Report - TMS_C153.exe

Malicious Library UPX PE File DllRegisterServer dll PE32 MZP Format
ScreenShot
Created 2024.08.19 15:24 Machine s1_win7_x6401
Filename TMS_C153.exe
Type PE32 executable (GUI) Intel 80386, for MS Windows
AI Score
1
Behavior Score
1.8
ZERO API file : clean
VT API (file) 3 detected (AIDetectMalware, Malicious, susgen)
md5 1ce9a063972f6f5266b78f7be6365fd6
sha256 01cc833f1667363611254017eb3a754c08770413bf6884053b48144fc58439d0
ssdeep 24576:mJiuBoABwMwBJ7GnWh05DO+giIF77k4xWWCEfFl31JmiPdliznrCWzg4PD:mzoIwtJphkg5fmfrCoPD
imphash 0678c51977f5c507f9b52d566924c096
impfuzzy 192:f3zOG1Glc03meuuEaSUvK9ugoaqTBD57CPbOQadn:f3P1q9Ez9YPcPbOQM
  Network IP location

Signature (6cnts)

Level Description
notice Allocates read-write-execute memory (usually to unpack itself)
notice File has been identified by 3 AntiVirus engines on VirusTotal as malicious
notice Foreign language identified in PE resource
info One or more processes crashed
info The executable contains unknown PE section names indicative of a packer (could be a false positive)
info The executable uses a known packer

Rules (6cnts)

Level Name Description Collection
watch Malicious_Library_Zero Malicious_Library binaries (upload)
watch UPX_Zero UPX packed file binaries (upload)
info DllRegisterServer_Zero execute regsvr32.exe binaries (upload)
info IsPE32 (no description) binaries (upload)
info mzp_file_format MZP(Delphi) file format binaries (upload)
info PE_Header_Zero PE File Signature binaries (upload)

Network (0cnts) ?

Request CC ASN Co IP4 Rule ? ZERO ?

Suricata ids

PE API

IAT(Import Address Table) Library

kernel32.dll
 0x55d17c DeleteCriticalSection
 0x55d180 LeaveCriticalSection
 0x55d184 EnterCriticalSection
 0x55d188 InitializeCriticalSection
 0x55d18c VirtualFree
 0x55d190 VirtualAlloc
 0x55d194 LocalFree
 0x55d198 LocalAlloc
 0x55d19c GetVersion
 0x55d1a0 GetCurrentThreadId
 0x55d1a4 InterlockedDecrement
 0x55d1a8 InterlockedIncrement
 0x55d1ac VirtualQuery
 0x55d1b0 WideCharToMultiByte
 0x55d1b4 MultiByteToWideChar
 0x55d1b8 lstrlenA
 0x55d1bc lstrcpynA
 0x55d1c0 LoadLibraryExA
 0x55d1c4 GetThreadLocale
 0x55d1c8 GetStartupInfoA
 0x55d1cc GetProcAddress
 0x55d1d0 GetModuleHandleA
 0x55d1d4 GetModuleFileNameA
 0x55d1d8 GetLocaleInfoA
 0x55d1dc GetCommandLineA
 0x55d1e0 FreeLibrary
 0x55d1e4 FindFirstFileA
 0x55d1e8 FindClose
 0x55d1ec ExitProcess
 0x55d1f0 ExitThread
 0x55d1f4 CreateThread
 0x55d1f8 WriteFile
 0x55d1fc UnhandledExceptionFilter
 0x55d200 RtlUnwind
 0x55d204 RaiseException
 0x55d208 GetStdHandle
user32.dll
 0x55d210 GetKeyboardType
 0x55d214 LoadStringA
 0x55d218 MessageBoxA
 0x55d21c CharNextA
advapi32.dll
 0x55d224 RegQueryValueExA
 0x55d228 RegOpenKeyExA
 0x55d22c RegCloseKey
oleaut32.dll
 0x55d234 SysFreeString
 0x55d238 SysReAllocStringLen
 0x55d23c SysAllocStringLen
kernel32.dll
 0x55d244 TlsSetValue
 0x55d248 TlsGetValue
 0x55d24c LocalAlloc
 0x55d250 GetModuleHandleA
advapi32.dll
 0x55d258 RegSetValueExA
 0x55d25c RegQueryValueExA
 0x55d260 RegQueryValueA
 0x55d264 RegOpenKeyExA
 0x55d268 RegFlushKey
 0x55d26c RegCreateKeyExA
 0x55d270 RegCloseKey
kernel32.dll
 0x55d278 lstrcpyA
 0x55d27c WriteFile
 0x55d280 WaitForSingleObject
 0x55d284 VirtualQuery
 0x55d288 VirtualAlloc
 0x55d28c Sleep
 0x55d290 SizeofResource
 0x55d294 SetThreadLocale
 0x55d298 SetFilePointer
 0x55d29c SetEvent
 0x55d2a0 SetErrorMode
 0x55d2a4 SetEndOfFile
 0x55d2a8 ResumeThread
 0x55d2ac ResetEvent
 0x55d2b0 ReleaseMutex
 0x55d2b4 ReadFile
 0x55d2b8 MultiByteToWideChar
 0x55d2bc MulDiv
 0x55d2c0 LockResource
 0x55d2c4 LoadResource
 0x55d2c8 LoadLibraryA
 0x55d2cc LeaveCriticalSection
 0x55d2d0 IsBadReadPtr
 0x55d2d4 InitializeCriticalSection
 0x55d2d8 GlobalUnlock
 0x55d2dc GlobalReAlloc
 0x55d2e0 GlobalHandle
 0x55d2e4 GlobalLock
 0x55d2e8 GlobalFree
 0x55d2ec GlobalFindAtomA
 0x55d2f0 GlobalDeleteAtom
 0x55d2f4 GlobalAlloc
 0x55d2f8 GlobalAddAtomA
 0x55d2fc GetVersionExA
 0x55d300 GetVersion
 0x55d304 GetTimeZoneInformation
 0x55d308 GetTickCount
 0x55d30c GetThreadLocale
 0x55d310 GetTempPathA
 0x55d314 GetSystemInfo
 0x55d318 GetStringTypeExA
 0x55d31c GetStdHandle
 0x55d320 GetProcAddress
 0x55d324 GetModuleHandleA
 0x55d328 GetModuleFileNameA
 0x55d32c GetLocaleInfoA
 0x55d330 GetLocalTime
 0x55d334 GetLastError
 0x55d338 GetFullPathNameA
 0x55d33c GetFileSize
 0x55d340 GetExitCodeThread
 0x55d344 GetDiskFreeSpaceA
 0x55d348 GetDateFormatA
 0x55d34c GetCurrentThreadId
 0x55d350 GetCurrentProcessId
 0x55d354 GetCPInfo
 0x55d358 GetACP
 0x55d35c FreeResource
 0x55d360 InterlockedIncrement
 0x55d364 InterlockedExchange
 0x55d368 InterlockedDecrement
 0x55d36c FreeLibrary
 0x55d370 FormatMessageA
 0x55d374 FindResourceA
 0x55d378 FindFirstFileA
 0x55d37c FindClose
 0x55d380 FileTimeToLocalFileTime
 0x55d384 FileTimeToDosDateTime
 0x55d388 EnumCalendarInfoA
 0x55d38c EnterCriticalSection
 0x55d390 DeleteCriticalSection
 0x55d394 CreateThread
 0x55d398 CreateMutexA
 0x55d39c CreateFileA
 0x55d3a0 CreateEventA
 0x55d3a4 CompareStringA
 0x55d3a8 CloseHandle
version.dll
 0x55d3b0 VerQueryValueA
 0x55d3b4 GetFileVersionInfoSizeA
 0x55d3b8 GetFileVersionInfoA
gdi32.dll
 0x55d3c0 UnrealizeObject
 0x55d3c4 StretchBlt
 0x55d3c8 SetWindowOrgEx
 0x55d3cc SetWindowExtEx
 0x55d3d0 SetWinMetaFileBits
 0x55d3d4 SetViewportOrgEx
 0x55d3d8 SetViewportExtEx
 0x55d3dc SetTextColor
 0x55d3e0 SetStretchBltMode
 0x55d3e4 SetROP2
 0x55d3e8 SetPixel
 0x55d3ec SetMapMode
 0x55d3f0 SetEnhMetaFileBits
 0x55d3f4 SetDIBColorTable
 0x55d3f8 SetBrushOrgEx
 0x55d3fc SetBkMode
 0x55d400 SetBkColor
 0x55d404 SelectPalette
 0x55d408 SelectObject
 0x55d40c SelectClipRgn
 0x55d410 SaveDC
 0x55d414 RoundRect
 0x55d418 RestoreDC
 0x55d41c Rectangle
 0x55d420 RectVisible
 0x55d424 RealizePalette
 0x55d428 Polyline
 0x55d42c Polygon
 0x55d430 PolyPolyline
 0x55d434 PlayEnhMetaFile
 0x55d438 PatBlt
 0x55d43c MoveToEx
 0x55d440 MaskBlt
 0x55d444 LineTo
 0x55d448 IntersectClipRect
 0x55d44c GetWindowOrgEx
 0x55d450 GetWinMetaFileBits
 0x55d454 GetViewportOrgEx
 0x55d458 GetTextMetricsA
 0x55d45c GetTextExtentPointA
 0x55d460 GetTextExtentPoint32A
 0x55d464 GetSystemPaletteEntries
 0x55d468 GetStockObject
 0x55d46c GetPixel
 0x55d470 GetPaletteEntries
 0x55d474 GetObjectA
 0x55d478 GetEnhMetaFilePaletteEntries
 0x55d47c GetEnhMetaFileHeader
 0x55d480 GetEnhMetaFileBits
 0x55d484 GetDeviceCaps
 0x55d488 GetDIBits
 0x55d48c GetDIBColorTable
 0x55d490 GetDCOrgEx
 0x55d494 GetCurrentPositionEx
 0x55d498 GetCurrentObject
 0x55d49c GetClipBox
 0x55d4a0 GetBrushOrgEx
 0x55d4a4 GetBitmapBits
 0x55d4a8 GdiFlush
 0x55d4ac ExtTextOutA
 0x55d4b0 ExtCreateRegion
 0x55d4b4 ExtCreatePen
 0x55d4b8 ExcludeClipRect
 0x55d4bc DeleteObject
 0x55d4c0 DeleteEnhMetaFile
 0x55d4c4 DeleteDC
 0x55d4c8 CreateSolidBrush
 0x55d4cc CreateRectRgn
 0x55d4d0 CreatePenIndirect
 0x55d4d4 CreatePen
 0x55d4d8 CreatePalette
 0x55d4dc CreateHalftonePalette
 0x55d4e0 CreateFontIndirectA
 0x55d4e4 CreateDIBitmap
 0x55d4e8 CreateDIBSection
 0x55d4ec CreateCompatibleDC
 0x55d4f0 CreateCompatibleBitmap
 0x55d4f4 CreateBrushIndirect
 0x55d4f8 CreateBitmap
 0x55d4fc CopyEnhMetaFileA
 0x55d500 CombineRgn
 0x55d504 BitBlt
user32.dll
 0x55d50c CreateWindowExA
 0x55d510 WindowFromPoint
 0x55d514 WinHelpA
 0x55d518 WaitMessage
 0x55d51c ValidateRect
 0x55d520 UpdateWindow
 0x55d524 UnregisterClassA
 0x55d528 UnionRect
 0x55d52c UnhookWindowsHookEx
 0x55d530 TranslateMessage
 0x55d534 TranslateMDISysAccel
 0x55d538 TrackPopupMenu
 0x55d53c SystemParametersInfoA
 0x55d540 ShowWindow
 0x55d544 ShowScrollBar
 0x55d548 ShowOwnedPopups
 0x55d54c ShowCursor
 0x55d550 ShowCaret
 0x55d554 SetWindowRgn
 0x55d558 SetWindowsHookExA
 0x55d55c SetWindowTextA
 0x55d560 SetWindowPos
 0x55d564 SetWindowPlacement
 0x55d568 SetWindowLongW
 0x55d56c SetWindowLongA
 0x55d570 SetTimer
 0x55d574 SetScrollRange
 0x55d578 SetScrollPos
 0x55d57c SetScrollInfo
 0x55d580 SetRect
 0x55d584 SetPropA
 0x55d588 SetParent
 0x55d58c SetMenuItemInfoA
 0x55d590 SetMenu
 0x55d594 SetKeyboardState
 0x55d598 SetForegroundWindow
 0x55d59c SetFocus
 0x55d5a0 SetCursor
 0x55d5a4 SetClipboardData
 0x55d5a8 SetClassLongA
 0x55d5ac SetCaretPos
 0x55d5b0 SetCapture
 0x55d5b4 SetActiveWindow
 0x55d5b8 SendMessageA
 0x55d5bc ScrollWindowEx
 0x55d5c0 ScrollWindow
 0x55d5c4 ScreenToClient
 0x55d5c8 RemovePropA
 0x55d5cc RemoveMenu
 0x55d5d0 ReleaseDC
 0x55d5d4 ReleaseCapture
 0x55d5d8 RegisterWindowMessageA
 0x55d5dc RegisterClipboardFormatA
 0x55d5e0 RegisterClassA
 0x55d5e4 RedrawWindow
 0x55d5e8 PtInRect
 0x55d5ec PostQuitMessage
 0x55d5f0 PostMessageA
 0x55d5f4 PeekMessageA
 0x55d5f8 OpenClipboard
 0x55d5fc OffsetRect
 0x55d600 OemToCharA
 0x55d604 MsgWaitForMultipleObjects
 0x55d608 MoveWindow
 0x55d60c MessageBoxA
 0x55d610 MessageBeep
 0x55d614 MapWindowPoints
 0x55d618 MapVirtualKeyA
 0x55d61c LoadStringA
 0x55d620 LoadKeyboardLayoutA
 0x55d624 LoadIconA
 0x55d628 LoadCursorA
 0x55d62c LoadBitmapA
 0x55d630 KillTimer
 0x55d634 IsZoomed
 0x55d638 IsWindowVisible
 0x55d63c IsWindowUnicode
 0x55d640 IsWindowEnabled
 0x55d644 IsWindow
 0x55d648 IsRectEmpty
 0x55d64c IsIconic
 0x55d650 IsDialogMessageA
 0x55d654 IsClipboardFormatAvailable
 0x55d658 IsChild
 0x55d65c IsCharAlphaNumericA
 0x55d660 IsCharAlphaA
 0x55d664 InvalidateRect
 0x55d668 IntersectRect
 0x55d66c InsertMenuItemA
 0x55d670 InsertMenuA
 0x55d674 InflateRect
 0x55d678 HideCaret
 0x55d67c GetWindowThreadProcessId
 0x55d680 GetWindowTextLengthW
 0x55d684 GetWindowTextW
 0x55d688 GetWindowTextA
 0x55d68c GetWindowRect
 0x55d690 GetWindowPlacement
 0x55d694 GetWindowLongW
 0x55d698 GetWindowLongA
 0x55d69c GetWindowDC
 0x55d6a0 GetTopWindow
 0x55d6a4 GetSystemMetrics
 0x55d6a8 GetSystemMenu
 0x55d6ac GetSysColorBrush
 0x55d6b0 GetSysColor
 0x55d6b4 GetSubMenu
 0x55d6b8 GetScrollRange
 0x55d6bc GetScrollPos
 0x55d6c0 GetScrollInfo
 0x55d6c4 GetPropA
 0x55d6c8 GetParent
 0x55d6cc GetWindow
 0x55d6d0 GetMessageTime
 0x55d6d4 GetMenuStringA
 0x55d6d8 GetMenuState
 0x55d6dc GetMenuItemInfoA
 0x55d6e0 GetMenuItemID
 0x55d6e4 GetMenuItemCount
 0x55d6e8 GetMenu
 0x55d6ec GetLastActivePopup
 0x55d6f0 GetKeyboardState
 0x55d6f4 GetKeyboardLayoutList
 0x55d6f8 GetKeyboardLayout
 0x55d6fc GetKeyState
 0x55d700 GetKeyNameTextA
 0x55d704 GetIconInfo
 0x55d708 GetForegroundWindow
 0x55d70c GetFocus
 0x55d710 GetDoubleClickTime
 0x55d714 GetDlgItem
 0x55d718 GetDlgCtrlID
 0x55d71c GetDesktopWindow
 0x55d720 GetDCEx
 0x55d724 GetDC
 0x55d728 GetCursorPos
 0x55d72c GetCursor
 0x55d730 GetClipboardData
 0x55d734 GetClientRect
 0x55d738 GetClassNameA
 0x55d73c GetClassInfoA
 0x55d740 GetCaretPos
 0x55d744 GetCapture
 0x55d748 GetActiveWindow
 0x55d74c FrameRect
 0x55d750 FindWindowExA
 0x55d754 FindWindowA
 0x55d758 FillRect
 0x55d75c EqualRect
 0x55d760 EnumWindows
 0x55d764 EnumThreadWindows
 0x55d768 EnumClipboardFormats
 0x55d76c EndPaint
 0x55d770 EnableWindow
 0x55d774 EnableScrollBar
 0x55d778 EnableMenuItem
 0x55d77c EmptyClipboard
 0x55d780 DrawTextW
 0x55d784 DrawTextA
 0x55d788 DrawMenuBar
 0x55d78c DrawIconEx
 0x55d790 DrawIcon
 0x55d794 DrawFrameControl
 0x55d798 DrawFocusRect
 0x55d79c DrawEdge
 0x55d7a0 DispatchMessageA
 0x55d7a4 DestroyWindow
 0x55d7a8 DestroyMenu
 0x55d7ac DestroyIcon
 0x55d7b0 DestroyCursor
 0x55d7b4 DestroyCaret
 0x55d7b8 DeleteMenu
 0x55d7bc DefWindowProcA
 0x55d7c0 DefMDIChildProcA
 0x55d7c4 DefFrameProcA
 0x55d7c8 CreatePopupMenu
 0x55d7cc CreateMenu
 0x55d7d0 CreateIcon
 0x55d7d4 CreateCaret
 0x55d7d8 CopyImage
 0x55d7dc CloseClipboard
 0x55d7e0 ClientToScreen
 0x55d7e4 CheckMenuItem
 0x55d7e8 CallWindowProcA
 0x55d7ec CallNextHookEx
 0x55d7f0 BeginPaint
 0x55d7f4 CharNextA
 0x55d7f8 CharLowerBuffA
 0x55d7fc CharLowerA
 0x55d800 CharUpperBuffA
 0x55d804 CharToOemA
 0x55d808 AdjustWindowRectEx
 0x55d80c ActivateKeyboardLayout
ole32.dll
 0x55d814 CoTaskMemFree
 0x55d818 StringFromCLSID
kernel32.dll
 0x55d820 Sleep
oleaut32.dll
 0x55d828 SafeArrayPtrOfIndex
 0x55d82c SafeArrayPutElement
 0x55d830 SafeArrayGetElement
 0x55d834 SafeArrayUnaccessData
 0x55d838 SafeArrayAccessData
 0x55d83c SafeArrayGetUBound
 0x55d840 SafeArrayGetLBound
 0x55d844 SafeArrayCreate
 0x55d848 VariantChangeType
 0x55d84c VariantCopyInd
 0x55d850 VariantCopy
 0x55d854 VariantClear
 0x55d858 VariantInit
ole32.dll
 0x55d860 CoCreateInstance
 0x55d864 CoGetMalloc
 0x55d868 CoUninitialize
 0x55d86c CoInitialize
 0x55d870 IsEqualGUID
oleaut32.dll
 0x55d878 CreateErrorInfo
 0x55d87c GetErrorInfo
 0x55d880 SetErrorInfo
 0x55d884 SafeArrayCopy
 0x55d888 SafeArrayUnaccessData
 0x55d88c SafeArrayAccessData
 0x55d890 SafeArrayGetUBound
 0x55d894 SafeArrayDestroy
 0x55d898 SafeArrayCreate
 0x55d89c SysFreeString
comctl32.dll
 0x55d8a4 ImageList_SetIconSize
 0x55d8a8 ImageList_GetIconSize
 0x55d8ac ImageList_Write
 0x55d8b0 ImageList_Read
 0x55d8b4 ImageList_GetDragImage
 0x55d8b8 ImageList_DragShowNolock
 0x55d8bc ImageList_SetDragCursorImage
 0x55d8c0 ImageList_DragMove
 0x55d8c4 ImageList_DragLeave
 0x55d8c8 ImageList_DragEnter
 0x55d8cc ImageList_EndDrag
 0x55d8d0 ImageList_BeginDrag
 0x55d8d4 ImageList_LoadImageA
 0x55d8d8 ImageList_Remove
 0x55d8dc ImageList_DrawEx
 0x55d8e0 ImageList_Draw
 0x55d8e4 ImageList_GetBkColor
 0x55d8e8 ImageList_SetBkColor
 0x55d8ec ImageList_ReplaceIcon
 0x55d8f0 ImageList_Add
 0x55d8f4 ImageList_GetImageCount
 0x55d8f8 ImageList_Destroy
 0x55d8fc ImageList_Create
 0x55d900 InitCommonControls
comdlg32.dll
 0x55d908 GetSaveFileNameA
 0x55d90c GetOpenFileNameA
kernel32.dll
 0x55d914 MulDiv

EAT(Export Address Table) is none



Similarity measure (PE file only) - Checking for service failure