Report - 12333.exe

Generic Malware Malicious Library ASPack UPX DllRegisterServer dll PE File PE32 OS Processor Check DLL
ScreenShot
Created 2024.08.06 09:27 Machine s1_win7_x6401
Filename 12333.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
13
Behavior Score
3.4
ZERO API file : mailcious
VT API (file) 39 detected (AIDetectMalware, Windows, Threat, Malicious, score, Unsafe, Save, Attribute, HighConfidence, FlyStudio, GenericRXAA, Real Protect, high, Generic Reputation PUA, Outbreak, Vilsel, Detected, RA@1qraug, Wacapew, 10ODIJ9, Eldorado, ZexaF, Yq0@aCqZdLmb, BScope, Bitrep, GenAsa, sGm5RiKUik, Dinwod, frindll, CoinMiner, confidence)
md5 2575fb6a535c5b03e282ed92151513ac
sha256 40cce677c34ca65bf3b860289766a10a70d996552bf3a3aa5e0eb707e241068e
ssdeep 12288:94dck9P+e+2eLZIiyDNYmSOcDS/lZ/zNg9xAX:94dc4PP+GiKNtSOcDS/lhJg9A
imphash 8e72be5e0890acbcbc6724ee3164e9b1
impfuzzy 192:K7PJM0gCe1UqT0E4zGxtsBPcRc2caKSZtQCC:4MVTTAED9C
  Network IP location

Signature (8cnts)

Level Description
danger File has been identified by 39 AntiVirus engines on VirusTotal as malicious
notice Allocates read-write-execute memory (usually to unpack itself)
notice Creates executable files on the filesystem
notice Drops an executable to the user AppData folder
notice Foreign language identified in PE resource
notice The binary likely contains encrypted or compressed data indicative of a packer
info The executable uses a known packer
info The file contains an unknown PE resource name possibly indicative of a packer

Rules (11cnts)

Level Name Description Collection
warning Generic_Malware_Zero Generic Malware binaries (upload)
watch ASPack_Zero ASPack packed file binaries (upload)
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info DllRegisterServer_Zero execute regsvr32.exe binaries (upload)
info IsDLL (no description) binaries (download)
info IsPE32 (no description) binaries (download)
info IsPE32 (no description) binaries (upload)
info OS_Processor_Check_Zero OS Processor Check binaries (upload)
info PE_Header_Zero PE File Signature binaries (download)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

KERNEL32.dll
 0x47f190 SetEndOfFile
 0x47f194 UnlockFile
 0x47f198 LockFile
 0x47f19c FlushFileBuffers
 0x47f1a0 SetFilePointer
 0x47f1a4 GetCurrentProcess
 0x47f1a8 DuplicateHandle
 0x47f1ac lstrcpynA
 0x47f1b0 SetLastError
 0x47f1b4 FileTimeToLocalFileTime
 0x47f1b8 FileTimeToSystemTime
 0x47f1bc LocalFree
 0x47f1c0 InterlockedDecrement
 0x47f1c4 CreateSemaphoreA
 0x47f1c8 ResumeThread
 0x47f1cc ReleaseSemaphore
 0x47f1d0 EnterCriticalSection
 0x47f1d4 LeaveCriticalSection
 0x47f1d8 GetProfileStringA
 0x47f1dc SetStdHandle
 0x47f1e0 IsBadCodePtr
 0x47f1e4 IsBadReadPtr
 0x47f1e8 CompareStringW
 0x47f1ec CompareStringA
 0x47f1f0 SetUnhandledExceptionFilter
 0x47f1f4 GetStringTypeW
 0x47f1f8 GetStringTypeA
 0x47f1fc IsBadWritePtr
 0x47f200 VirtualAlloc
 0x47f204 LCMapStringW
 0x47f208 LCMapStringA
 0x47f20c SetEnvironmentVariableA
 0x47f210 VirtualFree
 0x47f214 HeapCreate
 0x47f218 HeapDestroy
 0x47f21c GetEnvironmentVariableA
 0x47f220 GetFileType
 0x47f224 GetStdHandle
 0x47f228 SetHandleCount
 0x47f22c GetEnvironmentStringsW
 0x47f230 GetEnvironmentStrings
 0x47f234 FreeEnvironmentStringsW
 0x47f238 FreeEnvironmentStringsA
 0x47f23c UnhandledExceptionFilter
 0x47f240 GetACP
 0x47f244 HeapSize
 0x47f248 TerminateProcess
 0x47f24c GetLocalTime
 0x47f250 GetSystemTime
 0x47f254 GetTimeZoneInformation
 0x47f258 WriteFile
 0x47f25c WaitForMultipleObjects
 0x47f260 CreateFileA
 0x47f264 SetEvent
 0x47f268 FindResourceA
 0x47f26c LoadResource
 0x47f270 LockResource
 0x47f274 ReadFile
 0x47f278 GetModuleFileNameA
 0x47f27c WideCharToMultiByte
 0x47f280 MultiByteToWideChar
 0x47f284 GetCurrentThreadId
 0x47f288 ExitProcess
 0x47f28c GlobalSize
 0x47f290 GlobalFree
 0x47f294 DeleteCriticalSection
 0x47f298 InitializeCriticalSection
 0x47f29c lstrcatA
 0x47f2a0 lstrlenA
 0x47f2a4 WinExec
 0x47f2a8 lstrcpyA
 0x47f2ac FindNextFileA
 0x47f2b0 GlobalReAlloc
 0x47f2b4 HeapFree
 0x47f2b8 HeapReAlloc
 0x47f2bc GetProcessHeap
 0x47f2c0 HeapAlloc
 0x47f2c4 GetFullPathNameA
 0x47f2c8 FreeLibrary
 0x47f2cc LoadLibraryA
 0x47f2d0 GetLastError
 0x47f2d4 GetVersionExA
 0x47f2d8 WritePrivateProfileStringA
 0x47f2dc CreateThread
 0x47f2e0 CreateEventA
 0x47f2e4 Sleep
 0x47f2e8 GlobalAlloc
 0x47f2ec GlobalLock
 0x47f2f0 GlobalUnlock
 0x47f2f4 FindFirstFileA
 0x47f2f8 FindClose
 0x47f2fc GetFileAttributesA
 0x47f300 RaiseException
 0x47f304 RtlUnwind
 0x47f308 GetStartupInfoA
 0x47f30c GetOEMCP
 0x47f310 GetCPInfo
 0x47f314 GetProcessVersion
 0x47f318 SetErrorMode
 0x47f31c GlobalFlags
 0x47f320 GetCurrentThread
 0x47f324 GetFileTime
 0x47f328 GetFileSize
 0x47f32c TlsGetValue
 0x47f330 LocalReAlloc
 0x47f334 TlsSetValue
 0x47f338 TlsFree
 0x47f33c GlobalHandle
 0x47f340 TlsAlloc
 0x47f344 LocalAlloc
 0x47f348 SetCurrentDirectoryA
 0x47f34c GetVolumeInformationA
 0x47f350 GetModuleHandleA
 0x47f354 GetProcAddress
 0x47f358 MulDiv
 0x47f35c lstrcmpA
 0x47f360 GetVersion
 0x47f364 GlobalGetAtomNameA
 0x47f368 GlobalAddAtomA
 0x47f36c GlobalFindAtomA
 0x47f370 GlobalDeleteAtom
 0x47f374 lstrcmpiA
 0x47f378 GetCommandLineA
 0x47f37c GetTickCount
 0x47f380 WaitForSingleObject
 0x47f384 CloseHandle
 0x47f388 InterlockedIncrement
USER32.dll
 0x47f3ac OpenClipboard
 0x47f3b0 SetClipboardData
 0x47f3b4 EmptyClipboard
 0x47f3b8 GetSystemMetrics
 0x47f3bc GetCursorPos
 0x47f3c0 MessageBoxA
 0x47f3c4 SetWindowPos
 0x47f3c8 SendMessageA
 0x47f3cc DestroyCursor
 0x47f3d0 SetParent
 0x47f3d4 GetClipboardData
 0x47f3d8 PostMessageA
 0x47f3dc GetTopWindow
 0x47f3e0 GetParent
 0x47f3e4 CloseClipboard
 0x47f3e8 wsprintfA
 0x47f3ec GetFocus
 0x47f3f0 GetClientRect
 0x47f3f4 InvalidateRect
 0x47f3f8 ValidateRect
 0x47f3fc UpdateWindow
 0x47f400 EqualRect
 0x47f404 GetWindowRect
 0x47f408 SetForegroundWindow
 0x47f40c IsWindow
 0x47f410 GetMenuItemCount
 0x47f414 DestroyMenu
 0x47f418 IsChild
 0x47f41c ReleaseDC
 0x47f420 ScrollDC
 0x47f424 IsRectEmpty
 0x47f428 InvertRect
 0x47f42c FillRect
 0x47f430 GetDC
 0x47f434 SetCursor
 0x47f438 LoadCursorA
 0x47f43c SetCursorPos
 0x47f440 SetActiveWindow
 0x47f444 GetSysColor
 0x47f448 SetWindowLongA
 0x47f44c GetWindowLongA
 0x47f450 RedrawWindow
 0x47f454 EnableWindow
 0x47f458 IsWindowVisible
 0x47f45c OffsetRect
 0x47f460 PtInRect
 0x47f464 DestroyIcon
 0x47f468 IntersectRect
 0x47f46c InflateRect
 0x47f470 SetRect
 0x47f474 SetScrollPos
 0x47f478 SetScrollRange
 0x47f47c GetScrollRange
 0x47f480 SetCapture
 0x47f484 GetCapture
 0x47f488 ReleaseCapture
 0x47f48c LoadIconA
 0x47f490 TranslateMessage
 0x47f494 DrawFrameControl
 0x47f498 DrawEdge
 0x47f49c DrawFocusRect
 0x47f4a0 WindowFromPoint
 0x47f4a4 GetMessageA
 0x47f4a8 DispatchMessageA
 0x47f4ac SetRectEmpty
 0x47f4b0 RegisterClipboardFormatA
 0x47f4b4 CreateIconFromResourceEx
 0x47f4b8 CreateIconFromResource
 0x47f4bc DrawIconEx
 0x47f4c0 CreatePopupMenu
 0x47f4c4 AppendMenuA
 0x47f4c8 ModifyMenuA
 0x47f4cc CreateMenu
 0x47f4d0 CreateAcceleratorTableA
 0x47f4d4 GetDlgCtrlID
 0x47f4d8 GetSubMenu
 0x47f4dc EnableMenuItem
 0x47f4e0 ClientToScreen
 0x47f4e4 EnumDisplaySettingsA
 0x47f4e8 LoadImageA
 0x47f4ec SystemParametersInfoA
 0x47f4f0 ShowWindow
 0x47f4f4 IsWindowEnabled
 0x47f4f8 TranslateAcceleratorA
 0x47f4fc GetKeyState
 0x47f500 CopyAcceleratorTableA
 0x47f504 PostQuitMessage
 0x47f508 IsZoomed
 0x47f50c GetClassInfoA
 0x47f510 DefWindowProcA
 0x47f514 GetSystemMenu
 0x47f518 DeleteMenu
 0x47f51c GetMenu
 0x47f520 SetMenu
 0x47f524 PeekMessageA
 0x47f528 GetWindowTextA
 0x47f52c GetWindowTextLengthA
 0x47f530 CharUpperA
 0x47f534 GetWindowDC
 0x47f538 BeginPaint
 0x47f53c EndPaint
 0x47f540 TabbedTextOutA
 0x47f544 DrawTextA
 0x47f548 GrayStringA
 0x47f54c GetDlgItem
 0x47f550 DestroyWindow
 0x47f554 CreateDialogIndirectParamA
 0x47f558 EndDialog
 0x47f55c GetNextDlgTabItem
 0x47f560 GetWindowPlacement
 0x47f564 RegisterWindowMessageA
 0x47f568 GetForegroundWindow
 0x47f56c GetLastActivePopup
 0x47f570 GetMessageTime
 0x47f574 RemovePropA
 0x47f578 CallWindowProcA
 0x47f57c GetPropA
 0x47f580 UnhookWindowsHookEx
 0x47f584 SetPropA
 0x47f588 GetClassLongA
 0x47f58c CallNextHookEx
 0x47f590 SetWindowsHookExA
 0x47f594 CreateWindowExA
 0x47f598 GetMenuItemID
 0x47f59c UnregisterClassA
 0x47f5a0 RegisterClassA
 0x47f5a4 GetScrollPos
 0x47f5a8 AdjustWindowRectEx
 0x47f5ac MapWindowPoints
 0x47f5b0 SendDlgItemMessageA
 0x47f5b4 ScrollWindowEx
 0x47f5b8 IsDialogMessageA
 0x47f5bc SetWindowTextA
 0x47f5c0 MoveWindow
 0x47f5c4 CheckMenuItem
 0x47f5c8 SetMenuItemBitmaps
 0x47f5cc GetMenuState
 0x47f5d0 GetMenuCheckMarkDimensions
 0x47f5d4 GetClassNameA
 0x47f5d8 GetDesktopWindow
 0x47f5dc LoadStringA
 0x47f5e0 GetSysColorBrush
 0x47f5e4 IsIconic
 0x47f5e8 SetFocus
 0x47f5ec GetActiveWindow
 0x47f5f0 GetWindow
 0x47f5f4 DestroyAcceleratorTable
 0x47f5f8 SetWindowRgn
 0x47f5fc GetMessagePos
 0x47f600 ScreenToClient
 0x47f604 ChildWindowFromPointEx
 0x47f608 CopyRect
 0x47f60c LoadBitmapA
 0x47f610 WinHelpA
 0x47f614 KillTimer
 0x47f618 SetTimer
GDI32.dll
 0x47f024 SelectClipRgn
 0x47f028 DeleteObject
 0x47f02c CreateDIBitmap
 0x47f030 GetSystemPaletteEntries
 0x47f034 CreatePalette
 0x47f038 StretchBlt
 0x47f03c SelectPalette
 0x47f040 RealizePalette
 0x47f044 GetDIBits
 0x47f048 GetWindowExtEx
 0x47f04c GetViewportOrgEx
 0x47f050 GetWindowOrgEx
 0x47f054 BeginPath
 0x47f058 EndPath
 0x47f05c PathToRegion
 0x47f060 CreateEllipticRgn
 0x47f064 CreateRoundRectRgn
 0x47f068 GetTextColor
 0x47f06c GetBkMode
 0x47f070 GetBkColor
 0x47f074 GetROP2
 0x47f078 GetStretchBltMode
 0x47f07c GetPolyFillMode
 0x47f080 CreateCompatibleBitmap
 0x47f084 CreateDCA
 0x47f088 CreateBrushIndirect
 0x47f08c CreateHatchBrush
 0x47f090 CreateBitmap
 0x47f094 CreatePatternBrush
 0x47f098 SelectObject
 0x47f09c GetObjectA
 0x47f0a0 CreatePen
 0x47f0a4 PatBlt
 0x47f0a8 CombineRgn
 0x47f0ac CreateRectRgn
 0x47f0b0 CreatePolygonRgn
 0x47f0b4 CreateSolidBrush
 0x47f0b8 GetStockObject
 0x47f0bc CreateFontIndirectA
 0x47f0c0 EndPage
 0x47f0c4 EndDoc
 0x47f0c8 DeleteDC
 0x47f0cc StartDocA
 0x47f0d0 StartPage
 0x47f0d4 BitBlt
 0x47f0d8 CreateCompatibleDC
 0x47f0dc SetPixelV
 0x47f0e0 Ellipse
 0x47f0e4 Rectangle
 0x47f0e8 LPtoDP
 0x47f0ec DPtoLP
 0x47f0f0 GetCurrentObject
 0x47f0f4 RoundRect
 0x47f0f8 Pie
 0x47f0fc Chord
 0x47f100 Arc
 0x47f104 Polygon
 0x47f108 GetTextExtentPoint32A
 0x47f10c GetDeviceCaps
 0x47f110 SaveDC
 0x47f114 RestoreDC
 0x47f118 SetBkMode
 0x47f11c SetPolyFillMode
 0x47f120 SetROP2
 0x47f124 SetTextColor
 0x47f128 SetMapMode
 0x47f12c SetViewportOrgEx
 0x47f130 OffsetViewportOrgEx
 0x47f134 SetViewportExtEx
 0x47f138 ScaleViewportExtEx
 0x47f13c SetWindowOrgEx
 0x47f140 SetWindowExtEx
 0x47f144 ScaleWindowExtEx
 0x47f148 GetClipBox
 0x47f14c ExcludeClipRect
 0x47f150 MoveToEx
 0x47f154 LineTo
 0x47f158 GetClipRgn
 0x47f15c SetStretchBltMode
 0x47f160 CreateRectRgnIndirect
 0x47f164 SetBkColor
 0x47f168 FillRgn
 0x47f16c GetTextMetricsA
 0x47f170 Escape
 0x47f174 ExtTextOutA
 0x47f178 TextOutA
 0x47f17c RectVisible
 0x47f180 PtVisible
 0x47f184 GetViewportExtEx
 0x47f188 ExtSelectClipRgn
WINMM.dll
 0x47f620 midiStreamRestart
 0x47f624 midiStreamClose
 0x47f628 midiOutReset
 0x47f62c midiStreamStop
 0x47f630 midiStreamOut
 0x47f634 midiOutPrepareHeader
 0x47f638 midiStreamProperty
 0x47f63c midiStreamOpen
 0x47f640 midiOutUnprepareHeader
 0x47f644 waveOutOpen
 0x47f648 waveOutGetNumDevs
 0x47f64c waveOutClose
 0x47f650 waveOutReset
 0x47f654 waveOutPause
 0x47f658 waveOutWrite
 0x47f65c waveOutPrepareHeader
 0x47f660 waveOutUnprepareHeader
WINSPOOL.DRV
 0x47f668 ClosePrinter
 0x47f66c DocumentPropertiesA
 0x47f670 OpenPrinterA
ADVAPI32.dll
 0x47f000 RegCloseKey
 0x47f004 RegOpenKeyExA
 0x47f008 RegSetValueExA
 0x47f00c RegQueryValueA
 0x47f010 RegCreateKeyExA
SHELL32.dll
 0x47f3a0 ShellExecuteA
 0x47f3a4 Shell_NotifyIconA
ole32.dll
 0x47f6b4 OleInitialize
 0x47f6b8 OleUninitialize
 0x47f6bc CLSIDFromString
OLEAUT32.dll
 0x47f390 UnRegisterTypeLib
 0x47f394 RegisterTypeLib
 0x47f398 LoadTypeLib
COMCTL32.dll
 0x47f018 ImageList_Destroy
 0x47f01c None
WS2_32.dll
 0x47f678 recvfrom
 0x47f67c ioctlsocket
 0x47f680 recv
 0x47f684 getpeername
 0x47f688 accept
 0x47f68c WSAAsyncSelect
 0x47f690 closesocket
 0x47f694 inet_ntoa
 0x47f698 WSACleanup
comdlg32.dll
 0x47f6a0 GetSaveFileNameA
 0x47f6a4 GetOpenFileNameA
 0x47f6a8 ChooseColorA
 0x47f6ac GetFileTitleA

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure