Report - 49j8t349t83495vj945jfd.exe

Malicious Library Malicious Packer UPX PE File PE32 MZP Format
ScreenShot
Created 2024.05.18 20:06 Machine s1_win7_x6401
Filename 49j8t349t83495vj945jfd.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
5
Behavior Score
2.2
ZERO API file : clean
VT API (file) 36 detected (AIDetectMalware, Stealc, malicious, high confidence, ObfuscatedPoly, unsafe, Tedy, Save, Attribute, HighConfidence, GenKryptik, GXTE, Artemis, Injuke, Androm, eMaZ7QYfXnK, Steam, QBot, Detected, ai score=89, PSWTroj, ZelphiF, 6HW@aCLak9ki, Static AI, Malicious PE, susgen, GLYS)
md5 3aac4627c0904126c45ed250a7dee34e
sha256 744eddd9b4b8158a0ae22a864deb7c5a9741d192b2dc08eeaa54133fe5c328c4
ssdeep 24576:qH7t22yv9gVwu4w1v8QWgW2pNX0fqk27NoFo3t4aO78KLHidAp:q4jv91YV8QC2jiqkumct498KLHi
imphash c8c586524a23d4cd74a160dfb541091f
impfuzzy 192:f30Jk1uTbbuuArSUvK9RqooqE6pCPbOQRO:f3z1u3AA9LkPbOQk
  Network IP location

Signature (6cnts)

Level Description
danger File has been identified by 36 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
info Checks amount of memory in system
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The executable uses a known packer

Rules (6cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch Malicious_Packer_Zero Malicious Packer binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x469118 DeleteCriticalSection
 0x46911c LeaveCriticalSection
 0x469120 EnterCriticalSection
 0x469124 InitializeCriticalSection
 0x469128 VirtualFree
 0x46912c VirtualAlloc
 0x469130 LocalFree
 0x469134 LocalAlloc
 0x469138 GetVersion
 0x46913c GetCurrentThreadId
 0x469140 InterlockedDecrement
 0x469144 InterlockedIncrement
 0x469148 VirtualQuery
 0x46914c WideCharToMultiByte
 0x469150 MultiByteToWideChar
 0x469154 lstrlenA
 0x469158 lstrcpynA
 0x46915c LoadLibraryExA
 0x469160 GetThreadLocale
 0x469164 GetStartupInfoA
 0x469168 GetProcAddress
 0x46916c GetModuleHandleA
 0x469170 GetModuleFileNameA
 0x469174 GetLocaleInfoA
 0x469178 GetCommandLineA
 0x46917c FreeLibrary
 0x469180 FindFirstFileA
 0x469184 FindClose
 0x469188 ExitProcess
 0x46918c WriteFile
 0x469190 UnhandledExceptionFilter
 0x469194 RtlUnwind
 0x469198 RaiseException
 0x46919c GetStdHandle
user32.dll
 0x4691a4 GetKeyboardType
 0x4691a8 LoadStringA
 0x4691ac MessageBoxA
 0x4691b0 CharNextA
advapi32.dll
 0x4691b8 RegQueryValueExA
 0x4691bc RegOpenKeyExA
 0x4691c0 RegCloseKey
oleaut32.dll
 0x4691c8 SysFreeString
 0x4691cc SysReAllocStringLen
 0x4691d0 SysAllocStringLen
kernel32.dll
 0x4691d8 TlsSetValue
 0x4691dc TlsGetValue
 0x4691e0 LocalAlloc
 0x4691e4 GetModuleHandleA
advapi32.dll
 0x4691ec RegQueryValueExA
 0x4691f0 RegOpenKeyExA
 0x4691f4 RegCloseKey
kernel32.dll
 0x4691fc lstrcpyA
 0x469200 WriteFile
 0x469204 WaitForSingleObject
 0x469208 VirtualQuery
 0x46920c VirtualAlloc
 0x469210 Sleep
 0x469214 SizeofResource
 0x469218 SetThreadLocale
 0x46921c SetFilePointer
 0x469220 SetEvent
 0x469224 SetErrorMode
 0x469228 SetEndOfFile
 0x46922c ResetEvent
 0x469230 ReadFile
 0x469234 MulDiv
 0x469238 LockResource
 0x46923c LoadResource
 0x469240 LoadLibraryA
 0x469244 LeaveCriticalSection
 0x469248 InitializeCriticalSection
 0x46924c GlobalUnlock
 0x469250 GlobalReAlloc
 0x469254 GlobalHandle
 0x469258 GlobalLock
 0x46925c GlobalFree
 0x469260 GlobalFindAtomA
 0x469264 GlobalDeleteAtom
 0x469268 GlobalAlloc
 0x46926c GlobalAddAtomA
 0x469270 GetVersionExA
 0x469274 GetVersion
 0x469278 GetTickCount
 0x46927c GetThreadLocale
 0x469280 GetTempPathA
 0x469284 GetSystemInfo
 0x469288 GetStringTypeExA
 0x46928c GetStdHandle
 0x469290 GetProcAddress
 0x469294 GetModuleHandleA
 0x469298 GetModuleFileNameA
 0x46929c GetLocaleInfoA
 0x4692a0 GetLocalTime
 0x4692a4 GetLastError
 0x4692a8 GetFullPathNameA
 0x4692ac GetFileSize
 0x4692b0 GetDiskFreeSpaceA
 0x4692b4 GetDateFormatA
 0x4692b8 GetCurrentThreadId
 0x4692bc GetCurrentProcessId
 0x4692c0 GetCPInfo
 0x4692c4 GetACP
 0x4692c8 FreeResource
 0x4692cc InterlockedExchange
 0x4692d0 FreeLibrary
 0x4692d4 FormatMessageA
 0x4692d8 FindResourceA
 0x4692dc EnumCalendarInfoA
 0x4692e0 EnterCriticalSection
 0x4692e4 DeleteFileA
 0x4692e8 DeleteCriticalSection
 0x4692ec CreateThread
 0x4692f0 CreateFileA
 0x4692f4 CreateEventA
 0x4692f8 CompareStringA
 0x4692fc CloseHandle
version.dll
 0x469304 VerQueryValueA
 0x469308 GetFileVersionInfoSizeA
 0x46930c GetFileVersionInfoA
gdi32.dll
 0x469314 UnrealizeObject
 0x469318 StretchBlt
 0x46931c SetWindowOrgEx
 0x469320 SetViewportOrgEx
 0x469324 SetTextColor
 0x469328 SetStretchBltMode
 0x46932c SetROP2
 0x469330 SetPixel
 0x469334 SetDIBColorTable
 0x469338 SetBrushOrgEx
 0x46933c SetBkMode
 0x469340 SetBkColor
 0x469344 SelectPalette
 0x469348 SelectObject
 0x46934c SaveDC
 0x469350 RestoreDC
 0x469354 RectVisible
 0x469358 RealizePalette
 0x46935c PatBlt
 0x469360 MoveToEx
 0x469364 MaskBlt
 0x469368 LineTo
 0x46936c IntersectClipRect
 0x469370 GetWindowOrgEx
 0x469374 GetTextMetricsA
 0x469378 GetTextExtentPoint32A
 0x46937c GetSystemPaletteEntries
 0x469380 GetStockObject
 0x469384 GetPixel
 0x469388 GetPaletteEntries
 0x46938c GetObjectA
 0x469390 GetDeviceCaps
 0x469394 GetDIBits
 0x469398 GetDIBColorTable
 0x46939c GetDCOrgEx
 0x4693a0 GetDCPenColor
 0x4693a4 GetCurrentPositionEx
 0x4693a8 GetClipBox
 0x4693ac GetBrushOrgEx
 0x4693b0 GetBitmapBits
 0x4693b4 ExcludeClipRect
 0x4693b8 DeleteObject
 0x4693bc DeleteDC
 0x4693c0 CreateSolidBrush
 0x4693c4 CreatePenIndirect
 0x4693c8 CreatePalette
 0x4693cc CreateHalftonePalette
 0x4693d0 CreateFontIndirectA
 0x4693d4 CreateDIBitmap
 0x4693d8 CreateDIBSection
 0x4693dc CreateCompatibleDC
 0x4693e0 CreateCompatibleBitmap
 0x4693e4 CreateBrushIndirect
 0x4693e8 CreateBitmap
 0x4693ec BitBlt
user32.dll
 0x4693f4 CreateWindowExA
 0x4693f8 WindowFromPoint
 0x4693fc WinHelpA
 0x469400 WaitMessage
 0x469404 UpdateWindow
 0x469408 UnregisterClassA
 0x46940c UnhookWindowsHookEx
 0x469410 TranslateMessage
 0x469414 TranslateMDISysAccel
 0x469418 TrackPopupMenu
 0x46941c SystemParametersInfoA
 0x469420 ShowWindow
 0x469424 ShowScrollBar
 0x469428 ShowOwnedPopups
 0x46942c ShowCursor
 0x469430 SetWindowsHookExA
 0x469434 SetWindowTextA
 0x469438 SetWindowPos
 0x46943c SetWindowPlacement
 0x469440 SetWindowLongA
 0x469444 SetTimer
 0x469448 SetScrollRange
 0x46944c SetScrollPos
 0x469450 SetScrollInfo
 0x469454 SetRect
 0x469458 SetPropA
 0x46945c SetParent
 0x469460 SetMenuItemInfoA
 0x469464 SetMenu
 0x469468 SetForegroundWindow
 0x46946c SetFocus
 0x469470 SetCursor
 0x469474 SetClassLongA
 0x469478 SetCapture
 0x46947c SetActiveWindow
 0x469480 SendMessageA
 0x469484 ScrollWindow
 0x469488 ScreenToClient
 0x46948c RemovePropA
 0x469490 RemoveMenu
 0x469494 ReleaseDC
 0x469498 ReleaseCapture
 0x46949c RegisterWindowMessageA
 0x4694a0 RegisterClipboardFormatA
 0x4694a4 RegisterClassA
 0x4694a8 RedrawWindow
 0x4694ac PtInRect
 0x4694b0 PostQuitMessage
 0x4694b4 PostMessageA
 0x4694b8 PeekMessageA
 0x4694bc OffsetRect
 0x4694c0 OemToCharA
 0x4694c4 MessageBoxA
 0x4694c8 MapWindowPoints
 0x4694cc MapVirtualKeyA
 0x4694d0 LoadStringA
 0x4694d4 LoadKeyboardLayoutA
 0x4694d8 LoadIconA
 0x4694dc LoadCursorA
 0x4694e0 LoadBitmapA
 0x4694e4 KillTimer
 0x4694e8 IsZoomed
 0x4694ec IsWindowVisible
 0x4694f0 IsWindowEnabled
 0x4694f4 IsWindow
 0x4694f8 IsRectEmpty
 0x4694fc IsIconic
 0x469500 IsDialogMessageA
 0x469504 IsChild
 0x469508 InvalidateRect
 0x46950c IntersectRect
 0x469510 InsertMenuItemA
 0x469514 InsertMenuA
 0x469518 InflateRect
 0x46951c GetWindowThreadProcessId
 0x469520 GetWindowTextA
 0x469524 GetWindowRect
 0x469528 GetWindowPlacement
 0x46952c GetWindowLongA
 0x469530 GetWindowDC
 0x469534 GetTopWindow
 0x469538 GetSystemMetrics
 0x46953c GetSystemMenu
 0x469540 GetSysColorBrush
 0x469544 GetSysColor
 0x469548 GetSubMenu
 0x46954c GetScrollRange
 0x469550 GetScrollPos
 0x469554 GetScrollInfo
 0x469558 GetPropA
 0x46955c GetParent
 0x469560 GetWindow
 0x469564 GetMenuStringA
 0x469568 GetMenuState
 0x46956c GetMenuItemInfoA
 0x469570 GetMenuItemID
 0x469574 GetMenuItemCount
 0x469578 GetMenu
 0x46957c GetLastActivePopup
 0x469580 GetKeyboardState
 0x469584 GetKeyboardLayoutList
 0x469588 GetKeyboardLayout
 0x46958c GetKeyState
 0x469590 GetKeyNameTextA
 0x469594 GetIconInfo
 0x469598 GetForegroundWindow
 0x46959c GetFocus
 0x4695a0 GetDesktopWindow
 0x4695a4 GetDCEx
 0x4695a8 GetDC
 0x4695ac GetCursorPos
 0x4695b0 GetCursor
 0x4695b4 GetClientRect
 0x4695b8 GetClassNameA
 0x4695bc GetClassInfoA
 0x4695c0 GetCapture
 0x4695c4 GetActiveWindow
 0x4695c8 FrameRect
 0x4695cc FindWindowA
 0x4695d0 FillRect
 0x4695d4 EqualRect
 0x4695d8 EnumWindows
 0x4695dc EnumThreadWindows
 0x4695e0 EndPaint
 0x4695e4 EnableWindow
 0x4695e8 EnableScrollBar
 0x4695ec EnableMenuItem
 0x4695f0 DrawTextA
 0x4695f4 DrawMenuBar
 0x4695f8 DrawIconEx
 0x4695fc DrawIcon
 0x469600 DrawFrameControl
 0x469604 DrawEdge
 0x469608 DispatchMessageA
 0x46960c DestroyWindow
 0x469610 DestroyMenu
 0x469614 DestroyIcon
 0x469618 DestroyCursor
 0x46961c DeleteMenu
 0x469620 DefWindowProcA
 0x469624 DefMDIChildProcA
 0x469628 DefFrameProcA
 0x46962c CreatePopupMenu
 0x469630 CreateMenu
 0x469634 CreateIcon
 0x469638 ClientToScreen
 0x46963c CheckMenuItem
 0x469640 CallWindowProcA
 0x469644 CallNextHookEx
 0x469648 BeginPaint
 0x46964c CharNextA
 0x469650 CharLowerA
 0x469654 CharUpperBuffA
 0x469658 CharToOemA
 0x46965c AdjustWindowRectEx
 0x469660 ActivateKeyboardLayout
kernel32.dll
 0x469668 Sleep
oleaut32.dll
 0x469670 SafeArrayPtrOfIndex
 0x469674 SafeArrayPutElement
 0x469678 SafeArrayGetElement
 0x46967c SafeArrayUnaccessData
 0x469680 SafeArrayAccessData
 0x469684 SafeArrayGetUBound
 0x469688 SafeArrayGetLBound
 0x46968c SafeArrayCreate
 0x469690 VariantChangeType
 0x469694 VariantCopyInd
 0x469698 VariantCopy
 0x46969c VariantClear
 0x4696a0 VariantInit
comctl32.dll
 0x4696a8 ImageList_SetIconSize
 0x4696ac ImageList_GetIconSize
 0x4696b0 ImageList_Write
 0x4696b4 ImageList_Read
 0x4696b8 ImageList_GetDragImage
 0x4696bc ImageList_DragShowNolock
 0x4696c0 ImageList_SetDragCursorImage
 0x4696c4 ImageList_DragMove
 0x4696c8 ImageList_DragLeave
 0x4696cc ImageList_DragEnter
 0x4696d0 ImageList_EndDrag
 0x4696d4 ImageList_BeginDrag
 0x4696d8 ImageList_Remove
 0x4696dc ImageList_DrawEx
 0x4696e0 ImageList_Draw
 0x4696e4 ImageList_GetBkColor
 0x4696e8 ImageList_SetBkColor
 0x4696ec ImageList_ReplaceIcon
 0x4696f0 ImageList_Add
 0x4696f4 ImageList_GetImageCount
 0x4696f8 ImageList_Destroy
 0x4696fc ImageList_Create

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure