMenuBar
 0x1005a65c DrawIconEx
 0x1005a660 DrawIcon
 0x1005a664 DrawFrameControl
 0x1005a668 DrawEdge
 0x1005a66c DispatchMessageA
 0x1005a670 DestroyWindow
 0x1005a674 DestroyMenu
 0x1005a678 DestroyIcon
 0x1005a67c DestroyCursor
 0x1005a680 DeleteMenu
 0x1005a684 DefWindowProcA
 0x1005a688 DefMDIChildProcA
 0x1005a68c DefFrameProcA
 0x1005a690 CreatePopupMenu
 0x1005a694 CreateMenu
 0x1005a698 CreateIcon
 0x1005a69c ClientToScreen
 0x1005a6a0 CheckMenuItem
 0x1005a6a4 CallWindowProcA
 0x1005a6a8 CallNextHookEx
 0x1005a6ac BeginPaint
 0x1005a6b0 CharNextA
 0x1005a6b4 CharLowerA
 0x1005a6b8 CharToOemA
 0x1005a6bc AdjustWindowRectEx
 0x1005a6c0 ActivateKeyboardLayout
kernel32.dll
 0x1005a6c8 Sleep
oleaut32.dll
 0x1005a6d0 SafeArrayPtrOfIndex
 0x1005a6d4 SafeArrayGetUBound
 0x1005a6d8 SafeArrayGetLBound
 0x1005a6dc SafeArrayCreate
 0x1005a6e0 VariantChangeType
 0x1005a6e4 VariantCopy
 0x1005a6e8 VariantClear
 0x1005a6ec VariantInit
ole32.dll
 0x1005a6f4 CoUninitialize
 0x1005a6f8 CoInitialize
oleaut32.dll
 0x1005a700 GetErrorInfo
 0x1005a704 SysFreeString
comctl32.dll
 0x1005a70c ImageList_SetIconSize
 0x1005a710 ImageList_GetIconSize
 0x1005a714 ImageList_Write
 0x1005a718 ImageList_Read
 0x1005a71c ImageList_GetDragImage
 0x1005a720 ImageList_DragShowNolock
 0x1005a724 ImageList_SetDragCursorImage
 0x1005a728 ImageList_DragMove
 0x1005a72c ImageList_DragLeave
 0x1005a730 ImageList_DragEnter
 0x1005a734 ImageList_EndDrag
 0x1005a738 ImageList_BeginDrag
 0x1005a73c ImageList_Remove
 0x1005a740 ImageList_DrawEx
 0x1005a744 ImageList_Draw
 0x1005a748 ImageList_GetBkColor
 0x1005a74c ImageList_SetBkColor
 0x1005a750 ImageList_ReplaceIcon
 0x1005a754 ImageList_Add
 0x1005a758 ImageList_GetImageCount
 0x1005a75c ImageList_Destroy
 0x1005a760 ImageList_Create
shell32.dll
 0x1005a768 ShellExecuteExW

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure