Report - 2.exe

Generic Malware Malicious Packer Malicious Library ASPack UPX DllRegisterServer dll PE File PE32 OS Processor Check
ScreenShot
Created 2024.06.16 10:29 Machine s1_win7_x6401
Filename 2.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
10
Behavior Score
4.0
ZERO API file : mailcious
VT API (file) 48 detected (AIDetectMalware, Windows, Threat, Malicious, score, Midie, Unsafe, Save, Attribute, HighConfidence, FlyStudio, Artemis, TrojanX, Gotango, oNWjcIennkI, Real Protect, moderate, Detected, ai score=84, OSCF@5rs7jr, Wacatac, 1TYMTF4, Eldorado, ZexaF, Us0@aOswzuhb, R002H0CFE24, Static AI, Malicious PE, CoinMiner, confidence, 100%)
md5 1046a5b7a54fe184ab79e8925f1bfafe
sha256 43e6dfa30f18980c797aff5199f16a00a9a315e7f2da3691b1c5d2f67f44564d
ssdeep 24576:Ro/pOrPha3QvBArmszFDDDlV+rzUAV6cJQAhqdBK3IrI+Y0e+ZxMzQ3ko5QURE+F:R3vtVZ8LrIQLA3o5RE4EHqWI
imphash 3f5fc221e6882cd97918911d0ca040a7
impfuzzy 192:/ZAVUl6A70J5WJNvONU1T/Jx9TzSJQ0Ocncbcb5krP4MgiNKd:P8A7AAOO4QVa8EkrPNBNKd
  Network IP location

Signature (9cnts)

Level Description
danger File has been identified by 48 AntiVirus engines on VirusTotal as malicious
watch Communicates with host for which no DNS query was performed
notice Allocates read-write-execute memory (usually to unpack itself)
notice Creates a shortcut to an executable file
notice Foreign language identified in PE resource
notice Performs some HTTP requests
info Checks amount of memory in system
info The executable uses a known packer
info The file contains an unknown PE resource name possibly indicative of a packer

Rules (9cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (upload)
watch ASPack_Zero ASPack packed file binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch Malicious_Packer_Zero Malicious Packer binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info DllRegisterServer_Zero execute regsvr32.exe binaries (upload)
info IsPE32 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (4cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?
http://www.baidu.com/ JP Baidu, Inc. 119.63.197.139 clean
www.baidu.com JP Baidu, Inc. 119.63.197.151 clean
114.132.189.148 Unknown 114.132.189.148 mailcious
119.63.197.139 JP Baidu, Inc. 119.63.197.139 clean

Suricata ids

PE API

IAT(Import Address Table) Library

WINMM.dll
 0x59b70c midiStreamOut
 0x59b710 midiOutPrepareHeader
 0x59b714 waveOutUnprepareHeader
 0x59b718 waveOutPrepareHeader
 0x59b71c waveOutWrite
 0x59b720 waveOutPause
 0x59b724 waveOutReset
 0x59b728 waveOutClose
 0x59b72c waveOutGetNumDevs
 0x59b730 waveOutOpen
 0x59b734 midiStreamStop
 0x59b738 midiOutReset
 0x59b73c midiStreamClose
 0x59b740 midiStreamRestart
 0x59b744 midiOutUnprepareHeader
 0x59b748 midiStreamOpen
 0x59b74c midiStreamProperty
 0x59b750 waveOutRestart
WS2_32.dll
 0x59b768 htons
 0x59b76c WSAAsyncSelect
 0x59b770 closesocket
 0x59b774 send
 0x59b778 select
 0x59b77c WSACleanup
 0x59b780 WSAStartup
 0x59b784 socket
 0x59b788 __WSAFDIsSet
 0x59b78c recvfrom
 0x59b790 ioctlsocket
 0x59b794 connect
 0x59b798 gethostbyname
 0x59b79c inet_ntoa
 0x59b7a0 inet_addr
 0x59b7a4 shutdown
 0x59b7a8 WSAGetLastError
 0x59b7ac ntohl
 0x59b7b0 recv
 0x59b7b4 getpeername
 0x59b7b8 accept
KERNEL32.dll
 0x59b1b4 GetTimeZoneInformation
 0x59b1b8 GetVersion
 0x59b1bc CreateMutexA
 0x59b1c0 ReleaseMutex
 0x59b1c4 SuspendThread
 0x59b1c8 RaiseException
 0x59b1cc GetLocalTime
 0x59b1d0 RtlUnwind
 0x59b1d4 GetStartupInfoA
 0x59b1d8 GetOEMCP
 0x59b1dc GetCPInfo
 0x59b1e0 GetProcessVersion
 0x59b1e4 SetErrorMode
 0x59b1e8 GetProfileIntA
 0x59b1ec GlobalFlags
 0x59b1f0 GetCurrentThread
 0x59b1f4 GetFileTime
 0x59b1f8 TlsGetValue
 0x59b1fc LocalReAlloc
 0x59b200 TlsSetValue
 0x59b204 TlsFree
 0x59b208 GlobalHandle
 0x59b20c TlsAlloc
 0x59b210 LocalAlloc
 0x59b214 lstrcmpA
 0x59b218 GlobalGetAtomNameA
 0x59b21c GlobalAddAtomA
 0x59b220 GlobalFindAtomA
 0x59b224 GlobalDeleteAtom
 0x59b228 lstrcmpiA
 0x59b22c SetEndOfFile
 0x59b230 UnlockFile
 0x59b234 LockFile
 0x59b238 FlushFileBuffers
 0x59b23c DuplicateHandle
 0x59b240 lstrcpynA
 0x59b244 FileTimeToLocalFileTime
 0x59b248 FileTimeToSystemTime
 0x59b24c FormatMessageA
 0x59b250 LocalFree
 0x59b254 InterlockedDecrement
 0x59b258 InterlockedIncrement
 0x59b25c SetLastError
 0x59b260 TerminateProcess
 0x59b264 GetFileSize
 0x59b268 SetFilePointer
 0x59b26c WideCharToMultiByte
 0x59b270 MultiByteToWideChar
 0x59b274 GetCurrentProcess
 0x59b278 TerminateThread
 0x59b27c CreateSemaphoreA
 0x59b280 ResumeThread
 0x59b284 ReleaseSemaphore
 0x59b288 EnterCriticalSection
 0x59b28c LeaveCriticalSection
 0x59b290 GetProfileStringA
 0x59b294 WriteFile
 0x59b298 ReadFile
 0x59b29c WaitForMultipleObjects
 0x59b2a0 CreateFileA
 0x59b2a4 SetEvent
 0x59b2a8 FindResourceA
 0x59b2ac LoadResource
 0x59b2b0 LockResource
 0x59b2b4 lstrlenW
 0x59b2b8 GetModuleFileNameA
 0x59b2bc GetCurrentThreadId
 0x59b2c0 ExitProcess
 0x59b2c4 GlobalSize
 0x59b2c8 GlobalFree
 0x59b2cc DeleteCriticalSection
 0x59b2d0 InitializeCriticalSection
 0x59b2d4 lstrcatA
 0x59b2d8 lstrlenA
 0x59b2dc WinExec
 0x59b2e0 lstrcpyA
 0x59b2e4 FindNextFileA
 0x59b2e8 GetDriveTypeA
 0x59b2ec GlobalReAlloc
 0x59b2f0 HeapFree
 0x59b2f4 HeapReAlloc
 0x59b2f8 InterlockedExchange
 0x59b2fc GetProcessHeap
 0x59b300 HeapAlloc
 0x59b304 GetUserDefaultLCID
 0x59b308 GetFullPathNameA
 0x59b30c FreeLibrary
 0x59b310 LoadLibraryA
 0x59b314 GetLastError
 0x59b318 GetVersionExA
 0x59b31c WritePrivateProfileStringA
 0x59b320 GetPrivateProfileStringA
 0x59b324 CreateThread
 0x59b328 CreateEventA
 0x59b32c Sleep
 0x59b330 GlobalAlloc
 0x59b334 GlobalLock
 0x59b338 GlobalUnlock
 0x59b33c FindFirstFileA
 0x59b340 FindClose
 0x59b344 GetFileAttributesA
 0x59b348 DeleteFileA
 0x59b34c CopyFileA
 0x59b350 CreateDirectoryA
 0x59b354 GetCurrentDirectoryA
 0x59b358 SetCurrentDirectoryA
 0x59b35c GetVolumeInformationA
 0x59b360 GetModuleHandleA
 0x59b364 GetProcAddress
 0x59b368 MulDiv
 0x59b36c SetLocalTime
 0x59b370 GetCommandLineA
 0x59b374 GetTickCount
 0x59b378 CreateProcessA
 0x59b37c WaitForSingleObject
 0x59b380 CloseHandle
 0x59b384 HeapSize
 0x59b388 GetACP
 0x59b38c SetStdHandle
 0x59b390 GetFileType
 0x59b394 UnhandledExceptionFilter
 0x59b398 FreeEnvironmentStringsA
 0x59b39c FreeEnvironmentStringsW
 0x59b3a0 GetEnvironmentStrings
 0x59b3a4 GetEnvironmentStringsW
 0x59b3a8 SetHandleCount
 0x59b3ac GetStdHandle
 0x59b3b0 GetEnvironmentVariableA
 0x59b3b4 HeapDestroy
 0x59b3b8 HeapCreate
 0x59b3bc VirtualFree
 0x59b3c0 SetEnvironmentVariableA
 0x59b3c4 LCMapStringA
 0x59b3c8 LCMapStringW
 0x59b3cc VirtualAlloc
 0x59b3d0 IsBadWritePtr
 0x59b3d4 GetStringTypeA
 0x59b3d8 GetStringTypeW
 0x59b3dc SetUnhandledExceptionFilter
 0x59b3e0 CompareStringA
 0x59b3e4 CompareStringW
 0x59b3e8 IsBadReadPtr
 0x59b3ec IsBadCodePtr
 0x59b3f0 GetSystemTime
USER32.dll
 0x59b450 SetFocus
 0x59b454 IsIconic
 0x59b458 PeekMessageA
 0x59b45c SetMenu
 0x59b460 GetMenu
 0x59b464 DeleteMenu
 0x59b468 GetSystemMenu
 0x59b46c DefWindowProcA
 0x59b470 GetClassInfoA
 0x59b474 IsZoomed
 0x59b478 GetActiveWindow
 0x59b47c GetWindow
 0x59b480 DestroyAcceleratorTable
 0x59b484 SetWindowRgn
 0x59b488 GetMessagePos
 0x59b48c PostQuitMessage
 0x59b490 CopyAcceleratorTableA
 0x59b494 GetKeyState
 0x59b498 TranslateAcceleratorA
 0x59b49c IsWindowEnabled
 0x59b4a0 ShowWindow
 0x59b4a4 SystemParametersInfoA
 0x59b4a8 LoadImageA
 0x59b4ac EnumDisplaySettingsA
 0x59b4b0 ClientToScreen
 0x59b4b4 EnableMenuItem
 0x59b4b8 GetSubMenu
 0x59b4bc GetDlgCtrlID
 0x59b4c0 CreateAcceleratorTableA
 0x59b4c4 CreateMenu
 0x59b4c8 ModifyMenuA
 0x59b4cc AppendMenuA
 0x59b4d0 CreatePopupMenu
 0x59b4d4 DrawIconEx
 0x59b4d8 CreateIconFromResource
 0x59b4dc CreateIconFromResourceEx
 0x59b4e0 RegisterClipboardFormatA
 0x59b4e4 ScreenToClient
 0x59b4e8 ChildWindowFromPointEx
 0x59b4ec CopyRect
 0x59b4f0 LoadBitmapA
 0x59b4f4 WinHelpA
 0x59b4f8 KillTimer
 0x59b4fc SetTimer
 0x59b500 ReleaseCapture
 0x59b504 GetCapture
 0x59b508 SetCapture
 0x59b50c GetScrollRange
 0x59b510 SetScrollRange
 0x59b514 SetScrollPos
 0x59b518 SetRect
 0x59b51c InflateRect
 0x59b520 IntersectRect
 0x59b524 DestroyIcon
 0x59b528 PtInRect
 0x59b52c OffsetRect
 0x59b530 GetSysColorBrush
 0x59b534 LoadStringA
 0x59b538 IsWindowVisible
 0x59b53c EnableWindow
 0x59b540 RedrawWindow
 0x59b544 GetWindowLongA
 0x59b548 SetWindowLongA
 0x59b54c GetSysColor
 0x59b550 SetActiveWindow
 0x59b554 SetCursorPos
 0x59b558 LoadCursorA
 0x59b55c SetCursor
 0x59b560 GetDC
 0x59b564 FillRect
 0x59b568 InvertRect
 0x59b56c IsRectEmpty
 0x59b570 ReleaseDC
 0x59b574 IsChild
 0x59b578 TrackPopupMenu
 0x59b57c DestroyMenu
 0x59b580 SetForegroundWindow
 0x59b584 GetWindowRect
 0x59b588 EqualRect
 0x59b58c UpdateWindow
 0x59b590 ValidateRect
 0x59b594 InvalidateRect
 0x59b598 GetClientRect
 0x59b59c GetFocus
 0x59b5a0 GetParent
 0x59b5a4 GetTopWindow
 0x59b5a8 PostMessageA
 0x59b5ac IsWindow
 0x59b5b0 SetParent
 0x59b5b4 DestroyCursor
 0x59b5b8 SendMessageA
 0x59b5bc SetWindowPos
 0x59b5c0 MessageBeep
 0x59b5c4 MessageBoxA
 0x59b5c8 GetCursorPos
 0x59b5cc GetSystemMetrics
 0x59b5d0 IsClipboardFormatAvailable
 0x59b5d4 EmptyClipboard
 0x59b5d8 SetClipboardData
 0x59b5dc OpenClipboard
 0x59b5e0 GetClipboardData
 0x59b5e4 CloseClipboard
 0x59b5e8 wsprintfA
 0x59b5ec WaitForInputIdle
 0x59b5f0 SetRectEmpty
 0x59b5f4 DispatchMessageA
 0x59b5f8 GetMessageA
 0x59b5fc WindowFromPoint
 0x59b600 DrawFocusRect
 0x59b604 DrawEdge
 0x59b608 DrawFrameControl
 0x59b60c LoadIconA
 0x59b610 GetForegroundWindow
 0x59b614 GetDesktopWindow
 0x59b618 GetClassNameA
 0x59b61c GetDlgItem
 0x59b620 FindWindowExA
 0x59b624 GetWindowTextA
 0x59b628 TabbedTextOutA
 0x59b62c DrawTextA
 0x59b630 GrayStringA
 0x59b634 ClipCursor
 0x59b638 GetCursor
 0x59b63c UnregisterClassA
 0x59b640 GetDoubleClickTime
 0x59b644 FrameRect
 0x59b648 TranslateMessage
 0x59b64c GetWindowTextLengthA
 0x59b650 CharUpperA
 0x59b654 GetWindowDC
 0x59b658 BeginPaint
 0x59b65c EndPaint
 0x59b660 DestroyWindow
 0x59b664 CreateDialogIndirectParamA
 0x59b668 EndDialog
 0x59b66c GetNextDlgTabItem
 0x59b670 GetWindowPlacement
 0x59b674 RegisterWindowMessageA
 0x59b678 GetLastActivePopup
 0x59b67c GetMessageTime
 0x59b680 RemovePropA
 0x59b684 CallWindowProcA
 0x59b688 GetPropA
 0x59b68c UnhookWindowsHookEx
 0x59b690 SetPropA
 0x59b694 GetClassLongA
 0x59b698 CallNextHookEx
 0x59b69c SetWindowsHookExA
 0x59b6a0 CreateWindowExA
 0x59b6a4 GetMenuItemID
 0x59b6a8 GetMenuItemCount
 0x59b6ac RegisterClassA
 0x59b6b0 GetScrollPos
 0x59b6b4 ShowScrollBar
 0x59b6b8 SetScrollInfo
 0x59b6bc GetScrollInfo
 0x59b6c0 ScrollWindow
 0x59b6c4 AdjustWindowRectEx
 0x59b6c8 MapWindowPoints
 0x59b6cc SendDlgItemMessageA
 0x59b6d0 ScrollWindowEx
 0x59b6d4 IsDialogMessageA
 0x59b6d8 SetWindowTextA
 0x59b6dc MoveWindow
 0x59b6e0 CheckMenuItem
 0x59b6e4 SetMenuItemBitmaps
 0x59b6e8 GetMenuState
 0x59b6ec GetMenuCheckMarkDimensions
 0x59b6f0 wvsprintfA
GDI32.dll
 0x59b050 ExtSelectClipRgn
 0x59b054 LineTo
 0x59b058 MoveToEx
 0x59b05c EndDoc
 0x59b060 DeleteDC
 0x59b064 StartDocA
 0x59b068 StartPage
 0x59b06c BitBlt
 0x59b070 CreateCompatibleDC
 0x59b074 Ellipse
 0x59b078 Rectangle
 0x59b07c LPtoDP
 0x59b080 DPtoLP
 0x59b084 GetCurrentObject
 0x59b088 RoundRect
 0x59b08c GetDeviceCaps
 0x59b090 GetClipRgn
 0x59b094 SetStretchBltMode
 0x59b098 CreateRectRgnIndirect
 0x59b09c SetBkColor
 0x59b0a0 PtVisible
 0x59b0a4 RectVisible
 0x59b0a8 TextOutA
 0x59b0ac ExtTextOutA
 0x59b0b0 GetTextMetricsA
 0x59b0b4 Escape
 0x59b0b8 AbortDoc
 0x59b0bc CreateFontA
 0x59b0c0 SetBrushOrgEx
 0x59b0c4 ExcludeClipRect
 0x59b0c8 GetClipBox
 0x59b0cc ScaleWindowExtEx
 0x59b0d0 SetWindowExtEx
 0x59b0d4 OffsetWindowOrgEx
 0x59b0d8 SetWindowOrgEx
 0x59b0dc ScaleViewportExtEx
 0x59b0e0 SetViewportExtEx
 0x59b0e4 OffsetViewportOrgEx
 0x59b0e8 SetViewportOrgEx
 0x59b0ec SetMapMode
 0x59b0f0 SetTextColor
 0x59b0f4 GetViewportExtEx
 0x59b0f8 CopyMetaFileA
 0x59b0fc EndPage
 0x59b100 GetObjectA
 0x59b104 GetStockObject
 0x59b108 CreateFontIndirectA
 0x59b10c CreateSolidBrush
 0x59b110 FillRgn
 0x59b114 CreateRectRgn
 0x59b118 CombineRgn
 0x59b11c PatBlt
 0x59b120 CreatePen
 0x59b124 SelectObject
 0x59b128 CreatePatternBrush
 0x59b12c CreateBitmap
 0x59b130 CreateDCA
 0x59b134 CreateCompatibleBitmap
 0x59b138 GetPolyFillMode
 0x59b13c GetStretchBltMode
 0x59b140 GetROP2
 0x59b144 GetBkColor
 0x59b148 GetBkMode
 0x59b14c GetTextColor
 0x59b150 SetROP2
 0x59b154 SetPolyFillMode
