Report - 2.exe

Malicious Library VMProtect PE32 PE File
ScreenShot
Created 2023.12.15 19:00 Machine s1_win7_x6403
Filename 2.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score Not founds Behavior Score
1.8
ZERO API file : clean
VT API (file)
md5 f89eaa7fbb0a8b2e24ad2671d833b15f
sha256 38e73fb4a7a7f2db4050786998e0ddf0796666697161c3ea01ce3a0739216dd6
ssdeep 12288:144M2HpWtxkR9X+iQsN4hfqqxtATOAsRgK+hdqoxdow9Rmlcw5WBUod:1/mQ9OmMqqrASMfvTn6cd
imphash e4c3f9bfa4a5bcded21f9def30f93338
impfuzzy 192:Sw/KjbF5HFpg8U8TYdTYOi9W7uscAcRcPHNQyq:6FlTUnRE+HRq
  Network IP location

Signature (6cnts)

Level Description
notice Foreign language identified in PE resource
notice The binary likely contains encrypted or compressed data indicative of a packer
notice The executable is likely packed with VMProtect
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The file contains an unknown PE resource name possibly indicative of a packer

Rules (4cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch VMProtect_Zero VMProtect packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

WINMM.dll
 0x595f3a midiStreamRestart
 0x595f3e midiStreamClose
 0x595f42 midiOutReset
 0x595f46 midiStreamStop
 0x595f4a waveOutWrite
 0x595f4e waveOutPrepareHeader
 0x595f52 waveOutReset
 0x595f56 waveOutClose
 0x595f5a waveOutUnprepareHeader
 0x595f5e midiStreamOut
 0x595f62 midiOutPrepareHeader
 0x595f66 midiStreamProperty
 0x595f6a midiStreamOpen
 0x595f6e midiOutUnprepareHeader
 0x595f72 waveOutOpen
 0x595f76 waveOutGetNumDevs
 0x595f7a waveOutPause
WS2_32.dll
 0x595f82 closesocket
 0x595f86 accept
 0x595f8a getpeername
 0x595f8e ioctlsocket
 0x595f92 recvfrom
 0x595f96 WSAAsyncSelect
 0x595f9a recv
 0x595f9e WSACleanup
 0x595fa2 inet_ntoa
KERNEL32.dll
 0x595faa MultiByteToWideChar
 0x595fae SetLastError
 0x595fb2 GetTimeZoneInformation
 0x595fb6 GetVersion
 0x595fba InterlockedIncrement
 0x595fbe InterlockedDecrement
 0x595fc2 WideCharToMultiByte
 0x595fc6 LocalFree
 0x595fca FileTimeToSystemTime
 0x595fce FileTimeToLocalFileTime
 0x595fd2 lstrcpynA
 0x595fd6 DuplicateHandle
 0x595fda FlushFileBuffers
 0x595fde LockFile
 0x595fe2 UnlockFile
 0x595fe6 SetEndOfFile
 0x595fea lstrcmpiA
 0x595fee GlobalDeleteAtom
 0x595ff2 GlobalFindAtomA
 0x595ff6 GlobalAddAtomA
 0x595ffa GlobalGetAtomNameA
 0x595ffe GetSystemDirectoryA
 0x596002 LocalAlloc
 0x596006 TlsAlloc
 0x59600a GlobalHandle
 0x59600e TlsFree
 0x596012 TlsSetValue
 0x596016 LocalReAlloc
 0x59601a TlsGetValue
 0x59601e GetFileTime
 0x596022 GetCurrentThread
 0x596026 GlobalFlags
 0x59602a SetErrorMode
 0x59602e GetProcessVersion
 0x596032 GetCPInfo
 0x596036 GetOEMCP
 0x59603a GetStartupInfoA
 0x59603e RtlUnwind
 0x596042 GetSystemTime
 0x596046 GetLocalTime
 0x59604a RaiseException
 0x59604e HeapSize
 0x596052 GetACP
 0x596056 UnhandledExceptionFilter
 0x59605a FreeEnvironmentStringsA
 0x59605e FreeEnvironmentStringsW
 0x596062 GetEnvironmentStrings
 0x596066 GetEnvironmentStringsW
 0x59606a SetHandleCount
 0x59606e GetStdHandle
 0x596072 GetFileType
 0x596076 GetEnvironmentVariableA
 0x59607a HeapDestroy
 0x59607e HeapCreate
 0x596082 VirtualFree
 0x596086 SetEnvironmentVariableA
 0x59608a LCMapStringA
 0x59608e LCMapStringW
 0x596092 VirtualAlloc
 0x596096 IsBadWritePtr
 0x59609a SetUnhandledExceptionFilter
 0x59609e GetStringTypeA
 0x5960a2 GetStringTypeW
 0x5960a6 CompareStringA
 0x5960aa CompareStringW
 0x5960ae IsBadReadPtr
 0x5960b2 IsBadCodePtr
 0x5960b6 SetStdHandle
 0x5960ba TerminateProcess
 0x5960be GetCurrentProcess
 0x5960c2 GetFileSize
 0x5960c6 SetFilePointer
 0x5960ca CreateSemaphoreA
 0x5960ce ResumeThread
 0x5960d2 ReleaseSemaphore
 0x5960d6 EnterCriticalSection
 0x5960da LeaveCriticalSection
 0x5960de GetProfileStringA
 0x5960e2 WriteFile
 0x5960e6 ReadFile
 0x5960ea GetLastError
 0x5960ee WaitForMultipleObjects
 0x5960f2 CreateFileA
 0x5960f6 SetEvent
 0x5960fa FindResourceA
 0x5960fe LoadResource
 0x596102 LockResource
 0x596106 GetModuleFileNameA
 0x59610a GetCurrentThreadId
 0x59610e ExitProcess
 0x596112 GlobalSize
 0x596116 GlobalFree
 0x59611a DeleteCriticalSection
 0x59611e InitializeCriticalSection
 0x596122 lstrcatA
 0x596126 WinExec
 0x59612a lstrcpyA
 0x59612e FindNextFileA
 0x596132 GlobalReAlloc
 0x596136 HeapFree
 0x59613a HeapReAlloc
 0x59613e GetProcessHeap
 0x596142 HeapAlloc
 0x596146 GetFullPathNameA
 0x59614a FreeLibrary
 0x59614e LoadLibraryA
 0x596152 lstrlenA
 0x596156 GetVersionExA
 0x59615a WritePrivateProfileStringA
 0x59615e CreateThread
 0x596162 CreateEventA
 0x596166 Sleep
 0x59616a GlobalAlloc
 0x59616e GlobalLock
 0x596172 GlobalUnlock
 0x596176 FindFirstFileA
 0x59617a FindClose
 0x59617e GetFileAttributesA
 0x596182 SetCurrentDirectoryA
 0x596186 GetVolumeInformationA
 0x59618a GetModuleHandleA
 0x59618e GetProcAddress
 0x596192 MulDiv
 0x596196 GetCommandLineA
 0x59619a GetTickCount
 0x59619e WaitForSingleObject
 0x5961a2 CloseHandle
 0x5961a6 InterlockedExchange
 0x5961aa lstrcmpA
USER32.dll
 0x5961b2 ScrollWindowEx
 0x5961b6 IsDialogMessageA
 0x5961ba SetWindowTextA
 0x5961be MoveWindow
 0x5961c2 CheckMenuItem
 0x5961c6 SetMenuItemBitmaps
 0x5961ca GetMenuState
 0x5961ce GetMenuCheckMarkDimensions
 0x5961d2 LoadStringA
 0x5961d6 GetSysColorBrush
 0x5961da DrawFrameControl
 0x5961de DrawEdge
 0x5961e2 DrawFocusRect
 0x5961e6 WindowFromPoint
 0x5961ea GetMessageA
 0x5961ee UnregisterClassA
 0x5961f2 SetRectEmpty
 0x5961f6 RegisterClipboardFormatA
 0x5961fa CreateIconFromResourceEx
 0x5961fe CreateIconFromResource
 0x596202 DrawIconEx
 0x596206 CreatePopupMenu
 0x59620a AppendMenuA
 0x59620e ModifyMenuA
 0x596212 CreateMenu
 0x596216 CreateAcceleratorTableA
 0x59621a GetDlgCtrlID
 0x59621e GetSubMenu
 0x596222 EnableMenuItem
 0x596226 ClientToScreen
 0x59622a EnumDisplaySettingsA
 0x59622e LoadImageA
 0x596232 ShowWindow
 0x596236 IsWindowEnabled
 0x59623a TranslateAcceleratorA
 0x59623e GetKeyState
 0x596242 CopyAcceleratorTableA
 0x596246 PostQuitMessage
 0x59624a IsZoomed
 0x59624e GetSystemMenu
 0x596252 DeleteMenu
 0x596256 GetClassInfoA
 0x59625a DefWindowProcA
 0x59625e GetMenu
 0x596262 SetMenu
 0x596266 PeekMessageA
 0x59626a IsIconic
 0x59626e SetFocus
 0x596272 GetActiveWindow
 0x596276 GetWindow
 0x59627a DestroyAcceleratorTable
 0x59627e GetMessagePos
 0x596282 ChildWindowFromPointEx
 0x596286 CopyRect
 0x59628a LoadBitmapA
 0x59628e WinHelpA
 0x596292 KillTimer
 0x596296 SetTimer
 0x59629a ReleaseCapture
 0x59629e GetCapture
 0x5962a2 SetCapture
 0x5962a6 GetScrollRange
 0x5962aa SetScrollRange
 0x5962ae SetScrollPos
 0x5962b2 InflateRect
 0x5962b6 SetRect
 0x5962ba DestroyIcon
 0x5962be PtInRect
 0x5962c2 OffsetRect
 0x5962c6 IsWindowVisible
 0x5962ca EnableWindow
 0x5962ce RedrawWindow
 0x5962d2 GetWindowLongA
 0x5962d6 SetWindowLongA
 0x5962da GetSysColor
 0x5962de SetActiveWindow
 0x5962e2 SetCursorPos
 0x5962e6 LoadCursorA
 0x5962ea SetCursor
 0x5962ee GetDC
 0x5962f2 FillRect
 0x5962f6 IsRectEmpty
 0x5962fa ReleaseDC
 0x5962fe IsChild
 0x596302 DestroyMenu
 0x596306 SetForegroundWindow
 0x59630a GetWindowRect
 0x59630e EqualRect
 0x596312 UpdateWindow
 0x596316 ValidateRect
 0x59631a InvalidateRect
 0x59631e GetClientRect
 0x596322 GetFocus
 0x596326 GetParent
 0x59632a GetTopWindow
 0x59632e PostMessageA
 0x596332 IsWindow
 0x596336 SetParent
 0x59633a DestroyCursor
 0x59633e SendMessageA
 0x596342 SetWindowPos
 0x596346 MessageBoxA
 0x59634a GetCursorPos
 0x59634e GetSystemMetrics
 0x596352 EmptyClipboard
 0x596356 SetClipboardData
 0x59635a OpenClipboard
 0x59635e GetClipboardData
 0x596362 CloseClipboard
 0x596366 wsprintfA
 0x59636a SendDlgItemMessageA
 0x59636e MapWindowPoints
 0x596372 AdjustWindowRectEx
 0x596376 GetScrollPos
 0x59637a RegisterClassA
 0x59637e GetMenuItemCount
 0x596382 GetMenuItemID
 0x596386 CreateWindowExA
 0x59638a SetWindowsHookExA
 0x59638e CallNextHookEx
 0x596392 GetClassLongA
 0x596396 SetPropA
 0x59639a UnhookWindowsHookEx
 0x59639e GetPropA
 0x5963a2 CallWindowProcA
 0x5963a6 RemovePropA
 0x5963aa GetMessageTime
 0x5963ae GetLastActivePopup
 0x5963b2 GetForegroundWindow
 0x5963b6 RegisterWindowMessageA
 0x5963ba GetWindowPlacement
 0x5963be GetNextDlgTabItem
 0x5963c2 EndDialog
 0x5963c6 CreateDialogIndirectParamA
 0x5963ca DestroyWindow
 0x5963ce GrayStringA
 0x5963d2 DrawTextA
 0x5963d6 TabbedTextOutA
 0x5963da EndPaint
 0x5963de BeginPaint
 0x5963e2 GetWindowDC
 0x5963e6 CharUpperA
 0x5963ea GetWindowTextLengthA
 0x5963ee GetWindowTextA
 0x5963f2 GetDlgItem
 0x5963f6 GetClassNameA
 0x5963fa GetDesktopWindow
 0x5963fe SystemParametersInfoA
 0x596402 TranslateMessage
 0x596406 SetWindowRgn
 0x59640a LoadIconA
 0x59640e ScreenToClient
 0x596412 IntersectRect
 0x596416 DispatchMessageA
GDI32.dll
 0x59641e RoundRect
 0x596422 GetTextMetricsA
 0x596426 Escape
 0x59642a ExtTextOutA
 0x59642e TextOutA
 0x596432 RectVisible
 0x596436 PtVisible
 0x59643a GetViewportExtEx
 0x59643e ExtSelectClipRgn
 0x596442 GetCurrentObject
 0x596446 DPtoLP
 0x59644a LPtoDP
 0x59644e Rectangle
 0x596452 Ellipse
 0x596456 CreateCompatibleDC
 0x59645a GetTextExtentPoint32A
 0x59645e StartPage
 0x596462 StartDocA
 0x596466 DeleteDC
 0x59646a EndDoc
 0x59646e EndPage
 0x596472 CreateFontIndirectA
 0x596476 GetStockObject
 0x59647a CreateSolidBrush
 0x59647e CombineRgn
 0x596482 CreateRectRgn
 0x596486 FillRgn
 0x59648a PatBlt
 0x59648e CreatePen
 0x596492 GetObjectA
 0x596496 SelectObject
 0x59649a CreateBitmap
 0x59649e CreateDCA
 0x5964a2 CreateCompatibleBitmap
 0x5964a6 GetPolyFillMode
 0x5964aa GetStretchBltMode
 0x5964ae GetROP2
 0x5964b2 GetBkColor
 0x5964b6 GetBkMode
 0x5964ba GetTextColor
 0x5964be CreateRoundRectRgn
 0x5964c2 CreateEllipticRgn
 0x5964c6 PathToRegion
 0x5964ca EndPath
 0x5964ce BeginPath
 0x5964d2 GetWindowOrgEx
 0x5964d6 GetViewportOrgEx
 0x5964da GetWindowExtEx
 0x5964de GetDIBits
 0x5964e2 RealizePalette
 0x5964e6 SelectPalette
 0x5964ea StretchBlt
 0x5964ee CreatePalette
 0x5964f2 GetSystemPaletteEntries
 0x5964f6 CreateDIBitmap
 0x5964fa BitBlt
 0x5964fe DeleteObject
 0x596502 SelectClipRgn
 0x596506 CreatePolygonRgn
 0x59650a GetClipRgn
 0x59650e SetStretchBltMode
 0x596512 CreateRectRgnIndirect
 0x596516 SetBkColor
 0x59651a SaveDC
 0x59651e RestoreDC
 0x596522 SetBkMode
 0x596526 SetPolyFillMode
 0x59652a SetROP2
 0x59652e SetTextColor
 0x596532 SetMapMode
 0x596536 SetViewportOrgEx
 0x59653a OffsetViewportOrgEx
 0x59653e SetViewportExtEx
 0x596542 ScaleViewportExtEx
 0x596546 SetWindowOrgEx
 0x59654a SetWindowExtEx
 0x59654e ScaleWindowExtEx
 0x596552 GetClipBox
 0x596556 ExcludeClipRect
 0x59655a MoveToEx
 0x59655e LineTo
 0x596562 GetDeviceCaps
WINSPOOL.DRV
 0x59656a OpenPrinterA
 0x59656e DocumentPropertiesA
 0x596572 ClosePrinter
comdlg32.dll
 0x59657a GetSaveFileNameA
 0x59657e GetOpenFileNameA
 0x596582 ChooseColorA
 0x596586 GetFileTitleA
ADVAPI32.dll
 0x59658e RegQueryValueA
 0x596592 RegSetValueExA
 0x596596 RegOpenKeyExA
 0x59659a RegCloseKey
 0x59659e RegCreateKeyExA
SHELL32.dll
 0x5965a6 Shell_NotifyIconA
 0x5965aa ShellExecuteA
ole32.dll
 0x5965b2 OleInitialize
 0x5965b6 OleUninitialize
 0x5965ba CLSIDFromString
OLEAUT32.dll
 0x5965c2 UnRegisterTypeLib
 0x5965c6 RegisterTypeLib
 0x5965ca LoadTypeLib
COMCTL32.dll
 0x5965d2 None
 0x5965d6 ImageList_Destroy
KERNEL32.dll
 0x5965de VirtualProtect
 0x5965e2 GetModuleFileNameA
 0x5965e6 ExitProcess
USER32.dll
 0x5965ee MessageBoxA

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure