Report - %E5%8C%97%E7%AC%99%E5%87%BA%E8%A1%8C16.5.exe

Generic Malware Malicious Packer Malicious Library ASPack VMProtect UPX DllRegisterServer dll PE File PE32 OS Processor Check DLL
ScreenShot
Created 2024.06.15 08:21 Machine s1_win7_x6401
Filename %E5%8C%97%E7%AC%99%E5%87%BA%E8%A1%8C16.5.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
12
Behavior Score
3.2
ZERO API file : mailcious
VT API (file)
md5 596e9b32324853cc471332f6289689bd
sha256 6423a8d276077980132945bde5742faaaa6ba82ac093035e146380ca0374f5c3
ssdeep 98304:ApP7EO03YmBvMKyDRuu28z13crN5LHOVou0+JsAGcn5HdtAatrbM5ZCUVWCLK5gC:CerMdFjz13cr/LHOVou0+JsAGcn5Hdtl
imphash b7e5f0e6dd37b0406f3d6115a9488a3d
impfuzzy 192:mPhUw+goCxFUqT0iTGmtsKpc1cncpK6AGNOQb/AFQX:C+vmT/aauNOQboSX
  Network IP location

Signature (9cnts)

Level Description
watch Communicates with host for which no DNS query was performed
notice Allocates read-write-execute memory (usually to unpack itself)
notice Creates executable files on the filesystem
notice Drops an executable to the user AppData folder
notice Foreign language identified in PE resource
notice The binary likely contains encrypted or compressed data indicative of a packer
info Checks amount of memory in system
info The executable uses a known packer
info The file contains an unknown PE resource name possibly indicative of a packer

Rules (18cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (download)
warning Generic_Malware_Zero Generic Malware binaries (upload)
watch ASPack_Zero ASPack packed file binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (download)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch Malicious_Packer_Zero Malicious Packer binaries (upload)
watch UPX_Zero UPX packed file binaries (download)
watch UPX_Zero UPX packed file binaries (upload)
watch VMProtect_Zero VMProtect packed file binaries (download)
watch VMProtect_Zero VMProtect packed file binaries (upload)
info DllRegisterServer_Zero execute regsvr32.exe binaries (upload)
info IsDLL (no description) binaries (download)
info IsPE32 (no description) binaries (download)
info IsPE32 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (download)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (download)
info PE_Header_Zero PE File Signature binaries (upload)

Network (1cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
47.76.164.119 Unknown 47.76.164.119 mailcious

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.dll
 0x4cb184 SetStdHandle
 0x4cb188 IsBadCodePtr
 0x4cb18c CompareStringW
 0x4cb190 CompareStringA
 0x4cb194 GetStringTypeW
 0x4cb198 GetStringTypeA
 0x4cb19c SetUnhandledExceptionFilter
 0x4cb1a0 VirtualAlloc
 0x4cb1a4 LCMapStringW
 0x4cb1a8 LCMapStringA
 0x4cb1ac SetEnvironmentVariableA
 0x4cb1b0 VirtualFree
 0x4cb1b4 HeapCreate
 0x4cb1b8 HeapDestroy
 0x4cb1bc GetEnvironmentVariableA
 0x4cb1c0 GetFileType
 0x4cb1c4 GetStdHandle
 0x4cb1c8 SetHandleCount
 0x4cb1cc GetEnvironmentStringsW
 0x4cb1d0 GetEnvironmentStrings
 0x4cb1d4 FreeEnvironmentStringsW
 0x4cb1d8 FreeEnvironmentStringsA
 0x4cb1dc UnhandledExceptionFilter
 0x4cb1e0 GetACP
 0x4cb1e4 HeapSize
 0x4cb1e8 TerminateProcess
 0x4cb1ec GetLocalTime
 0x4cb1f0 GetSystemTime
 0x4cb1f4 GetTimeZoneInformation
 0x4cb1f8 RaiseException
 0x4cb1fc RtlUnwind
 0x4cb200 GetStartupInfoA
 0x4cb204 GetOEMCP
 0x4cb208 GetCPInfo
 0x4cb20c GetProcessVersion
 0x4cb210 SetErrorMode
 0x4cb214 GlobalFlags
 0x4cb218 GetCurrentThread
 0x4cb21c GetFileTime
 0x4cb220 GetFileSize
 0x4cb224 TlsGetValue
 0x4cb228 LocalReAlloc
 0x4cb22c TlsSetValue
 0x4cb230 TlsFree
 0x4cb234 GlobalHandle
 0x4cb238 TlsAlloc
 0x4cb23c LocalAlloc
 0x4cb240 lstrcmpA
 0x4cb244 GetVersion
 0x4cb248 GlobalGetAtomNameA
 0x4cb24c GlobalAddAtomA
 0x4cb250 GlobalFindAtomA
 0x4cb254 GlobalDeleteAtom
 0x4cb258 lstrcmpiA
 0x4cb25c WritePrivateProfileStringA
 0x4cb260 GetModuleHandleW
 0x4cb264 LoadLibraryW
 0x4cb268 IsBadWritePtr
 0x4cb26c IsBadReadPtr
 0x4cb270 GetCurrentProcess
 0x4cb274 CreateSemaphoreA
 0x4cb278 ResumeThread
 0x4cb27c ReleaseSemaphore
 0x4cb280 EnterCriticalSection
 0x4cb284 LeaveCriticalSection
 0x4cb288 GetProfileStringA
 0x4cb28c WriteFile
 0x4cb290 WaitForMultipleObjects
 0x4cb294 CreateFileA
 0x4cb298 SetEvent
 0x4cb29c FindResourceA
 0x4cb2a0 LoadResource
 0x4cb2a4 LockResource
 0x4cb2a8 ReadFile
 0x4cb2ac lstrlenW
 0x4cb2b0 GetModuleFileNameA
 0x4cb2b4 WideCharToMultiByte
 0x4cb2b8 MultiByteToWideChar
 0x4cb2bc GetCurrentThreadId
 0x4cb2c0 ExitProcess
 0x4cb2c4 GlobalSize
 0x4cb2c8 GlobalFree
 0x4cb2cc DeleteCriticalSection
 0x4cb2d0 InitializeCriticalSection
 0x4cb2d4 lstrcatA
 0x4cb2d8 lstrlenA
 0x4cb2dc WinExec
 0x4cb2e0 lstrcpyA
 0x4cb2e4 FindNextFileA
 0x4cb2e8 GlobalReAlloc
 0x4cb2ec HeapFree
 0x4cb2f0 HeapReAlloc
 0x4cb2f4 GetProcessHeap
 0x4cb2f8 HeapAlloc
 0x4cb2fc GetUserDefaultLCID
 0x4cb300 GetFullPathNameA
 0x4cb304 FreeLibrary
 0x4cb308 LoadLibraryA
 0x4cb30c GetLastError
 0x4cb310 GetVersionExA
 0x4cb314 SetEndOfFile
 0x4cb318 UnlockFile
 0x4cb31c LockFile
 0x4cb320 FlushFileBuffers
 0x4cb324 SetFilePointer
 0x4cb328 DuplicateHandle
 0x4cb32c lstrcpynA
 0x4cb330 SetLastError
 0x4cb334 FileTimeToLocalFileTime
 0x4cb338 FileTimeToSystemTime
 0x4cb33c LocalFree
 0x4cb340 InterlockedDecrement
 0x4cb344 InterlockedIncrement
 0x4cb348 CreateThread
 0x4cb34c CreateEventA
 0x4cb350 Sleep
 0x4cb354 GlobalAlloc
 0x4cb358 GlobalLock
 0x4cb35c GlobalUnlock
 0x4cb360 FindFirstFileA
 0x4cb364 FindClose
 0x4cb368 GetFileAttributesA
 0x4cb36c SetCurrentDirectoryA
 0x4cb370 GetVolumeInformationA
 0x4cb374 GetModuleHandleA
 0x4cb378 GetProcAddress
 0x4cb37c CloseHandle
 0x4cb380 MulDiv
 0x4cb384 GetCommandLineA
 0x4cb388 GetTickCount
 0x4cb38c WaitForSingleObject
USER32.dll
 0x4cb3f0 wsprintfA
 0x4cb3f4 CloseClipboard
 0x4cb3f8 GetClipboardData
 0x4cb3fc OpenClipboard
 0x4cb400 SetClipboardData
 0x4cb404 EmptyClipboard
 0x4cb408 GetSystemMetrics
 0x4cb40c GetCursorPos
 0x4cb410 MessageBoxA
 0x4cb414 SetWindowPos
 0x4cb418 SendMessageA
 0x4cb41c DestroyCursor
 0x4cb420 SetParent
 0x4cb424 IsWindow
 0x4cb428 PostMessageA
 0x4cb42c GetTopWindow
 0x4cb430 GetParent
 0x4cb434 GetFocus
 0x4cb438 GetClientRect
 0x4cb43c InvalidateRect
 0x4cb440 ValidateRect
 0x4cb444 UpdateWindow
 0x4cb448 EqualRect
 0x4cb44c GetWindowRect
 0x4cb450 SetForegroundWindow
 0x4cb454 DestroyMenu
 0x4cb458 IsChild
 0x4cb45c ReleaseDC
 0x4cb460 IsRectEmpty
 0x4cb464 FillRect
 0x4cb468 GetDC
 0x4cb46c SetCursor
 0x4cb470 LoadCursorA
 0x4cb474 SetCursorPos
 0x4cb478 SetActiveWindow
 0x4cb47c GetSysColor
 0x4cb480 RegisterClassExW
 0x4cb484 CreateWindowExW
 0x4cb488 GetClassLongA
 0x4cb48c SetClassLongA
 0x4cb490 CallNextHookEx
 0x4cb494 GetPropA
 0x4cb498 CallWindowProcW
 0x4cb49c CallWindowProcA
 0x4cb4a0 GetAsyncKeyState
 0x4cb4a4 SetWindowLongW
 0x4cb4a8 MessageBoxW
 0x4cb4ac GetForegroundWindow
 0x4cb4b0 LoadIconA
 0x4cb4b4 TranslateMessage
 0x4cb4b8 DrawFrameControl
 0x4cb4bc DrawEdge
 0x4cb4c0 DrawFocusRect
 0x4cb4c4 WindowFromPoint
 0x4cb4c8 GetMessageA
 0x4cb4cc DispatchMessageA
 0x4cb4d0 SetRectEmpty
 0x4cb4d4 RegisterClipboardFormatA
 0x4cb4d8 CreateIconFromResourceEx
 0x4cb4dc CreateIconFromResource
 0x4cb4e0 DrawIconEx
 0x4cb4e4 CreatePopupMenu
 0x4cb4e8 AppendMenuA
 0x4cb4ec ModifyMenuA
 0x4cb4f0 CreateMenu
 0x4cb4f4 CreateAcceleratorTableA
 0x4cb4f8 GetDlgCtrlID
 0x4cb4fc GetSubMenu
 0x4cb500 EnableMenuItem
 0x4cb504 ClientToScreen
 0x4cb508 EnumDisplaySettingsA
 0x4cb50c LoadImageA
 0x4cb510 SystemParametersInfoA
 0x4cb514 ShowWindow
 0x4cb518 IsWindowEnabled
 0x4cb51c TranslateAcceleratorA
 0x4cb520 GetKeyState
 0x4cb524 CopyAcceleratorTableA
 0x4cb528 PostQuitMessage
 0x4cb52c IsZoomed
 0x4cb530 GetClassInfoA
 0x4cb534 DefWindowProcA
 0x4cb538 GetSystemMenu
 0x4cb53c DeleteMenu
 0x4cb540 GetMenu
 0x4cb544 SetMenu
 0x4cb548 PeekMessageA
 0x4cb54c IsIconic
 0x4cb550 SetFocus
 0x4cb554 GetActiveWindow
 0x4cb558 GetWindow
 0x4cb55c DestroyAcceleratorTable
 0x4cb560 SetWindowRgn
 0x4cb564 GetMessagePos
 0x4cb568 ScreenToClient
 0x4cb56c ChildWindowFromPointEx
 0x4cb570 CopyRect
 0x4cb574 LoadBitmapA
 0x4cb578 WinHelpA
 0x4cb57c KillTimer
 0x4cb580 SetTimer
 0x4cb584 ReleaseCapture
 0x4cb588 GetCapture
 0x4cb58c SetCapture
 0x4cb590 GetScrollRange
 0x4cb594 SetScrollRange
 0x4cb598 SetScrollPos
 0x4cb59c GetWindowTextA
 0x4cb5a0 GetWindowTextLengthA
 0x4cb5a4 CharUpperA
 0x4cb5a8 GetWindowDC
 0x4cb5ac BeginPaint
 0x4cb5b0 EndPaint
 0x4cb5b4 TabbedTextOutA
 0x4cb5b8 DrawTextA
 0x4cb5bc GrayStringA
 0x4cb5c0 GetDlgItem
 0x4cb5c4 DestroyWindow
 0x4cb5c8 CreateDialogIndirectParamA
 0x4cb5cc EndDialog
 0x4cb5d0 GetNextDlgTabItem
 0x4cb5d4 GetWindowPlacement
 0x4cb5d8 RegisterWindowMessageA
 0x4cb5dc GetLastActivePopup
 0x4cb5e0 GetMessageTime
 0x4cb5e4 RemovePropA
 0x4cb5e8 UnhookWindowsHookEx
 0x4cb5ec SetPropA
 0x4cb5f0 SetWindowsHookExA
 0x4cb5f4 CreateWindowExA
 0x4cb5f8 GetMenuItemID
 0x4cb5fc GetMenuItemCount
 0x4cb600 RegisterClassA
 0x4cb604 GetScrollPos
 0x4cb608 AdjustWindowRectEx
 0x4cb60c MapWindowPoints
 0x4cb610 SendDlgItemMessageA
 0x4cb614 ScrollWindowEx
 0x4cb618 IsDialogMessageA
 0x4cb61c SetWindowTextA
 0x4cb620 MoveWindow
 0x4cb624 CheckMenuItem
 0x4cb628 SetMenuItemBitmaps
 0x4cb62c GetMenuState
 0x4cb630 GetMenuCheckMarkDimensions
 0x4cb634 GetClassNameA
 0x4cb638 GetDesktopWindow
 0x4cb63c LoadStringA
 0x4cb640 GetSysColorBrush
 0x4cb644 SetRect
 0x4cb648 InflateRect
 0x4cb64c IntersectRect
 0x4cb650 DestroyIcon
 0x4cb654 PtInRect
 0x4cb658 OffsetRect
 0x4cb65c IsWindowVisible
 0x4cb660 EnableWindow
 0x4cb664 RedrawWindow
 0x4cb668 GetWindowLongA
 0x4cb66c SetWindowLongA
 0x4cb670 UnregisterClassA
GDI32.dll
 0x4cb034 SetBkColor
 0x4cb038 CreateRectRgnIndirect
 0x4cb03c CreateDIBSection
 0x4cb040 SetStretchBltMode
 0x4cb044 GetClipRgn
 0x4cb048 CreatePolygonRgn
 0x4cb04c SelectClipRgn
 0x4cb050 DeleteObject
 0x4cb054 CreateDIBitmap
 0x4cb058 GetSystemPaletteEntries
 0x4cb05c CreatePalette
 0x4cb060 StretchBlt
 0x4cb064 SelectPalette
 0x4cb068 RealizePalette
 0x4cb06c GetDIBits
 0x4cb070 GetWindowExtEx
 0x4cb074 GetViewportOrgEx
 0x4cb078 GetWindowOrgEx
 0x4cb07c BeginPath
 0x4cb080 EndPath
 0x4cb084 PathToRegion
 0x4cb088 CreateEllipticRgn
 0x4cb08c CreateRoundRectRgn
 0x4cb090 GetTextColor
 0x4cb094 GetBkMode
 0x4cb098 GetBkColor
 0x4cb09c GetROP2
 0x4cb0a0 GetStretchBltMode
 0x4cb0a4 GetPolyFillMode
 0x4cb0a8 CreateCompatibleBitmap
 0x4cb0ac CreateDCA
 0x4cb0b0 CreateBitmap
 0x4cb0b4 SelectObject
 0x4cb0b8 CreatePen
 0x4cb0bc PatBlt
 0x4cb0c0 CombineRgn
 0x4cb0c4 CreateRectRgn
 0x4cb0c8 FillRgn
 0x4cb0cc CreateSolidBrush
 0x4cb0d0 CreateFontIndirectA
 0x4cb0d4 GetStockObject
 0x4cb0d8 GetObjectA
 0x4cb0dc EndPage
 0x4cb0e0 EndDoc
 0x4cb0e4 DeleteDC
 0x4cb0e8 StartDocA
 0x4cb0ec StartPage
 0x4cb0f0 BitBlt
 0x4cb0f4 CreateCompatibleDC
 0x4cb0f8 Ellipse
 0x4cb0fc Rectangle
 0x4cb100 LPtoDP
 0x4cb104 DPtoLP
 0x4cb108 GetCurrentObject
 0x4cb10c RoundRect
 0x4cb110 GetTextExtentPoint32A
 0x4cb114 GetDeviceCaps
 0x4cb118 SaveDC
 0x4cb11c GetTextMetricsA
 0x4cb120 Escape
 0x4cb124 ExtTextOutA
 0x4cb128 TextOutA
 0x4cb12c RectVisible
 0x4cb130 PtVisible
 0x4cb134 GetViewportExtEx
 0x4cb138 ExtSelectClipRgn
 0x4cb13c LineTo
 0x4cb140 MoveToEx
 0x4cb144 ExcludeClipRect
 0x4cb148 GetClipBox
 0x4cb14c ScaleWindowExtEx
 0x4cb150 SetWindowExtEx
 0x4cb154 SetWindowOrgEx
 0x4cb158 ScaleViewportExtEx
 0x4cb15c SetViewportExtEx
 0x4cb160 OffsetViewportOrgEx
 0x4cb164 SetViewportOrgEx
 0x4cb168 SetMapMode
 0x4cb16c SetTextColor
 0x4cb170 SetROP2
 0x4cb174 SetPolyFillMode
 0x4cb178 SetBkMode
 0x4cb17c RestoreDC
WINMM.dll
 0x4cb678 midiStreamClose
 0x4cb67c midiOutReset
 0x4cb680 midiStreamStop
 0x4cb684 midiStreamOut
 0x4cb688 midiOutPrepareHeader
 0x4cb68c midiStreamProperty
 0x4cb690 midiStreamOpen
 0x4cb694 midiOutUnprepareHeader
 0x4cb698 waveOutOpen
 0x4cb69c waveOutGetNumDevs
 0x4cb6a0 waveOutClose
 0x4cb6a4 waveOutReset
 0x4cb6a8 waveOutUnprepareHeader
 0x4cb6ac waveOutPrepareHeader
 0x4cb6b0 waveOutWrite
 0x4cb6b4 waveOutPause
 0x4cb6b8 midiStreamRestart
WINSPOOL.DRV
 0x4cb6c0 OpenPrinterA
 0x4cb6c4 DocumentPropertiesA
 0x4cb6c8 ClosePrinter
ADVAPI32.dll
 0x4cb000 RegQueryValueA
 0x4cb004 RegSetValueExA
 0x4cb008 RegOpenKeyExA
 0x4cb00c RegCloseKey
 0x4cb010 RegCreateKeyExA
SHELL32.dll
 0x4cb3e4 ShellExecuteA
 0x4cb3e8 Shell_NotifyIconA
ole32.dll
 0x4cb70c CLSIDFromProgID
 0x4cb710 OleInitialize
 0x4cb714 OleUninitialize
 0x4cb718 CLSIDFromString
 0x4cb71c CoCreateInstance
 0x4cb720 OleRun
OLEAUT32.dll
 0x4cb394 VariantInit
 0x4cb398 VariantCopy
 0x4cb39c VariantClear
 0x4cb3a0 VariantChangeType
 0x4cb3a4 SafeArrayGetUBound
 0x4cb3a8 SafeArrayGetLBound
 0x4cb3ac SafeArrayGetDim
 0x4cb3b0 SafeArrayUnaccessData
 0x4cb3b4 SafeArrayAccessData
 0x4cb3b8 SafeArrayGetElement
 0x4cb3bc VariantCopyInd
 0x4cb3c0 SysAllocString
 0x4cb3c4 SafeArrayDestroy
 0x4cb3c8 SafeArrayCreate
 0x4cb3cc SafeArrayPutElement
 0x4cb3d0 RegisterTypeLib
 0x4cb3d4 LHashValOfNameSys
 0x4cb3d8 LoadTypeLib
 0x4cb3dc UnRegisterTypeLib
COMCTL32.dll
 0x4cb018 ImageList_SetBkColor
 0x4cb01c None
 0x4cb020 ImageList_Destroy
 0x4cb024 ImageList_Read
 0x4cb028 ImageList_Duplicate
 0x4cb02c ImageList_GetImageCount
WS2_32.dll
 0x4cb6d0 WSACleanup
 0x4cb6d4 inet_ntoa
 0x4cb6d8 accept
 0x4cb6dc closesocket
 0x4cb6e0 WSAAsyncSelect
 0x4cb6e4 recvfrom
 0x4cb6e8 ioctlsocket
 0x4cb6ec recv
 0x4cb6f0 getpeername
comdlg32.dll
 0x4cb6f8 ChooseColorA
 0x4cb6fc GetSaveFileNameA
 0x4cb700 GetFileTitleA
 0x4cb704 GetOpenFileNameA

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure