Report - appst.exe

Generic Malware Malicious Library UPX PE64 PE File
ScreenShot
Created 2024.06.16 10:02 Machine s1_win7_x6401
Filename appst.exe
Type PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
AI Score Not founds Behavior Score
1.0
ZERO API file : clean
VT API (file) 5 detected (HackTool, KMSAuto, RnkBend)
md5 f05da219bf720502ed4a9d17c7bbcb65
sha256 e1107ea656eb0de7ac6c8fa2f0eba4e93085c01492a6f62015ce0425a893a2dc
ssdeep 49152:SKFr5jBni9WzxmAIknn/kIvJOJNBT1A1gJky1l:rr5VnnzxmhkP+x
imphash 43c7b1b36f30c0db451aaf50f98e2a77
impfuzzy 192:Wz1ctF7UESPeQOJPVsOUE8UQB+oi+8GSVoQHuDccUkcHy:Wz1c/7U9eQOJoi+hQOIvk4y
  Network IP location

Signature (3cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice File has been identified by 5 AntiVirus engines on VirusTotal as malicious
info Checks amount of memory in system

Rules (5cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsPE64 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x100304ed4 GetStdHandle
 0x100304edc GetConsoleMode
 0x100304ee4 TlsGetValue
 0x100304eec GetLastError
 0x100304ef4 SetLastError
 0x100304efc RaiseException
 0x100304f04 GetTickCount
 0x100304f0c ExitProcess
 0x100304f14 GetStartupInfoA
 0x100304f1c GetCommandLineA
 0x100304f24 GetCurrentProcessId
 0x100304f2c GetCurrentThreadId
 0x100304f34 GetCurrentProcess
 0x100304f3c ReadProcessMemory
 0x100304f44 GetModuleFileNameA
 0x100304f4c GetModuleHandleA
 0x100304f54 WriteFile
 0x100304f5c ReadFile
 0x100304f64 CloseHandle
 0x100304f6c SetFilePointer
 0x100304f74 SetEndOfFile
 0x100304f7c GetSystemInfo
 0x100304f84 LoadLibraryW
 0x100304f8c LoadLibraryA
 0x100304f94 GetProcAddress
 0x100304f9c FreeLibrary
 0x100304fa4 FormatMessageW
 0x100304fac DeleteFileW
 0x100304fb4 CreateFileW
 0x100304fbc GetFileAttributesW
 0x100304fc4 GetCurrentDirectoryW
 0x100304fcc GetFullPathNameW
 0x100304fd4 GetConsoleOutputCP
 0x100304fdc GetOEMCP
 0x100304fe4 GetProcessHeap
 0x100304fec HeapAlloc
 0x100304ff4 HeapFree
 0x100304ffc TlsAlloc
 0x100305004 TlsSetValue
 0x10030500c CreateThread
 0x100305014 ExitThread
 0x10030501c LocalAlloc
 0x100305024 LocalFree
 0x10030502c Sleep
 0x100305034 SuspendThread
 0x10030503c ResumeThread
 0x100305044 TerminateThread
 0x10030504c WaitForSingleObject
 0x100305054 SetThreadPriority
 0x10030505c GetThreadPriority
 0x100305064 GetCurrentThread
 0x10030506c OpenThread
 0x100305074 IsDebuggerPresent
 0x10030507c CreateEventA
 0x100305084 ResetEvent
 0x10030508c SetEvent
 0x100305094 InitializeCriticalSection
 0x10030509c DeleteCriticalSection
 0x1003050a4 EnterCriticalSection
 0x1003050ac LeaveCriticalSection
 0x1003050b4 TryEnterCriticalSection
 0x1003050bc GetEnvironmentStringsW
 0x1003050c4 FreeEnvironmentStringsW
 0x1003050cc MultiByteToWideChar
 0x1003050d4 WideCharToMultiByte
 0x1003050dc GetACP
 0x1003050e4 GetConsoleCP
 0x1003050ec RtlCaptureContext
 0x1003050f4 RtlLookupFunctionEntry
 0x1003050fc RtlVirtualUnwind
 0x100305104 RtlUnwindEx
 0x10030510c EnumResourceTypesA
 0x100305114 EnumResourceNamesA
 0x10030511c EnumResourceLanguagesA
 0x100305124 FindResourceA
 0x10030512c FindResourceExA
 0x100305134 LoadResource
 0x10030513c SizeofResource
 0x100305144 LockResource
 0x10030514c FreeResource
 0x100305154 FormatMessageA
 0x10030515c GlobalAddAtomA
 0x100305164 GetWindowsDirectoryA
 0x10030516c GetVersionExA
 0x100305174 CompareStringA
 0x10030517c GetLocaleInfoA
 0x100305184 GetDateFormatA
 0x10030518c EnumCalendarInfoA
 0x100305194 GetModuleFileNameW
 0x10030519c GetCommandLineW
 0x1003051a4 CreateProcessW
 0x1003051ac FindNextFileW
 0x1003051b4 CompareStringW
 0x1003051bc GetLocaleInfoW
 0x1003051c4 GetDateFormatW
 0x1003051cc FindFirstFileExW
 0x1003051d4 GlobalAlloc
 0x1003051dc GlobalReAlloc
 0x1003051e4 GlobalSize
 0x1003051ec GlobalLock
 0x1003051f4 GlobalUnlock
 0x1003051fc GetExitCodeProcess
 0x100305204 GlobalDeleteAtom
 0x10030520c DeviceIoControl
 0x100305214 FindClose
 0x10030521c MulDiv
 0x100305224 GetLocalTime
 0x10030522c FileTimeToLocalFileTime
 0x100305234 FileTimeToDosDateTime
 0x10030523c PeekNamedPipe
 0x100305244 GetCPInfo
 0x10030524c GetThreadLocale
 0x100305254 SetThreadLocale
 0x10030525c GetUserDefaultLCID
oleaut32.dll
 0x10030526c SysAllocStringLen
 0x100305274 SysFreeString
 0x10030527c SysReAllocStringLen
 0x100305284 SafeArrayCreate
 0x10030528c SafeArrayRedim
 0x100305294 SafeArrayGetUBound
 0x10030529c SafeArrayGetLBound
 0x1003052a4 SafeArrayAccessData
 0x1003052ac SafeArrayUnaccessData
 0x1003052b4 SafeArrayGetElement
 0x1003052bc SafeArrayPutElement
 0x1003052c4 SafeArrayPtrOfIndex
 0x1003052cc VariantChangeTypeEx
 0x1003052d4 VariantClear
 0x1003052dc VariantCopy
 0x1003052e4 VariantInit
user32.dll
 0x1003052f4 MessageBoxA
 0x1003052fc CharUpperBuffW
 0x100305304 CharLowerBuffW
 0x10030530c SendMessageA
 0x100305314 PostMessageA
 0x10030531c DefWindowProcA
 0x100305324 CallWindowProcA
 0x10030532c RegisterClassA
 0x100305334 UnregisterClassA
 0x10030533c GetClassInfoA
 0x100305344 CreateWindowExA
 0x10030534c RegisterClipboardFormatA
 0x100305354 GetClipboardFormatNameA
 0x10030535c CharToOemA
 0x100305364 CharUpperA
 0x10030536c CharUpperBuffA
 0x100305374 CharLowerA
 0x10030537c CharLowerBuffA
 0x100305384 GetMenuItemInfoA
 0x10030538c SetPropA
 0x100305394 GetPropA
 0x10030539c RemovePropA
 0x1003053a4 EnumPropsA
 0x1003053ac GetWindowLongA
 0x1003053b4 SetWindowLongA
 0x1003053bc GetClassLongA
 0x1003053c4 SetClassLongPtrA
 0x1003053cc GetClassNameA
 0x1003053d4 LoadBitmapA
 0x1003053dc LoadCursorA
 0x1003053e4 LoadIconA
 0x1003053ec LoadImageA
 0x1003053f4 SystemParametersInfoA
 0x1003053fc DispatchMessageW
 0x100305404 PeekMessageW
 0x10030540c SendMessageW
 0x100305414 DefWindowProcW
 0x10030541c CallWindowProcW
 0x100305424 RegisterClassW
 0x10030542c UnregisterClassW
 0x100305434 GetClassInfoW
 0x10030543c CreateWindowExW
 0x100305444 InsertMenuItemW
 0x10030544c GetMenuItemInfoW
 0x100305454 SetMenuItemInfoW
 0x10030545c DrawTextW
 0x100305464 DrawStateW
 0x10030546c SetWindowTextW
 0x100305474 GetWindowTextW
 0x10030547c GetWindowTextLengthW
 0x100305484 MessageBoxW
 0x10030548c GetWindowLongPtrW
 0x100305494 SetWindowLongPtrW
 0x10030549c DefFrameProcW
 0x1003054a4 DefMDIChildProcW
 0x1003054ac TranslateMessage
 0x1003054b4 PostQuitMessage
 0x1003054bc GetDoubleClickTime
 0x1003054c4 IsWindow
 0x1003054cc IsMenu
 0x1003054d4 DestroyWindow
 0x1003054dc ShowWindow
 0x1003054e4 ShowWindowAsync
 0x1003054ec ShowOwnedPopups
 0x1003054f4 MoveWindow
 0x1003054fc SetWindowPos
 0x100305504 GetWindowPlacement
 0x10030550c SetWindowPlacement
 0x100305514 BeginDeferWindowPos
 0x10030551c DeferWindowPos
 0x100305524 EndDeferWindowPos
 0x10030552c IsWindowVisible
 0x100305534 IsIconic
 0x10030553c BringWindowToTop
 0x100305544 IsZoomed
 0x10030554c OpenClipboard
 0x100305554 CloseClipboard
 0x10030555c SetClipboardData
 0x100305564 GetClipboardData
 0x10030556c CountClipboardFormats
 0x100305574 EnumClipboardFormats
 0x10030557c EmptyClipboard
 0x100305584 IsClipboardFormatAvailable
 0x10030558c SetFocus
 0x100305594 GetActiveWindow
 0x10030559c GetFocus
 0x1003055a4 GetKeyState
 0x1003055ac GetCapture
 0x1003055b4 SetCapture
 0x1003055bc ReleaseCapture
 0x1003055c4 MsgWaitForMultipleObjects
 0x1003055cc SetTimer
 0x1003055d4 KillTimer
 0x1003055dc EnableWindow
 0x1003055e4 IsWindowEnabled
 0x1003055ec GetSystemMetrics
 0x1003055f4 GetMenu
 0x1003055fc SetMenu
 0x100305604 DrawMenuBar
 0x10030560c GetSystemMenu
 0x100305614 CreateMenu
 0x10030561c CreatePopupMenu
 0x100305624 DestroyMenu
 0x10030562c EnableMenuItem
 0x100305634 GetSubMenu
 0x10030563c GetMenuItemCount
 0x100305644 RemoveMenu
 0x10030564c DeleteMenu
 0x100305654 GetMenuItemRect
 0x10030565c UpdateWindow
 0x100305664 SetActiveWindow
 0x10030566c GetForegroundWindow
 0x100305674 SetForegroundWindow
 0x10030567c WindowFromDC
 0x100305684 GetDC
 0x10030568c GetDCEx
 0x100305694 GetWindowDC
 0x10030569c ReleaseDC
 0x1003056a4 BeginPaint
 0x1003056ac EndPaint
 0x1003056b4 GetUpdateRect
 0x1003056bc SetWindowRgn
 0x1003056c4 InvalidateRect
 0x1003056cc InvalidateRgn
 0x1003056d4 RedrawWindow
 0x1003056dc ScrollWindowEx
 0x1003056e4 ShowScrollBar
 0x1003056ec EnableScrollBar
 0x1003056f4 GetClientRect
 0x1003056fc GetWindowRect
 0x100305704 AdjustWindowRectEx
 0x10030570c MessageBeep
 0x100305714 SetCursorPos
 0x10030571c SetCursor
 0x100305724 GetCursorPos
 0x10030572c CreateCaret
 0x100305734 DestroyCaret
 0x10030573c HideCaret
 0x100305744 ShowCaret
 0x10030574c SetCaretPos
 0x100305754 GetCaretPos
 0x10030575c ClientToScreen
 0x100305764 ScreenToClient
 0x10030576c MapWindowPoints
 0x100305774 WindowFromPoint
 0x10030577c GetSysColor
 0x100305784 GetSysColorBrush
 0x10030578c SetSysColors
 0x100305794 DrawFocusRect
 0x10030579c FillRect
 0x1003057a4 FrameRect
 0x1003057ac SetRect
 0x1003057b4 InflateRect
 0x1003057bc IntersectRect
 0x1003057c4 OffsetRect
 0x1003057cc GetDesktopWindow
 0x1003057d4 GetParent
 0x1003057dc SetParent
 0x1003057e4 EnumThreadWindows
 0x1003057ec GetTopWindow
 0x1003057f4 GetWindowThreadProcessId
 0x1003057fc GetLastActivePopup
 0x100305804 GetWindow
 0x10030580c CallNextHookEx
 0x100305814 DestroyCursor
 0x10030581c DestroyIcon
 0x100305824 CopyImage
 0x10030582c CreateIconIndirect
 0x100305834 GetIconInfo
 0x10030583c SetScrollInfo
 0x100305844 GetScrollInfo
 0x10030584c TranslateMDISysAccel
 0x100305854 DrawEdge
 0x10030585c DrawFrameControl
 0x100305864 TrackPopupMenuEx
 0x10030586c ChildWindowFromPointEx
 0x100305874 DrawIconEx
 0x10030587c FlashWindowEx
gdi32.dll
 0x10030588c CreateFontIndirectA
 0x100305894 EnumFontFamiliesA
 0x10030589c GetCharABCWidthsA
 0x1003058a4 GetTextExtentPointA
 0x1003058ac GetTextMetricsA
 0x1003058b4 GetObjectA
 0x1003058bc ExtTextOutA
 0x1003058c4 CreateFontIndirectW
 0x1003058cc EnumFontFamiliesExW
 0x1003058d4 GetCharABCWidthsW
 0x1003058dc GetTextExtentPoint32W
 0x1003058e4 GetTextExtentExPointW
 0x1003058ec GetObjectW
 0x1003058f4 TextOutW
 0x1003058fc ExtTextOutW
 0x100305904 GetRandomRgn
 0x10030590c Arc
 0x100305914 BitBlt
 0x10030591c Chord
 0x100305924 CombineRgn
 0x10030592c CreateBitmap
 0x100305934 CreateBrushIndirect
 0x10030593c CreateCompatibleBitmap
 0x100305944 CreateCompatibleDC
 0x10030594c CreateDIBitmap
 0x100305954 CreateEllipticRgn
 0x10030595c CreatePen
 0x100305964 CreatePenIndirect
 0x10030596c CreatePatternBrush
 0x100305974 CreateRectRgn
 0x10030597c CreateRoundRectRgn
 0x100305984 CreateSolidBrush
 0x10030598c DeleteDC
 0x100305994 DeleteObject
 0x10030599c Ellipse
 0x1003059a4 EqualRgn
 0x1003059ac ExcludeClipRect
 0x1003059b4 ExtCreateRegion
 0x1003059bc ExtFloodFill
 0x1003059c4 FillRgn
 0x1003059cc GetROP2
 0x1003059d4 GetBkColor
 0x1003059dc GetBitmapBits
 0x1003059e4 GetClipBox
 0x1003059ec GetClipRgn
 0x1003059f4 GetCurrentObject
 0x1003059fc GetDeviceCaps
 0x100305a04 GetDIBits
 0x100305a0c GetMapMode
 0x100305a14 GetObjectType
 0x100305a1c GetPixel
 0x100305a24 GetRegionData
 0x100305a2c GetRgnBox
 0x100305a34 GetStockObject
 0x100305a3c GetTextAlign
 0x100305a44 GetTextColor
 0x100305a4c GetViewportExtEx
 0x100305a54 GetViewportOrgEx
 0x100305a5c GetWindowExtEx
 0x100305a64 GetWindowOrgEx
 0x100305a6c IntersectClipRect
 0x100305a74 LineTo
 0x100305a7c MaskBlt
 0x100305a84 OffsetRgn
 0x100305a8c PatBlt
 0x100305a94 Pie
 0x100305a9c PaintRgn
 0x100305aa4 PtInRegion
 0x100305aac RectInRegion
 0x100305ab4 RectVisible
 0x100305abc Rectangle
 0x100305ac4 RestoreDC
 0x100305acc RealizePalette
 0x100305ad4 RoundRect
 0x100305adc SaveDC
 0x100305ae4 SelectClipRgn
 0x100305aec ExtSelectClipRgn
 0x100305af4 SelectObject
 0x100305afc SelectPalette
 0x100305b04 SetBkColor
 0x100305b0c SetBkMode
 0x100305b14 SetMapMode
 0x100305b1c SetPixel
 0x100305b24 SetPolyFillMode
 0x100305b2c StretchBlt
 0x100305b34 SetRectRgn
 0x100305b3c SetROP2
 0x100305b44 SetStretchBltMode
 0x100305b4c SetTextCharacterExtra
 0x100305b54 SetTextColor
 0x100305b5c SetTextAlign
 0x100305b64 CreateDIBSection
 0x100305b6c SetArcDirection
 0x100305b74 ExtCreatePen
 0x100305b7c MoveToEx
 0x100305b84 CreatePolygonRgn
 0x100305b8c DPtoLP
 0x100305b94 LPtoDP
 0x100305b9c Polygon
 0x100305ba4 Polyline
 0x100305bac PolyBezier
 0x100305bb4 SetViewportExtEx
 0x100305bbc SetViewportOrgEx
 0x100305bc4 SetWindowExtEx
 0x100305bcc SetWindowOrgEx
 0x100305bd4 OffsetViewportOrgEx
 0x100305bdc SetBrushOrgEx
 0x100305be4 GetDCOrgEx
version.dll
 0x100305bf4 GetFileVersionInfoSizeA
 0x100305bfc GetFileVersionInfoA
 0x100305c04 VerQueryValueA
shell32.dll
 0x100305c14 DragQueryFileA
 0x100305c1c DragQueryFileW
 0x100305c24 DragFinish
 0x100305c2c DragAcceptFiles
ole32.dll
 0x100305c3c OleInitialize
 0x100305c44 OleUninitialize
comctl32.dll
 0x100305c54 InitCommonControls
 0x100305c5c ImageList_Create
 0x100305c64 ImageList_Destroy
 0x100305c6c ImageList_GetImageCount
 0x100305c74 ImageList_SetImageCount
 0x100305c7c ImageList_Add
 0x100305c84 ImageList_Replace
 0x100305c8c ImageList_AddMasked
 0x100305c94 ImageList_DrawEx
 0x100305c9c ImageList_DrawIndirect
 0x100305ca4 ImageList_Remove
 0x100305cac ImageList_Copy
 0x100305cb4 ImageList_BeginDrag
 0x100305cbc ImageList_EndDrag
 0x100305cc4 ImageList_DragEnter
 0x100305ccc ImageList_DragLeave
 0x100305cd4 ImageList_DragMove
 0x100305cdc ImageList_DragShowNolock
 0x100305ce4 _TrackMouseEvent

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure