Report - App.dll

Generic Malware Malicious Library ASPack UPX PE File DLL PE64 OS Processor Check
ScreenShot
Created 2024.07.08 10:36 Machine s1_win7_x6403
Filename App.dll
Type PE32+ executable (DLL) (GUI) x86-64, for MS Windows
AI Score
1
Behavior Score
0.6
ZERO API file : clean
VT API (file)
md5 1afdf73c0d1ba126c63927b423c55205
sha256 271517dc4421fc19495b052cf22ae3f3d28a6d5c8edebddbc2b60671edc8ce7c
ssdeep 12288:SQtOANnC7/Mh9G5eExTmZlnVCMhvLpllJ/bWngmdMZWd6OtNosq5R:S1IG5eERmZlVCGv3/2XM2Nov
imphash dd5ce9710d7a0bc4a5baeed36f9d5110
impfuzzy 48:0YQJdGtpv8U9faOwOk6BF9rWtL3fuWyla3uv:PQJdGtpvZta7n6BF1WtL3fuW2
  Network IP location

Signature (3cnts)

Level Description
info Checks if process is being debugged by a debugger
info One or more processes crashed
info This executable has a PDB path

Rules (8cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (upload)
watch ASPack_Zero ASPack packed file binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info IsDLL (no description) binaries (upload)
info IsPE64 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.dll
 0x1800b6000 AreFileApisANSI
 0x1800b6008 ReadFile
 0x1800b6010 TryEnterCriticalSection
 0x1800b6018 HeapCreate
 0x1800b6020 HeapFree
 0x1800b6028 EnterCriticalSection
 0x1800b6030 GetFullPathNameW
 0x1800b6038 WriteFile
 0x1800b6040 GetDiskFreeSpaceW
 0x1800b6048 OutputDebugStringA
 0x1800b6050 LockFile
 0x1800b6058 LeaveCriticalSection
 0x1800b6060 InitializeCriticalSection
 0x1800b6068 SetFilePointer
 0x1800b6070 GetFullPathNameA
 0x1800b6078 SetEndOfFile
 0x1800b6080 UnlockFileEx
 0x1800b6088 GetTempPathW
 0x1800b6090 CreateMutexW
 0x1800b6098 WaitForSingleObject
 0x1800b60a0 CreateFileW
 0x1800b60a8 GetFileAttributesW
 0x1800b60b0 GetCurrentThreadId
 0x1800b60b8 UnmapViewOfFile
 0x1800b60c0 HeapValidate
 0x1800b60c8 HeapSize
 0x1800b60d0 MultiByteToWideChar
 0x1800b60d8 Sleep
 0x1800b60e0 GetTempPathA
 0x1800b60e8 FormatMessageW
 0x1800b60f0 GetDiskFreeSpaceA
 0x1800b60f8 GetLastError
 0x1800b6100 GetFileAttributesA
 0x1800b6108 GetFileAttributesExW
 0x1800b6110 OutputDebugStringW
 0x1800b6118 FlushViewOfFile
 0x1800b6120 CreateFileA
 0x1800b6128 LoadLibraryA
 0x1800b6130 WaitForSingleObjectEx
 0x1800b6138 DeleteFileA
 0x1800b6140 DeleteFileW
 0x1800b6148 HeapReAlloc
 0x1800b6150 CloseHandle
 0x1800b6158 GetSystemInfo
 0x1800b6160 LoadLibraryW
 0x1800b6168 HeapAlloc
 0x1800b6170 HeapCompact
 0x1800b6178 HeapDestroy
 0x1800b6180 UnlockFile
 0x1800b6188 GetProcAddress
 0x1800b6190 LocalFree
 0x1800b6198 LockFileEx
 0x1800b61a0 GetFileSize
 0x1800b61a8 DeleteCriticalSection
 0x1800b61b0 GetCurrentProcessId
 0x1800b61b8 GetProcessHeap
 0x1800b61c0 SystemTimeToFileTime
 0x1800b61c8 FreeLibrary
 0x1800b61d0 WideCharToMultiByte
 0x1800b61d8 GetSystemTimeAsFileTime
 0x1800b61e0 GetSystemTime
 0x1800b61e8 FormatMessageA
 0x1800b61f0 CreateFileMappingW
 0x1800b61f8 MapViewOfFile
 0x1800b6200 QueryPerformanceCounter
 0x1800b6208 GetTickCount
 0x1800b6210 FlushFileBuffers
 0x1800b6218 WriteConsoleW
 0x1800b6220 RtlCaptureContext
 0x1800b6228 RtlLookupFunctionEntry
 0x1800b6230 RtlVirtualUnwind
 0x1800b6238 UnhandledExceptionFilter
 0x1800b6240 SetUnhandledExceptionFilter
 0x1800b6248 GetCurrentProcess
 0x1800b6250 TerminateProcess
 0x1800b6258 IsProcessorFeaturePresent
 0x1800b6260 InitializeSListHead
 0x1800b6268 IsDebuggerPresent
 0x1800b6270 GetStartupInfoW
 0x1800b6278 GetModuleHandleW
 0x1800b6280 RtlUnwindEx
 0x1800b6288 InterlockedFlushSList
 0x1800b6290 SetLastError
 0x1800b6298 InitializeCriticalSectionAndSpinCount
 0x1800b62a0 TlsAlloc
 0x1800b62a8 TlsGetValue
 0x1800b62b0 TlsSetValue
 0x1800b62b8 TlsFree
 0x1800b62c0 LoadLibraryExW
 0x1800b62c8 EncodePointer
 0x1800b62d0 RaiseException
 0x1800b62d8 RtlPcToFileHeader
 0x1800b62e0 CreateThread
 0x1800b62e8 ExitThread
 0x1800b62f0 FreeLibraryAndExitThread
 0x1800b62f8 GetModuleHandleExW
 0x1800b6300 ExitProcess
 0x1800b6308 GetModuleFileNameW
 0x1800b6310 CompareStringW
 0x1800b6318 LCMapStringW
 0x1800b6320 GetTimeZoneInformation
 0x1800b6328 FindClose
 0x1800b6330 FindFirstFileExW
 0x1800b6338 FindNextFileW
 0x1800b6340 IsValidCodePage
 0x1800b6348 GetACP
 0x1800b6350 GetOEMCP
 0x1800b6358 GetCPInfo
 0x1800b6360 GetCommandLineA
 0x1800b6368 GetCommandLineW
 0x1800b6370 GetEnvironmentStringsW
 0x1800b6378 FreeEnvironmentStringsW
 0x1800b6380 SetEnvironmentVariableW
 0x1800b6388 GetStdHandle
 0x1800b6390 GetFileType
 0x1800b6398 GetStringTypeW
 0x1800b63a0 SetStdHandle
 0x1800b63a8 GetConsoleCP
 0x1800b63b0 GetConsoleMode
 0x1800b63b8 SetFilePointerEx

EAT(Export Address Table) Library

0x18002fc80 sqlite3_aggregate_context
0x18002fdd0 sqlite3_aggregate_count
0x180066ba0 sqlite3_auto_extension
0x180026b10 sqlite3_backup_finish
0x180025fc0 sqlite3_backup_init
0x18000f2b0 sqlite3_backup_pagecount
0x180026c40 sqlite3_backup_remaining
0x180026350 sqlite3_backup_step
0x180030930 sqlite3_bind_blob
0x180030950 sqlite3_bind_blob64
0x1800309a0 sqlite3_bind_double
0x180030a10 sqlite3_bind_int
0x180030a20 sqlite3_bind_int64
0x180030ab0 sqlite3_bind_null
0x180030ed0 sqlite3_bind_parameter_count
0x180030f20 sqlite3_bind_parameter_index
0x180030ee0 sqlite3_bind_parameter_name
0x180030af0 sqlite3_bind_pointer
0x180030bb0 sqlite3_bind_text
0x180030c20 sqlite3_bind_text16
0x180030bd0 sqlite3_bind_text64
0x180030c40 sqlite3_bind_value
0x180030da0 sqlite3_bind_zeroblob
0x180030e40 sqlite3_bind_zeroblob64
0x180038540 sqlite3_blob_bytes
0x1800382e0 sqlite3_blob_close
0x180037a70 sqlite3_blob_open
0x180038500 sqlite3_blob_read
0x180038560 sqlite3_blob_reopen
0x180038520 sqlite3_blob_write
0x180099ee0 sqlite3_busy_handler
0x180099fd0 sqlite3_busy_timeout
0x180066c90 sqlite3_cancel_auto_extension
0x1800992c0 sqlite3_changes
0x18002e820 sqlite3_clear_bindings
0x1800996d0 sqlite3_close
0x1800996e0 sqlite3_close_v2
0x18009c700 sqlite3_collation_needed
0x18009c770 sqlite3_collation_needed16
0x18002fe90 sqlite3_column_blob
0x18002ff00 sqlite3_column_bytes
0x18002ffa0 sqlite3_column_bytes16
0x18002fde0 sqlite3_column_count
0x180030600 sqlite3_column_database_name
0x180030610 sqlite3_column_database_name16
0x1800305e0 sqlite3_column_decltype
0x1800305f0 sqlite3_column_decltype16
0x180030040 sqlite3_column_double
0x1800300e0 sqlite3_column_int
0x180030180 sqlite3_column_int64
0x1800305c0 sqlite3_column_name
0x1800305d0 sqlite3_column_name16
0x180030640 sqlite3_column_origin_name
0x180030650 sqlite3_column_origin_name16
0x180030620 sqlite3_column_table_name
0x180030630 sqlite3_column_table_name16
0x180030220 sqlite3_column_text
0x180030360 sqlite3_column_text16
0x180030410 sqlite3_column_type
0x1800302d0 sqlite3_column_value
0x18009aab0 sqlite3_commit_hook
0x18009d5a0 sqlite3_compileoption_get
0x18009d430 sqlite3_compileoption_used
0x180097ca0 sqlite3_complete
0x180098220 sqlite3_complete16
0x180098780 sqlite3_config
0x18002fb70 sqlite3_context_db_handle
0x18009c530 sqlite3_create_collation
0x18009c600 sqlite3_create_collation16
0x18009c560 sqlite3_create_collation_v2
0x18009a520 sqlite3_create_function
0x18009a6c0 sqlite3_create_function16
0x18009a5f0 sqlite3_create_function_v2
0x18007e5c0 sqlite3_create_module
0x18007e5e0 sqlite3_create_module_v2
0x18009a650 sqlite3_create_window_function
0x18002fdf0 sqlite3_data_count
0x1800dc480 sqlite3_data_directory
0x180098e60 sqlite3_db_cacheflush
0x180098fb0 sqlite3_db_config
0x18009d380 sqlite3_db_filename
0x1800310c0 sqlite3_db_handle
0x180098da0 sqlite3_db_mutex
0x18009d3e0 sqlite3_db_readonly
0x180098db0 sqlite3_db_release_memory
0x180001240 sqlite3_db_status
0x18007f2e0 sqlite3_declare_vtab
0x180066b40 sqlite3_enable_load_extension
0x180018680 sqlite3_enable_shared_cache
0x18009b330 sqlite3_errcode
0x18009b060 sqlite3_errmsg
0x18009b1c0 sqlite3_errmsg16
0x180099e10 sqlite3_errstr
0x180065f50 sqlite3_exec
0x180031270 sqlite3_expanded_sql
0x18002e570 sqlite3_expired
0x18009b3c0 sqlite3_extended_errcode
0x18009ccb0 sqlite3_extended_result_codes
0x18009cd00 sqlite3_file_control
0x18002e650 sqlite3_finalize
0x180004290 sqlite3_free
0x1800786f0 sqlite3_free_table
0x18009c7e0 sqlite3_get_autocommit
0x18002fca0 sqlite3_get_auxdata
0x180078550 sqlite3_get_table
0x180003bb0 sqlite3_global_recover
0x180098310 sqlite3_initialize
0x18009a090 sqlite3_interrupt
0x180096e60 sqlite3_keyword_check
0x180096e50 sqlite3_keyword_count
0x180096e10 sqlite3_keyword_name
0x180099270 sqlite3_last_insert_rowid
0x1800982f0 sqlite3_libversion
0x180098300 sqlite3_libversion_number
0x18009b680 sqlite3_limit
0x180066ab0 sqlite3_load_extension
0x180006c20 sqlite3_log
0x180004200 sqlite3_malloc
0x180004230 sqlite3_malloc64
0x180003bb0 sqlite3_memory_alarm
0x180004000 sqlite3_memory_highwater
0x180003fb0 sqlite3_memory_used
0x180006b30 sqlite3_mprintf
0x180004270 sqlite3_msize
0x180003c60 sqlite3_mutex_alloc
0x180003cb0 sqlite3_mutex_enter
0x180003ca0 sqlite3_mutex_free
0x180003cd0 sqlite3_mutex_leave
0x180003cc0 sqlite3_mutex_try
0x180031130 sqlite3_next_stmt
0x18009c3f0 sqlite3_open
0x18009c410 sqlite3_open16
0x18009c400 sqlite3_open_v2
0x18000d750 sqlite3_os_end
0x18000d3f0 sqlite3_os_init
0x18009a850 sqlite3_overload_function
0x18006bde0 sqlite3_prepare
0x18006c0b0 sqlite3_prepare16
0x18006c0d0 sqlite3_prepare16_v2
0x18006c100 sqlite3_prepare16_v3
0x18006be10 sqlite3_prepare_v2
0x18006be40 sqlite3_prepare_v3
0x18009aa30 sqlite3_profile
0x180099f50 sqlite3_progress_handler
0x180006d10 sqlite3_randomness
0x180004550 sqlite3_realloc
0x1800045a0 sqlite3_realloc64
0x180003bb0 sqlite3_release_memory
0x18002e760 sqlite3_reset
0x180066d30 sqlite3_reset_auto_extension
0x18002ed20 sqlite3_result_blob
0x18002ed90 sqlite3_result_blob64
0x18002ee20 sqlite3_result_double
0x18002ee90 sqlite3_result_error
0x18002eec0 sqlite3_result_error16
0x18002f290 sqlite3_result_error_code
0x18002f380 sqlite3_result_error_nomem
0x18002f320 sqlite3_result_error_toobig
0x18002eef0 sqlite3_result_int
0x18002ef20 sqlite3_result_int64
0x18002ef50 sqlite3_result_null
0x18002ef70 sqlite3_result_pointer
0x18002f000 sqlite3_result_subtype
0x18002f010 sqlite3_result_text
0x18002f0c0 sqlite3_result_text16
0x18002f130 sqlite3_result_text16be
0x18002f0c0 sqlite3_result_text16le
0x18002f080 sqlite3_result_text64
0x18002f1a0 sqlite3_result_value
0x18002f1b0 sqlite3_result_zeroblob
0x18002f210 sqlite3_result_zeroblob64
0x18009ab90 sqlite3_rollback_hook
0x1800a4b00 sqlite3_rtree_geometry_callback
0x1800a4bb0 sqlite3_rtree_query_callback
0x18004dfd0 sqlite3_set_authorizer
0x18002fce0 sqlite3_set_auxdata
0x180099280 sqlite3_set_last_insert_rowid
0x1800986c0 sqlite3_shutdown
0x18009cc10 sqlite3_sleep
0x180006bc0 sqlite3_snprintf
0x180003fa0 sqlite3_soft_heap_limit
0x180003ee0 sqlite3_soft_heap_limit64
0x1800a4c70 sqlite3_sourceid
0x180031260 sqlite3_sql
0x1800010e0 sqlite3_status
0x180001000 sqlite3_status64
0x18002f670 sqlite3_step
0x180031110 sqlite3_stmt_busy
0x1800310f0 sqlite3_stmt_isexplain
0x1800310d0 sqlite3_stmt_readonly
0x180031180 sqlite3_stmt_status
0x1800066c0 sqlite3_str_append
0x1800066f0 sqlite3_str_appendall
0x180006610 sqlite3_str_appendchar
0x180006ce0 sqlite3_str_appendf
0x180006830 sqlite3_str_errcode
0x1800067c0 sqlite3_str_finish
0x180006840 sqlite3_str_length
0x1800068f0 sqlite3_str_new
0x180006870 sqlite3_str_reset
0x180006850 sqlite3_str_value
0x180004c70 sqlite3_str_vappendf
0x18005b1b0 sqlite3_strglob
0x180007a80 sqlite3_stricmp
0x18005b1d0 sqlite3_strlike
0x180007b40 sqlite3_strnicmp
0x18009b450 sqlite3_system_errno
0x18009c830 sqlite3_table_column_metadata
0x1800dc488 sqlite3_temp_directory
0x18009ce50 sqlite3_test_control
0x180003bc0 sqlite3_thread_cleanup
0x1800097a0 sqlite3_threadsafe
0x1800992d0 sqlite3_total_changes
0x18009a930 sqlite3_trace
0x18009a9b0 sqlite3_trace_v2
0x180031070 sqlite3_transfer_bindings
0x18009ab20 sqlite3_update_hook
0x18009d2f0 sqlite3_uri_boolean
0x18009d340 sqlite3_uri_int64
0x18009d220 sqlite3_uri_parameter
0x18002fb60 sqlite3_user_data
0x18002e8f0 sqlite3_value_blob
0x18002e970 sqlite3_value_bytes
0x18002e9b0 sqlite3_value_bytes16
0x180027590 sqlite3_value_double
0x18002eb60 sqlite3_value_dup
0x18002ec30 sqlite3_value_free
0x18002eb50 sqlite3_value_frombind
0x180027530 sqlite3_value_int
0x180027530 sqlite3_value_int64
0x18002eb30 sqlite3_value_nochange
0x180031ae0 sqlite3_value_numeric_type
0x18002ea00 sqlite3_value_pointer
0x18002e9f0 sqlite3_value_subtype
0x18002ea50 sqlite3_value_text
0x18002ea90 sqlite3_value_text16
0x18002ead0 sqlite3_value_text16be
0x18002ea90 sqlite3_value_text16le
0x18002eb10 sqlite3_value_type
0x1800c4c6c sqlite3_version
0x180003890 sqlite3_vfs_find
0x180003950 sqlite3_vfs_register
0x180003a30 sqlite3_vfs_unregister
0x180006a70 sqlite3_vmprintf
0x180006b70 sqlite3_vsnprintf
0x180089d00 sqlite3_vtab_collation
0x18007fc80 sqlite3_vtab_config
0x18002fb80 sqlite3_vtab_nochange
0x18007fc60 sqlite3_vtab_on_conflict
0x18009ac60 sqlite3_wal_autocheckpoint
0x18009aea0 sqlite3_wal_checkpoint
0x18009ad60 sqlite3_wal_checkpoint_v2
0x18009acf0 sqlite3_wal_hook
0x1800097a0 sqlite3_win32_is_nt
0x180009b70 sqlite3_win32_mbcs_to_utf8
0x180009ba0 sqlite3_win32_mbcs_to_utf8_v2
0x180009d70 sqlite3_win32_set_directory
0x180009cf0 sqlite3_win32_set_directory16
0x180009c50 sqlite3_win32_set_directory8
0x180009790 sqlite3_win32_sleep
0x180009b40 sqlite3_win32_unicode_to_utf8
0x180009be0 sqlite3_win32_utf8_to_mbcs
0x180009c10 sqlite3_win32_utf8_to_mbcs_v2
0x180009b10 sqlite3_win32_utf8_to_unicode
0x180009700 sqlite3_win32_write_debug


Similarity measure (PE file only) - Checking for service failure