Report - 051495d208bad010334f14c162600b66c7ef437ae3f6bd037e39bbfc4ccdb415.exe

Malicious Library UPX PE32 PE File MZP Format
ScreenShot
Created 2024.01.16 02:30 Machine s1_win7_x6401
Filename 051495d208bad010334f14c162600b66c7ef437ae3f6bd037e39bbfc4ccdb415.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
2
Behavior Score
2.6
ZERO API file : clean
VT API (file) 51 detected (AIDetectMalware, Crypminal, malicious, high confidence, score, Bandook, S30658091, GenericRXSJ, unsafe, Barys, Vpf0, Genus, EQDO, InjectorX, jpwctw, bAYPPbSL9bF, AGEN, Detected, ai score=88, Malware@#36xw9oc25dl1k, Casdet, Eldorado, ZelphiF, 1L1@aaV75KSO, BScope, Chgt, Gencirc, IlhU5mQht6w, Static AI, Suspicious PE, susgen, confidence, 100%)
md5 732717fb963205cdf2d23f4a177fcfcb
sha256 051495d208bad010334f14c162600b66c7ef437ae3f6bd037e39bbfc4ccdb415
ssdeep 24576:gHQ0YrUbu4hMYEzzFzN2ee6izSpzRhXp2GEnxfI6YlaicLhdmaHC3WDddyR83qQB:gHVC87dANmnxfI6YledmaHFDD3uy4a
imphash 143fb514080a5e1308eeabcd91abd91d
impfuzzy 192:ot3sxeuuGsSUvfK9ccoHXSIJfk7ccKqYk1G1K0PbOQHeDb:E31G19K1nT1VPbOQ+/
  Network IP location

Signature (6cnts)

Level Description
danger File has been identified by 51 AntiVirus engines on VirusTotal as malicious
notice A process attempted to delay the analysis task.
notice Allocates read-write-execute memory (usually to unpack itself)
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The file contains an unknown PE resource name possibly indicative of a packer

Rules (5cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

oleaut32.dll
 0x52e9b8 SysFreeString
 0x52e9bc SysReAllocStringLen
 0x52e9c0 SysAllocStringLen
advapi32.dll
 0x52e9c8 RegQueryValueExA
 0x52e9cc RegOpenKeyExA
 0x52e9d0 RegCloseKey
user32.dll
 0x52e9d8 GetKeyboardType
 0x52e9dc DestroyWindow
 0x52e9e0 LoadStringA
 0x52e9e4 MessageBoxA
 0x52e9e8 CharNextA
kernel32.dll
 0x52e9f0 GetACP
 0x52e9f4 Sleep
 0x52e9f8 VirtualFree
 0x52e9fc VirtualAlloc
 0x52ea00 GetTickCount
 0x52ea04 QueryPerformanceCounter
 0x52ea08 GetCurrentThreadId
 0x52ea0c InterlockedDecrement
 0x52ea10 InterlockedIncrement
 0x52ea14 VirtualQuery
 0x52ea18 WideCharToMultiByte
 0x52ea1c MultiByteToWideChar
 0x52ea20 lstrlenA
 0x52ea24 lstrcpynA
 0x52ea28 LoadLibraryExA
 0x52ea2c GetThreadLocale
 0x52ea30 GetStartupInfoA
 0x52ea34 GetProcAddress
 0x52ea38 GetModuleHandleA
 0x52ea3c GetModuleFileNameA
 0x52ea40 GetLocaleInfoA
 0x52ea44 GetCommandLineA
 0x52ea48 FreeLibrary
 0x52ea4c FindFirstFileA
 0x52ea50 FindClose
 0x52ea54 ExitProcess
 0x52ea58 ExitThread
 0x52ea5c CreateThread
 0x52ea60 CompareStringA
 0x52ea64 WriteFile
 0x52ea68 UnhandledExceptionFilter
 0x52ea6c RtlUnwind
 0x52ea70 RaiseException
 0x52ea74 GetStdHandle
kernel32.dll
 0x52ea7c TlsSetValue
 0x52ea80 TlsGetValue
 0x52ea84 LocalAlloc
 0x52ea88 GetModuleHandleA
user32.dll
 0x52ea90 CreateWindowExW
 0x52ea94 CreateWindowExA
 0x52ea98 WindowFromPoint
 0x52ea9c WaitMessage
 0x52eaa0 ValidateRect
 0x52eaa4 UpdateWindow
 0x52eaa8 UnregisterClassA
 0x52eaac UnionRect
 0x52eab0 UnhookWindowsHookEx
 0x52eab4 TranslateMessage
 0x52eab8 TranslateMDISysAccel
 0x52eabc TrackPopupMenu
 0x52eac0 SystemParametersInfoA
 0x52eac4 ShowWindow
 0x52eac8 ShowScrollBar
 0x52eacc ShowOwnedPopups
 0x52ead0 SetWindowsHookExA
 0x52ead4 SetWindowTextW
 0x52ead8 SetWindowTextA
 0x52eadc SetWindowPos
 0x52eae0 SetWindowPlacement
 0x52eae4 SetWindowLongW
 0x52eae8 SetWindowLongA
 0x52eaec SetTimer
 0x52eaf0 SetScrollRange
 0x52eaf4 SetScrollPos
 0x52eaf8 SetScrollInfo
 0x52eafc SetRect
 0x52eb00 SetPropA
 0x52eb04 SetParent
 0x52eb08 SetMenuItemInfoA
 0x52eb0c SetMenu
 0x52eb10 SetKeyboardState
 0x52eb14 SetForegroundWindow
 0x52eb18 SetFocus
 0x52eb1c SetCursor
 0x52eb20 SetClipboardData
 0x52eb24 SetClassLongA
 0x52eb28 SetCaretPos
 0x52eb2c SetCapture
 0x52eb30 SetActiveWindow
 0x52eb34 SendMessageW
 0x52eb38 SendMessageA
 0x52eb3c ScrollWindowEx
 0x52eb40 ScrollWindow
 0x52eb44 ScreenToClient
 0x52eb48 RemovePropA
 0x52eb4c RemoveMenu
 0x52eb50 ReleaseDC
 0x52eb54 ReleaseCapture
 0x52eb58 RegisterWindowMessageA
 0x52eb5c RegisterClipboardFormatA
 0x52eb60 RegisterClassW
 0x52eb64 RegisterClassA
 0x52eb68 RedrawWindow
 0x52eb6c PtInRect
 0x52eb70 PostQuitMessage
 0x52eb74 PostMessageA
 0x52eb78 PeekMessageW
 0x52eb7c PeekMessageA
 0x52eb80 OpenClipboard
 0x52eb84 OffsetRect
 0x52eb88 OemToCharA
 0x52eb8c MsgWaitForMultipleObjects
 0x52eb90 MessageBoxA
 0x52eb94 MessageBeep
 0x52eb98 MapWindowPoints
 0x52eb9c MapVirtualKeyA
 0x52eba0 LoadStringA
 0x52eba4 LoadKeyboardLayoutA
 0x52eba8 LoadIconA
 0x52ebac LoadCursorA
 0x52ebb0 LoadBitmapA
 0x52ebb4 KillTimer
 0x52ebb8 IsZoomed
 0x52ebbc IsWindowVisible
 0x52ebc0 IsWindowUnicode
 0x52ebc4 IsWindowEnabled
 0x52ebc8 IsWindow
 0x52ebcc IsRectEmpty
 0x52ebd0 IsIconic
 0x52ebd4 IsDialogMessageW
 0x52ebd8 IsDialogMessageA
 0x52ebdc IsChild
 0x52ebe0 IsCharAlphaNumericA
 0x52ebe4 IsCharAlphaA
 0x52ebe8 InvalidateRect
 0x52ebec IntersectRect
 0x52ebf0 InsertMenuItemA
 0x52ebf4 InsertMenuA
 0x52ebf8 InflateRect
 0x52ebfc GetWindowThreadProcessId
 0x52ec00 GetWindowTextLengthW
 0x52ec04 GetWindowTextW
 0x52ec08 GetWindowTextA
 0x52ec0c GetWindowRect
 0x52ec10 GetWindowPlacement
 0x52ec14 GetWindowLongW
 0x52ec18 GetWindowLongA
 0x52ec1c GetWindowDC
 0x52ec20 GetUpdateRect
 0x52ec24 GetTopWindow
 0x52ec28 GetSystemMetrics
 0x52ec2c GetSystemMenu
 0x52ec30 GetSysColorBrush
 0x52ec34 GetSysColor
 0x52ec38 GetSubMenu
 0x52ec3c GetScrollRange
 0x52ec40 GetScrollPos
 0x52ec44 GetScrollInfo
 0x52ec48 GetPropA
 0x52ec4c GetParent
 0x52ec50 GetWindow
 0x52ec54 GetMessageTime
 0x52ec58 GetMessagePos
 0x52ec5c GetMenuStringA
 0x52ec60 GetMenuState
 0x52ec64 GetMenuItemInfoA
 0x52ec68 GetMenuItemID
 0x52ec6c GetMenuItemCount
 0x52ec70 GetMenu
 0x52ec74 GetLastActivePopup
 0x52ec78 GetKeyboardState
 0x52ec7c GetKeyboardLayoutNameA
 0x52ec80 GetKeyboardLayoutList
 0x52ec84 GetKeyboardLayout
 0x52ec88 GetKeyState
 0x52ec8c GetKeyNameTextA
 0x52ec90 GetIconInfo
 0x52ec94 GetForegroundWindow
 0x52ec98 GetFocus
 0x52ec9c GetDoubleClickTime
 0x52eca0 GetDesktopWindow
 0x52eca4 GetDCEx
 0x52eca8 GetDC
 0x52ecac GetCursorPos
 0x52ecb0 GetCursor
 0x52ecb4 GetClipboardData
 0x52ecb8 GetClientRect
 0x52ecbc GetClassLongA
 0x52ecc0 GetClassInfoW
 0x52ecc4 GetClassInfoA
 0x52ecc8 GetCaretPos
 0x52eccc GetCapture
 0x52ecd0 GetAsyncKeyState
 0x52ecd4 GetActiveWindow
 0x52ecd8 FrameRect
 0x52ecdc FindWindowA
 0x52ece0 FillRect
 0x52ece4 EqualRect
 0x52ece8 EnumWindows
 0x52ecec EnumThreadWindows
 0x52ecf0 EnumClipboardFormats
 0x52ecf4 EnumChildWindows
 0x52ecf8 EndPaint
 0x52ecfc EnableWindow
 0x52ed00 EnableScrollBar
 0x52ed04 EnableMenuItem
 0x52ed08 EmptyClipboard
 0x52ed0c DrawTextExW
 0x52ed10 DrawTextExA
 0x52ed14 DrawTextA
 0x52ed18 DrawMenuBar
 0x52ed1c DrawIconEx
 0x52ed20 DrawIcon
 0x52ed24 DrawFrameControl
 0x52ed28 DrawFocusRect
 0x52ed2c DrawEdge
 0x52ed30 DispatchMessageW
 0x52ed34 DispatchMessageA
 0x52ed38 DestroyWindow
 0x52ed3c DestroyMenu
 0x52ed40 DestroyIcon
 0x52ed44 DestroyCursor
 0x52ed48 DestroyCaret
 0x52ed4c DeleteMenu
 0x52ed50 DefWindowProcW
 0x52ed54 DefWindowProcA
 0x52ed58 DefMDIChildProcA
 0x52ed5c DefFrameProcA
 0x52ed60 CreatePopupMenu
 0x52ed64 CreateMenu
 0x52ed68 CreateIcon
 0x52ed6c CreateCaret
 0x52ed70 CloseClipboard
 0x52ed74 ClientToScreen
 0x52ed78 CheckMenuItem
 0x52ed7c CharNextW
 0x52ed80 CallWindowProcW
 0x52ed84 CallWindowProcA
 0x52ed88 CallNextHookEx
 0x52ed8c BringWindowToTop
 0x52ed90 BeginPaint
 0x52ed94 CharNextA
 0x52ed98 CharLowerBuffA
 0x52ed9c CharLowerA
 0x52eda0 CharUpperBuffA
 0x52eda4 CharToOemA
 0x52eda8 AdjustWindowRectEx
 0x52edac ActivateKeyboardLayout
gdi32.dll
 0x52edb4 UnrealizeObject
 0x52edb8 StretchDIBits
 0x52edbc StretchBlt
 0x52edc0 StartPage
 0x52edc4 StartDocA
 0x52edc8 SetWindowOrgEx
 0x52edcc SetWindowExtEx
 0x52edd0 SetWinMetaFileBits
 0x52edd4 SetViewportOrgEx
 0x52edd8 SetViewportExtEx
 0x52eddc SetTextColor
 0x52ede0 SetTextAlign
 0x52ede4 SetStretchBltMode
 0x52ede8 SetROP2
 0x52edec SetPixel
 0x52edf0 SetMapMode
 0x52edf4 SetEnhMetaFileBits
 0x52edf8 SetDIBColorTable
 0x52edfc SetBrushOrgEx
 0x52ee00 SetBkMode
 0x52ee04 SetBkColor
 0x52ee08 SetAbortProc
 0x52ee0c SelectPalette
 0x52ee10 SelectObject
 0x52ee14 SelectClipRgn
 0x52ee18 SaveDC
 0x52ee1c RoundRect
 0x52ee20 RestoreDC
 0x52ee24 Rectangle
 0x52ee28 RectVisible
 0x52ee2c RealizePalette
 0x52ee30 Polyline
 0x52ee34 Polygon
 0x52ee38 PolyPolyline
 0x52ee3c PlayEnhMetaFile
 0x52ee40 PatBlt
 0x52ee44 MoveToEx
 0x52ee48 MaskBlt
 0x52ee4c LineTo
 0x52ee50 LPtoDP
 0x52ee54 IntersectClipRect
 0x52ee58 GetWindowOrgEx
 0x52ee5c GetWinMetaFileBits
 0x52ee60 GetTextMetricsA
 0x52ee64 GetTextExtentPointA
 0x52ee68 GetTextExtentPoint32A
 0x52ee6c GetTextExtentExPointA
 0x52ee70 GetSystemPaletteEntries
 0x52ee74 GetStockObject
 0x52ee78 GetRgnBox
 0x52ee7c GetPixel
 0x52ee80 GetPaletteEntries
 0x52ee84 GetObjectA
 0x52ee88 GetMapMode
 0x52ee8c GetEnhMetaFilePaletteEntries
 0x52ee90 GetEnhMetaFileHeader
 0x52ee94 GetEnhMetaFileBits
 0x52ee98 GetDeviceCaps
 0x52ee9c GetDIBits
 0x52eea0 GetDIBColorTable
 0x52eea4 GetDCOrgEx
 0x52eea8 GetCurrentPositionEx
 0x52eeac GetClipBox
 0x52eeb0 GetBrushOrgEx
 0x52eeb4 GetBitmapBits
 0x52eeb8 ExtTextOutA
 0x52eebc ExtCreatePen
 0x52eec0 ExcludeClipRect
 0x52eec4 EndPage
 0x52eec8 EndDoc
 0x52eecc DeleteObject
 0x52eed0 DeleteEnhMetaFile
 0x52eed4 DeleteDC
 0x52eed8 DPtoLP
 0x52eedc CreateSolidBrush
 0x52eee0 CreateRectRgn
 0x52eee4 CreatePenIndirect
 0x52eee8 CreatePalette
 0x52eeec CreateICA
 0x52eef0 CreateHalftonePalette
 0x52eef4 CreateFontIndirectA
 0x52eef8 CreateDIBitmap
 0x52eefc CreateDIBSection
 0x52ef00 CreateDCA
 0x52ef04 CreateCompatibleDC
 0x52ef08 CreateCompatibleBitmap
 0x52ef0c CreateBrushIndirect
 0x52ef10 CreateBitmap
 0x52ef14 CopyEnhMetaFileA
 0x52ef18 BitBlt
version.dll
 0x52ef20 VerQueryValueA
 0x52ef24 GetFileVersionInfoSizeA
 0x52ef28 GetFileVersionInfoA
kernel32.dll
 0x52ef30 lstrcpyA
 0x52ef34 WriteFile
 0x52ef38 WideCharToMultiByte
 0x52ef3c WaitForSingleObject
 0x52ef40 VirtualQuery
 0x52ef44 VirtualAlloc
 0x52ef48 SizeofResource
 0x52ef4c SetThreadLocale
 0x52ef50 SetLastError
 0x52ef54 SetFilePointer
 0x52ef58 SetEvent
 0x52ef5c SetErrorMode
 0x52ef60 SetEndOfFile
 0x52ef64 ResumeThread
 0x52ef68 ResetEvent
 0x52ef6c ReadFile
 0x52ef70 MultiByteToWideChar
 0x52ef74 MulDiv
 0x52ef78 LockResource
 0x52ef7c LoadResource
 0x52ef80 LoadLibraryA
 0x52ef84 LeaveCriticalSection
 0x52ef88 InitializeCriticalSection
 0x52ef8c GlobalUnlock
 0x52ef90 GlobalSize
 0x52ef94 GlobalLock
 0x52ef98 GlobalFree
 0x52ef9c GlobalFindAtomA
 0x52efa0 GlobalDeleteAtom
 0x52efa4 GlobalAlloc
 0x52efa8 GlobalAddAtomA
 0x52efac GetVersionExA
 0x52efb0 GetVersion
 0x52efb4 GetTickCount
 0x52efb8 GetThreadLocale
 0x52efbc GetStdHandle
 0x52efc0 GetProfileStringA
 0x52efc4 GetProcAddress
 0x52efc8 GetModuleHandleA
 0x52efcc GetModuleFileNameA
 0x52efd0 GetLocaleInfoA
 0x52efd4 GetLocalTime
 0x52efd8 GetLastError
 0x52efdc GetFullPathNameA
 0x52efe0 GetFileAttributesA
 0x52efe4 GetExitCodeThread
 0x52efe8 GetDiskFreeSpaceA
 0x52efec GetDateFormatA
 0x52eff0 GetCurrentThreadId
 0x52eff4 GetCurrentProcessId
 0x52eff8 GetCPInfo
 0x52effc GetACP
 0x52f000 FreeResource
 0x52f004 InterlockedIncrement
 0x52f008 InterlockedExchange
 0x52f00c InterlockedDecrement
 0x52f010 FreeLibrary
 0x52f014 FormatMessageA
 0x52f018 FindResourceA
 0x52f01c FindFirstFileA
 0x52f020 FindClose
 0x52f024 EnumCalendarInfoA
 0x52f028 EnterCriticalSection
 0x52f02c DeleteCriticalSection
 0x52f030 CreateThread
 0x52f034 CreateFileA
 0x52f038 CreateEventA
 0x52f03c CompareStringW
 0x52f040 CompareStringA
 0x52f044 CloseHandle
advapi32.dll
 0x52f04c RegQueryValueExA
 0x52f050 RegOpenKeyExA
 0x52f054 RegFlushKey
 0x52f058 RegCreateKeyExA
 0x52f05c RegCloseKey
kernel32.dll
 0x52f064 Sleep
ole32.dll
 0x52f06c IsEqualGUID
olepro32.dll
 0x52f074 OleLoadPicture
oleaut32.dll
 0x52f07c GetErrorInfo
 0x52f080 SysFreeString
ole32.dll
 0x52f088 CreateStreamOnHGlobal
 0x52f08c CoTaskMemFree
 0x52f090 CoTaskMemAlloc
 0x52f094 CoCreateGuid
 0x52f098 CLSIDFromProgID
 0x52f09c StringFromCLSID
 0x52f0a0 CoCreateInstance
 0x52f0a4 CoUninitialize
 0x52f0a8 CoInitialize
oleaut32.dll
 0x52f0b0 SafeArrayPtrOfIndex
 0x52f0b4 SafeArrayPutElement
 0x52f0b8 SafeArrayGetElement
 0x52f0bc SafeArrayUnaccessData
 0x52f0c0 SafeArrayAccessData
 0x52f0c4 SafeArrayGetUBound
 0x52f0c8 SafeArrayGetLBound
 0x52f0cc SafeArrayCreate
 0x52f0d0 VariantChangeType
 0x52f0d4 VariantCopyInd
 0x52f0d8 VariantCopy
 0x52f0dc VariantClear
 0x52f0e0 VariantInit
comctl32.dll
 0x52f0e8 _TrackMouseEvent
 0x52f0ec ImageList_SetIconSize
 0x52f0f0 ImageList_GetIconSize
 0x52f0f4 ImageList_Write
 0x52f0f8 ImageList_Read
 0x52f0fc ImageList_GetDragImage
 0x52f100 ImageList_DragShowNolock
 0x52f104 ImageList_DragMove
 0x52f108 ImageList_DragLeave
 0x52f10c ImageList_DragEnter
 0x52f110 ImageList_EndDrag
 0x52f114 ImageList_BeginDrag
 0x52f118 ImageList_Remove
 0x52f11c ImageList_DrawEx
 0x52f120 ImageList_Replace
 0x52f124 ImageList_Draw
 0x52f128 ImageList_GetBkColor
 0x52f12c ImageList_SetBkColor
 0x52f130 ImageList_Add
 0x52f134 ImageList_SetImageCount
 0x52f138 ImageList_GetImageCount
 0x52f13c ImageList_Destroy
 0x52f140 ImageList_Create
imm32.dll
 0x52f148 ImmGetCompositionStringW
 0x52f14c ImmReleaseContext
 0x52f150 ImmGetContext
shell32.dll
 0x52f158 ShellExecuteA
 0x52f15c SHGetFileInfoA
winspool.drv
 0x52f164 OpenPrinterA
 0x52f168 EnumPrintersA
 0x52f16c DocumentPropertiesA
 0x52f170 ClosePrinter
advapi32.dll
 0x52f178 RegNotifyChangeKeyValue
kernel32.dll
 0x52f180 MulDiv
kernel32.dll
 0x52f188 MulDiv

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure