ScreenShot
Created | 2024.01.12 08:05 | Machine | s1_win7_x6401 |
Filename | tuc5.exe | ||
Type | PE32 executable (GUI) Intel 80386, for MS Windows, InnoSetup self-extracting archive | ||
AI Score |
|
Behavior Score |
|
ZERO API | file : malware | ||
VT API (file) | 25 detected (malicious, moderate confidence, ObfuscatedPoly, unsafe, Munp, Vwvq, Artemis, FileRepMalware, Generic Reputation PUA, Emotet, SRMNXW, Floxif, FileInfector) | ||
md5 | eb7073f79738bc3871d8fdcdda2f6d07 | ||
sha256 | 836702e8e9b5cc72d071836f7aece14f2f55103db492110feb3d1df399cb5a7e | ||
ssdeep | 98304:Ci5y4bUjbSiDmlFQh0GSRxSe5hbFSXQrUCngi+5PpkE:n5boj5D+yh0GSrSUbIALngrF | ||
imphash | e92b45c54aa05ec107d5ef90662e6b33 | ||
impfuzzy | 48:8cfp1rcQX0gebPCkr+ZbLdH9oOZGwt+Eu55T/lGB:8cfpdcqNebqkrmlH+2 |
Network IP location
Signature (15cnts)
Level | Description |
---|---|
warning | File has been identified by 25 AntiVirus engines on VirusTotal as malicious |
watch | Communicates with host for which no DNS query was performed |
watch | Tries to unhook Windows functions monitored by Cuckoo |
notice | Allocates read-write-execute memory (usually to unpack itself) |
notice | Checks for the Locally Unique Identifier on the system for a suspicious privilege |
notice | Creates executable files on the filesystem |
notice | Drops an executable to the user AppData folder |
notice | Queries for potentially installed applications |
notice | Uses Windows utilities for basic Windows functionality |
info | Checks amount of memory in system |
info | Checks if process is being debugged by a debugger |
info | Command line console output was observed |
info | One or more processes crashed |
info | Queries for the computername |
info | The executable contains unknown PE section names indicative of a packer (could be a false positive) |
Rules (23cnts)
Level | Name | Description | Collection |
---|---|---|---|
danger | Win32_Trojan_Emotet_2_Zero | Win32 Trojan Emotet | binaries (download) |
danger | Win32_Trojan_Emotet_2_Zero | Win32 Trojan Emotet | binaries (upload) |
danger | Win32_Trojan_Gen_1_0904B0_Zero | Win32 Trojan Emotet | binaries (download) |
warning | Generic_Malware_Zero | Generic Malware | binaries (download) |
watch | Admin_Tool_IN_Zero | Admin Tool Sysinternals | binaries (download) |
watch | ConfuserEx_Zero | Confuser .NET | binaries (download) |
watch | ConfuserEx_Zero | Confuser .NET | binaries (upload) |
watch | Malicious_Library_Zero | Malicious_Library | binaries (download) |
watch | Malicious_Library_Zero | Malicious_Library | binaries (upload) |
watch | Malicious_Packer_Zero | Malicious Packer | binaries (download) |
watch | UPX_Zero | UPX packed file | binaries (download) |
watch | UPX_Zero | UPX packed file | binaries (upload) |
info | DllRegisterServer_Zero | execute regsvr32.exe | binaries (download) |
info | IsDLL | (no description) | binaries (download) |
info | IsPE32 | (no description) | binaries (download) |
info | IsPE32 | (no description) | binaries (upload) |
info | IsPE64 | (no description) | binaries (download) |
info | mzp_file_format | MZP(Delphi) file format | binaries (download) |
info | mzp_file_format | MZP(Delphi) file format | binaries (upload) |
info | OS_Processor_Check_Zero | OS Processor Check | binaries (download) |
info | PE_Header_Zero | PE File Signature | binaries (download) |
info | PE_Header_Zero | PE File Signature | binaries (upload) |
info | zip_file_format | ZIP file format | binaries (download) |
PE API
IAT(Import Address Table) Library
kernel32.dll
0x40c0b4 DeleteCriticalSection
0x40c0b8 LeaveCriticalSection
0x40c0bc EnterCriticalSection
0x40c0c0 InitializeCriticalSection
0x40c0c4 VirtualFree
0x40c0c8 VirtualAlloc
0x40c0cc LocalFree
0x40c0d0 LocalAlloc
0x40c0d4 WideCharToMultiByte
0x40c0d8 TlsSetValue
0x40c0dc TlsGetValue
0x40c0e0 MultiByteToWideChar
0x40c0e4 GetModuleHandleA
0x40c0e8 GetLastError
0x40c0ec GetCommandLineA
0x40c0f0 WriteFile
0x40c0f4 SetFilePointer
0x40c0f8 SetEndOfFile
0x40c0fc RtlUnwind
0x40c100 ReadFile
0x40c104 RaiseException
0x40c108 GetStdHandle
0x40c10c GetFileSize
0x40c110 GetSystemTime
0x40c114 GetFileType
0x40c118 ExitProcess
0x40c11c CreateFileA
0x40c120 CloseHandle
user32.dll
0x40c128 MessageBoxA
oleaut32.dll
0x40c130 VariantChangeTypeEx
0x40c134 VariantCopyInd
0x40c138 VariantClear
0x40c13c SysStringLen
0x40c140 SysAllocStringLen
advapi32.dll
0x40c148 RegQueryValueExA
0x40c14c RegOpenKeyExA
0x40c150 RegCloseKey
0x40c154 OpenProcessToken
0x40c158 LookupPrivilegeValueA
kernel32.dll
0x40c160 WriteFile
0x40c164 VirtualQuery
0x40c168 VirtualProtect
0x40c16c VirtualFree
0x40c170 VirtualAlloc
0x40c174 Sleep
0x40c178 SetLastError
0x40c17c SetFilePointer
0x40c180 SetErrorMode
0x40c184 SetEndOfFile
0x40c188 RemoveDirectoryA
0x40c18c ReadFile
0x40c190 LoadLibraryA
0x40c194 IsDBCSLeadByte
0x40c198 GetWindowsDirectoryA
0x40c19c GetVersionExA
0x40c1a0 GetUserDefaultLangID
0x40c1a4 GetSystemInfo
0x40c1a8 GetSystemDefaultLCID
0x40c1ac GetProcAddress
0x40c1b0 GetModuleHandleA
0x40c1b4 GetModuleFileNameA
0x40c1b8 GetLocaleInfoA
0x40c1bc GetLastError
0x40c1c0 GetFullPathNameA
0x40c1c4 GetFileSize
0x40c1c8 GetFileAttributesA
0x40c1cc GetExitCodeProcess
0x40c1d0 GetEnvironmentVariableA
0x40c1d4 GetCurrentProcess
0x40c1d8 GetCommandLineA
0x40c1dc InterlockedExchange
0x40c1e0 FormatMessageA
0x40c1e4 DeleteFileA
0x40c1e8 CreateProcessA
0x40c1ec CreateFileA
0x40c1f0 CreateDirectoryA
0x40c1f4 CloseHandle
user32.dll
0x40c1fc TranslateMessage
0x40c200 SetWindowLongA
0x40c204 PeekMessageA
0x40c208 MsgWaitForMultipleObjects
0x40c20c MessageBoxA
0x40c210 LoadStringA
0x40c214 ExitWindowsEx
0x40c218 DispatchMessageA
0x40c21c DestroyWindow
0x40c220 CreateWindowExA
0x40c224 CallWindowProcA
0x40c228 CharPrevA
comctl32.dll
0x40c230 InitCommonControls
advapi32.dll
0x40c238 AdjustTokenPrivileges
EAT(Export Address Table) is none
kernel32.dll
0x40c0b4 DeleteCriticalSection
0x40c0b8 LeaveCriticalSection
0x40c0bc EnterCriticalSection
0x40c0c0 InitializeCriticalSection
0x40c0c4 VirtualFree
0x40c0c8 VirtualAlloc
0x40c0cc LocalFree
0x40c0d0 LocalAlloc
0x40c0d4 WideCharToMultiByte
0x40c0d8 TlsSetValue
0x40c0dc TlsGetValue
0x40c0e0 MultiByteToWideChar
0x40c0e4 GetModuleHandleA
0x40c0e8 GetLastError
0x40c0ec GetCommandLineA
0x40c0f0 WriteFile
0x40c0f4 SetFilePointer
0x40c0f8 SetEndOfFile
0x40c0fc RtlUnwind
0x40c100 ReadFile
0x40c104 RaiseException
0x40c108 GetStdHandle
0x40c10c GetFileSize
0x40c110 GetSystemTime
0x40c114 GetFileType
0x40c118 ExitProcess
0x40c11c CreateFileA
0x40c120 CloseHandle
user32.dll
0x40c128 MessageBoxA
oleaut32.dll
0x40c130 VariantChangeTypeEx
0x40c134 VariantCopyInd
0x40c138 VariantClear
0x40c13c SysStringLen
0x40c140 SysAllocStringLen
advapi32.dll
0x40c148 RegQueryValueExA
0x40c14c RegOpenKeyExA
0x40c150 RegCloseKey
0x40c154 OpenProcessToken
0x40c158 LookupPrivilegeValueA
kernel32.dll
0x40c160 WriteFile
0x40c164 VirtualQuery
0x40c168 VirtualProtect
0x40c16c VirtualFree
0x40c170 VirtualAlloc
0x40c174 Sleep
0x40c178 SetLastError
0x40c17c SetFilePointer
0x40c180 SetErrorMode
0x40c184 SetEndOfFile
0x40c188 RemoveDirectoryA
0x40c18c ReadFile
0x40c190 LoadLibraryA
0x40c194 IsDBCSLeadByte
0x40c198 GetWindowsDirectoryA
0x40c19c GetVersionExA
0x40c1a0 GetUserDefaultLangID
0x40c1a4 GetSystemInfo
0x40c1a8 GetSystemDefaultLCID
0x40c1ac GetProcAddress
0x40c1b0 GetModuleHandleA
0x40c1b4 GetModuleFileNameA
0x40c1b8 GetLocaleInfoA
0x40c1bc GetLastError
0x40c1c0 GetFullPathNameA
0x40c1c4 GetFileSize
0x40c1c8 GetFileAttributesA
0x40c1cc GetExitCodeProcess
0x40c1d0 GetEnvironmentVariableA
0x40c1d4 GetCurrentProcess
0x40c1d8 GetCommandLineA
0x40c1dc InterlockedExchange
0x40c1e0 FormatMessageA
0x40c1e4 DeleteFileA
0x40c1e8 CreateProcessA
0x40c1ec CreateFileA
0x40c1f0 CreateDirectoryA
0x40c1f4 CloseHandle
user32.dll
0x40c1fc TranslateMessage
0x40c200 SetWindowLongA
0x40c204 PeekMessageA
0x40c208 MsgWaitForMultipleObjects
0x40c20c MessageBoxA
0x40c210 LoadStringA
0x40c214 ExitWindowsEx
0x40c218 DispatchMessageA
0x40c21c DestroyWindow
0x40c220 CreateWindowExA
0x40c224 CallWindowProcA
0x40c228 CharPrevA
comctl32.dll
0x40c230 InitCommonControls
advapi32.dll
0x40c238 AdjustTokenPrivileges
EAT(Export Address Table) is none