 0x59b158 SetBkMode
 0x59b15c RestoreDC
 0x59b160 SaveDC
 0x59b164 CreateRoundRectRgn
 0x59b168 CreateEllipticRgn
 0x59b16c PathToRegion
 0x59b170 EndPath
 0x59b174 BeginPath
 0x59b178 GetWindowOrgEx
 0x59b17c GetViewportOrgEx
 0x59b180 GetWindowExtEx
 0x59b184 GetDIBits
 0x59b188 RealizePalette
 0x59b18c SelectPalette
 0x59b190 StretchBlt
 0x59b194 CreatePalette
 0x59b198 GetSystemPaletteEntries
 0x59b19c CreateDIBitmap
 0x59b1a0 DeleteObject
 0x59b1a4 SelectClipRgn
 0x59b1a8 GetTextExtentPoint32A
 0x59b1ac CreatePolygonRgn
WINSPOOL.DRV
 0x59b758 OpenPrinterA
 0x59b75c DocumentPropertiesA
 0x59b760 ClosePrinter
ADVAPI32.dll
 0x59b000 RegQueryValueExA
 0x59b004 RegOpenKeyExA
 0x59b008 RegSetValueExA
 0x59b00c RegDeleteValueA
 0x59b010 RegQueryValueA
 0x59b014 RegCreateKeyExA
 0x59b018 RegOpenKeyA
 0x59b01c RegCloseKey
SHELL32.dll
 0x59b43c ShellExecuteA
 0x59b440 Shell_NotifyIconA
 0x59b444 SHChangeNotify
 0x59b448 SHGetSpecialFolderPathA
ole32.dll
 0x59b7d8 CoTaskMemAlloc
 0x59b7dc OleDuplicateData
 0x59b7e0 RevokeDragDrop
 0x59b7e4 CoLockObjectExternal
 0x59b7e8 DoDragDrop
 0x59b7ec OleIsCurrentClipboard
 0x59b7f0 OleFlushClipboard
 0x59b7f4 OleSetClipboard
 0x59b7f8 CoTaskMemFree
 0x59b7fc ReleaseStgMedium
 0x59b800 CLSIDFromProgID
 0x59b804 OleRun
 0x59b808 CoCreateInstance
 0x59b80c CreateStreamOnHGlobal
 0x59b810 CLSIDFromString
 0x59b814 OleUninitialize
 0x59b818 OleInitialize
 0x59b81c OleGetClipboard
OLEAUT32.dll
 0x59b3f8 SafeArrayGetUBound
 0x59b3fc VariantChangeType
 0x59b400 VariantClear
 0x59b404 SafeArrayGetLBound
 0x59b408 VarDateFromStr
 0x59b40c SafeArrayGetDim
 0x59b410 SafeArrayUnaccessData
 0x59b414 SafeArrayAccessData
 0x59b418 SafeArrayGetElement
 0x59b41c UnRegisterTypeLib
 0x59b420 LoadTypeLib
 0x59b424 LHashValOfNameSys
 0x59b428 RegisterTypeLib
 0x59b42c SysAllocString
 0x59b430 VariantInit
 0x59b434 VariantCopyInd
COMCTL32.dll
 0x59b024 ImageList_GetImageInfo
 0x59b028 ImageList_GetImageCount
 0x59b02c ImageList_SetBkColor
 0x59b030 ImageList_AddMasked
 0x59b034 ImageList_Draw
 0x59b038 None
 0x59b03c ImageList_Destroy
 0x59b040 ImageList_Create
 0x59b044 ImageList_Read
 0x59b048 ImageList_Duplicate
WININET.dll
 0x59b6f8 InternetCloseHandle
 0x59b6fc InternetOpenUrlA
 0x59b700 InternetOpenA
 0x59b704 InternetGetConnectedState
comdlg32.dll
 0x59b7c0 ChooseColorA
 0x59b7c4 GetOpenFileNameA
 0x59b7c8 GetSaveFileNameA
 0x59b7cc PrintDlgA
 0x59b7d0 GetFileTitleA

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure