Report - win.txt.exe

UPX PE File DLL PE64
ScreenShot
Created 2024.07.22 14:25 Machine s1_win7_x6402
Filename win.txt.exe
Type PE32+ executable (DLL) (console) x86-64, for MS Windows
AI Score Not founds Behavior Score
1.8
ZERO API file : malware
VT API (file) 2 detected ()
md5 ad49cc932660b3b8ce1460da383b814b
sha256 e1d835e3af9f0cfcc79043be39b8451062c96b7d10e9c88158dc3e426f51264e
ssdeep 196608:Iv0RLExL3w8Hsid3Cf0miLii5pJiCIw4kVLu:oPA8Hl3Cf0BzbrS
imphash 6bb22b5ae424fa0e612e196a871759c5
impfuzzy 48:nlUM39nKmFeFT+2F4I9bnXiX1dvKlQ9GkP1vm/GWqgjJ6:n2M3hKmWTHF4I9bnXiX1hiQ9GklkqgjY
  Network IP location

Signature (6cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice Creates a suspicious process
notice File has been identified by 2 AntiVirus engines on VirusTotal as malicious
info Checks amount of memory in system
info Checks if process is being debugged by a debugger
info One or more processes crashed

Rules (4cnts)

Level Name Description Collection
watch UPX_Zero UPX packed file binaries (upload)
info IsDLL (no description) binaries (upload)
info IsPE64 (no description) binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.dll
 0x1f4cfb41c AddVectoredExceptionHandler
 0x1f4cfb424 CloseHandle
 0x1f4cfb42c CreateEventA
 0x1f4cfb434 CreateSemaphoreA
 0x1f4cfb43c DeleteCriticalSection
 0x1f4cfb444 DuplicateHandle
 0x1f4cfb44c EnterCriticalSection
 0x1f4cfb454 FormatMessageA
 0x1f4cfb45c FreeLibrary
 0x1f4cfb464 GetCurrentProcess
 0x1f4cfb46c GetCurrentProcessId
 0x1f4cfb474 GetCurrentThread
 0x1f4cfb47c GetCurrentThreadId
 0x1f4cfb484 GetHandleInformation
 0x1f4cfb48c GetLastError
 0x1f4cfb494 GetModuleHandleA
 0x1f4cfb49c GetModuleHandleW
 0x1f4cfb4a4 GetProcAddress
 0x1f4cfb4ac GetProcessAffinityMask
 0x1f4cfb4b4 GetSystemTimeAsFileTime
 0x1f4cfb4bc GetThreadContext
 0x1f4cfb4c4 GetThreadPriority
 0x1f4cfb4cc GetTickCount64
 0x1f4cfb4d4 InitializeCriticalSection
 0x1f4cfb4dc IsDBCSLeadByteEx
 0x1f4cfb4e4 IsDebuggerPresent
 0x1f4cfb4ec LeaveCriticalSection
 0x1f4cfb4f4 LoadLibraryA
 0x1f4cfb4fc LoadLibraryW
 0x1f4cfb504 LocalFree
 0x1f4cfb50c MultiByteToWideChar
 0x1f4cfb514 OpenProcess
 0x1f4cfb51c OutputDebugStringA
 0x1f4cfb524 RaiseException
 0x1f4cfb52c ReleaseSemaphore
 0x1f4cfb534 RemoveVectoredExceptionHandler
 0x1f4cfb53c ResetEvent
 0x1f4cfb544 ResumeThread
 0x1f4cfb54c RtlCaptureContext
 0x1f4cfb554 RtlLookupFunctionEntry
 0x1f4cfb55c RtlUnwindEx
 0x1f4cfb564 RtlVirtualUnwind
 0x1f4cfb56c SetEvent
 0x1f4cfb574 SetLastError
 0x1f4cfb57c SetProcessAffinityMask
 0x1f4cfb584 SetThreadContext
 0x1f4cfb58c SetThreadPriority
 0x1f4cfb594 Sleep
 0x1f4cfb59c SuspendThread
 0x1f4cfb5a4 TlsAlloc
 0x1f4cfb5ac TlsGetValue
 0x1f4cfb5b4 TlsSetValue
 0x1f4cfb5bc TryEnterCriticalSection
 0x1f4cfb5c4 VirtualProtect
 0x1f4cfb5cc VirtualQuery
 0x1f4cfb5d4 WaitForMultipleObjects
 0x1f4cfb5dc WaitForSingleObject
 0x1f4cfb5e4 WideCharToMultiByte
 0x1f4cfb5ec __C_specific_handler
msvcrt.dll
 0x1f4cfb5fc ___lc_codepage_func
 0x1f4cfb604 ___mb_cur_max_func
 0x1f4cfb60c __iob_func
 0x1f4cfb614 _amsg_exit
 0x1f4cfb61c _beginthreadex
 0x1f4cfb624 _endthreadex
 0x1f4cfb62c _errno
 0x1f4cfb634 _fstat64
 0x1f4cfb63c _initterm
 0x1f4cfb644 _lock
 0x1f4cfb64c _lseeki64
 0x1f4cfb654 _setjmp
 0x1f4cfb65c _ultoa
 0x1f4cfb664 _unlock
 0x1f4cfb66c _wfopen
 0x1f4cfb674 abort
 0x1f4cfb67c calloc
 0x1f4cfb684 exit
 0x1f4cfb68c fclose
 0x1f4cfb694 fflush
 0x1f4cfb69c fopen
 0x1f4cfb6a4 fprintf
 0x1f4cfb6ac fputc
 0x1f4cfb6b4 fputs
 0x1f4cfb6bc free
 0x1f4cfb6c4 fwrite
 0x1f4cfb6cc getenv
 0x1f4cfb6d4 iswctype
 0x1f4cfb6dc localeconv
 0x1f4cfb6e4 longjmp
 0x1f4cfb6ec malloc
 0x1f4cfb6f4 memchr
 0x1f4cfb6fc memcmp
 0x1f4cfb704 memcpy
 0x1f4cfb70c memmove
 0x1f4cfb714 memset
 0x1f4cfb71c printf
 0x1f4cfb724 realloc
 0x1f4cfb72c setlocale
 0x1f4cfb734 setvbuf
 0x1f4cfb73c signal
 0x1f4cfb744 strchr
 0x1f4cfb74c strcmp
 0x1f4cfb754 strcoll
 0x1f4cfb75c strerror
 0x1f4cfb764 strftime
 0x1f4cfb76c strlen
 0x1f4cfb774 strncmp
 0x1f4cfb77c strtoul
 0x1f4cfb784 strxfrm
 0x1f4cfb78c system
 0x1f4cfb794 towlower
 0x1f4cfb79c towupper
 0x1f4cfb7a4 vfprintf
 0x1f4cfb7ac wcscoll
 0x1f4cfb7b4 wcsftime
 0x1f4cfb7bc wcslen
 0x1f4cfb7c4 wcsxfrm
 0x1f4cfb7cc _write
 0x1f4cfb7d4 _strdup
 0x1f4cfb7dc _read
 0x1f4cfb7e4 _fileno
 0x1f4cfb7ec _fdopen

EAT(Export Address Table) Library

0x1f4c1c090 _GCC_specific_handler
0x1f4c1c410 _Unwind_Backtrace
0x1f4c1c3f0 _Unwind_DeleteException
0x1f4c1c040 _Unwind_FindEnclosingFunction
0x1f4c1c3c0 _Unwind_ForcedUnwind
0x1f4c1bfe0 _Unwind_GetCFA
0x1f4c1c070 _Unwind_GetDataRelBase
0x1f4c1bfa0 _Unwind_GetGR
0x1f4c1bff0 _Unwind_GetIP
0x1f4c1c000 _Unwind_GetIPInfo
0x1f4c1c020 _Unwind_GetLanguageSpecificData
0x1f4c1c030 _Unwind_GetRegionStart
0x1f4c1c080 _Unwind_GetTextRelBase
0x1f4c1c2b0 _Unwind_RaiseException
0x1f4c1c2f0 _Unwind_Resume
0x1f4c1c3a0 _Unwind_Resume_or_Rethrow
0x1f4c1bfc0 _Unwind_SetGR
0x1f4c1c010 _Unwind_SetIP
0x1f4c2c190 _ZN9__gnu_cxx11char_traitsIcE2eqERKcS3_
0x1f4c2c1c0 _ZN9__gnu_cxx11char_traitsIcE6lengthEPKc
0x1f4c89ed0 _ZNSt11char_traitsIcE6lengthEPKc
0x1f4ca3140 _ZNSt15__new_allocatorIcED2Ev
0x1f4cadee0 _ZNSt7__cxx1112basic_stringIcSt11char_traitsIcESaIcEE12_Alloc_hiderD1Ev
0x1f4cae0f0 _ZNSt7__cxx1112basic_stringIcSt11char_traitsIcESaIcEE12_M_constructIPKcEEvT_S8_St20forward_iterator_tag
0x1f4cb1220 _ZNSt7__cxx1112basic_stringIcSt11char_traitsIcESaIcEEC1IS3_EEPKcRKS3_
0x1f4cbc8e0 _ZSt12__str_concatINSt7__cxx1112basic_stringIcSt11char_traitsIcESaIcEEEET_PKNS6_10value_typeENS6_9size_typeES9_SA_RKNS6_14allocator_typeE
0x1f4cbef40 _ZSt23__is_constant_evaluatedv
0x1f4cc1690 _ZStplIcSt11char_traitsIcESaIcEENSt7__cxx1112basic_stringIT_T0_T1_EERKS8_PKS5_
0x1f4cc3950 _ZZNSt7__cxx1112basic_stringIcSt11char_traitsIcESaIcEE12_M_constructIPKcEEvT_S8_St20forward_iterator_tagEN6_GuardC1EPS4_
0x1f4cc3970 _ZZNSt7__cxx1112basic_stringIcSt11char_traitsIcESaIcEE12_M_constructIPKcEEvT_S8_St20forward_iterator_tagEN6_GuardD1Ev
0x1f4c1c620 __emutls_get_address
0x1f4c1c820 __emutls_register_common
0x1f4c28150 __pth_gpointer_locked
0x1f4c25ab0 __pthread_clock_nanosleep
0x1f4c28ba0 __pthread_shallcancel
0x1f4cfd040 __xl_f
0x1f4c28970 _pthread_cleanup_dest
0x1f4c29250 _pthread_get_state
0x1f4c28c50 _pthread_invoke_cancel
0x1f4cf8cb0 _pthread_key_dest
0x1f4c26a10 _pthread_rel_time_in_ms
0x1f4c29260 _pthread_set_state
0x1f4c28c00 _pthread_setnobreak
0x1f4c26990 _pthread_time_in_ms
0x1f4c269e0 _pthread_time_in_ms_from_timespec
0x1f4c29930 _pthread_tryjoin
0x1f4c26b10 _pthread_wait_for_multiple_objects
0x1f4c26a90 _pthread_wait_for_single_object
0x1f4c25980 cond_print
0x1f4c25930 cond_print_set
0x1f4c25ca0 do_sema_b_wait_intern
0x1f4c292a0 pthread_attr_destroy
0x1f4c292e0 pthread_attr_getdetachstate
0x1f4c29320 pthread_attr_getinheritsched
0x1f4c29f90 pthread_attr_getschedparam
0x1f4c29fd0 pthread_attr_getschedpolicy
0x1f4c29360 pthread_attr_getscope
0x1f4c29370 pthread_attr_getstack
0x1f4c293a0 pthread_attr_getstackaddr
0x1f4c293c0 pthread_attr_getstacksize
0x1f4c29280 pthread_attr_init
0x1f4c292b0 pthread_attr_setdetachstate
0x1f4c292f0 pthread_attr_setinheritsched
0x1f4c29f70 pthread_attr_setschedparam
0x1f4c29fb0 pthread_attr_setschedpolicy
0x1f4c29330 pthread_attr_setscope
0x1f4c29390 pthread_attr_setstack
0x1f4c293b0 pthread_attr_setstackaddr
0x1f4c293d0 pthread_attr_setstacksize
0x1f4c28f90 pthread_cancel
0x1f4c26290 pthread_cond_broadcast
0x1f4c25fb0 pthread_cond_destroy
0x1f4c25b70 pthread_cond_init
0x1f4c26160 pthread_cond_signal
0x1f4c26970 pthread_cond_timedwait
0x1f4c26980 pthread_cond_timedwait_relative_np
0x1f4c263c0 pthread_cond_wait
0x1f4c25a10 pthread_condattr_destroy
0x1f4c25a70 pthread_condattr_getclock
0x1f4c25a50 pthread_condattr_getpshared
0x1f4c25a30 pthread_condattr_init
0x1f4c25a90 pthread_condattr_setclock
0x1f4c25b40 pthread_condattr_setpshared
0x1f4c29510 pthread_create
0x1f4c27da0 pthread_create_wrapper
0x1f4c28df0 pthread_delay_np
0x1f4c28f00 pthread_delay_np_ms
0x1f4c29b00 pthread_detach
0x1f4c28960 pthread_equal
0x1f4c28ac0 pthread_exit
0x1f4c28aa0 pthread_get_concurrency
0x1f4c28a60 pthread_getclean
0x1f4c29c50 pthread_getconcurrency
0x1f4c289d0 pthread_getevent
0x1f4c28a10 pthread_gethandle
0x1f4c29da0 pthread_getname_np
0x1f4c29ff0 pthread_getschedparam
0x1f4c287b0 pthread_getspecific
0x1f4c297a0 pthread_join
0x1f4c28540 pthread_key_create
0x1f4c286c0 pthread_key_delete
0x1f4c291b0 pthread_kill
0x1f4c270b0 pthread_mutex_destroy
0x1f4c27060 pthread_mutex_init
0x1f4c26c30 pthread_mutex_lock
0x1f4c26d80 pthread_mutex_timedlock
0x1f4c26fe0 pthread_mutex_trylock
0x1f4c26f20 pthread_mutex_unlock
0x1f4c27100 pthread_mutexattr_destroy
0x1f4c271f0 pthread_mutexattr_getprioceiling
0x1f4c271c0 pthread_mutexattr_getprotocol
0x1f4c27160 pthread_mutexattr_getpshared
0x1f4c27110 pthread_mutexattr_gettype
0x1f4c270f0 pthread_mutexattr_init
0x1f4c27200 pthread_mutexattr_setprioceiling
0x1f4c271d0 pthread_mutexattr_setprotocol
0x1f4c27190 pthread_mutexattr_setpshared
0x1f4c27130 pthread_mutexattr_settype
0x1f4c282d0 pthread_num_processors_np
0x1f4c283c0 pthread_once
0x1f4c2a660 pthread_rwlock_destroy
0x1f4c2a4a0 pthread_rwlock_init
0x1f4c2a7a0 pthread_rwlock_rdlock
0x1f4c2a860 pthread_rwlock_timedrdlock
0x1f4c2acc0 pthread_rwlock_timedwrlock
0x1f4c2a940 pthread_rwlock_tryrdlock
0x1f4c2aa00 pthread_rwlock_trywrlock
0x1f4c2aad0 pthread_rwlock_unlock
0x1f4c2ab80 pthread_rwlock_wrlock
0x1f4c2ae40 pthread_rwlockattr_destroy
0x1f4c2ae70 pthread_rwlockattr_getpshared
0x1f4c2ae50 pthread_rwlockattr_init
0x1f4c2ae90 pthread_rwlockattr_setpshared
0x1f4c28980 pthread_self
0x1f4c28ab0 pthread_set_concurrency
0x1f4c28330 pthread_set_num_processors_np
0x1f4c293e0 pthread_setcancelstate
0x1f4c29470 pthread_setcanceltype
0x1f4c29c60 pthread_setconcurrency
0x1f4c29c70 pthread_setname_np
0x1f4c2a060 pthread_setschedparam
0x1f4c28840 pthread_setspecific
0x1f4c27220 pthread_spin_destroy
0x1f4c27210 pthread_spin_init
0x1f4c27230 pthread_spin_lock
0x1f4c27250 pthread_spin_trylock
0x1f4c27270 pthread_spin_unlock
0x1f4c28d30 pthread_testcancel
0x1f4c282c0 pthread_timechange_handler_np
0x1f4c27580 pthread_tls_init
0x1f4c2a400 rwl_print
0x1f4c2a3f0 rwl_print_set
0x1f4c29f40 sched_get_priority_max
0x1f4c29f10 sched_get_priority_min
0x1f4c2a110 sched_getscheduler
0x1f4c2a180 sched_setscheduler
0x1f4c2a210 sched_yield
0x1f4c281a0 thread_print
0x1f4c28190 thread_print_set


Similarity measure (PE file only) - Checking for service failure