Report - Pikabot.dll

Malicious Library UPX PE32 PE File DLL MZP Format
ScreenShot
Created 2023.12.14 13:02 Machine s1_win7_x6401
Filename Pikabot.dll
Type PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
AI Score
7
Behavior Score
2.0
ZERO API file : clean
VT API (file) 33 detected (AIDetectMalware, malicious, high confidence, score, unsafe, Save, confidence, Pikabot, Injuke, CrypterX, YXDLMZ, moderate, Detected, ai score=97, Qakbot, ABRisk, HXWM, BScope, TrojanBanker, Qbot, Chgt, CLOUD, Static AI, Malicious PE, susgen, Kryptik, EPGV)
md5 61c58c2bebffb3b3590f24675721fa5b
sha256 a93fb9f75e3a93a7334c24f60b3ede274f51ac87c07d7b45320a0081867de2df
ssdeep 24576:kIaMIOzjvVDdJSOLyVMMRB6q9ZeZzZy0M1i:bTnHzWVP/zeZsFI
imphash f5bc4ec0da51e649a1c0c02fdc5c7f44
impfuzzy 192:f3cJk1sTVAadbuuaxSUvK9y3ooqEho72POQRj:f3r1sl9aq9/YPOQd
  Network IP location

Signature (4cnts)

Level Description
danger File has been identified by 33 AntiVirus engines on VirusTotal as malicious
notice Foreign language identified in PE resource
notice The binary likely contains encrypted or compressed data indicative of a packer
info The executable contains unknown PE section names indicative of a packer (could be a false positive)

Rules (6cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsDLL (no description) binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x48612c DeleteCriticalSection
 0x486130 LeaveCriticalSection
 0x486134 EnterCriticalSection
 0x486138 InitializeCriticalSection
 0x48613c VirtualFree
 0x486140 VirtualAlloc
 0x486144 LocalFree
 0x486148 LocalAlloc
 0x48614c GetVersion
 0x486150 GetCurrentThreadId
 0x486154 InterlockedDecrement
 0x486158 InterlockedIncrement
 0x48615c VirtualQuery
 0x486160 WideCharToMultiByte
 0x486164 MultiByteToWideChar
 0x486168 lstrlenA
 0x48616c lstrcpynA
 0x486170 LoadLibraryExA
 0x486174 GetThreadLocale
 0x486178 GetStartupInfoA
 0x48617c GetProcAddress
 0x486180 GetModuleHandleA
 0x486184 GetModuleFileNameA
 0x486188 GetLocaleInfoA
 0x48618c GetCommandLineA
 0x486190 FreeLibrary
 0x486194 FindFirstFileA
 0x486198 FindClose
 0x48619c ExitProcess
 0x4861a0 WriteFile
 0x4861a4 UnhandledExceptionFilter
 0x4861a8 RtlUnwind
 0x4861ac RaiseException
 0x4861b0 GetStdHandle
user32.dll
 0x4861b8 GetKeyboardType
 0x4861bc LoadStringA
 0x4861c0 MessageBoxA
 0x4861c4 CharNextA
advapi32.dll
 0x4861cc RegQueryValueExA
 0x4861d0 RegOpenKeyExA
 0x4861d4 RegCloseKey
oleaut32.dll
 0x4861dc SysFreeString
 0x4861e0 SysReAllocStringLen
 0x4861e4 SysAllocStringLen
kernel32.dll
 0x4861ec TlsSetValue
 0x4861f0 TlsGetValue
 0x4861f4 TlsFree
 0x4861f8 TlsAlloc
 0x4861fc LocalFree
 0x486200 LocalAlloc
advapi32.dll
 0x486208 RegQueryValueExA
 0x48620c RegOpenKeyExA
 0x486210 RegCloseKey
 0x486214 GetUserNameA
kernel32.dll
 0x48621c lstrcpyA
 0x486220 WriteFile
 0x486224 WaitForSingleObject
 0x486228 VirtualQuery
 0x48622c VirtualAlloc
 0x486230 Sleep
 0x486234 SizeofResource
 0x486238 SetThreadLocale
 0x48623c SetFilePointer
 0x486240 SetEvent
 0x486244 SetErrorMode
 0x486248 SetEndOfFile
 0x48624c ResetEvent
 0x486250 ReadFile
 0x486254 MulDiv
 0x486258 LockResource
 0x48625c LoadResource
 0x486260 LoadLibraryA
 0x486264 LeaveCriticalSection
 0x486268 InitializeCriticalSection
 0x48626c GlobalUnlock
 0x486270 GlobalReAlloc
 0x486274 GlobalHandle
 0x486278 GlobalLock
 0x48627c GlobalFree
 0x486280 GlobalFindAtomA
 0x486284 GlobalDeleteAtom
 0x486288 GlobalAlloc
 0x48628c GlobalAddAtomA
 0x486290 GetVersionExA
 0x486294 GetVersion
 0x486298 GetTickCount
 0x48629c GetThreadLocale
 0x4862a0 GetTempPathA
 0x4862a4 GetSystemInfo
 0x4862a8 GetStringTypeExA
 0x4862ac GetStdHandle
 0x4862b0 GetProcAddress
 0x4862b4 GetModuleHandleA
 0x4862b8 GetModuleFileNameA
 0x4862bc GetLocaleInfoA
 0x4862c0 GetLocalTime
 0x4862c4 GetLastError
 0x4862c8 GetFullPathNameA
 0x4862cc GetFileSize
 0x4862d0 GetDiskFreeSpaceA
 0x4862d4 GetDateFormatA
 0x4862d8 GetCurrentThreadId
 0x4862dc GetCurrentProcessId
 0x4862e0 GetCPInfo
 0x4862e4 GetACP
 0x4862e8 FreeResource
 0x4862ec InterlockedExchange
 0x4862f0 FreeLibrary
 0x4862f4 FormatMessageA
 0x4862f8 FindResourceA
 0x4862fc FindFirstFileA
 0x486300 FindClose
 0x486304 FileTimeToLocalFileTime
 0x486308 FileTimeToDosDateTime
 0x48630c EnumCalendarInfoA
 0x486310 EnterCriticalSection
 0x486314 DeleteFileA
 0x486318 DeleteCriticalSection
 0x48631c CreateThread
 0x486320 CreateFileA
 0x486324 CreateEventA
 0x486328 CompareStringA
 0x48632c CloseHandle
version.dll
 0x486334 VerQueryValueA
 0x486338 GetFileVersionInfoSizeA
 0x48633c GetFileVersionInfoA
gdi32.dll
 0x486344 UnrealizeObject
 0x486348 StretchBlt
 0x48634c SetWindowOrgEx
 0x486350 SetWinMetaFileBits
 0x486354 SetViewportOrgEx
 0x486358 SetTextColor
 0x48635c SetStretchBltMode
 0x486360 SetROP2
 0x486364 SetPixel
 0x486368 SetEnhMetaFileBits
 0x48636c SetDIBColorTable
 0x486370 SetBrushOrgEx
 0x486374 SetBkMode
 0x486378 SetBkColor
 0x48637c SelectPalette
 0x486380 SelectObject
 0x486384 SelectClipRgn
 0x486388 SaveDC
 0x48638c RestoreDC
 0x486390 Rectangle
 0x486394 RectVisible
 0x486398 RealizePalette
 0x48639c Polyline
 0x4863a0 Polygon
 0x4863a4 PlayEnhMetaFile
 0x4863a8 PatBlt
 0x4863ac MoveToEx
 0x4863b0 MaskBlt
 0x4863b4 LineTo
 0x4863b8 IntersectClipRect
 0x4863bc GetWindowOrgEx
 0x4863c0 GetWinMetaFileBits
 0x4863c4 GetTextMetricsA
 0x4863c8 GetTextExtentPointA
 0x4863cc GetTextExtentPoint32A
 0x4863d0 GetTextCharset
 0x4863d4 GetSystemPaletteEntries
 0x4863d8 GetStockObject
 0x4863dc GetROP2
 0x4863e0 GetPixel
 0x4863e4 GetPaletteEntries
 0x4863e8 GetObjectA
 0x4863ec GetGraphicsMode
 0x4863f0 GetFontLanguageInfo
 0x4863f4 GetEnhMetaFilePaletteEntries
 0x4863f8 GetEnhMetaFileHeader
 0x4863fc GetEnhMetaFileBits
 0x486400 GetEnhMetaFileW
 0x486404 GetDeviceCaps
 0x486408 GetDIBits
 0x48640c GetDIBColorTable
 0x486410 GetDCOrgEx
 0x486414 GetCurrentPositionEx
 0x486418 GetClipRgn
 0x48641c GetClipBox
 0x486420 GetBrushOrgEx
 0x486424 GetBkMode
 0x486428 GetBitmapBits
 0x48642c GdiFlush
 0x486430 ExtTextOutA
 0x486434 ExcludeClipRect
 0x486438 DeleteObject
 0x48643c DeleteEnhMetaFile
 0x486440 DeleteDC
 0x486444 CreateSolidBrush
 0x486448 CreateRectRgn
 0x48644c CreatePenIndirect
 0x486450 CreatePalette
 0x486454 CreateHalftonePalette
 0x486458 CreateFontIndirectA
 0x48645c CreateDIBitmap
 0x486460 CreateDIBSection
 0x486464 CreateCompatibleDC
 0x486468 CreateCompatibleBitmap
 0x48646c CreateBrushIndirect
 0x486470 CreateBitmap
 0x486474 CopyEnhMetaFileA
 0x486478 BitBlt
user32.dll
 0x486480 CreateWindowExA
 0x486484 WindowFromPoint
 0x486488 WinHelpA
 0x48648c WaitMessage
 0x486490 UpdateWindow
 0x486494 UnregisterClassA
 0x486498 UnhookWindowsHookEx
 0x48649c TranslateMessage
 0x4864a0 TranslateMDISysAccel
 0x4864a4 TrackPopupMenu
 0x4864a8 SystemParametersInfoA
 0x4864ac ShowWindow
 0x4864b0 ShowScrollBar
 0x4864b4 ShowOwnedPopups
 0x4864b8 ShowCursor
 0x4864bc ShowCaret
 0x4864c0 SetWindowsHookExA
 0x4864c4 SetWindowTextA
 0x4864c8 SetWindowPos
 0x4864cc SetWindowPlacement
 0x4864d0 SetWindowLongA
 0x4864d4 SetTimer
 0x4864d8 SetScrollRange
 0x4864dc SetScrollPos
 0x4864e0 SetScrollInfo
 0x4864e4 SetRect
 0x4864e8 SetPropA
 0x4864ec SetParent
 0x4864f0 SetMenuItemInfoA
 0x4864f4 SetMenu
 0x4864f8 SetForegroundWindow
 0x4864fc SetFocus
 0x486500 SetCursor
 0x486504 SetClipboardData
 0x486508 SetClassLongA
 0x48650c SetCapture
 0x486510 SetActiveWindow
 0x486514 SendMessageA
 0x486518 ScrollWindow
 0x48651c ScreenToClient
 0x486520 RemovePropA
 0x486524 RemoveMenu
 0x486528 ReleaseDC
 0x48652c ReleaseCapture
 0x486530 RegisterWindowMessageA
 0x486534 RegisterClipboardFormatA
 0x486538 RegisterClassA
 0x48653c RedrawWindow
 0x486540 PtInRect
 0x486544 PostQuitMessage
 0x486548 PostMessageA
 0x48654c PeekMessageA
 0x486550 OpenClipboard
 0x486554 OffsetRect
 0x486558 OemToCharA
 0x48655c MessageBoxA
 0x486560 MessageBeep
 0x486564 MapWindowPoints
 0x486568 MapVirtualKeyA
 0x48656c LoadStringA
 0x486570 LoadKeyboardLayoutA
 0x486574 LoadIconA
 0x486578 LoadCursorA
 0x48657c LoadBitmapA
 0x486580 KillTimer
 0x486584 IsZoomed
 0x486588 IsWindowVisible
 0x48658c IsWindowEnabled
 0x486590 IsWindow
 0x486594 IsRectEmpty
 0x486598 IsIconic
 0x48659c IsDialogMessageA
 0x4865a0 IsChild
 0x4865a4 InvalidateRect
 0x4865a8 IntersectRect
 0x4865ac InsertMenuItemA
 0x4865b0 InsertMenuA
 0x4865b4 InflateRect
 0x4865b8 HideCaret
 0x4865bc GetWindowThreadProcessId
 0x4865c0 GetWindowTextA
 0x4865c4 GetWindowRect
 0x4865c8 GetWindowPlacement
 0x4865cc GetWindowLongA
 0x4865d0 GetWindowDC
 0x4865d4 GetTopWindow
 0x4865d8 GetSystemMetrics
 0x4865dc GetSystemMenu
 0x4865e0 GetSysColorBrush
 0x4865e4 GetSysColor
 0x4865e8 GetSubMenu
 0x4865ec GetScrollRange
 0x4865f0 GetScrollPos
 0x4865f4 GetScrollInfo
 0x4865f8 GetPropA
 0x4865fc GetParent
 0x486600 GetWindow
 0x486604 GetMenuStringA
 0x486608 GetMenuState
 0x48660c GetMenuItemInfoA
 0x486610 GetMenuItemID
 0x486614 GetMenuItemCount
 0x486618 GetMenu
 0x48661c GetLastActivePopup
 0x486620 GetKeyboardState
 0x486624 GetKeyboardLayoutList
 0x486628 GetKeyboardLayout
 0x48662c GetKeyState
 0x486630 GetKeyNameTextA
 0x486634 GetIconInfo
 0x486638 GetForegroundWindow
 0x48663c GetFocus
 0x486640 GetDesktopWindow
 0x486644 GetDCEx
 0x486648 GetDC
 0x48664c GetCursorPos
 0x486650 GetCursor
 0x486654 GetClipboardData
 0x486658 GetClientRect
 0x48665c GetClassNameA
 0x486660 GetClassInfoA
 0x486664 GetCapture
 0x486668 GetActiveWindow
 0x48666c FrameRect
 0x486670 FindWindowA
 0x486674 FillRect
 0x486678 EqualRect
 0x48667c EnumWindows
 0x486680 EnumThreadWindows
 0x486684 EndPaint
 0x486688 EnableWindow
 0x48668c EnableScrollBar
 0x486690 EnableMenuItem
 0x486694 EmptyClipboard
 0x486698 DrawTextA
 0x48669c DrawStateA
 0x4866a0 DrawMenuBar
 0x4866a4 DrawIconEx
 0x4866a8 DrawIcon
 0x4866ac DrawFrameControl
 0x4866b0 DrawFocusRect
 0x4866b4 DrawEdge
 0x4866b8 DispatchMessageA
 0x4866bc DestroyWindow
 0x4866c0 DestroyMenu
 0x4866c4 DestroyIcon
 0x4866c8 DestroyCursor
 0x4866cc DeleteMenu
 0x4866d0 DefWindowProcA
 0x4866d4 DefMDIChildProcA
 0x4866d8 DefFrameProcA
 0x4866dc CreatePopupMenu
 0x4866e0 CreateMenu
 0x4866e4 CreateIcon
 0x4866e8 CloseClipboard
 0x4866ec ClientToScreen
 0x4866f0 CheckMenuItem
 0x4866f4 CallWindowProcA
 0x4866f8 CallNextHookEx
 0x4866fc BeginPaint
 0x486700 CharNextA
 0x486704 CharLowerBuffA
 0x486708 CharLowerA
 0x48670c CharUpperBuffA
 0x486710 CharToOemA
 0x486714 AdjustWindowRectEx
 0x486718 ActivateKeyboardLayout
kernel32.dll
 0x486720 Sleep
oleaut32.dll
 0x486728 SafeArrayPtrOfIndex
 0x48672c SafeArrayGetUBound
 0x486730 SafeArrayGetLBound
 0x486734 SafeArrayCreate
 0x486738 VariantChangeType
 0x48673c VariantCopy
 0x486740 VariantClear
 0x486744 VariantInit
comctl32.dll
 0x48674c ImageList_SetIconSize
 0x486750 ImageList_GetIconSize
 0x486754 ImageList_Write
 0x486758 ImageList_Read
 0x48675c ImageList_GetDragImage
 0x486760 ImageList_DragShowNolock
 0x486764 ImageList_SetDragCursorImage
 0x486768 ImageList_DragMove
 0x48676c ImageList_DragLeave
 0x486770 ImageList_DragEnter
 0x486774 ImageList_EndDrag
 0x486778 ImageList_BeginDrag
 0x48677c ImageList_Remove
 0x486780 ImageList_DrawEx
 0x486784 ImageList_Draw
 0x486788 ImageList_GetBkColor
 0x48678c ImageList_SetBkColor
 0x486790 ImageList_ReplaceIcon
 0x486794 ImageList_Add
 0x486798 ImageList_GetImageCount
 0x48679c ImageList_Destroy
 0x4867a0 ImageList_Create
 0x4867a4 InitCommonControls
winmm.dll
 0x4867ac sndPlaySoundA

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure