Report - TMS_C024.exe

Malicious Library UPX PE File DllRegisterServer dll PE32 MZP Format
ScreenShot
Created 2024.08.19 15:40 Machine s1_win7_x6403
Filename TMS_C024.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
1
Behavior Score
1.8
ZERO API file : mailcious
VT API (file) 9 detected (Midie, malicious, ai score=83)
md5 b8df4ec39884a6248d88482299a55744
sha256 e0be0617c7760b88ed5bf00e0b4931c8f11ce8fca34edc36b460f9ba1640031d
ssdeep 49152:smorAiZlgFBlnPJOjRHPmXPDKAFjjdjjA/YiY0Y0Y0Y0YI:smocfnlP2uKAFjjdjjA/YiY0Y0Y0Y0YI
imphash c0b84a4062daea7e8ade24b9710b5f1c
impfuzzy 192:f3JuG1Glc0FGeuuEaSUvK9ugoaqTB+57sPbOQad9:f3Z1q/Ez9YPpPbOQc
  Network IP location

Signature (6cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice File has been identified by 9 AntiVirus engines on VirusTotal as malicious
notice Foreign language identified in PE resource
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The executable uses a known packer

Rules (6cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info DllRegisterServer_Zero execute regsvr32.exe binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x5da190 DeleteCriticalSection
 0x5da194 LeaveCriticalSection
 0x5da198 EnterCriticalSection
 0x5da19c InitializeCriticalSection
 0x5da1a0 VirtualFree
 0x5da1a4 VirtualAlloc
 0x5da1a8 LocalFree
 0x5da1ac LocalAlloc
 0x5da1b0 GetVersion
 0x5da1b4 GetCurrentThreadId
 0x5da1b8 InterlockedDecrement
 0x5da1bc InterlockedIncrement
 0x5da1c0 VirtualQuery
 0x5da1c4 WideCharToMultiByte
 0x5da1c8 MultiByteToWideChar
 0x5da1cc lstrlenA
 0x5da1d0 lstrcpynA
 0x5da1d4 LoadLibraryExA
 0x5da1d8 GetThreadLocale
 0x5da1dc GetStartupInfoA
 0x5da1e0 GetProcAddress
 0x5da1e4 GetModuleHandleA
 0x5da1e8 GetModuleFileNameA
 0x5da1ec GetLocaleInfoA
 0x5da1f0 GetCommandLineA
 0x5da1f4 FreeLibrary
 0x5da1f8 FindFirstFileA
 0x5da1fc FindClose
 0x5da200 ExitProcess
 0x5da204 ExitThread
 0x5da208 CreateThread
 0x5da20c WriteFile
 0x5da210 UnhandledExceptionFilter
 0x5da214 RtlUnwind
 0x5da218 RaiseException
 0x5da21c GetStdHandle
user32.dll
 0x5da224 GetKeyboardType
 0x5da228 LoadStringA
 0x5da22c MessageBoxA
 0x5da230 CharNextA
advapi32.dll
 0x5da238 RegQueryValueExA
 0x5da23c RegOpenKeyExA
 0x5da240 RegCloseKey
oleaut32.dll
 0x5da248 SysFreeString
 0x5da24c SysReAllocStringLen
 0x5da250 SysAllocStringLen
kernel32.dll
 0x5da258 TlsSetValue
 0x5da25c TlsGetValue
 0x5da260 LocalAlloc
 0x5da264 GetModuleHandleA
advapi32.dll
 0x5da26c RegSetValueExA
 0x5da270 RegQueryValueExA
 0x5da274 RegQueryValueA
 0x5da278 RegOpenKeyExA
 0x5da27c RegFlushKey
 0x5da280 RegCreateKeyExA
 0x5da284 RegCloseKey
kernel32.dll
 0x5da28c lstrcpyA
 0x5da290 lstrcmpA
 0x5da294 WriteFile
 0x5da298 WaitForSingleObject
 0x5da29c VirtualQuery
 0x5da2a0 VirtualAlloc
 0x5da2a4 Sleep
 0x5da2a8 SizeofResource
 0x5da2ac SetThreadLocale
 0x5da2b0 SetFilePointer
 0x5da2b4 SetEvent
 0x5da2b8 SetErrorMode
 0x5da2bc SetEndOfFile
 0x5da2c0 ResumeThread
 0x5da2c4 ResetEvent
 0x5da2c8 ReleaseMutex
 0x5da2cc ReadFile
 0x5da2d0 MultiByteToWideChar
 0x5da2d4 MulDiv
 0x5da2d8 LockResource
 0x5da2dc LoadResource
 0x5da2e0 LoadLibraryA
 0x5da2e4 LeaveCriticalSection
 0x5da2e8 IsBadReadPtr
 0x5da2ec InitializeCriticalSection
 0x5da2f0 GlobalUnlock
 0x5da2f4 GlobalSize
 0x5da2f8 GlobalReAlloc
 0x5da2fc GlobalHandle
 0x5da300 GlobalLock
 0x5da304 GlobalFree
 0x5da308 GlobalFindAtomA
 0x5da30c GlobalDeleteAtom
 0x5da310 GlobalAlloc
 0x5da314 GlobalAddAtomA
 0x5da318 GetVersionExA
 0x5da31c GetVersion
 0x5da320 GetTimeZoneInformation
 0x5da324 GetTickCount
 0x5da328 GetThreadLocale
 0x5da32c GetTempPathA
 0x5da330 GetSystemInfo
 0x5da334 GetStringTypeExA
 0x5da338 GetStdHandle
 0x5da33c GetProcAddress
 0x5da340 GetModuleHandleA
 0x5da344 GetModuleFileNameA
 0x5da348 GetLocaleInfoA
 0x5da34c GetLocalTime
 0x5da350 GetLastError
 0x5da354 GetFullPathNameA
 0x5da358 GetFileSize
 0x5da35c GetExitCodeThread
 0x5da360 GetDiskFreeSpaceA
 0x5da364 GetDateFormatA
 0x5da368 GetCurrentThreadId
 0x5da36c GetCurrentProcessId
 0x5da370 GetCPInfo
 0x5da374 GetACP
 0x5da378 FreeResource
 0x5da37c InterlockedIncrement
 0x5da380 InterlockedExchange
 0x5da384 InterlockedDecrement
 0x5da388 FreeLibrary
 0x5da38c FormatMessageA
 0x5da390 FindResourceA
 0x5da394 FindFirstFileA
 0x5da398 FindClose
 0x5da39c FileTimeToLocalFileTime
 0x5da3a0 FileTimeToDosDateTime
 0x5da3a4 EnumCalendarInfoA
 0x5da3a8 EnterCriticalSection
 0x5da3ac DeleteCriticalSection
 0x5da3b0 CreateThread
 0x5da3b4 CreateMutexA
 0x5da3b8 CreateFileA
 0x5da3bc CreateEventA
 0x5da3c0 CompareStringA
 0x5da3c4 CloseHandle
version.dll
 0x5da3cc VerQueryValueA
 0x5da3d0 GetFileVersionInfoSizeA
 0x5da3d4 GetFileVersionInfoA
gdi32.dll
 0x5da3dc UnrealizeObject
 0x5da3e0 StretchBlt
 0x5da3e4 SetWindowOrgEx
 0x5da3e8 SetWindowExtEx
 0x5da3ec SetWinMetaFileBits
 0x5da3f0 SetViewportOrgEx
 0x5da3f4 SetViewportExtEx
 0x5da3f8 SetTextColor
 0x5da3fc SetStretchBltMode
 0x5da400 SetROP2
 0x5da404 SetPixel
 0x5da408 SetMapMode
 0x5da40c SetEnhMetaFileBits
 0x5da410 SetDIBColorTable
 0x5da414 SetBrushOrgEx
 0x5da418 SetBkMode
 0x5da41c SetBkColor
 0x5da420 SelectPalette
 0x5da424 SelectObject
 0x5da428 SelectClipRgn
 0x5da42c SaveDC
 0x5da430 RoundRect
 0x5da434 RestoreDC
 0x5da438 Rectangle
 0x5da43c RectVisible
 0x5da440 RealizePalette
 0x5da444 Polyline
 0x5da448 Polygon
 0x5da44c PolyPolyline
 0x5da450 PlayEnhMetaFile
 0x5da454 PatBlt
 0x5da458 MoveToEx
 0x5da45c MaskBlt
 0x5da460 LineTo
 0x5da464 LPtoDP
 0x5da468 IntersectClipRect
 0x5da46c GetWindowOrgEx
 0x5da470 GetWinMetaFileBits
 0x5da474 GetViewportOrgEx
 0x5da478 GetTextMetricsA
 0x5da47c GetTextExtentPointA
 0x5da480 GetTextExtentPoint32A
 0x5da484 GetSystemPaletteEntries
 0x5da488 GetStockObject
 0x5da48c GetPixel
 0x5da490 GetPaletteEntries
 0x5da494 GetOutlineTextMetricsA
 0x5da498 GetObjectA
 0x5da49c GetNearestColor
 0x5da4a0 GetEnhMetaFilePaletteEntries
 0x5da4a4 GetEnhMetaFileHeader
 0x5da4a8 GetEnhMetaFileBits
 0x5da4ac GetDeviceCaps
 0x5da4b0 GetDIBits
 0x5da4b4 GetDIBColorTable
 0x5da4b8 GetDCOrgEx
 0x5da4bc GetCurrentPositionEx
 0x5da4c0 GetCurrentObject
 0x5da4c4 GetClipRgn
 0x5da4c8 GetClipBox
 0x5da4cc GetBrushOrgEx
 0x5da4d0 GetBitmapBits
 0x5da4d4 GdiFlush
 0x5da4d8 ExtTextOutA
 0x5da4dc ExtSelectClipRgn
 0x5da4e0 ExtCreateRegion
 0x5da4e4 ExtCreatePen
 0x5da4e8 ExcludeClipRect
 0x5da4ec Ellipse
 0x5da4f0 DeleteObject
 0x5da4f4 DeleteEnhMetaFile
 0x5da4f8 DeleteDC
 0x5da4fc CreateSolidBrush
 0x5da500 CreateRectRgn
 0x5da504 CreatePolygonRgn
 0x5da508 CreatePenIndirect
 0x5da50c CreatePen
 0x5da510 CreatePalette
 0x5da514 CreateHalftonePalette
 0x5da518 CreateFontIndirectA
 0x5da51c CreateDIBitmap
 0x5da520 CreateDIBSection
 0x5da524 CreateCompatibleDC
 0x5da528 CreateCompatibleBitmap
 0x5da52c CreateBrushIndirect
 0x5da530 CreateBitmap
 0x5da534 CopyEnhMetaFileA
 0x5da538 CombineRgn
 0x5da53c BitBlt
user32.dll
 0x5da544 CreateWindowExA
 0x5da548 WindowFromPoint
 0x5da54c WinHelpA
 0x5da550 WaitMessage
 0x5da554 ValidateRect
 0x5da558 UpdateWindow
 0x5da55c UnregisterClassA
 0x5da560 UnionRect
 0x5da564 UnhookWindowsHookEx
 0x5da568 TranslateMessage
 0x5da56c TranslateMDISysAccel
 0x5da570 TrackPopupMenu
 0x5da574 SystemParametersInfoA
 0x5da578 ShowWindow
 0x5da57c ShowScrollBar
 0x5da580 ShowOwnedPopups
 0x5da584 ShowCursor
 0x5da588 ShowCaret
 0x5da58c SetWindowRgn
 0x5da590 SetWindowsHookExA
 0x5da594 SetWindowTextA
 0x5da598 SetWindowPos
 0x5da59c SetWindowPlacement
 0x5da5a0 SetWindowLongW
 0x5da5a4 SetWindowLongA
 0x5da5a8 SetTimer
 0x5da5ac SetScrollRange
 0x5da5b0 SetScrollPos
 0x5da5b4 SetScrollInfo
 0x5da5b8 SetRect
 0x5da5bc SetPropA
 0x5da5c0 SetParent
 0x5da5c4 SetMenuItemInfoA
 0x5da5c8 SetMenu
 0x5da5cc SetKeyboardState
 0x5da5d0 SetForegroundWindow
 0x5da5d4 SetFocus
 0x5da5d8 SetCursor
 0x5da5dc SetClipboardData
 0x5da5e0 SetClassLongA
 0x5da5e4 SetCaretPos
 0x5da5e8 SetCapture
 0x5da5ec SetActiveWindow
 0x5da5f0 SendMessageA
 0x5da5f4 ScrollWindowEx
 0x5da5f8 ScrollWindow
 0x5da5fc ScreenToClient
 0x5da600 RemovePropA
 0x5da604 RemoveMenu
 0x5da608 ReleaseDC
 0x5da60c ReleaseCapture
 0x5da610 RegisterWindowMessageA
 0x5da614 RegisterClipboardFormatA
 0x5da618 RegisterClassA
 0x5da61c RedrawWindow
 0x5da620 PtInRect
 0x5da624 PostQuitMessage
 0x5da628 PostMessageA
 0x5da62c PeekMessageA
 0x5da630 OpenClipboard
 0x5da634 OffsetRect
 0x5da638 OemToCharA
 0x5da63c MsgWaitForMultipleObjects
 0x5da640 MoveWindow
 0x5da644 MessageBoxA
 0x5da648 MessageBeep
 0x5da64c MapWindowPoints
 0x5da650 MapVirtualKeyA
 0x5da654 LoadStringA
 0x5da658 LoadKeyboardLayoutA
 0x5da65c LoadIconA
 0x5da660 LoadCursorA
 0x5da664 LoadBitmapA
 0x5da668 KillTimer
 0x5da66c IsZoomed
 0x5da670 IsWindowVisible
 0x5da674 IsWindowUnicode
 0x5da678 IsWindowEnabled
 0x5da67c IsWindow
 0x5da680 IsRectEmpty
 0x5da684 IsIconic
 0x5da688 IsDialogMessageA
 0x5da68c IsClipboardFormatAvailable
 0x5da690 IsChild
 0x5da694 IsCharAlphaNumericA
 0x5da698 IsCharAlphaA
 0x5da69c InvalidateRect
 0x5da6a0 IntersectRect
 0x5da6a4 InsertMenuItemA
 0x5da6a8 InsertMenuA
 0x5da6ac InflateRect
 0x5da6b0 HideCaret
 0x5da6b4 GetWindowThreadProcessId
 0x5da6b8 GetWindowTextLengthW
 0x5da6bc GetWindowTextW
 0x5da6c0 GetWindowTextA
 0x5da6c4 GetWindowRect
 0x5da6c8 GetWindowPlacement
 0x5da6cc GetWindowLongW
 0x5da6d0 GetWindowLongA
 0x5da6d4 GetWindowDC
 0x5da6d8 GetTopWindow
 0x5da6dc GetSystemMetrics
 0x5da6e0 GetSystemMenu
 0x5da6e4 GetSysColorBrush
 0x5da6e8 GetSysColor
 0x5da6ec GetSubMenu
 0x5da6f0 GetScrollRange
 0x5da6f4 GetScrollPos
 0x5da6f8 GetScrollInfo
 0x5da6fc GetPropA
 0x5da700 GetParent
 0x5da704 GetWindow
 0x5da708 GetMessageTime
 0x5da70c GetMenuStringA
 0x5da710 GetMenuState
 0x5da714 GetMenuItemInfoA
 0x5da718 GetMenuItemID
 0x5da71c GetMenuItemCount
 0x5da720 GetMenu
 0x5da724 GetLastActivePopup
 0x5da728 GetKeyboardState
 0x5da72c GetKeyboardLayoutList
 0x5da730 GetKeyboardLayout
 0x5da734 GetKeyState
 0x5da738 GetKeyNameTextA
 0x5da73c GetIconInfo
 0x5da740 GetForegroundWindow
 0x5da744 GetFocus
 0x5da748 GetDoubleClickTime
 0x5da74c GetDlgItem
 0x5da750 GetDlgCtrlID
 0x5da754 GetDesktopWindow
 0x5da758 GetDCEx
 0x5da75c GetDC
 0x5da760 GetCursorPos
 0x5da764 GetCursor
 0x5da768 GetClipboardData
 0x5da76c GetClientRect
 0x5da770 GetClassNameA
 0x5da774 GetClassInfoA
 0x5da778 GetCaretPos
 0x5da77c GetCapture
 0x5da780 GetActiveWindow
 0x5da784 FrameRect
 0x5da788 FindWindowExA
 0x5da78c FindWindowA
 0x5da790 FillRect
 0x5da794 EqualRect
 0x5da798 EnumWindows
 0x5da79c EnumThreadWindows
 0x5da7a0 EnumClipboardFormats
 0x5da7a4 EndPaint
 0x5da7a8 EnableWindow
 0x5da7ac EnableScrollBar
 0x5da7b0 EnableMenuItem
 0x5da7b4 EmptyClipboard
 0x5da7b8 DrawTextExA
 0x5da7bc DrawTextW
 0x5da7c0 DrawTextA
 0x5da7c4 DrawMenuBar
 0x5da7c8 DrawIconEx
 0x5da7cc DrawIcon
 0x5da7d0 DrawFrameControl
 0x5da7d4 DrawFocusRect
 0x5da7d8 DrawEdge
 0x5da7dc DispatchMessageA
 0x5da7e0 DestroyWindow
 0x5da7e4 DestroyMenu
 0x5da7e8 DestroyIcon
 0x5da7ec DestroyCursor
 0x5da7f0 DestroyCaret
 0x5da7f4 DeleteMenu
 0x5da7f8 DefWindowProcA
 0x5da7fc DefMDIChildProcA
 0x5da800 DefFrameProcA
 0x5da804 CreatePopupMenu
 0x5da808 CreateMenu
 0x5da80c CreateIcon
 0x5da810 CreateCaret
 0x5da814 CopyImage
 0x5da818 CloseClipboard
 0x5da81c ClientToScreen
 0x5da820 CheckMenuItem
 0x5da824 CallWindowProcA
 0x5da828 CallNextHookEx
 0x5da82c BeginPaint
 0x5da830 CharNextA
 0x5da834 CharLowerBuffA
 0x5da838 CharLowerA
 0x5da83c CharUpperBuffA
 0x5da840 CharToOemA
 0x5da844 AdjustWindowRectEx
 0x5da848 ActivateKeyboardLayout
ole32.dll
 0x5da850 CoTaskMemFree
 0x5da854 StringFromCLSID
kernel32.dll
 0x5da85c Sleep
oleaut32.dll
 0x5da864 SafeArrayPtrOfIndex
 0x5da868 SafeArrayPutElement
 0x5da86c SafeArrayGetElement
 0x5da870 SafeArrayUnaccessData
 0x5da874 SafeArrayAccessData
 0x5da878 SafeArrayGetUBound
 0x5da87c SafeArrayGetLBound
 0x5da880 SafeArrayRedim
 0x5da884 SafeArrayCreate
 0x5da888 VariantChangeType
 0x5da88c VariantCopyInd
 0x5da890 VariantCopy
 0x5da894 VariantClear
 0x5da898 VariantInit
ole32.dll
 0x5da8a0 CoCreateInstance
 0x5da8a4 CoGetMalloc
 0x5da8a8 CoUninitialize
 0x5da8ac CoInitialize
 0x5da8b0 IsEqualGUID
oleaut32.dll
 0x5da8b8 CreateErrorInfo
 0x5da8bc GetErrorInfo
 0x5da8c0 SetErrorInfo
 0x5da8c4 SafeArrayCopy
 0x5da8c8 SafeArrayUnaccessData
 0x5da8cc SafeArrayAccessData
 0x5da8d0 SafeArrayGetUBound
 0x5da8d4 SafeArrayDestroy
 0x5da8d8 SafeArrayCreate
 0x5da8dc SysFreeString
comctl32.dll
 0x5da8e4 ImageList_SetIconSize
 0x5da8e8 ImageList_GetIconSize
 0x5da8ec ImageList_Write
 0x5da8f0 ImageList_Read
 0x5da8f4 ImageList_GetDragImage
 0x5da8f8 ImageList_DragShowNolock
 0x5da8fc ImageList_SetDragCursorImage
 0x5da900 ImageList_DragMove
 0x5da904 ImageList_DragLeave
 0x5da908 ImageList_DragEnter
 0x5da90c ImageList_EndDrag
 0x5da910 ImageList_BeginDrag
 0x5da914 ImageList_LoadImageA
 0x5da918 ImageList_Remove
 0x5da91c ImageList_DrawEx
 0x5da920 ImageList_Replace
 0x5da924 ImageList_Draw
 0x5da928 ImageList_GetBkColor
 0x5da92c ImageList_SetBkColor
 0x5da930 ImageList_ReplaceIcon
 0x5da934 ImageList_Add
 0x5da938 ImageList_GetImageCount
 0x5da93c ImageList_Destroy
 0x5da940 ImageList_Create
 0x5da944 InitCommonControls
comdlg32.dll
 0x5da94c GetSaveFileNameA
 0x5da950 GetOpenFileNameA
kernel32.dll
 0x5da958 MulDiv
kernel32.dll
 0x5da960 MulDiv

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure